Third-Party Risk,
Managed Properly
The FCA expects regulated firms to manage third-party risk with the same rigour they apply to internal operations. My Supplier List provides the structured supplier assessment, continuous monitoring, and audit trail that financial services compliance teams need to satisfy regulatory expectations.
Why Financial Services Firms Need Structured Third-Party Management
The Financial Conduct Authority's supervisory statement SS2/21 on outsourcing and third-party risk management made it clear that regulated firms cannot outsource their regulatory obligations. When a bank, insurer, or asset manager relies on a third party to deliver a critical or important function, the FCA holds the regulated firm responsible for the outcome. The PRA's expectations under SS2/21 require firms to maintain a register of all outsourcing and third-party arrangements, assess concentration risk, and have documented exit strategies for critical suppliers.
Operational resilience requirements, which came fully into force in March 2025, add another layer. Firms must identify their important business services, set impact tolerances, and demonstrate that they can remain within those tolerances during severe but plausible disruption scenarios — including the failure of a critical third-party supplier. This requires not just knowing who your suppliers are, but understanding the dependencies between them, the services they support, and the risks they introduce to your operational resilience framework.
My Supplier List provides the structured assessment and continuous monitoring framework that financial services compliance teams need. Every supplier is assessed across five risk pillars: Financial health (including CCJ checks and credit monitoring), Compliance status, Operational capability, Cyber risk posture, and ESG commitments. For critical and important suppliers, the platform supports enhanced due diligence workflows with deeper assessment questionnaires, more frequent review cycles, and automated alerts when risk indicators change.
The platform's contract management module tracks key contractual terms including termination provisions, service level agreements, and data processing arrangements — giving your compliance and procurement teams a single view of every third-party relationship along with the documentation regulators expect to see during supervisory visits.
Designed for Regulated Firms
Capabilities aligned to FCA and PRA expectations for third-party risk management and operational resilience.
5-Pillar Risk Assessment
Structured risk scoring across Financial, Compliance, Operational, Cyber, and ESG dimensions. Configurable weightings for critical vs non-critical suppliers. CCJ and credit health checks integrated.
Enhanced Due Diligence
Tiered assessment workflows. Standard due diligence for routine suppliers, enhanced due diligence for critical and important functions, with deeper questionnaires and more frequent review cycles.
Contract & Exit Planning
Track contractual terms, termination provisions, and service levels. Document exit strategies and transition plans for critical suppliers as required by SS2/21.
Financial Health Monitoring
Monitor supplier financial health with CCJ checks, credit score tracking, and early warning indicators. Identify concentration risk across your third-party portfolio.
Regulatory Reporting
Generate the third-party risk reports that boards and regulators expect. Outsourcing registers, risk dashboards, and audit trail documentation for supervisory visits.
Anti-Money Laundering Checks
Compliance packs covering Bribery Act 2010, money laundering regulations, sanctions screening, and politically exposed person (PEP) checks for your supplier onboarding process.
Regulatory Framework Alignment
FCA/PRA SS2/21 — Outsourcing and Third-Party Risk
Maintain a register of all outsourcing arrangements. Assess concentration risk. Document exit strategies for critical suppliers. Conduct proportionate due diligence on all third parties.
Operational Resilience (PS21/3)
Identify important business services, map third-party dependencies, and set impact tolerances. The platform tracks which suppliers support which services and flags resilience risks.
Senior Managers & Certification Regime (SM&CR)
Senior managers are personally accountable for third-party risk management. The platform provides the audit trail and reporting that demonstrates reasonable steps have been taken.
UK GDPR & Data Protection Act 2018
Track data processing agreements, assess processor compliance, and maintain records of processing activities across your third-party supply chain as required by Article 30.
Ready for Your Next Supervisory Visit?
See how regulated firms use My Supplier List to demonstrate robust third-party risk management to the FCA and PRA.