SS2/21 Outsourcing: The PRA Register and Notification Guide

SS2/21 is the PRA’s supervisory statement on outsourcing and third-party risk management. Its main scope covers UK banks, building societies and PRA-designated investment firms; insurance and reinsurance firms and groups in scope of Solvency II, including Lloyd’s and managing agents; and UK branches of overseas banks and insurers. It has been the working reference for outsourcing teams since 31 March 2022, and it is now on the move: on 18 March 2027 an updated version takes effect alongside a new package of reporting rules in policy statement PS7/26. Get SS2/21 outsourcing compliance wrong and the failure shows up in two places the PRA watches closely, the notification you owe before you sign and the records you must be able to produce on request.

SS2/21 sets out PRA supervisory expectations rather than creating rules itself. For banks, the principal binding sources include the Notifications and Outsourcing Parts of the PRA Rulebook and Articles 30-32 of Commission Delegated Regulation (EU) 2017/565 as it forms part of UK law. For insurers, the principal outsourcing requirements include the Notifications and Conditions Governing Business Parts of the PRA Rulebook. Third-country branches are also subject to the relevant branch-governance provisions. SS2/21 explains how the PRA expects firms to comply with those requirements and adds detailed expectations on matters including data security and stressed exits.

Related reading: our guide to the DORA Register of Information, the EU concept that UK teams most often confuse with the SS2/21 Outsourcing Register.

The dates that anchor SS2/21 outsourcing compliance

Outsourcing work is deadline-shaped, so it helps to see the calendar in one place. These are the operative dates that frame the current regime and the next.

  • 31 March 2021: outsourcing arrangements entered into on or after this date were expected to meet SS2/21 in full by the following year.
  • 31 December 2021: the point from which the EBA Outsourcing Guidelines expect banks to hold an up-to-date register of all outsourcing arrangements, the Outsourcing Register, which subsumed the older Cloud Register.
  • 31 March 2022: the compliance date for SS2/21. Legacy agreements signed before 31 March 2021 were to be reviewed and updated at the first appropriate renewal or revision point.
  • 12 November 2024: the PRA, FCA and Bank of England published PS16/24 (FCA PS24/16), the final rules for the critical third parties oversight regime, effective 1 January 2025 but only biting once HM Treasury designates a firm.
  • 13 December 2024: the PRA opened CP17/24 on operational incident and outsourcing and third-party reporting, the consultation that became PS7/26.
  • March 2026: PS7/26 was published, with an updated SS2/21, giving firms a twelve-month preparation window.
  • 18 March 2027: PS7/26 and the updated SS2/21 take effect, introducing a structured material third-party register submitted to the regulator, a standardised notification template, and operational incident reporting.

The rest of this guide separates the current framework from the rules effective on 18 March 2027. Firms should not assume that every arrangement signed in 2026 belongs in the future return: the PRA Register will cover material third-party arrangements for in-scope entities, subject to the reporting exclusions in the updated SS2/21. The FCA will notify firms when the annual submission window opens.

Who the statement binds, and the arrangements it reaches

SS2/21 applies to UK banks, building societies and PRA-designated investment firms, to insurers and groups in scope of Solvency II including the Society of Lloyd’s and managing agents, and to UK branches of overseas banks and insurers. Credit unions and non-directive firms sit largely outside the detailed expectations, but a defined subset still applies to them, including the notification requirement in Notifications 2.3(1)(e) and the record-keeping and information-gathering provisions.

The definition of outsourcing is the gate to most of the requirements. The PRA Rulebook defines it as an arrangement under which a service provider performs a process, service or activity that the firm would otherwise carry out itself, whether directly or by sub-outsourcing. That definition derives from Article 2(3) of the retained MiFID Org Regulation. The test the PRA applies is whether the third party performs the function on a recurrent or ongoing basis.

Here is the trap that catches teams first: assuming that an arrangement outside the outsourcing definition is outside the regime. It is not that simple. SS2/21 defines a separate category of non-outsourcing third-party arrangements, and it expects firms to assess the materiality and risk of every third-party arrangement regardless of whether it meets the outsourcing definition. Where a non-outsourcing arrangement is material or high risk, the PRA expects controls as strong as those that would apply to an outsourcing arrangement of equivalent materiality. A material data-broker feed or an off-the-shelf machine-learning model can sit outside the outsourcing definition and still demand the same governance.

The PRA also identifies requirements that apply to all third-party arrangements regardless of classification: Fundamental Rules 2, 3, 5, 6 and 7; for relevant individuals, the Conduct Rules and Senior Manager Conduct Rules or insurance equivalents; the applicable business-continuity and data-protection requirements; and the Operational Resilience Parts. Certain arrangements among regulated firms, such as clearing, settlement and custody, fall outside outsourcing but carry their own regulatory requirements and stay subject to these baseline expectations.

Materiality: the test that drives every downstream duty

Almost every obligation in SS2/21 is switched on by one classification decision, whether an arrangement is material. The PRA Rulebook defines material outsourcing as the outsourcing of services so important that their weakness or failure would cast serious doubt on the firm’s continuing satisfaction of the Threshold Conditions or compliance with the Fundamental Rules. SS2/21 treats material outsourcing as encompassing the retained-law concept of a critical or important operational function, using the single term material to avoid parallel labels.

Some arrangements are effectively material on their face. SS2/21 expects a firm to treat an arrangement as material where a defect could materially impair UK financial stability, the firm’s ability to meet the Threshold Conditions or Fundamental Rules, or its financial or operational resilience. It also expects material classification where the outsourced service involves an entire regulated activity such as portfolio management, or an internal control or key function, unless the firm is satisfied that a failure would not affect that function. Beyond those, the statement lists further criteria to weigh, from ICT and reputational risk to data-confidentiality impact, substitutability, and the cost of bringing the service back in-house.

Materiality and proportionality are separate but complementary. Materiality assesses the potential impact of an outsourcing or third-party arrangement on the individual firm, including its safety and soundness, operational resilience and ability to comply with legal and regulatory obligations. Proportionality concerns how the firm meets SS2/21 in light of its size, organisation, activities and systemic significance. A smaller firm can still have a material arrangement, but the materiality assessment remains firm-specific; both materiality and proportionality can change over time and should be reassessed.

For firms that also read the EU rulebook, this is the same discipline that runs through DORA resilience testing for smaller firms, where proportionality shapes the method without removing the obligation.

Materiality is not a one-time stamp. SS2/21 expects reassessment before signing, at review points, when a firm scales up its use of a service, and when a significant change at the provider alters the risk. An arrangement that starts non-material can cross the line.

Notifying the PRA before you sign

Notifications 2.3(1)(e) requires every PRA-regulated firm, credit unions and non-directive firms included, to notify the PRA when entering into or significantly changing a material outsourcing arrangement. The timing expectation is the part teams underestimate. The PRA expects the notification before the firm enters the arrangement, and it expects a notification before a previously non-material arrangement is planned to become material. The regulator weighs the timeliness of these notifications when it assesses compliance with Fundamental Rule 7, the open-and-cooperative duty.

SS2/21 expects a material-outsourcing notification to include at least the information listed in paragraph 54 of the EBA Outsourcing Guidelines. Mapping the submission to that paragraph provides a practical completeness check before filing.

A common error is to read the notification as a post-signature formality, a note filed once the deal is done. Filed late, it undercuts the very purpose of the duty, which is to give the PRA a window to ask questions, request additional information, or expect the firm to enhance its due diligence before it commits. In some cases a notification is expected before a final provider is even chosen, for example during a major migration when the firm is still shortlisting.

Two practical points round this out. Notifications 2.3(1)(e) is limited to material outsourcing, but a material non-outsourcing third-party arrangement may still be information of which the PRA would reasonably expect notice under Fundamental Rule 7 and Senior Manager Conduct Standard 4, so the PRA expects firms to bring those to its attention in a similar way. And a UK consolidated group entering a single material outsourcing arrangement that covers multiple firms may be able to make one notification, provided it lists every firm that will receive the service.

The Outsourcing Register, and why “register of information” means two different things

SS2/21 expects all firms to keep appropriate records of their outsourcing arrangements. From 31 December 2021 the EBA Outsourcing Guidelines expect banks to maintain an up-to-date register of all outsourcing arrangements, distinguishing material from non-material, known as the Outsourcing Register. That register absorbed the earlier Cloud Register. The PRA’s view is that a firm complying with the notification requirement would already hold records of its material outsourcing, and those records should also be good enough to support the concentration-risk expectations in the statement.

The UK and EU regimes use different records. Under current SS2/21, all firms keep appropriate outsourcing records, while banks maintain an Outsourcing Register covering all outsourcing arrangements and distinguishing material from non-material arrangements. The PRA may request outsourcing data. Under DORA Article 28, in-scope EU financial entities maintain and update a Register of Information at entity, sub-consolidated and consolidated levels for all contractual arrangements on the use of ICT services.

DORA Article 28(3) requires at least annual reporting of specified summary information and requires the full Register, or requested sections, to be made available to the competent authority on request. The Register uses the standard templates in Commission Implementing Regulation (EU) 2024/2956. A group with both UK and EU regulated entities may therefore need separate UK and DORA datasets with overlapping fields but different scopes and submission mechanics. Our DORA Register of Information guide sets out the EU side in full.

Concentration risk is the reason the register earns its keep instead of sitting as a compliance artefact. SS2/21 expects firms and groups to reassess their overall reliance on third parties, and to manage concentration and vendor lock-in that can arise from multiple arrangements with the same provider, from fourth-party dependencies where unconnected suppliers rely on the same subcontractor, from providers that are hard to substitute, and from geographic clustering such as an offshoring hub in a single jurisdiction. A register that cannot be sliced by provider, sub-provider and location cannot answer the concentration question the PRA is really asking.

Governance, the SM&CR and the accountable SMF

SS2/21 is blunt on the point that boards and senior managers cannot outsource their responsibilities. A firm that outsources remains fully accountable for its regulatory obligations, and the board is expected to set the control environment and the firm’s appetite for outsourcing and third-party risk, to understand the firm’s reliance on critical service providers, and to receive management information clear enough to challenge it. These board-engagement principles were drawn from the R. Raphaels and Sons Final Notice of 29 May 2019, where the FCA and PRA jointly fined the bank over outsourcing failings, so they are grounded in a real enforcement case, not abstract good practice.

Accountability is pinned to an individual through the Senior Managers and Certification Regime. Allocation of Responsibilities 4.1(21) for banks, and the equivalent insurance rule, require firms to allocate a Prescribed Responsibility for the firm’s regulatory obligations in relation to outsourcing to a Senior Management Function. The PRA generally expects this to sit with the Chief Operations function, SMF24, where a firm has one, though it does not require it. The prescribed responsibility covers the firm’s overall outsourcing framework, policy and controls, while responsibility for individual arrangements can stay with the relevant business lines, and the SMF’s Statement of Responsibilities should describe the role in appropriate detail. Firms working through the wider accountability changes will find the interaction set out in our guide to the 2026 SM&CR reforms.

The written outsourcing policy is the board’s instrument for all of this. SS2/21 expects the board to approve, review and implement a written policy that draws on the firm’s business-continuity, data-protection, ICT, information-security, operational-resilience and risk-management policies. The statement lists the minimum contents, from the board’s role in material outsourcing decisions and conflicts-of-interest procedures through to ongoing oversight, exit strategies and termination. There is no single template and the policy need not be one document, but it has to be detailed enough to guide staff in practice. Behind all of it sits the empty-shell warning: a firm must retain enough non-financial resource to oversee what it has outsourced, or it risks failing the suitability Threshold Condition and the requirement to be capable of effective supervision.

Written agreements: the minimum SS2/21 expects

All outsourcing must be set out in a written agreement, and for material outsourcing SS2/21 lists the terms the agreement should cover as a minimum. Treat the list as a contracting checklist. It covers the outsourced function and its start, renewal and end dates, governing law and financial obligations, whether material sub-outsourcing is permitted and on what conditions, and the locations where the service is provided or data is kept, processed or transferred, with notice of any change.

The agreement also has to lock in the controls that make oversight possible: provisions on data accessibility, availability, integrity and confidentiality, the firm’s right to monitor performance against service levels, the provider’s reporting obligations including notice of anything that could materially affect delivery, business-continuity and contingency testing keyed to the firm’s impact tolerances, prompt access to firm-owned data on the provider’s insolvency or resolution, and the firm’s and the PRA’s rights to inspect and audit. For banks, the agreement should reference the Bank of England’s resolution powers, including sections 48Z and 70C to 70D of the Banking Act 2009, which implement Articles 68 and 71 of the Bank Recovery and Resolution Directive.

The clause firms most often leave soft is the termination-and-exit provision. SS2/21 expects material outsourcing agreements to carry termination rights and exit strategies covering both stressed and non-stressed scenarios, with both parties committing to support the testing of termination plans. Where a provider is unable or unwilling to contractually facilitate compliance with the firm’s regulatory obligations and expectations, SS2/21 expects the firm to make the PRA aware. That escalation is itself part of the expected behaviour.

Sub-outsourcing and the supply chain you cannot see

Sub-outsourcing, sometimes called chain outsourcing, is where a provider passes an outsourced function further down the line. SS2/21 flags it as a risk amplifier, because long chains across multiple jurisdictions limit a firm’s ability to manage the arrangement and can create dependencies the firm never intended and may not even see. The statement expects firms to assess sub-outsourcing risk before signing, to keep visibility of the supply chain, and to encourage providers to maintain current lists of their subcontractors.

For material sub-outsourcing, the bar is specific. A firm should only agree to it where the sub-outsourcing will not create undue operational risk and where the sub-provider undertakes to comply with all applicable requirements and to grant the firm, the Bank and the PRA the same access, audit and information rights as the primary provider. The written agreement should say whether material sub-outsourcing is permitted, specify any activities that cannot be sub-outsourced, require the provider to notify the firm of planned sub-outsourcing early enough for a risk assessment, and give the firm rights to object and to terminate. SS2/21 gives concrete examples of when a firm might terminate, such as a provider adding a sub-outsourcer with a history of data breaches without notice.

The point auditors probe here is fourth-party concentration. A firm can use several unconnected providers and still carry a single hidden dependency if those providers all rely on the same subcontractor. That is the failure the register and concentration-risk assessment are meant to surface, and why sub-outsourcing oversight cannot stop at the first supplier.

Data, audit rights and the assurance you actually use

Where a material outsourcing involves the transfer of or access to data, SS2/21 expects firms to define and document their own and the provider’s respective responsibilities. In cloud arrangements this is framed through the shared responsibility model, under which the firm stays responsible for what is in the cloud, including correctly classifying data and configuring and monitoring it, while the provider is responsible for the infrastructure that runs the service. The statement expects firms to classify data by sensitivity, to apply strong controls for data in transit, in memory and at rest, and to plan for deletion of firm data from all provider locations on exit, subject to data-protection and retention obligations. The UK GDPR and the Data Protection Act 2018 sit alongside these expectations.

Audit rights are only worth as much as their exercise. SS2/21 is explicit that negotiating adequate access, audit and information rights is not enough; firms have to use them when appropriate. For material outsourcing, agreements should give the firm, its auditors, the PRA and the Bank full and unrestricted audit and information rights, extending where relevant to penetration-test results, financial information, and the provider’s auditors, personnel and premises. Firms can mix offsite methods such as certificates and independent reports with onsite audits, individually or as pooled audits shared with other clients of the same provider. The level of assurance scales with the firm’s significance and the arrangement’s materiality.

Certificates deserve caution. SS2/21 expects firms not to treat the mere existence of a certificate as evidence that a service is being delivered in line with the firm’s obligations; the firm has to assess whether its scope, content and the qualifications behind it meet its needs. A clean report on the wrong scope tells you very little.

Business continuity and the stressed exit

For each material outsourcing, SS2/21 expects a business-continuity plan and a documented exit strategy, and it expects the exit strategy to distinguish a stressed exit, following the failure or insolvency of a provider, from a planned non-stressed exit for commercial or strategic reasons. The PRA’s focus is the outcome, whether the firm can keep delivering its important business services within its impact tolerances through a disruption, rather than the method by which it gets there.

Stressed exits are where plans tend to be thin, because they are the hardest to test and the least likely to be needed, right up until they are. SS2/21 expects firms to identify viable forms of exit, such as bringing the service back in-house, moving to a back-up provider, or using transitional tools like escrow, and to test those plans as far as possible. In cloud arrangements it expects firms to choose resiliency options in proportion to materiality, from multiple availability zones to retaining the ability to bring data and applications back on-premises. It also expects firms to start their continuity and exit plans during the pre-outsourcing phase, so due diligence itself surfaces alternative providers and the cost and timing of an exit.

Testing is meant to connect to the wider operational-resilience regime instead of running in a silo. SS2/21 suggests aligning continuity and exit testing with the scenario testing firms already run under the Operational Resilience Parts, using a third-party failure as one of the severe-but-plausible scenarios. Where a firm is in scope of the CBEST framework, insider and supply-chain scenarios are expected to feature in that testing, and lessons from tests are meant to feed back into the plans.

What changes on 18 March 2027: PS7/26 and the submitted register

The most consequential development is the one that has not fully bitten yet. Following CP17/24, the PRA published PS7/26, with the FCA and Bank of England publishing their equivalents, and an updated SS2/21 takes effect on 18 March 2027 after a twelve-month preparation period. The reforms turn several of the disciplines above into structured reporting obligations, and they are what a register of information and notification duties really points at.

From 18 March 2027, the PRA will require in-scope firms to maintain and submit an entity-level Register of material third-party arrangements, covering material outsourcing and material non-outsourcing arrangements. The PRA requirements exclude third-country branches, non-directive firms and credit unions with less than £50 million in total assets. The submitted Register also excludes specified categories, including basic utilities, process-support services without privileged access and, subject to exceptions, pure intragroup arrangements with no external provider. Firms must upload the Register through FCA RegData when the annual submission window opens and will have 90 calendar days to submit.

Material third-party notifications must be filed through FCA Connect before entering into or significantly changing the arrangement. The notification process is not regulatory approval, and the notification and Register use separate but aligned templates.

PS7/26 also introduces PRA operational-incident reporting for UK banks, building societies, PRA-designated investment firms and branches of overseas banks, and for UK Solvency II firms, Lloyd’s and managing agents. A firm must report when an incident meets the applicable PRA threshold relating to safety and soundness, policyholder protection or, for O-SIIs and relevant Solvency II firms, UK financial stability. The firm submits one report and updates it through initial, intermediate and final phases.

The initial phase is due as soon as reasonably practicable, with the PRA expecting submission within 24 hours after the firm determines that the threshold is met. Intermediate updates are required following significant changes. The final phase is due within 30 working days after resolution, with up to 60 working days in total where additional time is needed.

Sitting beside all of this is the critical third parties regime from PS16/24, effective from 1 January 2025 but only applying to a firm once HM Treasury designates it. That regime regulates the systemic suppliers themselves rather than the firms that use them, and the register data firms submit under PS7/26 is one of the inputs that can inform a designation. The practical point is that the arrangements you sign and classify through 2026 are the ones you will describe in the first submitted register, so the register data model, materiality logic and notification template are worth building now. Firms already running EU obligations can borrow structure from their approach to DORA ICT incident reporting, which shares the phased-reporting logic even though the thresholds differ.

Frequently Asked Questions

Is SS2/21 legally binding, or just guidance?

SS2/21 is a supervisory statement, so it sets out the PRA’s expectations without creating rules directly. The binding obligations sit in the PRA Rulebook, chiefly the Notifications, Outsourcing and Conditions Governing Business Parts, and in retained EU law such as Articles 30 to 32 of the retained MiFID Org Regulation. The PRA treats SS2/21 as its primary reference for how it reads and applies those requirements.

When do we have to notify the PRA about a material outsourcing arrangement?

Before entering into it. Notifications 2.3(1)(e) requires notification when entering or significantly changing a material outsourcing arrangement, and the PRA expects the notification ahead of signing, with the content covering at least the information in paragraph 54 of the EBA Outsourcing Guidelines. The regulator also expects a notification before a previously non-material arrangement is planned to become material, and it considers the timeliness of notifications when assessing Fundamental Rule 7.

Do the rules apply to arrangements that are not outsourcing?

Partly, and this is a common blind spot. The granular outsourcing requirements apply only to outsourcing as defined in the PRA Rulebook. But SS2/21 expects firms to assess the materiality and risk of every third-party arrangement, and to apply controls to a material non-outsourcing arrangement that are as strong as those for an equivalent outsourcing. Fundamental Rules, conduct rules, business-continuity and operational-resilience requirements apply to all third-party arrangements regardless of classification.

How does the SS2/21 Outsourcing Register differ from the DORA Register of Information?

Under current SS2/21, all firms keep appropriate outsourcing records, while banks maintain an Outsourcing Register covering all outsourcing arrangements and distinguishing material from non-material arrangements. Under DORA Article 28, in-scope EU financial entities maintain a Register of Information for all contractual arrangements on the use of ICT services; they report specified summary information at least annually and provide the full Register or requested sections when the competent authority asks. From 18 March 2027, the PRA adds a separate standardised submission covering reportable material third-party arrangements for its defined in-scope population.

Which SMF should own outsourcing under the SM&CR?

Firms must allocate a Prescribed Responsibility for the firm’s regulatory obligations on outsourcing to a Senior Management Function. The PRA generally expects this to be the Chief Operations function, SMF24, where the firm has one, but does not require it. The responsibility covers the overall outsourcing framework, policy and controls, and the SMF’s Statement of Responsibilities should describe it in appropriate detail. Responsibility for individual arrangements can stay with the relevant business lines.

How does proportionality change what a non-significant firm has to do?

Proportionality affects how a firm meets the expectations, not whether an arrangement is material. A non-significant firm may meet some expectations in a lighter way and can expect its outsourcing to attract supervisory scrutiny in line with its significance, but it must still notify material outsourcing, keep records, and put appropriate controls around material arrangements. Being small does not reclassify a material contract as non-material.

What is actually changing on 18 March 2027?

From 18 March 2027, in-scope firms must submit an annual entity-level Register of material third-party arrangements through FCA RegData and notify new or significantly changed material third-party arrangements through FCA Connect. Third-country branches, non-directive firms and credit unions with less than £50 million in total assets are outside these PRA Register and notification requirements. PS7/26 also introduces phased operational-incident reporting for the specified PRA banking and insurance population. The updated SS2/21 provides the materiality criteria, reporting exclusions and template guidance.

Related Articles

Key Takeaways

  • SS2/21 sets PRA supervisory expectations; the binding obligations arise from the PRA Rulebook and applicable UK-law provisions. The statement’s original compliance date was 31 March 2022, and the current version is the November 2024 update.
  • Materiality is the switch that turns on most obligations, and it is a property of the arrangement, kept separate from the proportionality that flows from a firm’s size and significance.
  • Material outsourcing must be notified to the PRA before the firm enters into it, with content built off paragraph 54 of the EBA Outsourcing Guidelines; late notification undercuts Fundamental Rule 7.
  • Non-outsourcing third-party arrangements are not exempt: material ones need controls as strong as an equivalent outsourcing, and may need to be brought to the PRA’s attention under Fundamental Rule 7.
  • Under current SS2/21, banks maintain the all-outsourcing Outsourcing Register and all firms keep appropriate outsourcing records; DORA’s Register of Information is a separate EU dataset with a different scope and reporting framework.
  • Written agreements for material outsourcing carry a defined minimum, including resolution-power references for banks and tested stressed-exit rights.
  • From 18 March 2027, in-scope firms must submit an entity-level Register of reportable material third-party arrangements through FCA RegData and file material third-party notifications through FCA Connect; PS7/26 also introduces phased PRA operational-incident reporting for the specified banking and insurance population.

Sources and References

  • PRA Supervisory Statement SS2/21, Outsourcing and third party risk management (PRA Rulebook guidance): prarulebook.co.uk
  • PRA SS2/21 (November 2024 update, current until 18 March 2027): bankofengland.co.uk
  • PRA Policy Statement PS7/21, Outsourcing and third party risk management (March 2021): bankofengland.co.uk
  • PRA Policy Statement PS7/26, Operational resilience: Operational incident and third-party reporting (March 2026): bankofengland.co.uk
  • PRA SS2/21 (18 March 2026 update PDF, effective 18 March 2027): bankofengland.co.uk
  • PRA Consultation Paper CP17/24, Operational incident and outsourcing and third-party reporting (December 2024): bankofengland.co.uk
  • PRA Policy Statement PS16/24, Operational resilience: Critical third parties to the UK financial sector (November 2024): bankofengland.co.uk
  • FCA Policy Statement PS24/16, Operational resilience: Critical third parties to the UK financial sector: fca.org.uk
  • EBA Guidelines on outsourcing arrangements (EBA/GL/2019/02), version applied in the UK: bankofengland.co.uk
  • FCA Handbook, Systems and Controls Sourcebook (SYSC): handbook.fca.org.uk
  • FCA Finalised Guidance FG16/5, Guidance for firms outsourcing to the cloud and other third party IT services: fca.org.uk
  • Regulation (EU) 2022/2554 (DORA), Article 28 Register of Information: eur-lex.europa.eu

Getting ahead of the 2027 register

SS2/21 already requires robust governance, risk assessment and records for outsourcing and other third-party arrangements. PS7/26 nevertheless creates new implementation work: in-scope firms must identify material third-party arrangements across outsourcing and non-outsourcing services, map them to the prescribed notification and Register fields, submit notifications through FCA Connect and upload the annual Register through FCA RegData. Existing outsourcing records are a starting point, but firms will need scope, data-model, governance and submission-control changes before 18 March 2027.

Last updated: July 2026

Disclaimer: The information on RegReportingDesk.com is for educational and informational purposes only. It does not constitute legal, regulatory, tax, or compliance advice. Always consult your compliance officer, legal counsel, or the relevant supervisory authority for guidance specific to your institution.

Similar Posts