UK and EU regulators coordinate oversight of critical technology providers
Key Takeaways
- 01UK financial regulators and the European Supervisory Authorities have agreed a framework to coordinate oversight of critical third-party providers.
- 02The MoU supports information sharing and cooperation during incidents, including cyber-attacks and power outages.
- 03The UK CTP regime took effect on 1 January 2025 and applies after HM Treasury designates a provider.
- 04Designated UK CTPs must provide assurance, conduct resilience testing and report major incidents.
- 05Providers operating across the UK and EU may face more coordinated regulatory scrutiny under the UK regime and DORA.
The UK’s Financial Conduct Authority (FCA), Bank of England and Prudential Regulation Authority (PRA) have signed a Memorandum of Understanding with the European Supervisory Authorities to coordinate oversight of critical third-party providers.
The arrangement is intended to support cooperation where providers are relevant to both the UK’s critical third party (CTP) regime and the EU’s Digital Operational Resilience Act (DORA) framework. It provides for information-sharing and coordinated oversight, including during operational incidents such as cyber-attacks or power outages.
The UK CTP rules took effect on 1 January 2025, but apply to a provider only after HM Treasury designates it as a CTP. HM Treasury decides which third-party service providers fall within the regime.
Once designated, a CTP must provide regular assurance to regulators, carry out resilience testing and report major incidents. The MoU does not itself create these duties; it gives UK and EU authorities a mechanism to work together where a provider is subject to oversight on both sides.
The development is particularly relevant to major technology, cloud, data and other outsourced-service providers that support financial firms in the UK and EU. Those designated in the UK, or classed as critical under DORA, may face more coordinated supervisory engagement and cross-border information sharing during resilience and cybersecurity incidents.