Insights · Vendor management

IT vendor and outsourcing management for FCA, PRA and SRA regulated firms

How to manage IT providers when you are regulated in the UK: a register, tiering, due diligence, contract terms, ongoing oversight and the new third-party reporting rules.
The short answer

Regulators treat your IT providers as part of your control environment. The FCA’s SYSC 8 says outsourcing does not relieve you of responsibility, and the PRA’s SS2/21 sets detailed expectations for dual-regulated firms on due diligence, contract terms, oversight and exit. From 18 March 2027, new or significantly changed material third-party arrangements must also be notified to your regulator. Keep a register, tier your vendors and contract for the controls you need.

Key points
  • You stay responsible for outsourced IT. Due diligence before, supervision during and an exit plan after.
  • Keep a register of providers and tier them by criticality; material arrangements get the closest scrutiny.
  • Contracts should cover security obligations, access and audit rights, incident notification, subcontractors and data return.
  • From 18 March 2027, material third-party arrangements feed into regulatory reporting.
  • Your MSP is itself a critical vendor. Assess it like one.

Why vendor management is now an IT topic

A modern firm runs on providers: cloud platforms, email, managed IT, security tooling, payment, case management and market-data services. When one fails or is breached, your regulator will ask what you did to choose it, contract with it and watch it. UK regulators now ask that question through operational resilience, outsourcing and, from March 2027, third-party reporting rules. The SRA asks it too, through a law firm’s duty to protect client confidentiality and client money.

Build a register and tier it

List every provider that touches firm data or supports a critical process, including cloud services staff adopted informally. Record what it does, what data it holds, where it runs, who owns the relationship and when it was last reviewed. Then tier them:

  • Critical or material. A provider whose failure or breach could significantly disrupt your important business services, harm clients or affect your ability to meet regulatory requirements. SYSC 8 speaks of critical or important functions, and the PRA’s SS2/21 of material outsourcing.
  • Important. Failure would disrupt normal operations or expose client data, but you could cope for a while.
  • Standard. Low impact, low data sensitivity.

Due diligence before you sign

Scale the checks to the tier. For a critical provider, look for:

  • Independent assurance: an ISO 27001 certificate with a relevant scope, or an independent audit report, that you have actually read.
  • Security controls that match your requirements, and a way to verify them.
  • Where data is stored and processed, and which subcontractors are involved.
  • Incident history, breach notification practice and business continuity arrangements.
  • Financial stability, insurance and how the provider vets and supervises its own staff.
  • How you would leave: data return, transition help and the time it would take.

What the contract should say

The PRA’s SS2/21 and the FCA’s guidance on cloud and third-party IT (FG16/5) point to the same essentials, and they are a good template for any regulated firm, including law firms. Contracts with IT providers should include:

  • Security obligations that match the standards you verified during due diligence, so you have recourse if the provider falls short.
  • Access and audit rights for you and your regulator. You can audit, join pooled audits, review the provider’s control environment or accept independent audit reports, in proportion to the criticality of the service and the sensitivity of the data.
  • Incident notification and cooperation. The provider must tell you promptly about incidents that affect your service or data, and help with remediation.
  • Subcontracting controls. Disclosure of current arrangements, notice of changes, a right to object and termination options if concerns are not resolved.
  • Exit and data return or destruction when the contract ends, with transition help.

Add the practical terms too: service levels, support hours, notice periods and business continuity commitments.

Ongoing oversight

  • Review each provider on a schedule based on its tier, and record the outcome.
  • Collect assurance reports and certificates each year and check scope and dates.
  • Track service performance and incidents against the contract.
  • Require notice of material changes, such as new subcontractors or data locations.
  • Test your exit plan for critical providers, on paper at least.

Your MSP is a critical vendor

A managed service provider usually holds privileged access to your systems, which makes it one of your most important providers. Ask it what it would ask of anyone else: its certificates and their scope, how it vets and supervises engineers, how it controls and logs privileged access, how it handles incidents and how quickly it will tell you about one. At Cre8 IT we expect these questions, and we can supply the evidence as part of onboarding.

Sources and further reading

Last reviewed 25 September 2026. This guide is general information, not legal or regulatory advice. Rules change, so check the current text and take advice from your compliance officer or legal adviser before relying on it.

Written by
CEO, Cre8 IT
Rob Crossley is CEO of Cre8 IT, a managed IT and cyber security company that has supported businesses across the UK, the UAE and Saudi Arabia since 2012. Cre8 IT is certified to ISO 27001:2022 and ISO 9001 and is a certified Microsoft Partner.
FAQ

Frequently asked questions

Is our managed IT provider a “material” outsourcing?

It often is. Ask whether a failure or breach of the service could significantly disrupt your important business services, harm clients or affect your ability to meet regulatory requirements. Assess this yourself, record the reasoning and revisit it when the arrangement changes.

Do we need a right to audit in every IT contract?

UK regulators expect contracts to give you, and them, effective access and audit rights. That can be your own audit, a pooled audit, a review of the provider’s control environment or independent audit reports, depending on how critical the service and how sensitive the data. On-site audits are not always needed.

How often should we review our providers?

Match the frequency to risk. Critical providers deserve at least an annual review, including assurance reports and performance. Lower tiers can be reviewed less often, provided you still notice material changes.
Related guides

Keep reading

Each guide links to the regulator’s own text and shows when it was last reviewed.
FCA and PRA

FCA and PRA IT requirements: what regulated firms need to evidence

A plain-English guide to UK operational resilience (SYSC 15A and SS1/21), outsourcing (SYSC 8 and SS2/21), the new incident and third-party reporting rules, and the evidence a regulated firm should be able to show.
7 min read · Reviewed 25 September 2026
ISO 27001

ISO 27001 for regulated firms: how it supports FCA, PRA and SRA expectations

What ISO/IEC 27001:2022 certifies, how its controls map to FCA, PRA and SRA expectations, and how to read a supplier’s certificate.
4 min read · Reviewed 25 September 2026
Audit readiness

IT audit readiness for regulated firms: an evidence-first checklist

How to be ready when a regulator, auditor or client asks for proof of your IT and security controls: the evidence pack, a mock audit and a six-week plan.
3 min read · Reviewed 25 September 2026

Talk to a specialist about your obligations

Tell us about your firm and your regulator, and we will suggest a practical first step, whether that is a gap assessment or ongoing support.