The short answerRegulators treat your IT providers as part of your control environment. The FCA’s SYSC 8 says outsourcing does not relieve you of responsibility, and the PRA’s SS2/21 sets detailed expectations for dual-regulated firms on due diligence, contract terms, oversight and exit. From 18 March 2027, new or significantly changed material third-party arrangements must also be notified to your regulator. Keep a register, tier your vendors and contract for the controls you need.
Key points- You stay responsible for outsourced IT. Due diligence before, supervision during and an exit plan after.
- Keep a register of providers and tier them by criticality; material arrangements get the closest scrutiny.
- Contracts should cover security obligations, access and audit rights, incident notification, subcontractors and data return.
- From 18 March 2027, material third-party arrangements feed into regulatory reporting.
- Your MSP is itself a critical vendor. Assess it like one.
Why vendor management is now an IT topic
A modern firm runs on providers: cloud platforms, email, managed IT, security tooling, payment, case management and market-data services. When one fails or is breached, your regulator will ask what you did to choose it, contract with it and watch it. UK regulators now ask that question through operational resilience, outsourcing and, from March 2027, third-party reporting rules. The SRA asks it too, through a law firm’s duty to protect client confidentiality and client money.
Build a register and tier it
List every provider that touches firm data or supports a critical process, including cloud services staff adopted informally. Record what it does, what data it holds, where it runs, who owns the relationship and when it was last reviewed. Then tier them:
- Critical or material. A provider whose failure or breach could significantly disrupt your important business services, harm clients or affect your ability to meet regulatory requirements. SYSC 8 speaks of critical or important functions, and the PRA’s SS2/21 of material outsourcing.
- Important. Failure would disrupt normal operations or expose client data, but you could cope for a while.
- Standard. Low impact, low data sensitivity.
Due diligence before you sign
Scale the checks to the tier. For a critical provider, look for:
- Independent assurance: an ISO 27001 certificate with a relevant scope, or an independent audit report, that you have actually read.
- Security controls that match your requirements, and a way to verify them.
- Where data is stored and processed, and which subcontractors are involved.
- Incident history, breach notification practice and business continuity arrangements.
- Financial stability, insurance and how the provider vets and supervises its own staff.
- How you would leave: data return, transition help and the time it would take.
What the contract should say
The PRA’s SS2/21 and the FCA’s guidance on cloud and third-party IT (FG16/5) point to the same essentials, and they are a good template for any regulated firm, including law firms. Contracts with IT providers should include:
- Security obligations that match the standards you verified during due diligence, so you have recourse if the provider falls short.
- Access and audit rights for you and your regulator. You can audit, join pooled audits, review the provider’s control environment or accept independent audit reports, in proportion to the criticality of the service and the sensitivity of the data.
- Incident notification and cooperation. The provider must tell you promptly about incidents that affect your service or data, and help with remediation.
- Subcontracting controls. Disclosure of current arrangements, notice of changes, a right to object and termination options if concerns are not resolved.
- Exit and data return or destruction when the contract ends, with transition help.
Add the practical terms too: service levels, support hours, notice periods and business continuity commitments.
Ongoing oversight
- Review each provider on a schedule based on its tier, and record the outcome.
- Collect assurance reports and certificates each year and check scope and dates.
- Track service performance and incidents against the contract.
- Require notice of material changes, such as new subcontractors or data locations.
- Test your exit plan for critical providers, on paper at least.
Your MSP is a critical vendor
A managed service provider usually holds privileged access to your systems, which makes it one of your most important providers. Ask it what it would ask of anyone else: its certificates and their scope, how it vets and supervises engineers, how it controls and logs privileged access, how it handles incidents and how quickly it will tell you about one. At Cre8 IT we expect these questions, and we can supply the evidence as part of onboarding.
Sources and further reading
Last reviewed 25 September 2026. This guide is general information, not legal or regulatory advice. Rules change, so check the current text and take advice from your compliance officer or legal adviser before relying on it.
CEO, Cre8 IT
Rob Crossley is CEO of Cre8 IT, a managed IT and cyber security company that has supported businesses across the UK, the UAE and Saudi Arabia since 2012. Cre8 IT is certified to ISO 27001:2022 and ISO 9001 and is a certified Microsoft Partner.