Your guide to this week in regulation
TechnicalStay up to date with our latest round up of financial regulation.
By: Klaas de Vries
06 Aug 2026 6 min read

In July 2026, the Bank of England, the PRA, and the FCA began overseeing their first critical third parties. All four providers deliver key IT services to the financial sector, leading to concentration risk and challenging operational resilience. This gives regulators better visibility over how these suppliers manage risk, and greater assurance over their ability to support operational resilience across the financial sector.
In insurance, third parties like claims administrators, policy admin platforms, model vendors, and managing general agents are just as widely used, and just as exposed to concentration risk. A service outage at any of them could stop claims being paid and cause real financial harm to customers. Yet none of them count as infrastructure providers, so none of them sit on the critical third parties list, and they're unlikely to be added.
With that in mind, firms need to identify systemic risk due to their third-parties and ensure they’re mitigating the risk effectively.
When it comes to operational resilience, insurers are in unique position. Disruption at a large cloud or software provider could affect their operations, with knock on implications for business as usual, payouts and reputational damage. Meanwhile, insurers are also likely to be paying claims for other organisations affected by the same third-party event.
Despite being two sides of the same coin, most insurers will manage these impacts separately. Operations typically focus on supplier resilience, while underwriting owns accumulation. The impact of the outage will be measured in two different ways, by two different teams who rarely compare figures. The risk function should centralise that view, to get a clearer understanding of the firm’s exposure in the event of a third-party outage or failure.
Concentration risk is a key concern for operational resilience and third-party risk management, but it can extend further. In the insurance sector, a small number of vendors supply the catastrophe models, pricing tools, and rating engines to support capital modelling and pricing. That means that the underlying logic for many of these decisions will be the same and so will the outputs.
This isn’t an operational dependency and would typically fall under model risk management, with strict requirement on inventories, validation, change policies, and ownership. Collectively, the framework asks whether the model is fit for purpose, whether it behaves as expected, and if operators understand its limitations. It doesn’t ask how many other firms are putting the same question to the same model and arriving at the same answer, or what the repercussions of that could be.
A resilient insurance market relies on the difference between firms’ individual assessment of risk. However, if a large proportion of them rely on the same model, those views are less independent than they look. Additionally, those firms all have the same weak spots, created by the same underlying assumptions and features within their shared model.
Artificial intelligence (AI) will exacerbate this, with similar tools applied across the market to tackle similar tasks, based on similar assumptions. Many of these won’t appear in the model inventory at all, because they were bought as software rather than commissioned as models. If those assumptions need to change, the market is likely to find out at much the same time.
Business continuity and operational resilience isn’t designed with this in mind. There’s no outage to recover from and the systems remain available and continue to produce consistent results. It’s the consistency across the market, rather than any individual result, that creates the exposure.
When insurers come under strain, they typically decide that some lines of business aren't worth writing anymore. Limits come down, prices go up, exclusions go in, and the activity that depended on that cover stops.
That can have a significant impact on the economy, as insurance is essential to support a wide range of services. For examples, suppliers ship goods on credit because the seller is protected by trade credit insurance. Lenders won’t complete a mortgage without buildings cover, and contractors can’t win work without professional indemnity insurance.
In short, insurers don’t necessarily need to collapse, or suffer significant outages, to cause economic harm. They just need to collectively withdraw from certain markets, which is made more likely by reliance on the same underlying models.
Regulatory oversight of critical third parties is undoubtedly a good thing, helping to manage concentration risk and reduce the impact of services outages. But insurers need to remember that third-party risk doesn’t begin and end with the critical third-parties, or even the outsourcing register itself. Exposures can be more complex than expected, covering a broader range of departments and creating a different type of concentration risk around decision making.
As insurers prepare for the new incident and third-party reporting requirements under PS26/2 and PS7/26, many will already be improving the data they hold on material third parties. Firms should use that work to look at dependencies across the business, wherever they could affect customer outcomes, claims payment, or the firm's ability to stay within impact tolerances.
To address these gaps and establish a more comprehensive view of third-party risk, firms can take a range of practical actions such as:
For further information on how insurers can manage third-party risk, contact Klaas de Vries.
Stay up to date with our latest round up of financial regulation.
The FCA has reformed CASS 6 and 7 to ease the regulatory burden and align with Consumer Duty. Here's what's changed and what CASS firms should do next.
The Mills Review looks at how AI is changing retail financial services, setting out seven recommendations for the FCA. Here's what it means for AI governance and Boards.