There is a persistent assumption in procurement conversations that transferring an operation transfers the risk attached to it. Outsourced financial oversight is the discipline that exists because British regulators have taken the opposite position, consistently and in writing: the firm that delegates the activity retains the obligation to control it.
This matters more in 2026 than it did five years ago, and not because the principle changed. It matters because the reporting requirements built around that principle have become specific, dated and enforceable.
Accountability does not travel with the contract
The governing position is set out in the Prudential Regulation Authority’s supervisory statement on outsourcing and third party risk management, known as SS2/21. It applies to UK banks, investment firms and insurers, and to UK branches of overseas firms, and it addresses the outsourcing lifecycle in sequence: governance and record-keeping, the pre-outsourcing assessment, the content of the agreement itself, data security, access and audit rights, sub-outsourcing, and business continuity and exit planning.
Two features of that structure deserve attention from anyone negotiating a support contract. The first is that audit and information rights are treated as a chapter in their own right, not as a clause to be conceded during commercial negotiation. The second is that sub-outsourcing is addressed separately, which means the regulator’s interest extends past the counterparty to whoever the counterparty subcontracts to.
| SS2/21 area | What the firm must be able to demonstrate | What it means in a support contract |
|---|---|---|
| Governance and record-keeping | A documented register of arrangements and a named accountable owner | Oversight cannot sit with procurement alone |
| Pre-outsourcing assessment | Materiality assessed before signature, and reassessed periodically | Due diligence is a recurring obligation, not a one-off |
| Access, audit and information rights | The right to examine the provider’s operation in practice | Rights must be contractual, not goodwill |
| Sub-outsourcing | Visibility of who else performs the work | Subcontracted delivery must be disclosed and approved |
| Business continuity and exit | A workable plan to withdraw or transfer | Exit terms drafted at the start, not at the dispute |
The critical third parties regime changed who is supervised, not who is responsible
A common misreading of recent policy is that the new critical third parties regime shifts responsibility onto large suppliers. It does not.
The regime, finalised jointly by the Financial Conduct Authority, the PRA and the Bank of England in policy statement PS24/16, took effect on 1 January 2025 and brings designated providers within the regulators’ direct oversight — requiring assurance, information and notifications, along with resilience testing and scenario exercises. Designation itself is a decision for HM Treasury, on the regulators’ recommendation, and applies only to providers whose failure could threaten the stability of the sector.
The practical consequence for most firms is narrow. A typical outsourced support arrangement will never involve a designated critical third party, and the firm’s own oversight obligation under SS2/21 is unaffected either way. The regime addresses systemic concentration risk in a handful of very large suppliers. It is not a route by which an operational obligation leaves the balance sheet.

What changes in March 2027
The substantive development is reporting. In March 2026 the Bank of England published policy statement PS7/26 on operational incident and third-party reporting, alongside an updated SS2/21 that takes effect on 18 March 2027.
The requirement that will occupy operations teams is the register of material third party arrangements. All material arrangements must be listed, whether or not they meet the definition of outsourcing — a distinction firms have historically used to keep certain supplier relationships outside their formal outsourcing governance. The updated statement also expands the expectations and worked examples for assessing which arrangements qualify as material.
Building outsourced financial oversight into the arrangement
Firms that treat this as a documentation exercise complete the register and change nothing. Firms that treat it as a design constraint select differently.
Four questions separate an arrangement that can be evidenced from one that cannot. Can the firm exercise audit rights in practice, or only in principle? Is every delivery location and subcontractor disclosed and approved? Does the provider report against the firm’s own resilience thresholds, or only against its own service levels? And is there an exit plan that has been costed rather than merely drafted?
That is why due diligence on bpo financial services providers increasingly opens with audit rights, sub-outsourcing disclosure and exit terms rather than with price per contact. The delivery location question is more consequential than it appears, because oversight expectations travel with the work — an issue examined in this analysis of what changes when support operates across multiple jurisdictions.
There is also a measurement trap here. Evidencing oversight means showing that the firm monitored something meaningful, and a monthly satisfaction figure does not constitute control. As covered in this piece on why a single satisfaction score can describe very different underlying experiences, aggregate reporting is precisely the kind of evidence that looks adequate until somebody asks what it excludes.
FAQ: Outsourced Financial Oversight: What Regulators Expect
It is the set of governance, monitoring and contractual controls a regulated firm must maintain over activities it has delegated to a third party. UK regulators treat the obligation as non-transferable: the provider performs the work, but the firm remains accountable for its resilience, its data handling and its outcomes for customers.
No. The PRA’s expectations on outsourcing and third party risk management apply to the arrangement itself, covering pre-contract assessment, audit rights, sub-outsourcing visibility and exit planning. Delegating the activity increases the documentation burden rather than reducing it, because the firm must now evidence control over an operation it does not run.
Materiality is assessed by the firm rather than prescribed by a list, based on the significance of the arrangement to its important business services. The updated supervisory statement expands the guidance and worked examples on making that assessment, and the register that takes effect in 2027 must capture all material arrangements, whether or not they meet the technical definition of outsourcing.
Almost never. Designation is reserved for providers whose disruption could threaten the stability of the UK financial system, is decided by HM Treasury, and applies to a small number of suppliers — predominantly large technology and infrastructure firms. An outsourced contact operation would not ordinarily fall within scope.
A documented materiality assessment, contractual audit and information rights that can actually be exercised, full disclosure of delivery locations and subcontractors, agreed reporting against the firm’s own resilience thresholds, and a costed exit plan. Each of these is far cheaper to secure before signature than to retrofit during a supervisory review.

Offshore BPO analyst covering the UK, South Africa, and the Philippines. Writing on outsourcing strategy, compliance, and CX operations across all three markets — from British buyers to offshore operators.




