How UK firms should manage outsourcing risk under FCA SYSC 8, FG16/5 cloud guidance and the critical third parties regime, from due diligence to exit.

Almost every regulated firm now relies on someone else to run part of its business. Cloud hosting, payment processing, compliance software, customer support and even core banking platforms are routinely delivered by third parties. That reliance brings real benefits in cost, capacity and innovation, but it does not move the regulatory burden anywhere. If a supplier fails, the firm answers to the regulator and to its customers, not the supplier.
The Financial Conduct Authority sets the baseline for outsourcing risk management in its Senior Management Arrangements, Systems and Controls sourcebook, known as SYSC. The central principle is simple and unforgiving: a firm that outsources a critical or important function remains fully responsible for discharging all of its obligations under the regulatory system, and cannot delegate any part of that responsibility to a supplier. On top of SYSC 8 sit the FCA cloud guidance FG16/5, the operational resilience rules, and the new critical third parties regime run jointly by the Bank of England, the Prudential Regulation Authority and the FCA.
This guide walks through what the rules actually say, how to tell a critical or important function from an ordinary supplier relationship, and how to build an outsourcing lifecycle that stands up to scrutiny from due diligence through to exit. Every rule cited here is drawn from the primary FCA and Bank of England sources listed at the end.
The regulatory definition of outsourcing is broader than many firms assume. FG16/5, the FCA finalised guidance on outsourcing to the cloud and other third-party IT services, states that where a third party delivers services on behalf of a regulated firm, including a cloud provider, this is considered outsourcing, and firms need to consider the relevant regulatory obligations and how they comply with them. The exact form of the service, whether public cloud, private cloud, Infrastructure as a Service, Platform as a Service or Software as a Service, does not in itself change the obligations placed on the firm.
The reason this matters is that outsourcing does not shift accountability. FG16/5 is explicit that regulated firms retain full responsibility and accountability for discharging all of their regulatory responsibilities, and that firms cannot delegate any part of this responsibility to a third party. The supplier may run the servers, but the firm still owns the regulatory outcome.
SYSC 8 sets out the general outsourcing requirements. Firms should also be aware that other, more specific requirements can apply depending on their permissions and business model, including the MiFID Organisation Regulation for investment firms and Solvency II obligations for insurers. The starting point for most firms, though, is to work out which of their arrangements count as outsourcing at all, and then which of those are critical or important.
Not every supplier relationship attracts the full weight of the rules. The classification of a function drives the obligations, so getting it right is the single most important judgement in outsourcing risk management. SYSC 8.1.4R sets the test. An operational function is regarded as critical or important if a defect or failure in its performance would materially impair the continuing compliance of a firm with the conditions and obligations of its authorisation, its other obligations under the regulatory system, its financial performance, or the soundness or the continuity of its relevant services and activities.
In plain terms, if the supplier stopped tomorrow and the firm could no longer meet its regulatory obligations, keep serving customers, or stay financially sound, the function is almost certainly critical or important. Cloud hosting for a core trading platform, an outsourced client-money reconciliation service, or a payments engine would typically qualify. FG16/5 also identifies material outsourcing, defined as outsourcing of such importance that weakness or failure of the services would cast serious doubt upon the firm's continuing satisfaction of the threshold conditions or compliance with the Principles for Businesses.
Where a function is not critical or important, the firm still cannot ignore it. SYSC 8.1.3 provides that a firm should take the section into account in a manner that is proportionate given the nature, scale and complexity of the outsourcing. So the classification does not remove obligations for lower-risk arrangements; it scales them. The table below sets out the practical difference.
| Consideration | Critical or important function | Non-critical function |
|---|---|---|
| Governing rule | Full SYSC 8.1 conditions apply | SYSC 8.1 applied proportionately (SYSC 8.1.3) |
| Firm's responsibility | Remains fully responsible for all obligations (SYSC 8.1.6) | Retains responsibility, proportionate oversight |
| Due diligence | Formal, documented, risk-assessed before contract | Proportionate to nature, scale and complexity |
| FCA notification | Required when entering or significantly changing the arrangement | Not generally required |
| Exit plan | Documented, tested exit and continuity plan expected | Proportionate contingency arrangements |
| Example | Cloud hosting for a core platform, payments engine | Standardised advice, training, cleaning, invoicing |
For a critical or important function, SYSC 8.1.6R states that the firm remains fully responsible for discharging all of its obligations under the regulatory system and must in particular ensure that four things do not happen. The outsourcing must not result in the delegation by senior personnel of their responsibility. The relationship and obligations of the firm towards its clients under the regulatory system must not be altered. The conditions with which the firm must comply in order to be authorised, and to remain so, must not be undermined. And none of the other conditions subject to which the firm's authorisation was granted must be removed or modified.
SYSC 8.1.1R adds a critical supervisory safeguard. A firm must not undertake the outsourcing of important operational functions in such a way as to impair materially the quality of its internal control, or the ability of the FCA to monitor the firm's compliance with all its obligations under the regulatory system. Outsourcing can never be structured so that it puts the firm's controls or the regulator's supervision out of reach.
SYSC 8.1.8R then lists the specific conditions a firm must take reasonable steps to satisfy. These are the operational backbone of any outsourcing arrangement and should map directly onto contract clauses and oversight controls. The chart below shows how the eleven conditions cluster into the areas a firm needs to build capability around.
The eleven conditions in SYSC 8.1.8R grouped by the control theme they address, showing where firms should concentrate oversight effort.
The SYSC 8.1.8R conditions describe a lifecycle rather than a single event. A firm must satisfy itself that the service provider has the ability, capacity and any authorisation required by law to perform the outsourced functions reliably and professionally, and must establish methods for assessing the standard of the provider's performance. It must retain the necessary expertise to supervise the outsourced functions effectively and manage the associated risks, and must actually carry out that supervision rather than assume the supplier has it covered.
FG16/5 fleshes out the practical expectations at each stage. Before entering an arrangement, a firm should have a clear and documented business case, carry out and document a risk assessment, and ensure the outsourcing does not worsen the firm's operational risk. During the relationship it should be clear about where responsibility between the firm and its provider begins and ends, allocate day-to-day and strategic ownership, and ensure staff have the skills and resources to oversee and test the outsourced activity. It should also monitor concentration risk and consider what action it would take if the outsource provider failed.
Exit is where many arrangements are weakest. SYSC 8.1.8R requires that the firm must be able to terminate the arrangement where necessary without detriment to the continuity and quality of its provision of services to clients. FG16/5 states that firms should have exit plans and termination arrangements that are understood, documented and fully tested, know how they would transition to an alternative provider while maintaining business continuity, place an obligation on the provider to cooperate fully with the firm and any new provider, and know how they would remove data from the provider's systems on exit. The steps below track the lifecycle the rules describe.

A written agreement is not optional for the arrangements that matter. The clearest expression of this is SYSC 8.1.9R, which requires that the respective rights and obligations of the firm and of the service provider are clearly allocated and set out in a written agreement. The contract is where the SYSC 8.1.8R conditions become enforceable, so vague or generic supplier terms of business rarely satisfy the rules on their own.
Access and confidentiality run through the conditions. SYSC 8.1.8R requires that the service provider must co-operate with the FCA and any other relevant competent authority in connection with the outsourced activities, and that the firm, its auditors and the FCA must have effective access to data related to the outsourced activities and to the business premises of the service provider, with the regulator able to exercise those rights. The provider must also protect any confidential information relating to the firm and its clients. FG16/5 stresses that even where a contract is not governed by UK law, the firm should still ensure effective access to data and business premises for the firm, its auditor and the relevant regulator.
SYSC 8.1.11R reinforces the supervisory dimension. A firm must make available on request to the FCA all information necessary to enable the regulator to supervise the compliance of the performance of the outsourced activities with the requirements of the regulatory system. In short, outsourcing must never become a place where information goes to hide. Firms building this discipline into a wider control framework can see how the pieces fit together in the Nasara Connect control platform.
SYSC 8 does not stand alone. The FCA operational resilience rules in PS21/3 require firms to identify their important business services, set an impact tolerance for each, and remain within that tolerance through severe but plausible disruption, with a transitional period that ran to 31 March 2025. Crucially for outsourcing, it remains the firm's responsibility to stay within its impact tolerances even where a third party supports or delivers an important business service, so third-party relationships must be actively managed for resilience, not just cost.
The most significant recent development is the critical third parties regime. In the joint policy statement PS16/24, published on 12 November 2024, the Bank of England, the PRA and the FCA set out final rules for critical third parties, or CTPs. Under the Financial Services and Markets Act as amended in 2023, HM Treasury may designate a third party as a CTP only where a failure in, or disruption to, its services could threaten the stability of, or confidence in, the UK financial system. The regime imposes six CTP Fundamental Rules and eight Operational Risk and Resilience Requirements covering governance, risk management, supply chain risk, technology and cyber resilience, change management, mapping, incident management and termination of services. The rules took effect from 1 January 2025, applying once an HM Treasury designation order is in force.
The critical point for regulated firms is that the CTP regime does not let them off the hook. PS16/24 states that the regime does not impose additional, explicit requirements on firms but complements their existing requirements. Once a third party is designated a CTP, firms remain accountable and responsible for managing the risks in any outsourcing or third party arrangements they have with that CTP. Designation is not a badge of resilience a firm can rely on in place of its own diligence. Firms preparing their broader systems and controls before or after authorisation can review the Nasara Connect authorisation support to see how outsourcing governance fits into the wider framework.
Outsourcing risk management under the FCA regime rests on one durable idea: you can outsource the activity, but never the accountability. SYSC 8.1 makes the firm fully responsible for critical or important functions, requires that outsourcing never impairs the firm's own controls or the FCA's ability to supervise, and sets out concrete conditions on supplier capability, oversight, regulator access, confidentiality, termination and continuity. FG16/5 shows how those obligations apply to cloud and IT services, and the critical third parties regime adds a systemic layer without diluting any firm's individual duties.
The practical answer is to treat outsourcing as a lifecycle with a documented trail at every stage: classify the function honestly, do real due diligence, write the conditions into an enforceable contract, notify the regulator where required, oversee the arrangement continuously, and keep a tested exit plan ready. Firms that build this discipline into their day-to-day governance find that supervisory scrutiny becomes a formality rather than a fire drill. If you want to see how this maps onto a working control framework, explore the options on the Nasara Connect platform.
SYSC 8.1.4R defines an operational function as critical or important if a defect or failure in its performance would materially impair a firm's continuing compliance with the conditions and obligations of its authorisation, its other obligations under the regulatory system, its financial performance, or the soundness or continuity of its relevant services and activities. If the loss of a supplier would stop the firm meeting its obligations or serving clients, the function is likely critical or important.
No. FG16/5 states that regulated firms retain full responsibility and accountability for discharging all of their regulatory responsibilities and cannot delegate any part of that responsibility to a third party. SYSC 8.1.6R adds that when a firm outsources a critical or important function it remains fully responsible for discharging all of its obligations under the regulatory system.
Yes. FG16/5 confirms that where a third party delivers services on behalf of a regulated firm, including a cloud provider, this is considered outsourcing. The specific form of the service, whether public, private or hybrid cloud, or IaaS, PaaS or SaaS, does not change the regulatory obligations placed on the firm.
SYSC 8.1.9R requires the respective rights and obligations of the firm and the provider to be clearly allocated and set out in a written agreement. The conditions in SYSC 8.1.8R should be reflected in the contract, including the ability to terminate without detriment to clients, effective access to data and premises for the firm, its auditors and the FCA, cooperation with the regulator, protection of confidential information, and a contingency plan for disaster recovery.
FG16/5 reminds firms of their obligation to notify the FCA when entering into, or significantly changing, material or critical outsourcing arrangements. New rules requiring firms to notify the FCA of their material third party arrangements are due to apply from 18 March 2027, so firms should track the register and reporting requirements as they come into force.
The critical third parties regime, set out in the joint Bank of England, PRA and FCA policy statement PS16/24 and effective from 1 January 2025, lets HM Treasury designate third parties whose failure could threaten UK financial stability, and gives the regulators oversight powers over them. It does not impose new explicit requirements on firms or reduce their own duties. Firms remain accountable for managing the risks in any arrangement with a designated critical third party.
Nasara Control helps UK firms send and control payments with lower fees, better rates and full visibility.
Practical guides and updates for UK firms, straight to your inbox.