THIRD PARTYCURRENT
Regulation & Standards · Regulatory Analysis

PRA finalizes material third-party reporting for 2027 implementation

The UK policy expands reporting beyond outsourcing, separates notification from register templates, and gives firms a year to govern the data behind material third-party arrangements.

Third Party Current editorial graphic. Source material: Bank of England Prudential Regulation Authority; analysis and presentation by Third Party Current.

Material relationships move into a common record

The policy broadens attention from material outsourcing to material third-party arrangements. That distinction matters because operational dependence can arise through software, data, infrastructure, group services, and other arrangements that do not fit a narrow outsourcing label. Firms need a relationship model capable of preserving the service, legal entity, materiality logic, subcontracting context, and responsible business function.

The PRA says the data will support oversight of operational resilience and potential concentration or critical nodes. For firms, the immediate task is not simply to complete a template. It is to govern the data well enough that a notification, register entry, internal inventory, contract record, and resilience assessment describe the same arrangement.

Notification and register are separate moments

The final package uses separate templates for notification and register reporting while keeping fields broadly consistent. That recognizes a practical difference: firms may need to notify a planned arrangement before every field is final, while the recurring register requires a maintained operational record. Systems should preserve the relationship between those records without pretending incomplete information is final.

Buyers should ask vendors to demonstrate a planned material arrangement, an amended contract, a changed service, and a periodic register submission. The platform should show required and optional fields, provenance, validation, ownership, effective dates, approvals, and a reproducible export rather than only a configurable questionnaire.

A year for data architecture

The March 2027 implementation date gives firms time to identify source systems and reconcile terminology across procurement, legal, finance, security, operational resilience, risk, and regulatory reporting. Waiting until the reporting deadline would turn a governance problem into a manual data-cleaning exercise.

Third Party Current will track the future-effective SS2/21 version separately from the currently effective version. Product claims tied to the policy will be treated as documented support assertions unless workflow, output, and implementation evidence are independently observed.

What we will watch next

Third Party Current will watch for later primary-source evidence that changes the maintained company, capability, or standards record. The next useful evidence may include implementation documentation, release details, regulator findings, corrected methods, product packaging, customer-observable workflow, or a subsequent company statement. Until then, the dated source and its stated boundary remain attached to this analysis.