THIRD PARTYCURRENT
Regulation & Standards · Primary-source analysis

PRA SS2/21 makes outsourcing exit plans testable

For material outsourcing, the current supervisory statement treats exit as a planned, owned, costed, and risk-based test—not a clause that can wait for supplier failure.

Third Party Current editorial graphic. Source material: Prudential Regulation Authority; analysis and presentation by Third Party Current.

Exit planning starts before the relationship is signed

The direct operating answer in SS2/21 is that a material outsourcing exit cannot be left as a generic termination right. The Prudential Regulation Authority expects firms to develop a documented exit plan during the pre-outsourcing phase and to keep it commensurate with the arrangement's materiality and risk. That timing matters: the firm has to confront dependencies, replacement options, data access, transition constraints, and internal capacity while it can still shape selection and contracting—not when a supplier is already failing or leverage has disappeared.

A useful plan therefore connects the legal exit route to an executable operating sequence. SS2/21 points firms toward estimated cost, resources, and time; the data and assets that must be returned, transferred, or deleted; the services that must continue; and the people authorized to decide and act. A contract may create rights, but the exit record must show how the firm would preserve compliance and operational continuity while those rights are exercised.

A testable plan has triggers and success criteria

The statement expects firms to define indicators that could trigger an exit and criteria for judging whether it worked. Those controls make the plan more than a narrative. A trigger might relate to performance deterioration, an unremedied control weakness, a material change, financial distress, termination, or another event within the firm's approved framework. Success criteria can then address time, cost, functionality, data integrity, regulatory obligations, and whether important business services remain within their impact tolerances.

Ownership must also be visible. The record should identify who maintains the plan, who signs it off, who monitors trigger conditions, who can activate it, and which business, technology, legal, risk, security, procurement, data, and continuity owners must participate. Where a replacement provider or internal transfer is contemplated, the plan should preserve the assumptions behind that option rather than treating an untested market alternative as assured capacity.

Testing has to expose the stressed path

SS2/21 says stressed exit plans should be tested and that testing of implemented outsourcing arrangements should be risk based. That does not require every firm to run an identical full migration exercise. It does require a proportionate method capable of finding false assumptions before an actual exit. Tabletop exercises, data-retrieval tests, transition rehearsals, recovery exercises, controlled service-component transfers, and evidence reviews can test different parts of the plan when their scope and limitations are recorded.

The test should make the difficult conditions explicit. Can the firm obtain usable data if ordinary supplier cooperation is constrained? Do inventories identify subcontractors and technical dependencies? Can a receiving environment preserve required security, reconciliation, access, and audit records? Does the timeline still work if the exit coincides with an incident or capacity shortage? Lessons, failures, and changed assumptions should update the maintained plan; a passed checkbox without that learning loop does not demonstrate continuing viability.

What a buyer should require from an exit-workflow demonstration

A defensible technology evaluation begins with one material arrangement and follows its exit record from pre-contract assessment through approval, monitoring, test, remediation, and possible activation. The demonstration should show the governed service and dependency inventory, data priorities, contractual rights, trigger evidence, owners, decision history, test scenarios, findings, due dates, approvals, and exportable audit trail. It should also show how a material change in the service updates the plan rather than leaving an obsolete document attached to the vendor record.

Software can coordinate the evidence, but it cannot establish that an alternative provider has capacity, that a transition is legally permitted, that data is complete, or that the firm's service will remain within tolerance. This article analyzes the current November 2024 version of SS2/21 linked below. The PRA page also identifies a future version with a later effective date; teams should preserve that version boundary and re-evaluate before its effective date instead of silently treating future text as current.

What we will watch next

Third Party Current will watch for later primary-source evidence that changes the maintained company, capability, or standards record. The next useful evidence may include implementation documentation, release details, regulator findings, corrected methods, product packaging, customer-observable workflow, or a subsequent company statement. Until then, the dated source and its stated boundary remain attached to this analysis.

Primary source: Prudential Regulation Authority · Supervisory statement.

Source boundary: This article independently analyzes the current November 2024 version of PRA Supervisory Statement SS2/21. It is not legal, regulatory, resilience, contracting, technology, or risk-acceptance advice, and it does not treat the separately identified future version as presently effective.

Editorial record: Published July 27, 2026; last reviewed July 27, 2026. Corrections policy.