THIRD PARTYCURRENT
United Kingdom prudential supervisory statement

PRA SS2/21

SS2/21 sets expectations for governance, materiality, pre-contract assessment, due diligence, contracts, data security, access and audit rights, subcontracting, monitoring, business continuity, concentration, and exit across outsourcing and third-party arrangements.

What the authority establishes

SS2/21 sets expectations for governance, materiality, pre-contract assessment, due diligence, contracts, data security, access and audit rights, subcontracting, monitoring, business continuity, concentration, and exit across outsourcing and third-party arrangements.

The statement is an operating blueprint for material third-party governance. Its future version also supports expanded notification and register reporting, making data quality, relationship classification, subcontractor visibility, and retained evidence central buyer requirements.

The record is written for operational interpretation, not legal advice. Applicability depends on entity type, jurisdiction, relationship, service, data, criticality, contractual commitments, and later authority guidance.

Who should read it

The primary audiences named in this review are UK banks, building societies, insurers, and investment firms within PRA scope, outsourcing and third-party risk leaders, operational-resilience, procurement, legal, compliance, and audit teams, material third-party providers serving PRA-regulated firms. Those roles may divide responsibility differently, but the operating record should still show scope, accountable ownership, evidence, review, exceptions, and the final decision.

Third-party lifecycle implications

Governance

Teams should determine what this authority expects at the governance stage, which function owns the judgment, what evidence must be retained, and what later change would reopen the record.

Materiality Assessment

Teams should determine what this authority expects at the materiality assessment stage, which function owns the judgment, what evidence must be retained, and what later change would reopen the record.

Due Diligence

Teams should determine what this authority expects at the due diligence stage, which function owns the judgment, what evidence must be retained, and what later change would reopen the record.

Contracting

Teams should determine what this authority expects at the contracting stage, which function owns the judgment, what evidence must be retained, and what later change would reopen the record.

Register Reporting

Teams should determine what this authority expects at the register reporting stage, which function owns the judgment, what evidence must be retained, and what later change would reopen the record.

Ongoing Monitoring

Teams should determine what this authority expects at the ongoing monitoring stage, which function owns the judgment, what evidence must be retained, and what later change would reopen the record.

Subcontractor Oversight

Teams should determine what this authority expects at the subcontractor oversight stage, which function owns the judgment, what evidence must be retained, and what later change would reopen the record.

Continuity And Exit

Teams should determine what this authority expects at the continuity and exit stage, which function owns the judgment, what evidence must be retained, and what later change would reopen the record.

Capabilities that may support the work

These links identify relevant operating capabilities; they do not state that any product creates compliance.

Intake And Inventory

establishing an accountable record of relationships, products, owners, and critical services. Buyers should test the workflow against their own scope and evidence requirements.

Inherent Risk Tiering

using relationship context to determine proportional diligence and review. Buyers should test the workflow against their own scope and evidence requirements.

Due Diligence And Assessments

collecting and reviewing evidence before and during a relationship. Buyers should test the workflow against their own scope and evidence requirements.

Evidence Collection

preserving source material, responses, and reviewer context. Buyers should test the workflow against their own scope and evidence requirements.

Continuous Monitoring

bringing material external and internal change into an owned response workflow. Buyers should test the workflow against their own scope and evidence requirements.

Issue Remediation

assigning findings, deadlines, exceptions, and closure evidence. Buyers should test the workflow against their own scope and evidence requirements.

Fourth-Party Visibility

identifying and explaining important downstream dependencies. Buyers should test the workflow against their own scope and evidence requirements.

Regulatory Mapping

connecting program records to obligations and examination needs. Buyers should test the workflow against their own scope and evidence requirements.

Reporting

turning program activity into operator, executive, and board-ready information. Buyers should test the workflow against their own scope and evidence requirements.

Offboarding

closing access, data, evidence, and residual obligations when a relationship ends. Buyers should test the workflow against their own scope and evidence requirements.

What software cannot decide

Software can structure records, route work, preserve evidence, surface change, and support reporting. It cannot determine legal applicability, set risk appetite, negotiate accountable contract terms, validate every external claim, accept residual risk, or make management responsible for an outcome. Those remain organizational decisions.

Related market changes

APRA CPS 230 enters force

Australian prudential entities now need a governed operating record that joins material service-provider data with operational-resilience decisions.

APRA finalizes targeted CPS 230 amendments

Exception management and regulatory reporting depend on versioned rules, relationship facts, accountable approval, and governed source data.

PRA finalizes material third-party notification and register reporting

Firms have a defined period to reconcile relationship, service, materiality, contract, and resilience data across internal systems.