ICAEW Registered Auditors  ·  90+ UK-Based Experts

Financial Services Outsourcing and Accountability

AC
Acumon Chartered Accountants ·5 min read

The rule that governs outsourcing in financial services is one sentence long and disposes of most arguments about it. Where a firm outsources critical or important operational functions, "it remains fully responsible for discharging all of its obligations". You can outsource the activity. You cannot outsource the accountability.

SYSC 8: the outsourcing rules

Chapter 8 of the FCA's Senior Management Arrangements, Systems and Controls sourcebook sets the framework. The opening rule requires a firm relying on a third party for operational functions critical to its regulated activities to take reasonable steps to avoid undue additional operational risk, and not to outsource important operational functions in a way that materially impairs the quality of its internal control or the FCA's ability to monitor its compliance.

The definition of what counts is the test that matters. A function is critical or important if a defect or failure in its performance would materially impair the firm's continuing compliance with its obligations, its financial performance, or the soundness or continuity of its services. Note what that excludes and includes: it is not about contract value, and a cheap arrangement can be critical.

The rules also carve out functions that are not critical or important — advisory services, legal advice, staff training and standardised market information services among them.

The obligations that attach

Where an arrangement is in scope, SYSC 8 requires:

  • Due skill, care and diligence in entering into, managing and terminating the arrangement;
  • A capable provider — one with the ability, capacity, organisational structure and any authorisation required to perform the function reliably and professionally;
  • A written agreement clearly allocating the respective rights and obligations of both parties;
  • Retained rights of information, audit and inspection, and access to the relevant premises and records;
  • Retained expertise inside the firm, sufficient to supervise the function and manage its risks;
  • An exit that works — the ability to terminate without detriment to the continuity and quality of service to clients.

Two consequences are stated expressly and are worth quoting at anyone who thinks outsourcing transfers risk. Outsourcing must not relieve senior management of their responsibility, must not alter the firm's relationship with and obligations to its clients, and must not prejudice the conditions of its authorisation.

There is also a notification expectation. Guidance in SYSC 8, read with the supervision manual, says a firm should notify the FCA when it intends to rely on a third party for critical or important operational functions — material outsourcing is a matter of serious regulatory impact under Principle 11.

Operational resilience: a separate regime with a date that has passed

Firms routinely conflate outsourcing with operational resilience. They are different chapters with different scopes.

SYSC 15A applies to enhanced scope senior managers regime firms, banks, designated investment firms, building societies, Solvency II firms, recognised investment exchanges, e-money institutions, payment institutions and others. It requires a firm to:

  • Identify its important business services — and to treat each distinct service separately rather than bundling a collection of services into one;
  • Set an impact tolerance for each — the maximum tolerable level of disruption;
  • Map the people, processes, technology, facilities and information necessary to deliver each service;
  • Carry out scenario testing of its ability to remain within tolerance during a severe but plausible disruption;
  • Maintain a written self-assessment, updated regularly and retained for at least six years.

The rules came into force on 31 March 2022, and firms had until 31 March 2025 to be able to operate within their impact tolerances. That deadline has gone. Mapping and testing were supposed to be done, and the investment made, before it. A firm still describing this as a programme rather than a steady state is late.

Critical third parties

The newest layer changes who the regulator can act against. The Bank of England, PRA and FCA jointly published the critical third parties regime, with rules in force from 1 January 2025 and a new sourcebook in the FCA Handbook.

The purpose is systemic: statutory powers to raise the resilience of services that designated third parties provide to firms and market infrastructures, reducing the risk of sector-wide disruption. Two points are commonly misunderstood.

Designation is HM Treasury's decision. The regulators may recommend third parties for designation, but the Treasury decides.

It does not displace your own obligations. The regime applies to the designated provider. A firm using a designated cloud or data provider still owes everything SYSC 8 and SYSC 15A require of it. If anything, the existence of the regime is evidence that the concentration risk is real.

Insurers: a different chapter again

One frequent error deserves naming. SYSC 13 is the operational risk chapter for insurers — it applies to insurers other than non-directive friendly societies, UK insurance special purpose vehicles, and Swiss general insurers for their UK branch activities. It is not the general operational risk chapter for banks and investment firms, and citing it at those firms is a tell.

Its content is useful where it applies: the Basel definition of operational risk as the risk of loss resulting from inadequate or failed internal processes, people and systems or from external events; controls over recruitment, training, segregation of duties and remuneration aligned to risk appetite; IT security framed as confidentiality, integrity and availability; pre-engagement due diligence on outsourcing with contractual auditor and regulator access; documented and regularly tested business continuity; and the observation that insurance may mitigate financial impact but never substitutes for systems and controls.

Where firms actually get caught

In our experience the failures are rarely in the contract. They are in the classification, the intra-group assumption, and the exit.

Classification. A function is scoped out at onboarding as non-critical and never revisited as the business grows around it. The test is about the consequence of failure, and consequences change.

Intra-group arrangements. A service taken from a parent or affiliate is still outsourcing. The written agreement, audit rights and exit plan requirements do not soften because the counterparty shares your letterhead.

The exit that was never tested. A termination right is not an exit plan. The requirement is to be able to terminate without detriment to clients, which means knowing where the data is, in what format, and how long migration takes.

Note also that the PRA maintains its own supervisory expectations on outsourcing and third party risk management for banks, building societies, designated investment firms and Solvency II insurers, and these have been updated more than once. Check the current version and its effective date before relying on a summary.

Acumon supports regulated firms on third party risk through internal audit, financial services audit and risk management work, with governance support where the issue is board oversight rather than contract terms. If your outsourcing register has not been reclassified since it was created, that is the exercise worth doing first.

Get in Touch

Ready for Accountants Who Move Your Business Forward?

Tell us what you need. Within one business day, a qualified accountant will be in touch to talk it through and give you a clear, fixed-fee quote — no obligation.

Visit us1-2 Craven Road, Ealing, London, W5 2UA

Speak to a Specialist

Fill this in and we'll come back to you within one business day.

No obligation. Your details stay private.
Call Now Get in Touch