TPRM glossary

Critical third party, a designation, not a description

A critical third party is a provider whose failure would threaten the stability of a whole financial system rather than one firm, and which regulators have therefore designated for direct oversight. In the UK, HM Treasury designates; under DORA, the European Supervisory Authorities do. It is a formal status, not a synonym for an important vendor. Also called CTP, Critical ICT third-party service provider.

Two meanings, and only one of them is regulatory

Internally, most firms call a vendor critical when its failure would stop a business service. That is a tiering judgement, made by you, using your own criteria, and it drives how much diligence the vendor gets.

The regulatory meaning is narrower and is not yours to make. It applies where a provider is systemically important across many firms — the cloud platforms, payment infrastructure and core banking providers a sector concentrates on — and designation brings that provider itself into scope for direct requirements and supervision. In the UK, HM Treasury designates critical third parties and the Bank of England, PRA and FCA set the rules, which took effect at the start of 2025. Under DORA, the ESAs designate critical ICT third-party service providers and one of them acts as Lead Overseer.

What designation changes for you

Less than firms expect. Designation puts obligations on the provider; it does not transfer your own. You remain accountable for the outsourced service, for your exit arrangements, and for the resilience of the business service the provider supports. Supervisors have been consistent that a designated provider is not a provider you may stop managing.

What it does change is what you can rely on. Designated providers face direct oversight and testing, which improves the evidence available to you and reduces the argument about whether a hyperscaler will complete your questionnaire. The obligation to understand your own concentration in that provider is unaffected.

Common questions

Who decides that a third party is critical?
In the UK, HM Treasury makes the designation on a recommendation from the Bank of England, PRA or FCA. Under DORA, the European Supervisory Authorities designate critical ICT third-party service providers and appoint a Lead Overseer. Neither is something a firm decides for itself.
Does a designated critical third party still need assessing?
Yes. Designation adds supervision of the provider; it does not remove your accountability for the service you have outsourced, your exit plan, or your own concentration in it. Regulators have been explicit that outsourcing a function does not outsource responsibility for it.
Is "critical third party" the same as our internal critical tier?
No, and conflating them causes real confusion in reporting. Your critical tier is your own judgement about business impact. A critical third party is a formal regulatory designation applying to a handful of systemically important providers. Most vendors in your critical tier will never be designated.

Definitions are the easy part. Evidence is not.

See what your vendors actually expose — scored, monitored and evidenced in one place.