Skip to main content
Checklist4 min read

FCA Outsourcing Due-Diligence Checklist

22-item checklist for UK FCA-regulated firms evaluating outsourcing providers. Covers governance, data protection, operational resilience, and exit planning.

ChecklistAAbdi Mohamed4 min read
Summarise with AI

This practical checklist is for UK firms assessing an outsourcing or third-party arrangement. FCA requirements vary by firm type, permission, activity, and whether the arrangement is material, critical, important, or supports an important business service. Use the checklist with the rules and guidance that apply to your firm.

Outsourcing does not transfer regulatory accountability. The firm remains responsible for managing the arrangement, protecting customers, maintaining operational resilience, and giving the FCA the information and access it is entitled to receive.

This article is general information, not legal advice. Compliance and legal teams should confirm the applicable Handbook provisions and sector-specific rules before contracting.

Official references

FCA: Outsourcing and operational resilience

FCA Handbook: SYSC 8 Outsourcing

FCA Handbook: SUP 15 Notifications

FCA: PS21/3 Building operational resilience

FCA: Consumer Duty

ICO: International transfers

The FCA states that new operational-incident and third-party reporting requirements take effect on 18 March 2027. Firms should track implementation and assess the new obligations before that date.

The 22-item due-diligence checklist

0 of 22 completed

0%

1

1. Governance — Name the accountable executive and operational owner.

Record who approves the arrangement, who manages it day to day, who challenges performance, and how issues reach the appropriate committee or board.

2

2. Governance — Define the business purpose and expected customer or operational outcome.

Describe the problem being solved, the service boundary, expected benefits, affected customers, and the evidence that will show whether the arrangement works.

3

3. Governance — Apply the firm’s own outsourcing and third-party policy.

Confirm the policy, risk appetite, approval route, record keeping, review cycle, and any enhanced requirements for higher-risk arrangements.

4

4. Governance — Check conflicts, incentives, and concentration at group level.

Consider related-party arrangements, commercial incentives, common subcontractors, geographic concentration, and dependency on the same technology or facility.

5

5. Classification — Decide whether the arrangement is outsourcing and which rules apply.

Map the activity against the FCA definition and the rules applicable to the firm’s type and permissions. Do not assume every third-party service is outsourcing—or that non-outsourcing services are risk-free.

6

6. Classification — Assess materiality, criticality, importance, and regulatory notification.

Document the classification and check the applicable notification route and timing, including Principle 11, SUP 15, sector rules, and the third-party reporting requirements due from 18 March 2027.

7

7. Classification — Identify important business services and impact tolerances.

Where the provider supports an important business service, map the dependency and confirm how provider failure could affect the firm’s ability to remain within its impact tolerance.

8

8. Provider — Verify legal identity, ownership, permissions, and operating locations.

Confirm the contracting entity, beneficial ownership, registrations, service locations, data locations, and any regulatory status relevant to the outsourced activity.

9

9. Provider — Assess financial and operational viability.

Review evidence proportionate to the risk: financial statements, insurance, staffing capacity, key-person dependency, business model, and ability to continue through disruption.

10

10. Provider — Test competence, staffing, vetting, and training.

Verify role requirements, screening, references, professional credentials, supervision, training, quality assurance, staff turnover controls, and replacement arrangements.

11

11. Provider — Review information security, technology, and physical controls.

Assess identity and access management, encryption, logging, endpoint controls, secure development where relevant, vulnerability management, incident response, workplace security, and independent assurance.

12

12. Contract — Put the scope, responsibilities, and service levels in writing.

Define services, locations, hours, inputs, outputs, acceptance criteria, performance measures, reporting, escalation, charges, change control, and responsibility for customer outcomes.

13

13. Contract — Preserve information, audit, inspection, and regulatory access rights.

Where applicable, ensure the firm, its auditors, the FCA, and other competent authorities can obtain information and effective access to relevant data and premises.

14

14. Contract — Control subcontracting and material service changes.

Require disclosure and an agreed approval or notification process for subcontractors, location changes, control changes, and developments that may materially affect delivery or compliance.

15

15. Contract — Set termination, continuity, cooperation, and confidentiality terms.

Include termination rights, cooperation with regulators, protection of confidential information, continuity during termination, assistance, data return or destruction, and transition responsibilities.

16

16. Data — Map personal, confidential, and regulated information.

Record categories, systems, locations, users, purposes, retention, onward disclosures, privileged or special-category data, and the minimum access needed.

17

17. Data — Put UK GDPR processor and international-transfer arrangements in place.

Where applicable, execute Article 28 terms. For a restricted transfer, select a lawful transfer route; if relying on an appropriate safeguard, complete the required transfer risk assessment or data protection test and apply additional measures.

18

18. Data — Agree security-incident and personal-data-breach procedures.

Define immediate containment and escalation, information the provider must supply, decision rights, evidence preservation, regulatory assessment, customer communications, testing, and notification timeframes that support the firm’s legal duties.

19

19. Resilience — Review business continuity and disaster recovery.

Confirm recovery objectives, alternative facilities and connectivity, backup arrangements, staffing contingencies, crisis contacts, dependency maps, test evidence, and remediation of failed tests.

20

20. Resilience — Test severe but plausible provider-failure scenarios.

Include cyberattack, loss of site or connectivity, data corruption, critical subcontractor failure, provider insolvency, sudden staff loss, and an extended outage. Test the firm’s response, not only the provider’s plan.

21

21. Oversight — Define management information, assurance, and customer-outcome monitoring.

Set thresholds and trends for quality, timeliness, incidents, complaints, vulnerable-customer outcomes where relevant, rework, staff capacity, control failures, and remediation. Review the evidence at a frequency proportionate to risk.

22

22. Exit — Approve a tested exit and substitution plan before dependency becomes critical.

Specify exit triggers, decision authority, notice, transition resources, data extraction, knowledge transfer, access revocation, records retention, alternative providers or in-house options, customer communications, and continuity during transition.

Save this checklist

Print or save this page as a PDF to keep your checklist handy.

Key takeaways

1

FCA requirements vary by firm type, permission, activity, and the arrangement’s classification.

2

Outsourcing does not transfer the regulated firm’s accountability to the provider.

3

Contracts, access rights, data transfers, resilience, outcome monitoring, and exit all need proportionate evidence.

4

New FCA operational-incident and third-party reporting requirements take effect on 18 March 2027.

WE ARE TREBA

Need a diligence-ready delivery proposal?

We’ll document the operating model, scope, controls, service levels, data flows, governance, and exit assumptions for your team to assess.