Skip to Content
Financial Regulatory Developments Focus

Filters
The following posts provide a snapshot of selected UK, EU and global financial regulatory developments of interest to banks, investment firms, broker-dealers, market infrastructures, asset managers and corporates.
  • UK Approach to Critical Third-Party Supplier Designation Published
    03/31/2024

    The Financial Services and Markets Act 2023 established a framework for the regulation of third parties who provide significant services to financial institutions, giving HM Treasury power to designate an entity as a "critical third party" if its failure would pose financial stability or confidence risk to the U.K. We discussed this in our client note, "The U.K.'s New Regime for Critical Third Party Supervision". HM Treasury published on March 21, 2024, its policy approach to designation of critical third parties.

    When designating CTPs, HM Treasury is required by the FSM Act 2023 to consider the materiality of the third party's services to the delivery of essential activities, services or operations in the financial sector as well as the number and type of licensed firms to which the services are provided. This is a process where HM Treasury carries out the designation; a "critical third party" is not a status that firms would apply for. The policy paper sets out the process for designation, including receipt of a recommendation from one of the financial regulators and assessment of the basis for making a designation decision. HM Treasury discusses how it will engage with the relevant third-party service provider and the regulators, including communicating its decision. The process for de-designating a critical third party is also described.

    Read more.
  • UK Regulators Propose Rules for Supervising Critical Third Parties
    12/12/2023

    Following feedback to their July discussion paper, the U.K. regulators—the Bank of England, Prudential Regulation Authority and Financial Conduct Authority—have launched a joint consultation proposing rules and regulatory expectations for critical third parties. This follows concerns that the financial sector relies heavily on unregulated service providers, particularly in the IT sector, for critical infrastructure whose failure could cause systemic issues or customer issues. The Financial Services and Markets Act 2023 gave HM Treasury powers to designate an entity as a "critical third party" if its failure would pose financial stability or confidence risk to the U.K. and the regulators will have new direct powers over third parties that provide critical services to authorized firms, their service providers and financial market infrastructures. The regulators' rules would only apply to the services provided by a CTP to one of those firms. Responses to the consultation may be submitted until March 15, 2024.

    Read more.
  • First Commencement Regulations Under UK Financial Services and Markets Act 2023
    08/03/2023

    The Financial Services and Markets Act 2023 (Commencement No. 1) Regulations 2023 were made on July 10, 2023 and will bring into force provisions under the Financial Services and Markets Act 2023 (which we discuss in our client note, "A Boost for U.K. Financial Services: The U.K. Financial Services and Markets Act 2023") from either July 11, 2023, August 29, 2023 or January 1, 2024.

    Read more
  • UK Regulators Propose Requirements for Critical Third Parties' Services to UK Regulated Firms
    07/21/2022

    The Bank of England, Prudential Regulation Authority and Financial Conduct Authority (together, the supervisory authorities) have published a discussion paper proposing measures to supervise and enhance the resilience of critical third parties (CTPs) to the U.K. financial sector. Responses to the discussion paper may be submitted until December 23, 2022. The supervisory authorities intend to consult on proposed requirements for CTPs in 2023.

    Currently, the supervisory authorities' direct powers over entities providing critical services to U.K. authorized firms, their service providers (authorized e-money institutions, payment institutions and registered account information services) and financial market infrastructures (together, U.K. regulated firms) are limited. The Financial Services and Markets Bill, introduced to Parliament yesterday, would grant HM Treasury and the supervisory authorities' new express powers to oversee such third parties. HM Treasury will be able to designate an entity as a CTP if it provides services to U.K. regulated firms and its failure would pose financial stability or confidence risk to the U.K.

    Read more.
  • European Systemic Risk Board Publishes Recommendation on Pan-European Systemic Cyber Incident Coordination Framework
    01/27/2022

    The European Systemic Risk Board has published a Recommendation on a pan-European systemic cyber incident coordination framework for EU national regulators. The ESRB observes that major cyber incidents may pose a systemic risk to the financial system, as they are capable of disrupting critical financial services and operations. This could in turn lead to contagion or an erosion of confidence in the financial system. The COVID-19 pandemic has also brought the threat of cyber incidents to the fore, as the number of cyber incidents reported to the ECB increased by 54% between 2019 and 2020. The Recommendation aims to build on the proposed roles of the European Supervisory Authorities under the EU's proposed Regulation on digital operational resilience for the financial sector. DORA is intended to strengthen digital operational resilience considering the risks arising from the increase in digital opportunities within the financial sector.

    Read more.
  • European Supervisory Authorities Publish Joint Response on Proposed EU Digital Operational Resilience Act
    02/09/2021

    The European Supervisory Authorities (the European Securities and Markets Authority, the European Banking Authority and the European Insurance and Occupational Pensions Authority) have published a letter to the European Parliament, the Council of the European Union and the European Commission, setting out responses to the proposed EU Digital Operational Resilience Act, a new piece of EU regulation on digital operational resilience for the financial sector. The European Commission first published the draft DORA in September 2020. It forms part of the European Commission's digital finance strategy, which aims to embrace digital finance for the benefit of consumers and businesses while ensuring digital transformation is soundly regulated. The DORA is particularly focused on combatting risks arising from information and communication technologies in order to protect operational resilience and the performance of the financial system.

    Read more.
  • European Commission Proposals for Digital Operational Resilience Regulation and Amending Directive
    09/24/2020

    The European Commission has published proposals for a new EU Regulation on digital operational resilience for the financial sector and a new EU Directive amending certain pieces of existing EU financial services legislation to strengthen digital operational resilience and provide legal certainty on crypto-assets. The new legislation has been proposed as a result of the risks arising from the increase in digital opportunities within the financial sector. There are currently no detailed rules at EU level on digital operational resilience, exposing the need for comprehensive and harmonized legislation governing this area.

    Read more.
  • Basel Committee on Banking Supervision Proposes Principles for Operational Risk
    08/06/2020

    The Basel Committee on Banking Supervision has opened a consultation on proposed principles for operational resilience and updated Principles for the Sound Management of Operational Risk (PSMOR). The consultation closes on November 6, 2020.

    Read more.
  • UK Conduct Regulator Update on COVID-19 Response and 2020 Expectations
    06/04/2020

    The U.K. Financial Conduct Authority’s Executive Director of Supervision for Investment, Wholesale and Specialists, Megan Butler, has given a speech setting out the FCA’s current priorities, its expectations of firms during the COVID-19 pandemic and the outcomes it is focusing on for the wealth management sector, as well as the future priorities for financial regulation.
     
    The FCA initially prioritized immediate relief for firms and consumers, including on mortgages and unsecured lending products, at the outset of the COVID-19 crisis, but is now looking at how it will respond to the challenges of COVID-19 on a more long-term basis. This longer-term approach includes ensuring a good level of operational resilience (in line with the FCA’s ongoing consultation on that topic), that markets can continue to function well, that customers are treated fairly and protected from scams and that the FCA understands firms’ financial resilience so that they can fail in an orderly manner. 

    Read more.
  • UK Regulators Launch Consultation on Operational Resilience in Financial Services
    12/05/2019

    The Bank of England, U.K. Prudential Regulation Authority and U.K. Financial Conduct Authority have published a shared policy summary and consultation papers on strengthening operational resilience in the financial services sector. The consultation impacts banks, building societies, PRA-designated investment firms, firms subject to the Solvency II Directive, recognized investment exchanges, CCPs, central securities depositories, payment system operators, FCA enhanced scope SM&CR firms and entities authorized and registered under the Payment Services Regulations 2017 and Electronic Money Regulations 2011. Responses to the consultation should be submitted by April 3, 2020.

    Read more.
  • UK Parliamentary Committee Launches Inquiry Into Operational Resilience in the Financial Services Sector
    11/23/2018

    The U.K. Treasury Committee has announced the launch of a new Inquiry into IT failures in the financial services sector. The Inquiry has been launched in response to recent IT failures at a number of financial institutions that have led to consumers being unable to access their bank accounts or becoming subject to fraud.

    The Committee will assess the causes and consequences of these recent IT failures. Among other things, the Committee will consider the extent to which such incidents are becoming more frequent, sources of concentration risk in the financial sector, the impact of legacy IT systems, the effect of outsourcing on operational resilience, best practices in responding to operational incidents and whether the U.K. regulators are able to regulate firms' capabilities for responding to such incidents.

    Written submissions can be made to the Committee by January 18, 2019. The Committee will also appoint a special advisor to provide policy advice to the Committee on the issues. Individuals interested in the role should respond to the call for Expressions of Interest.

    View the announcement.
  • UK Regulators Seek Views on Improving Operational Resilience of Firms and Financial Market Infrastructures
    07/05/2018

    The Bank of England, the U.K. Prudential Regulation Authority and the U.K. Financial Conduct Authority have published a joint discussion paper entitled "Building the UK financial sector’s operational resilience." The Discussion Paper is aimed at opening a dialogue with the financial services industry on achieving what the Authorities view as a "step change" in the operational resilience of firms and Financial Market Infrastructures and at generating debate about the expectations regulators and the wider public might have of the operational resilience of financial services institutions.

    While the existing regulatory framework already supports operational resilience, the BoE, PRA and FCA are together considering the extent to which they might supplement existing policies, to improve the resilience of the financial system as a whole and increase the focus on operational resilience within firms and FMIs.

    Read more.