For Gibraltar-based entities, 2026 is also the year for full implementation. The Financial Services (Operational Resilience) Regulations 2023 established a transition period that culminates in a hard compliance deadline of July 2026.
By 13 July 2026, firms must have:
- Full Mapping: Fully mapped all people, processes, technology, facilities, and information necessary to deliver their Important Business Services (IBS).
- Rigorous Testing: Conducted rigorous scenario testing to prove they can remain within impact tolerances.
- Vulnerability Resolution: Addressed and remediated any vulnerabilities identified during the mapping and testing phases.
The GFSC has announced thematic reviews, which will intensely scrutinise the rationale behind IBS identification and the rigour of scenario testing.
For EU operations, 2026 marks the move into the advanced assurance phase of DORA, following the application date of 17 January 2025.
The regulatory demand is now for “provable resilience.” Boards must demand evidence from severe but plausible scenario tests that prove the firm can maintain its most critical services through a crisis.
Board members must be able to answer crucial questions: “What have we tested, what broke when we tested it, and what is our certified tolerance for failure?”
While these resilience mandates hold firms accountable for their entire value chain, regulators have recognised a critical vulnerability that individual firms cannot solve alone: the systemic risk posed by the handful of tech giants upon which the entire sector depends.
Critical Third Parties (Major Cloud, AI & IT providers)
In a seismic shift for the financial services supply chain, regulators are no longer limiting their oversight to the firms they license.
Under powers granted by the Financial Services and Markets Act 2023, UK financial regulators have established a new regime for “Critical Third Parties” (CTPs), granting them direct statutory powers to oversee the technology and service providers deemed critical to the stability of the financial system.
This means that for the first time, major cloud companies and other key technology providers can be directly supervised by financial regulators like the Bank of England and the PRA. They will be required to meet minimum resilience standards and are subject to information requests, skilled person reviews, and enforcement action. This is a landmark change because it directly addresses the systemic concentration risk created by the entire financial sector’s reliance on a small number of powerful tech giants.
The strategic implication is that third-party risk is no longer a bilateral negotiation between firm and supplier but a trilateral relationship with a regulator also a key counterparty. For firms, this provides a new layer of assurance, but it also means their critical suppliers are now subject to direct intervention that could reshape service delivery, pricing, and contractual terms in ways previously unimaginable.

Consumer Duty
The new Consumer Duty also impacts all firm’s distribution chains and business partners involved in the construction or delivery of financial services products. See here for a detailed overview of the Consumer Duty regime for UK and Gibraltar firms.
Consumer Duty Compliance for Gibraltar and UK Payment Service Providers
Regulators Now Have “X-Ray Vision” Into Your Supply Chain: The New Perimeter
Regulators are surgically excising ambiguity about where responsibility lies in complex value chains through a “look-through” supervisory approach. This includes on-site inspections of any material outsourced functions such as financial crime controls but also looks at how the adequacy of the business partner’s governance frameworks.
Under this model, the authorised firm is held fully accountable for the entire ecosystem operating under its licence, including the actions of its partners and their subcontractors. This approach is particularly critical in complex structures like the BIN Sponsorship model, where a licensed sponsor provides its licence and scheme access to third-party Program Managers, making the sponsor unequivocally accountable for the entire ecosystem operating under its name.
In some cases, UK and Gibraltar firms seeking to use new categories of service provider within their core infrastructure or distribution supply chain may find that this also triggers a material change notification on the basis that is might impact their ability to continue to meet the threshold conditions for authorisation:
- In Gibraltar, under Section 83A of the Financial Services Act 2019, regulated firms have a mandatory obligation to obtain the GFSC’s consent for any “material change” to their business plan, financial resources, or corporate governance arrangements and even if a proposed relationship does not meet this threshold firms are still required to notify such arrangements under the 12th Core Principle (open and cooperative dealing);
In the UK under SYSC 13.9.and SUP 15.3, firms are generally required to notify the regulator when they intend to enter into or significantly change a material outsourcing arrangement and for changes that impact resources, management, supervision or integrity.
The message from regulators is unambiguous: the perimeter of responsibility is expanding. It is pushing outwards from the regulated firm into its supply chain and downwards into the operational details of its partners. The corporate veils that once separated a firm from its suppliers are becoming increasingly transparent to supervisory scrutiny.
This evolution demands more than just stronger contracts and better due diligence. It requires a cultural shift where third-party risk management is elevated to a core strategic function, owned and understood at the board level.
The critical question for firms is no longer “Who does this work for us?” but “How do we prove we are in control of our entire, end-to-end value chain, from our boardroom to the data centre?”
Answering that question is the new benchmark for operational excellence and the ultimate determinant of which firms will be trusted to operate in this new, supply chain transparent era.