What Good Supplier Assurance Looks Like for Financial Services Firms

Supplier assurance

Good supplier assurance means having continuous, evidence-based confidence that a third-party can deliver the service it promised, protect the data it holds and keep operating through disruption. For a mid-tier bank, building society or insurer, that confidence must be provable to the FCA or PRA on request, not just felt internally by the procurement team.

Supplier assurance has moved from a contracting exercise to an ongoing regulatory obligation. DORA, SS2/21 and the FCA's operational resilience regime all treat third-parties as an extension of the firm itself, which means a weak supplier can become the firm's own weak point. This blog post sets out what good assurance actually looks like in practice and where most mid-tier firms still fall short.

 

What is supplier assurance in financial services?

Supplier assurance is the ongoing process of checking that a third or fourth-party can meet the operational, security and regulatory standards a financial services firm has committed to and having the evidence to prove it. It covers the full relationship, from due diligence before a contract is signed through to exit planning when it ends.

It is different from procurement. Procurement asks whether a supplier is good value and fit for purpose commercially. Assurance asks whether the supplier can be trusted with the firm's data, operations and regulatory obligations, and whether that trust can be evidenced to a regulator, auditor or the Board.

 

Why does supplier assurance matter more now?

Supplier assurance matters more now because regulation has closed the gap between what a firm does itself and what it outsources. Under DORA and the FCA's third-party oversight expectations, a firm cannot point to a supplier's failure as an excuse. The regulatory question is always the same: what did the firm do to know this could happen, and what did it do to stop it mattering?

For building societies, mid-tier banks and insurers, this shift has landed hardest. Many rely on a small number of critical suppliers for core banking platforms, payments, cloud hosting or claims processing, often without the internal resourcing that larger banks have for supplier oversight.

The Cyber security breaches survey 2025/2026 found that "just over one in ten businesses said they reviewed the risks posed by their immediate suppliers (15%) and under one in ten were looking at their wider supply chain (6%)".

A single supplier outage can now trigger an important business services impact assessment, a customer harm review and a regulatory notification, all from one contract that may never have been formally risk assessed.

 

What does good supplier assurance actually look like?

Good supplier assurance rests on five things working together: proportionate categorisation, evidence-based due diligence, ongoing monitoring rather than annual reviews, clear ownership and tested exit plans.

  1. Proportionate categorisation: Not every supplier needs the same scrutiny. Good assurance starts by mapping suppliers against the services they support, identifying which sit behind an important business service or hold sensitive customer data, and applying a level of due diligence that matches that risk. A stationery supplier does not need the same assurance as a core banking platform provider - treating them the same wastes effort.

  2. Evidence-based due diligence: A supplier's word that it has appropriate controls is not assurance. Good practice means requesting and reviewing actual evidence, such as SOC 2 reports, penetration test summaries, business continuity test results and financial stability checks, before a contract is signed and at defined intervals afterward. Firms that do this well build a standard evidence pack requirement into procurement, rather than chasing documents reactively when a regulator asks for them.

  3. Ongoing monitoring: Annual supplier reviews are no longer sufficient for critical relationships. Good assurance treats critical suppliers the way a firm treats its own operations, with defined metrics, incident reporting expectations and a live view of the supplier's financial and operational health between formal reviews. This is where most mid-tier firms still fall short, because ongoing monitoring is resource intensive without the right tools or a fourth-party mapping exercise to know what to watch.

  4. Clear ownership: Every critical supplier relationship needs a named owner inside the firm who understands both the commercial relationship and the regulatory obligations attached to it. Where assurance sits solely with procurement or solely with a risk team disconnected from the relationship, gaps appear. Good practice brings risk, resilience and the business owner together, with a single accountable person who can answer for the relationship end to end.

  5. Tested exit plans: A firm should be able to answer, in specific terms, how it would move a critical service away from a supplier if it needed to, and how long that would realistically take. Exit plans that exist only on paper and have never been tested tend to fail exactly when they are needed, during a genuine supplier failure rather than a planned migration.

 

How does supplier assurance connect to operational resilience?

Supplier assurance is the evidence base that operational resilience is built on. A firm cannot credibly set impact tolerances for its important business services without understanding which suppliers sit behind them, and it cannot pass a severe but plausible scenario test if a critical supplier's own resilience has never been checked.

Regulators increasingly ask to see this connection directly. A resilience self-assessment that treats suppliers as a separate workstream, rather than an integrated part of the mapping and testing process, tends to draw follow-up questions. Firms that get this right treat supplier assurance and operational resilience as one continuous discipline, not two separate compliance exercises run by different teams.

 

What should a mid-tier firm do first if its supplier assurance is behind?

The first step is an honest inventory: which suppliers exist, which of them are critical to an important business service or hold sensitive data, and which have never had a proper risk assessment. Most firms find this list is smaller and more manageable than expected once it is broken down by actual risk rather than spend or contract volume.

From there, the priority is closing the evidence gap on the highest-risk suppliers first, rather than trying to bring every supplier up to the same standard at once. A firm that can demonstrate strong, evidenced oversight of its five most critical suppliers is in a far stronger regulatory position than one with a thin, generic review process applied evenly across two hundred.

Good supplier assurance is not a document sitting in a folder for when the regulator asks. It is a live, evidenced discipline that tells a firm, at any point, exactly how exposed it is through the suppliers it depends on, and what it would do about it.

 

Where we can help

Most mid-tier financial services firms already know which suppliers they rely on. Few know, with evidence, exactly how exposed they are through them.

We help mid-tier banks, building societies and insurers build that picture - from supplier categorisation and due diligence through to exit planning and testing, so that assurance holds up under regulatory scrutiny rather than just internal sign-off.

If you want a clear view of where your supplier assurance stands today, our third-party risk specialists can walk through it with you.

See more...