Good supplier assurance means having continuous, evidence-based confidence that a third-party can deliver the service it promised, protect the data it holds and keep operating through disruption. For a mid-tier bank, building society or insurer, that confidence must be provable to the FCA or PRA on request, not just felt internally by the procurement team.
Supplier assurance has moved from a contracting exercise to an ongoing regulatory obligation. DORA, SS2/21 and the FCA's operational resilience regime all treat third-parties as an extension of the firm itself, which means a weak supplier can become the firm's own weak point. This blog post sets out what good assurance actually looks like in practice and where most mid-tier firms still fall short.
What is supplier assurance in financial services?
Supplier assurance is the ongoing process of checking that a third or fourth-party can meet the operational, security and regulatory standards a financial services firm has committed to and having the evidence to prove it. It covers the full relationship, from due diligence before a contract is signed through to exit planning when it ends.
It is different from procurement. Procurement asks whether a supplier is good value and fit for purpose commercially. Assurance asks whether the supplier can be trusted with the firm's data, operations and regulatory obligations, and whether that trust can be evidenced to a regulator, auditor or the Board.
Why does supplier assurance matter more now?
Supplier assurance matters more now because regulation has closed the gap between what a firm does itself and what it outsources. Under DORA and the FCA's third-party oversight expectations, a firm cannot point to a supplier's failure as an excuse. The regulatory question is always the same: what did the firm do to know this could happen, and what did it do to stop it mattering?
For building societies, mid-tier banks and insurers, this shift has landed hardest. Many rely on a small number of critical suppliers for core banking platforms, payments, cloud hosting or claims processing, often without the internal resourcing that larger banks have for supplier oversight.
The Cyber security breaches survey 2025/2026 found that "just over one in ten businesses said they reviewed the risks posed by their immediate suppliers (15%) and under one in ten were looking at their wider supply chain (6%)".
A single supplier outage can now trigger an important business services impact assessment, a customer harm review and a regulatory notification, all from one contract that may never have been formally risk assessed.
What does good supplier assurance actually look like?
Good supplier assurance rests on five things working together: proportionate categorisation, evidence-based due diligence, ongoing monitoring rather than annual reviews, clear ownership and tested exit plans.
How does supplier assurance connect to operational resilience?
Supplier assurance is the evidence base that operational resilience is built on. A firm cannot credibly set impact tolerances for its important business services without understanding which suppliers sit behind them, and it cannot pass a severe but plausible scenario test if a critical supplier's own resilience has never been checked.
Regulators increasingly ask to see this connection directly. A resilience self-assessment that treats suppliers as a separate workstream, rather than an integrated part of the mapping and testing process, tends to draw follow-up questions. Firms that get this right treat supplier assurance and operational resilience as one continuous discipline, not two separate compliance exercises run by different teams.
What should a mid-tier firm do first if its supplier assurance is behind?
The first step is an honest inventory: which suppliers exist, which of them are critical to an important business service or hold sensitive data, and which have never had a proper risk assessment. Most firms find this list is smaller and more manageable than expected once it is broken down by actual risk rather than spend or contract volume.
From there, the priority is closing the evidence gap on the highest-risk suppliers first, rather than trying to bring every supplier up to the same standard at once. A firm that can demonstrate strong, evidenced oversight of its five most critical suppliers is in a far stronger regulatory position than one with a thin, generic review process applied evenly across two hundred.
Good supplier assurance is not a document sitting in a folder for when the regulator asks. It is a live, evidenced discipline that tells a firm, at any point, exactly how exposed it is through the suppliers it depends on, and what it would do about it.
Where we can help
Most mid-tier financial services firms already know which suppliers they rely on. Few know, with evidence, exactly how exposed they are through them.
We help mid-tier banks, building societies and insurers build that picture - from supplier categorisation and due diligence through to exit planning and testing, so that assurance holds up under regulatory scrutiny rather than just internal sign-off.
If you want a clear view of where your supplier assurance stands today, our third-party risk specialists can walk through it with you.