UKGI Compliance Manual

The rules and principles which apply 

Modern organisations increasingly depend on third-party suppliers to deliver operational, technical and specialist services. While outsourcing can improve efficiency, reduce costs and provide access to technology and expertise, it does not transfer accountability for compliance with FCA regulation or data protection legislation.

Under the UK GDPR and DPA 2018, organisations remain responsible for ensuring that personal data processed on their behalf is handled lawfully, fairly securely and transparently.

SYSC 8.1 sets out the FCA’s (the Regulator’s) rules and guidance for a firm which is outsourcing aspects of its operation or service.

SUP 15.3.8(e) requires firms to inform the Regulator of any new material outsourcing arrangements or any changes to such arrangements.

Further information on general FCA requirements in relation to outsource arrangements can be found in Section A.16.

The FCA have also published guidance for firms to consider when appointing third party IT suppliers which is outlined in Section A.16.2, which should be read in conjunction with the guidance in this section.

One of the earliest considerations should be determining whether the supplier acts as:

  • an independent controller;
  • a processor acting on the firm’s instructions; or
  • a joint controller

This distinction is important because it determines the legal responsibilities of each party and the contractual arrangements required under UK GDPR. Where a supplier acts as a processor, Article 28 UK GDPR requires specific contractual provisions to be included before any processing begins.

How this may affect firms.

Many of the most significant data protection incidents originate with supply chains rather than within organisations themselves. Cloud providers, software vendors, payroll providers, managed service providers, and professional advisers may all have access to personal data or critical systems.

Poor supplier oversight can expose firms to:

  • Personal data breaches
  • Cyber security incidents
  • Regulatory enforcement
  • Contractual disputes
  • Operational disruption

Any of these could lead to the firm experiencing financial losses, reputational damage, and loss of customer confidence. An effective supplier governance framework should therefore be viewed as an integral part of the firms’ risk management and corporate governance arrangements rather than simply a procurement exercise.

Risk Based Approach

Not every supplier presents the same level of risk, for example a company providing office stationery presents a very different risk profile from a cloud hosting provider or outsourced system. A practical starting point is to categorise suppliers according to factors such as:

  • the volume and sensitivity of personal data they access
  • whether they process special category or criminal offence data
  • the criticality of the service being provided
  • the level of access to internal systems
  • reliance on subcontractors
  • overseas processing arrangements; and
  • the potential impact if the supplier experienced a security or operational failure

Higher risk suppliers should receive greater scrutiny both before appointment and throughout the contractual relationship, we therefore recommend that before entering into such arrangements that firms complete a proof-of-concept exercise which examines the proposed arrangements, the extent to which personal data will be processed and the associated risks. We have included a Proof-of-Concept template at Document Download CORE37.

Conducting supplier due diligence

Before entering into a contract, firms should seek sufficient assurance that the supplier is capable of meeting both commercial and regulatory expectations. Due diligence commonly includes reviewing:

  • Organisational structure and financial stability
  • Relevant certifications such as ISO 27001 or cyber essentials
  • Information security policies
  • Privacy governance arrangements
  • Incident management processes
  • Business continuity and disaster recovery arrangements
  • Previous regulatory enforcement or significant security incidents/data breach history
  • Insurance arrangements; and
  • Experience delivering similar services.

The level of due diligence should always be proportionate to the level of risk presented.

Contractual Safeguards

Contracts should do more than describe the commercial relationship, they should establish clear expectations regarding information governance and data protection. Depending on the nature of the services, contract should typically address:

  • scope of processing
  • documented processing instructions
  • confidentiality obligations
  • technical and organisational security measures
  • audit rights
  • incident reporting arrangements
  • business continuity expectations
  • restrictions on subcontracting
  • international transfers
  • retention and deletion of information
  • support with data subject rights requests; and
  • responsibilities at contract termination.

Using standards contractual clauses and approved templates can help promote consistency while ensuring legal requirements are addressed.

Security Expectations

The UK GDPR requires firms to implement appropriate technical and organisational measures to protect personal data. Suppliers should be capable of demonstrating that they have implemented security measures appropriate to the risks associated with their services. Examples include:

  • encryption where appropriate;
  • strong authentication controls;
  • access management;
  • regular vulnerability management;
  • security monitoring;
  • staff awareness training;
  • secure software development practices;
  • logging and audit capabilities; and
  • tested incident response procedures.

Rather than requesting every available policy, firms often obtain better assurance by focusing on evidence that controls are operating effectively. More information on data security arrangements is included in Section K.6.2.

Managing outsource arrangements

Where key business functions are outsourced, governance arrangements should extend beyond the initial procurement exercise. Good practice includes considering the risks associated with:

  • operational resilience;
  • dependency on a single supplier
  • resilience of subcontracting arrangements
  • service continuity
  • regulatory obligations
  • exit planning; and
  • contingency arrangements should services become unavailable.

An exit strategy should be developed before services commence not at the point when a contract ends to be effective.

Firms should also ensure that before engaging overseas suppliers the requirements for international transfers have been considered to ensure an adequate level of protection of data equivalent to that required under UK GDPR. We cover international transfers in further detail in Section K.6.4.; a documented Transfer Risk Assessment (TRA) may be necessary depending on the circumstances. TRAs are explained in Section K.6.1.1..

Ongoing assurance

Supplier assurance should not end once a contract has been signed. Firms are encouraged to establish periodic review arrangements that may include:

  • annual supplier reviews;
  • security assurance updates;
  • review of certifications;
  • audit reports;
  • service performance meetings;
  • review of incidents and complaints;
  • reassessment of supplier risk; and
  • monitoring of contractual obligations.

Higher risk suppliers generally warrant more frequent oversight.

Managing security incidents

Contracts should establish clear reporting arrangements for security incidents affecting organisational information. Suppliers should understand when incidents should be reported and to who. Firms should set out what information it expects to be provided in an incident report and the expected timescales for notification as well as the responsibilities for each of the parties during investigations.

Prompt reporting enables firms to determine whether notification obligations to inform the ICO or FCA may arise. More information on incident reporting can be found in Section K.6.5..

Record Keeping

Maintaining evidence of supplier oversight is an important component of accountability, useful records may include:

  • supplier risk assessments (proof of concept)
  • completed due diligence
  • signed contracts
  • data processing agreements
  • security assessments
  • audit findings
  • supplier review meetings
  • corrective actions; and
  • contract exit plans

Well maintained records assist firms in demonstrating compliance during audits, investigations, or regulatory enquiries.

Firms seeking to strengthen supplier governance may wish to consider the following recommendations:

  • establish a supplier risk classification framework;
  • develop standard due diligence questions;
  • maintain an up-to-date register of suppliers processing personal data;
  • implement standard contractual clauses for processor arrangements;
  • define minimum information security requirements for suppliers;
  • schedule periodic assurance reviews for higher risk providers;
  • integrate supplier oversight into existing risk management processes; and
  • ensure procurement, legal, compliance, and IT teams collaborate throughout the supplier lifecycle.

By adopting a proportionate risk-based approach to supplier management, supported by appropriate contractual safeguards and ongoing assurance, firms can reduce regulatory exposure, improve operational resilience, and demonstrate that information trusted to them is being managed responsibly throughout the supply chain.