Docoply is researching how UK-regulated financial firms can compile supplier contracts, vendor data, due-diligence evidence, operational-resilience mappings and governance approvals into reviewed, source-linked records for the FCA's new material third-party reporting regime.
20-minute practitioner conversation · No confidential information required · Not legal or regulatory advice
Final rules and guidance for material third-party reporting were published by the FCA in March 2026, with the new requirements coming into force on 18 March 2027. From that date, in-scope firms must notify the FCA when they enter into a material third-party arrangement or make a significant change to an existing one, and must submit an annual register covering both material outsourcing and material non-outsourcing arrangements. The firm itself remains responsible for deciding whether an arrangement is material, and for approving and submitting the information it contains.
Source: FCA PS26/2 and Finalised Guidance FG26/4.
Our field-to-evidence mapping suggests that only a minority of the required information is likely to come directly from an executed supplier contract. Much of the record depends on information held by procurement, risk, security, operational resilience, finance, legal and governance teams.
This is a Docoply working research classification of the reporting fields. It is not an FCA categorisation and is being tested through practitioner interviews.
Details that typically originate in the executed agreement itself.
Records held in supplier and vendor-management systems, often maintained separately from the contract.
Mappings and assessments produced through operational-resilience work, not contract negotiation.
Due-diligence and audit findings gathered by risk, security and assurance teams.
Judgement-based decisions that depend on committee review and accountable sign-off.
Collect the contract pack, supplier inventory, materiality criteria and available risk and resilience evidence.
Extract candidate factual values and map existing records to the required reporting fields.
Identify missing, stale, contradictory or incorrectly classified information.
Route factual confirmation and judgement fields to named internal owners while preserving corrections and approval history.
Produce a reviewed record for the firm's own reporting process or existing GRC system.
Fictional example, one payment-processing arrangement — not a real firm or a completed FCA submission.
| Reporting information | Status | Evidence issue | Owner required |
|---|---|---|---|
| Provider legal identifier | Missing | No confirmed LEI in the vendor master | Procurement |
| Materiality assessment date | Blocked | Assessment has not been formally approved | Operational Risk |
| Service-delivery locations | Review | Contract and supplier questionnaire disagree | Vendor Risk |
| Annual contract value | Review | Contract and procurement record contain different values | Finance / Procurement |
| Cyber due diligence | Review | Assessment predates a significant service change | Information Security |
| Compliance remediation | Blocked | No approved owner or completion date | Compliance |
| Governance approval | Blocked | No committee or approval date recorded | Accountable Executive |
| Substitutability | Review | Rating was copied from an outdated exit plan | Operational Resilience |
Scroll sideways to see all columns.
Our current thinking, and the assumptions we are deliberately not making:
We are particularly interested in the last real arrangement your team assessed: what started the process, where the information came from, what caused rework and how the final record was approved.
A short research note mapping the FCA reporting fields to likely evidence sources across supplier contracts, vendor records, due-diligence files, operational-resilience assessments and governance approvals. It highlights where information may be missing, contradictory or require accountable human confirmation.
Download the PDFPractitioner research only — not regulatory advice.
We are conducting 20-minute research conversations with practitioners responsible for third-party risk, operational resilience, outsourcing, procurement and operational risk. We will not ask for confidential documents or begin with a generic software demonstration.
Please do not submit confidential, personal or commercially sensitive information.
This page describes ongoing product and practitioner research. It does not constitute legal, regulatory, tax or professional advice. Docoply is not endorsed, approved or certified by the Financial Conduct Authority, Prudential Regulation Authority or Bank of England. Firms remain responsible for determining whether arrangements are material, validating their information, obtaining appropriate approvals and making regulatory submissions.