Docoply Research

Material Third-Party Reporting: From fragmented evidence to reviewed records

Docoply is researching how UK-regulated financial firms can compile supplier contracts, vendor data, due-diligence evidence, operational-resilience mappings and governance approvals into reviewed, source-linked records for the FCA's new material third-party reporting regime.

20-minute practitioner conversation · No confidential information required · Not legal or regulatory advice

Contracts and vendor records
Evidence mapping and reconciliation
Missing information and owner review
Reviewed register record

A defined reporting requirement is creating a new evidence problem

Final rules and guidance for material third-party reporting were published by the FCA in March 2026, with the new requirements coming into force on 18 March 2027. From that date, in-scope firms must notify the FCA when they enter into a material third-party arrangement or make a significant change to an existing one, and must submit an annual register covering both material outsourcing and material non-outsourcing arrangements. The firm itself remains responsible for deciding whether an arrangement is material, and for approving and submitting the information it contains.

18 March 2027 New requirements come into force
Event-driven Notifications for new or significantly changed material arrangements
Annual Register of material third-party arrangements
Human accountability The firm retains responsibility for materiality, approval and submission

Source: FCA PS26/2 and Finalised Guidance FG26/4.

The final spreadsheet may not be the hardest part

Our field-to-evidence mapping suggests that only a minority of the required information is likely to come directly from an executed supplier contract. Much of the record depends on information held by procurement, risk, security, operational resilience, finance, legal and governance teams.

6 Directly from the executed contract
12 Contract candidate requiring confirmation
28 Normally outside the contract
4 Master-data or external lookup
3 Submission-level or pre-populated

This is a Docoply working research classification of the reporting fields. It is not an FCA categorisation and is being tested through practitioner interviews.

Five evidence domains may need to come together

Contract and provider facts

Details that typically originate in the executed agreement itself.

  • Legal provider identity
  • Arrangement dates
  • Service description
  • Contract value
  • Renewal and termination provisions
  • Subcontracting terms

Vendor and entity data

Records held in supplier and vendor-management systems, often maintained separately from the contract.

  • Internal arrangement reference
  • Legal entity identifiers
  • Group relationship
  • Provider location
  • Service-delivery locations
  • Existing supplier inventory

Operational-resilience evidence

Mappings and assessments produced through operational-resilience work, not contract negotiation.

  • Supported business services
  • Important Business Service mapping
  • Impact tolerances
  • Dependency analysis
  • Service-owner confirmation

Risk and assurance evidence

Due-diligence and audit findings gathered by risk, security and assurance teams.

  • Financial due diligence
  • Cyber due diligence
  • Most recent audit
  • Compliance gaps
  • Remediation ownership
  • Evidence freshness

Governance and exit decisions

Judgement-based decisions that depend on committee review and accountable sign-off.

  • Materiality assessment
  • Accountable approval
  • Governance committee
  • Approval date
  • Substitutability
  • Reintegration ability
  • Discontinuation impact
The working hypothesis is that the main operational burden lies in reconciling these evidence domains and obtaining confirmation from the correct internal owners.

What a source-linked workflow could look like

Intake

Collect the contract pack, supplier inventory, materiality criteria and available risk and resilience evidence.

Compile

Extract candidate factual values and map existing records to the required reporting fields.

Reconcile

Identify missing, stale, contradictory or incorrectly classified information.

Confirm and approve

Route factual confirmation and judgement fields to named internal owners while preserving corrections and approval history.

Export

Produce a reviewed record for the firm's own reporting process or existing GRC system.

Docoply would support evidence preparation and review. The customer would retain responsibility for regulatory interpretation, materiality decisions, factual confirmation, governance approval and submission.

What an evidence-readiness review may reveal

Fictional example, one payment-processing arrangement — not a real firm or a completed FCA submission.

27 fields ready 15 require review 11 blocked
Fictional evidence-readiness example for one payment-processing arrangement
Reporting informationStatusEvidence issueOwner required
Provider legal identifierMissingNo confirmed LEI in the vendor masterProcurement
Materiality assessment dateBlockedAssessment has not been formally approvedOperational Risk
Service-delivery locationsReviewContract and supplier questionnaire disagreeVendor Risk
Annual contract valueReviewContract and procurement record contain different valuesFinance / Procurement
Cyber due diligenceReviewAssessment predates a significant service changeInformation Security
Compliance remediationBlockedNo approved owner or completion dateCompliance
Governance approvalBlockedNo committee or approval date recordedAccountable Executive
SubstitutabilityReviewRating was copied from an outdated exit planOperational Resilience

Scroll sideways to see all columns.

What we need to learn from practitioners

Our current thinking, and the assumptions we are deliberately not making:

Current research questions

  • Where does information for one material third-party record come from?
  • Which fields create the most rework?
  • What can existing GRC or TPRM systems already populate reliably?
  • What work remains manual after a platform has been selected?
  • How are conflicting values resolved?
  • How is materiality reviewed and approved?
  • How frequently are arrangements added, amended, renewed or reassessed?
  • Which evidence becomes stale most quickly?
  • Would teams value an upstream evidence-compilation layer rather than another system of record?

What we are not assuming

  • That every firm needs a new register platform
  • That every third-party arrangement is material
  • That contracts contain all required information
  • That materiality should be automated
  • That page-level provenance alone creates sufficient value
  • That firms will buy before the workflow and timing are validated
  • That FCA and DORA requirements are interchangeable

We would value perspectives from people working in

Third-Party Risk Operational Resilience Outsourcing Operational Risk Procurement Supplier Management Regulatory Change Risk and Compliance GRC Implementation Financial-services consulting

We are particularly interested in the last real arrangement your team assessed: what started the process, where the information came from, what caused rework and how the final record was approved.

Read the field-to-evidence research note

FCA Material Third-Party Reporting: A Field-to-Evidence View

A short research note mapping the FCA reporting fields to likely evidence sources across supplier contracts, vendor records, due-diligence files, operational-resilience assessments and governance approvals. It highlights where information may be missing, contradictory or require accountable human confirmation.

Download the PDF

Practitioner research only — not regulatory advice.

Help us understand how this works in practice

We are conducting 20-minute research conversations with practitioners responsible for third-party risk, operational resilience, outsourcing, procurement and operational risk. We will not ask for confidential documents or begin with a generic software demonstration.

Please do not submit confidential, personal or commercially sensitive information.

Research basis

  • FCA Policy Statement PS26/2
  • FCA Finalised Guidance FG26/4
  • FCA material third-party reporting templates
  • Docoply field-to-evidence working analysis
  • Practitioner interviews and customer discovery

This page describes ongoing product and practitioner research. It does not constitute legal, regulatory, tax or professional advice. Docoply is not endorsed, approved or certified by the Financial Conduct Authority, Prudential Regulation Authority or Bank of England. Firms remain responsible for determining whether arrangements are material, validating their information, obtaining appropriate approvals and making regulatory submissions.