An IT service provider supporting an FCA-regulated firm should do more than keep its systems operational. It should help the business maintain secure, resilient and well-governed technology, while ensuring that appropriate records and evidence are available for management oversight, audits and regulatory enquiries.
Regulatory accountability, however, remains with the regulated firm. The FCA makes clear that firms retain full responsibility for meeting their regulatory obligations and cannot transfer that responsibility to an external service provider. An IT provider can support compliance efforts, but its appointment does not automatically make a business “FCA compliant”.
This distinction defines the provider’s role. Instead of offering a standard package and presenting it as a complete compliance solution, the provider should first understand the firm’s regulatory requirements, critical operational dependencies and risk profile. It can then recommend, implement and manage technology controls that are appropriate to the organisation.
1. Understand the firm’s regulatory context
There is no single technology checklist that applies identically to every FCA-regulated business. The controls required depend on the firm’s permissions, activities, clients, data, systems, size and risk profile. FCA Principle 3 requires firms to organise and control their affairs responsibly and effectively with adequate risk-management systems. The Systems and Controls sourcebook also makes clear that arrangements should reflect the nature, scale, complexity and risks of the business.
The provider should therefore identify:
- Which systems support regulated activities.
- What information those systems process.
- Which users and suppliers can access them.
- What would happen if they became unavailable or compromised.
Tivarri’s guide to FCA IT requirements for hedge funds and investment firms explains how these expectations can translate into practical technology controls.
2. Support due diligence and ongoing oversight
Before appointment, the provider should give the firm enough information to assess the proposed service and the risks it introduces. This should include the service scope, data-hosting locations, security model, relevant subcontractors, continuity arrangements, incident-notification process and available assurance reports.
Certifications such as ISO 27001 can support due diligence, but the FCA says assurance based on international standards is unlikely to be sufficient on its own for critical or important functions or material outsourcing. The firm must still assess whether the certification or audit covers the actual service, systems and locations it will use.
An IT provider should also be transparent about its supply chain. The FCA’s cloud and third-party IT guidance expects firms to identify relevant providers in the supply chain and ensure their regulatory requirements can continue to be met where subcontractors are involved.
3. Maintain proportionate security controls
An IT provider should operate a documented security framework aligned with the firm’s risk assessment. Depending on the environment, appropriate controls may include:
- Multi-factor authentication and risk-based access controls.
- Least-privilege and separately managed administrator accounts.
- Secure configuration, patching and vulnerability management.
- Endpoint, email and network protection.
- Encryption and data-loss controls.
- Central logging, alerting and security monitoring.
- Protected, segregated and regularly tested backups.
These practical controls can help firms meet broader systems-and-controls, information-security and resilience obligations. FCA guidance expects firms to conduct security risk assessments covering the provider and relevant technology assets, understand breach-notification arrangements and consider encryption, data segregation and data residency. The NCSC also recommends protecting backups against destructive actions and testing restoration before an incident occurs.
Tivarri’s resources on Microsoft Entra ID Plan 2 and vulnerability assessments provide further information on identity protection and technical security testing.
4. Support operational resilience, not only disaster recovery
Disaster recovery focuses mainly on restoring technology. Operational resilience asks whether the firm can continue delivering an important business service without exceeding the point at which disruption causes intolerable harm to clients or threatens the financial system or orderly operation of markets.
An IT provider should help the firm map the technology, information and third-party dependencies supporting each important service. Recovery objectives should be aligned with impact tolerances. Testing should cover severe but plausible events such as ransomware, cloud failure, telecommunications outages, identity-platform failure, data corruption, supplier failure and loss of normal communication channels. Results should record:
- Whether the service remained within tolerance.
- Which controls or workarounds failed.
- What remediation is required.
- Who owns each action.
- When the work will be completed.
5. Escalate incidents and preserve evidence
The provider should have agreed notification thresholds, named contacts and clear escalation routes. It should notify the firm promptly when an incident may affect regulated services, clients, information or regulatory obligations rather than waiting until every technical detail has been confirmed.
It should also preserve logs and other evidence, support containment and recovery, maintain an accurate incident timeline and contribute to post-incident analysis. Tivarri’s Cyber Attack Action Plan provides a practical framework for defining these responsibilities before a crisis occurs.
6. Produce evidence for governance and oversight
An IT service provider should give the regulated firm clear, timely information about the security, resilience and performance of its technology environment. This helps management oversee the service, challenge weaknesses and respond to audits or regulatory enquiries.
Useful management information includes:
- Asset and access records.
- Patch and vulnerability status.
- MFA and encryption coverage.
- Backup and restoration-test results.
- Security and operational incidents.
- Service-level performance.
- Control exceptions and accepted risks.
- Remediation actions, owners and deadlines.
Reports should explain the business impact of technical issues, highlight significant risks and show whether agreed actions are being completed.
7. Maintain a credible exit plan
The arrangement should allow the firm to transfer services without undue disruption or loss of access to its data. FCA guidance expects exit plans and termination arrangements to be understood, documented and fully tested.
The firm should know how it would move to another provider, maintain continuity, remove or retrieve its data and respond if the incumbent provider failed. The contract should also require the provider to cooperate with the firm and any replacement supplier during the transition.
The standard is evidence, not promises
The right IT service provider does more than claim to understand financial services. It helps the regulated firm translate its obligations into practical technology controls, identify critical dependencies, test resilience, respond effectively to incidents and produce clear evidence for management, auditors and regulators.
Technology can be outsourced. Accountability cannot. That is why regulated firms need a provider that combines technical capability with strong governance, transparent reporting and an understanding of operational risk.
Tivarri supports FCA-regulated firms in building secure, resilient and well-governed IT environments. Our services include managed IT support, cybersecurity, Microsoft 365, vulnerability assessments, backup and disaster recovery, and strategic technology guidance.
We work with firms to strengthen day-to-day controls, reduce technology risk, improve operational resilience and create the evidence needed for internal oversight, client assurance and regulatory scrutiny.
Whether you are reviewing an existing provider, preparing for growth or strengthening your control environment, Tivarri can help you identify gaps and put the right technology, processes and reporting in place.
To discuss how Tivarri can support your firm’s IT, cybersecurity and operational-resilience requirements, contact our team.
Sources
FCA Handbook, PRIN 2.1 — The Principles:
https://handbook.fca.org.uk/handbook/prin2/prin2s1
FCA Handbook, SYSC 3.1 — Systems and Controls:
https://handbook.fca.org.uk/handbook/sysc3/sysc3s1
FCA, FG16/5: Guidance for Firms Outsourcing to the Cloud and Other Third-Party IT Services, updated 2026:
https://www.fca.org.uk/publication/finalised-guidance/fg16-5.pdf
FCA, Operational Resilience: Insights and Observations One Year On, 2026:
https://www.fca.org.uk/publications/good-and-poor-practice/operational-resilience-insights-observations-one-year
FCA, PS26/2: Operational Incident and Third-Party Reporting, 2026:
https://www.fca.org.uk/publications/policy-statements/ps26-2-operational-incident-third-party-reporting
FCA, Reporting Operational Incidents, 2026:
https://www.fca.org.uk/firms/operational-resilience/reporting-operational-incidents
FCA, Reporting Material Third-Party Arrangements, 2026:
https://www.fca.org.uk/firms/outsourcing-and-operational-resilience/reporting-material-third-party-arrangements
ICO, What Needs to Be Included in a Controller–Processor Contract?:
https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/accountability-and-governance/contracts-and-liabilities-between-controllers-and-processors-multi/what-needs-to-be-included-in-the-contract/
NCSC, Principles for Ransomware-Resistant Cloud Backups, 2023:
https://www.ncsc.gov.uk/collection/ransomware-resistant-backups/principles-for-ransomware-resistant-cloud-backups
Tivarri, FCA IT Requirements for Hedge Funds and Investment Firms, 2026:
https://tivarri.com/blog/fca-it-requirements-for-hedge-funds-and-investment-firms/
Tivarri, What Is Microsoft Entra ID Plan 2?, 2026:
https://tivarri.com/blog/what-is-microsoft-entra-id-p2/
Tivarri, Cyber Attack Action Plan:
https://tivarri.com/cyber-attack-action-plan/
