Straven Co

A Straven Institute article · 2 min read · 2026

UK critical third parties regime and designation of AI providers

More from the Institute: The current body of work

The UK Critical Third Parties Regime: Designation of AI Providers in Financial Services and Insurance

In financial services and insurance, systemic dependency on artificial intelligence (AI) infrastructure is entering formal supervision under the UK’s critical third parties regime. This development demands action from organisations that buy or deploy AI solutions in regulated sectors.

The critical third parties regime designates providers of cloud computing, data analytics, and other essential AI infrastructure as critical to financial institutions’ operations. These AI providers are now subject to scrutiny by the Financial Conduct Authority (FCA), the Prudential Regulation Authority (PRA), and Her Majesty’s Treasury (HMT). The aim is to ensure these providers meet robust security, integrity, and resilience standards.

However, this development sharpens capability risk for organisations in financial services and insurance. Can AI solutions do what they claim? Are vendors’ assertions of high accuracy and precision substantiated by independent testing? Furthermore, does the organisation have a governance framework that can defend AI-related decisions when regulatory or judicial bodies ask questions?

The critical third parties regime also raises concerns about liability risk for organisations in financial services and insurance. What happens if an AI system fails to meet expectations or makes errors with consequences? Who is accountable for these issues: the vendor, the end-user organisation, or both?

To mitigate these risks, prudent organisations should take immediate action:

1. Conduct thorough due diligence on AI providers, examining their governance structure, compliance frameworks, and incident management processes.
2. Test AI solutions against real-world operations, not just theoretical scenarios, to assess performance and identify potential biases.

Straven & Co helps organisations navigate this landscape by providing independent validation of AI decisions. Through a rigorous assessment process, our firm examines the proposed solution against the organisation’s operations, its people, its governance obligations, and its legal exposure. Our verdict is plain: proceed, proceed with conditions, or do not. With no product to sell and nothing earned by recommending more, our judgment can be trusted.

Straven & Co examines AI decisions before they are acted on: stravenandco.com