IT ASSET VISIBILITY FOR LONDON FINANCIAL SERVICES: WHAT THE FCA'S NEW THIRD-PARTY RULES DON'T COVER

IT Asset Visibility for London Financial Services: What the FCA’s New Third-Party Rules Don’t Cover

On March 12, 2026, up to 447,936 customers of Lloyds, Halifax, and Bank of Scotland saw other people’s transactions, or had their own data shown to other users, during an IT glitch in the group’s mobile banking apps. It was the kind of failure that traces back to gaps in IT asset visibility for London financial services, not to any outside supplier. Of those, 114,182 clicked through far enough to see account details, National Insurance numbers, and payment references. Lloyds Banking Group paid roughly £139,000 in goodwill to about 3,625 affected customers.

The cause sat entirely inside the bank’s own systems. Lloyds told the Treasury Select Committee that an overnight update to the mobile apps, pushed between March 11 and 12, introduced a defect in the code. The defect sat in the application programming interface (API) the apps use to pull transaction data. Between 03:28 and 08:08 that morning, customers who opened their transaction list within fractions of a second of another customer doing the same could see the wrong account’s data. The Lloyds, Halifax, and Bank of Scotland apps carried the fault. Internet banking ran on a separate path and stayed clear.

Through 2025 and 2026, UK financial regulators built an entire reform package around a different kind of dependency: the supplier. Critical Third Party designation, material third-party registers, unified incident reporting. All of it aimed outward, at the vendors and platforms a firm relies on. The Lloyds incident happened somewhere that framework doesn’t reach: inside the shared infrastructure running underneath three separately branded apps.

What the new regime actually requires

On March 18, 2026, the Prudential Regulation Authority published PS7/26 — published jointly with the FCA under its own reference, PS26/2 — developed with the Financial Conduct Authority and the Bank of England. The policy standardizes operational incident reporting and how firms register material third-party arrangements, giving supervisors comparable, timely data on firm-level and sector-level resilience risk. Incident reporting now runs through a single form across initial, intermediate, and final phases, submitted via FCA Connect. The companion supervisory statement, SS1/26, takes effect March 18, 2027.

Running alongside it is the Critical Third Party (CTP) regime under the Financial Services and Markets Act. HM Treasury made its first CTP designations on July 10, 2026, effective July 13, 2026. The first four designees — AWS, Google Cloud, Microsoft, and Oracle — illustrate the regime’s scope: hyperscale infrastructure providers, not a shared internal API layer. Designated providers now sit under direct FCA and PRA rules on governance, supply chain, cyber, and change management. Firms using a designated CTP still carry their own responsibility for managing that relationship.

The evidence behind this focus is specific. The FCA has said more than 40% of the cyber incidents reported to it in 2025 involved a third-party provider. That’s a real case for tightening supplier oversight. It covers one source of dependency risk, not every source.

Where the Lloyds incident sits

The technical path ran entirely inside Lloyds’ own stack. An overnight change to the API design meant that two near-simultaneous requests to the same transaction function could break the isolation between accounts, mixing transaction and payment detail across customers. Three separately branded apps carried that same shared path. Lloyds, Halifax, and Bank of Scotland customers hit the same failure in the same overnight window.

CTP designation, material third-party registers, and third-party incident notification are the FCA’s third-party rules — and all of them cover arrangements with outside parties. None of them extends to a shared mobile API layer running across three of a firm’s own brands. Incident reporting under PS7/26 and SS1/26 still applies once an event like this reaches customers, but that’s reporting after the impact lands. The gap is structural: the framework is reactive, but what stops an incident like this is preventive visibility — knowing, before an overnight release ships, which configuration items, APIs, and data paths already cross brand boundaries.

A pattern, not a one-off

On June 3, 2026, Lloyds Banking Group had a second major outage, this time hitting Lloyds, Halifax, Bank of Scotland, Scottish Widows, and MBNA simultaneously from around 11:15 BST.

The wider pattern predates both 2026 incidents. The Treasury Committee had already found that nine of the UK’s largest banks and building societies accumulated at least 33 days of combined IT outages over the two years to early 2025. Industry coverage puts the same period at 158 individual failures totaling more than 803 hours. Multi-brand groups keep failing together at the infrastructure layer while the regulatory calendar for 2026 and 2027 points almost entirely outward.

The pattern is clear: internal shared infrastructure carries the same risk as external third parties, yet sits outside the new regulatory framework.

What asset visibility actually needs to cover

IT asset visibility for London financial services means a multi-brand firm applying the same standard of scrutiny internally that it now applies to external suppliers:

  • Which platforms, APIs, data stores, and identity layers cross brand or entity boundaries
  • Which customer-facing services depend on those shared components, and which changes touch them
  • How current that map stays between release cycles
  • Who owns a shared configuration item (CI) when separate brand teams each assume their app runs in isolation

That’s a discovery problem, not a one-time diagram. High-frequency scheduled discovery feeding a governed configuration management database (CMDB) keeps shared hosts, middleware, and relationships current between audits. ViVID™ service maps show the blast radius of a change on a shared API before it ships, not after hundreds of thousands of customers are affected.

Virima runs that discovery layer: agent, agentless, and API-based collection on scheduled cycles, feeding a UK financial services CMDB and dependency views that plug into ITSM platforms including ServiceNow, Jira, and Ivanti through a single integration hub. The goal is the same scrutiny the new regime applies to external providers, pointed at the shared paths that never appear on a third-party register. Teams that already treat IT asset management audits as inventory evidence use the same discovery feed so shared CIs stay current after cleanup cycles, not only on paper.

Map shared paths the new rules never list

PS7/26, SS1/26, and CTP designation raise the bar on external third-party transparency and incident reporting. The March 2026 Lloyds mobile API defect shows why that bar is incomplete for multi-brand groups: the failure path was internal shared infrastructure. IT asset visibility for London financial services means mapping the shared paths regulators don’t ask about yet.

If you are exploring a solution for maintaining operational resilience and inventory evidence under the FCA and PRA rules in PS7/26 and SS1/26, alongside HM Treasury’s CTP regime, check Virima’s pricing for discovery and CMDB scope that fits your estate.

Exploring discovery and CMDB capacity to support compliance work under PS7/26, SS1/26, and the UK Critical Third Party regime? Review Virima pricing plans for your estate size.

View Pricing

Frequently Asked Questions

Does the UK’s Critical Third Party regime cover incidents like the March 2026 Lloyds outage?

No. CTP designation brings specific external technology and service providers under direct FCA and PRA oversight. The March 2026 incident traced back to an internal API change on infrastructure shared across Lloyds, Halifax, and Bank of Scotland’s own apps, not to any designated external provider.

When do the FCA, PRA, and Bank of England’s new incident reporting rules take effect?

The joint policy package was published March 18, 2026, as PS7/26 (FCA reference PS26/2). Supervisory statement SS1/26 on incident reporting takes effect March 18, 2027.

Was the March 2026 Lloyds incident isolated?

No. A second multi-brand outage hit Lloyds, Halifax, Bank of Scotland, Scottish Widows, and MBNA on June 3, 2026. The Treasury Committee separately found nine major UK banks accumulated at least 33 days of combined IT outages over the prior two years.

Does Virima’s discovery and CMDB platform map shared infrastructure across separate banking brands?

Yes. Virima’s agent, agentless, and API-based discovery feeds one CMDB and ViVID™ dependency map across brand boundaries, so shared APIs, hosts, and data stores stay visible on the same schedule financial groups now apply to external third-party registers, without replacing existing ITSM tools like ServiceNow or Jira.

Move faster. Act safely.

Get live, explainable runtime truth across your entire estate — without platform lock-in.

Similar Posts