# FCA outsourcing rules (SYSC 8): checking a supplier

> SYSC 8 for firms buying software: which outsourcing provisions bind your firm, the 12 supplier conditions, the written agreement and when to notify the FCA.

Checklist · Advice firms · By Syed Husnain Khalid · Published 8 October 2026 · Last checked 8 October 2026
Drafted with AI. Each claim was checked against the primary sources listed below by AI on 8 October 2026; a person has not reviewed it yet.
Canonical: https://vexralabs.com/insights/fca-outsourcing-software-supplier

Short answer

SYSC 8 is the FCA Handbook’s outsourcing section. For firms that are not common platform firms, most of it is proportionate guidance, but the responsibility rule binds: a firm outsourcing a critical or important function **remains fully responsible for its regulatory obligations** (SYSC 8.1.6R). Check the supplier against SYSC 8.1.8R, agree written terms and tell the FCA about material outsourcing.

This guide is for compliance and operations leads at FCA-authorised firms, especially financial advice firms, choosing a software or cloud supplier. SYSC 8.1 was last updated on 23 October 2025, and new FCA rules on reporting material third-party arrangements apply from 18 March 2027. We are a small software supplier, so we answer these checks from the other side of the table. The sections cover what SYSC 8 is, which parts bind your firm, when software counts as outsourcing, the twelve supplier conditions, the written agreement, notifying the FCA, the 2027 changes and how to assess a small supplier.

## What is SYSC 8?

SYSC 8 is the outsourcing chapter of the FCA’s Senior Management Arrangements, Systems and Controls sourcebook (SYSC), part of the FCA Handbook. Its first section, [SYSC 8.1 General outsourcing requirements](https://www.handbook.fca.org.uk/handbook/SYSC/8/1.html), holds the rules most firms mean when they say “FCA outsourcing rules”.

SYSC 8.1.1R sets the aim. When relying on a third party for operational functions critical to its regulated activities on a continuous and satisfactory basis, a common platform firm must “ensure that it takes reasonable steps to avoid undue additional operational risk”. It must also not outsource important operational functions in a way that materially impairs two things:

- the quality of its internal control;
- the FCA’s ability to monitor the firm’s compliance with all obligations under the regulatory system.

SYSC 8.1.1AG tells other firms to take account of SYSC 8.1.1R as guidance, “as if should appeared in that rule instead of must”. The letter after each number shows its status: R is a rule and G is guidance.

**Diagram: Checking a software supplier under SYSC 8.** Six steps: classify whether the function is critical or important (SYSC 8.1.4R); check the supplier against the twelve conditions in SYSC 8.1.8R; agree a written agreement with the rights in SYSC 8.1.9R; notify the FCA of a material outsourcing arrangement (SUP 15.3.8G); monitor the supplier's performance; and keep an exit plan so the service continues if the arrangement ends (SYSC 8.1.8R(12)).

*Classification comes first: it decides how much of the rest applies.*

## Which firms must follow SYSC 8 as rules?

Common platform firms must follow most of SYSC 8.1 as rules. Other firms read most of it as guidance, applied in a proportionate manner, but every route keeps at least one binding rule. [SYSC 1 Annex 1](https://www.handbook.fca.org.uk/handbook/SYSC/1/Annex1.html) sets out the split for each type of firm.

SYSC 1 Annex 1 3.1G sends each type of firm to a different column. A common platform firm is a firm for which SYSC 4 to SYSC 10 apply in line with Column A of Table A (3.2G). A MiFID optional exemption firm is a firm that holds the optional exemption from MiFID, the EU-derived investment services rules (PERG 13.5 Q48); it follows Table B (3.2CR). [PERG 13.5 Q49](https://www.handbook.fca.org.uk/handbook/PERG/13/5.html)says that exemption “is likely to be relevant to many financial advisers”. All other firms follow Column B (3.3R), apart from the six types listed in 3.2E R: insurers and UK ISPVs, managing agents, the Society, full-scope UK AIFMs of unauthorised AIFs, MiFID optional exemption firms and third country firms. Management companies and full-scope UK AIFMs of authorised AIFs have their own columns (3.2AG, 3.2BR).

| Type of firm (SYSC 1 Annex 1) | Rules in SYSC 8.1 | Guidance in SYSC 8.1 |
| --- | --- | --- |
| Common platform firm (3.2G, Table A Column A) | 8.1.1R, 8.1.4AR, 8.1.5R, 8.1.6-AR, 8.1.7R to 8.1.10R, 8.1.11-AR, 8.1.11-BR | 8.1.-2G, 8.1.2G, 8.1.3G, 8.1.11-CG, 8.1.12G |
| MiFID optional exemption firm (3.2CR, Table B Column A) | 8.1.1R, 8.1.6-AR, 8.1.11-BR | 8.1.-1G, 8.1.2G, 8.1.3G, 8.1.4AR, 8.1.5R, 8.1.7R to 8.1.10R, 8.1.11-AR, 8.1.11-CG; 8.1.12G does not apply |
| All other firms (3.3R, Table A Column B) | 8.1.6R | 8.1.1R, 8.1.1AG, 8.1.2G, 8.1.3G, 8.1.4R, 8.1.5R, 8.1.5AG, 8.1.7R to 8.1.11R, 8.1.11AG, 8.1.12G |

Where a rule is shown as guidance, 3.3R(1) and 3.2CR(1) say it “should be read as guidance (as if ‘should’ appeared in that rule instead of ‘must’)” and applied proportionately, “taking into account the nature, scale and complexity of the firm’s business”.

SYSC 8.1.6R is the rule that binds firms in Column B. A firm other than a common platform firm that outsources critical or important operational functions, or any relevant services and activities, “remains fully responsible for discharging all of its obligations under the regulatory system” and must comply with four conditions:

1. the outsourcing must not result in the delegation by senior personnel of their responsibility;
2. the firm’s relationship and obligations towards its clients under the regulatory system must not be altered;
3. the conditions the firm must meet to be authorised, and to remain so, must not be undermined;
4. none of the other conditions of the firm’s authorisation must be removed or modified.

SYSC 8.1.6-AR sets the same four conditions for common platform firms and MiFID optional exemption firms, with responsibility for obligations under the UK law on markets in financial instruments. Your compliance person can confirm which type your firm is.

## Is using a software supplier outsourcing?

Usually, yes, where the supplier delivers a service on the firm’s behalf. The FCA’s cloud guidance, [FG16/5](https://www.fca.org.uk/publication/finalised-guidance/fg16-5.pdf), says (paragraph 3.3) that “where a third party delivers services on behalf of a regulated firm – including a cloud provider – this is considered outsourcing”.

FG16/5 is the FCA’s finalised guidance for firms outsourcing to the cloud and other third-party IT services. It treats cloud as including Software as a Service (SaaS), and it is relevant to all FSMA-authorised firms apart from banks, building societies, IFPRU investment firms and the payment and e-money institutions the EBA outsourcing guidelines address (paragraphs 1.4 and 2.2). The guidance is not binding (paragraph 1.8). Its web page was last updated on 18 March 2026.

The function the software supports decides how much of SYSC 8 applies. Under SYSC 8.1.4R, a function is critical or important “if a defect or failure in its performance would materially impair” the firm’s continuing compliance with its authorisation or other regulatory obligations, its financial performance, or the soundness or continuity of its relevant services and activities.

Outsourcing a function that is not critical or important still counts. SYSC 8.1.3G says the firm should take the SYSC 8.1 rules into account, in a manner proportionate to the nature, scale and complexity of the outsourcing, when meeting SYSC 4.1.1R, its duty to have effective risk processes and internal controls. SYSC 4.1.1R is a rule in every column of SYSC 1 Annex 1.

SYSC 8.1.5R names three functions that are not critical or important for a common platform firm; other firms take it as guidance (SYSC 8.1.5AG):

- advisory and other services outside the firm’s relevant services and activities, including legal advice, staff training, billing services and premises security;
- the purchase of standardised services, including market information services and price feeds;
- the recording and retention of telephone conversations or electronic communications subject to SYSC 10A.

## What must a firm check in a supplier?

SYSC 8.1.8R lists twelve conditions a firm must take the necessary steps to satisfy when it outsources a critical or important function. They are rules for common platform firms and guidance for the other two groups. SYSC 8.1.7R adds a duty of due skill, care and diligence when entering into, managing or terminating the arrangement.

| SYSC 8.1.8R condition | What it requires | A question for a software supplier (our suggestion) |
| --- | --- | --- |
| (1) Ability | The supplier has the ability, capacity, organisational structure and any authorisation required by law to perform reliably and professionally | Who builds and runs the system, and who covers when they are away? |
| (2) Performance | The supplier performs effectively and lawfully; the firm sets methods to assess its performance and reviews the service on an ongoing basis | Which service levels can we measure, and when do we review them? |
| (3) Supplier's supervision | The supplier properly supervises the outsourced work and manages its risks | How do you check your own work on our service? |
| (4) Action on failure | Appropriate action is taken if the supplier may not be performing effectively and lawfully | What happens when a service level is missed? |
| (5) Firm's supervision | The firm supervises the outsourced work, manages its risks and keeps the expertise and resources to do so | Who in our firm understands the system well enough to oversee it? |
| (6) Disclosure | The supplier discloses any development that may materially affect its ability to perform | Will you tell us in writing about changes that affect the service? |
| (7) Termination | The firm can terminate where necessary, with immediate effect when this is in the interest of its clients, without detriment to the continuity and quality of its services to clients | Can we end the contract at once where clients' interests require it? |
| (8) Co-operation | The supplier co-operates with the FCA and any other relevant competent authority | Will you co-operate with the FCA about our service? |
| (9) Access | The firm, its auditors and the FCA have effective access to data and, where necessary, to the supplier's business premises | Can we, our auditors and the FCA get the data we need? |
| (10) Confidentiality | The supplier protects confidential information about the firm and its clients | How do you protect confidential information about the firm and its clients? |
| (11) Disaster recovery | Firm and supplier keep a contingency plan for disaster recovery and test backup facilities periodically, where necessary | When were backups last restored in a test? |
| (12) Continuity on exit | The service continues at the same quality if the arrangement ends, by moving it to another supplier or bringing it in-house | How would we move the system to someone else, or run it ourselves? |

SYSC 8.1.11R adds that a firm other than a common platform firm must make available to the FCA, on request, all information needed to supervise the outsourced activities; Column B shows it as guidance.

## What should the written agreement include?

SYSC 8.1.9R requires a common platform firm to set out the rights and obligations of the firm and the supplier clearly in a written agreement, and other firms should do the same. The provision names five things the agreement keeps or ensures:

- the firm’s instruction rights;
- the firm’s termination rights;
- the firm’s rights of information;
- the firm’s right to inspections and access to books and premises;
- sub-outsourcing by the supplier only with the firm’s consent in writing.

The termination right works with condition (7) above: immediate termination where that is in clients’ interests, without detriment to continuity. Where the supplier processes client personal data, [UK GDPR Article 28(3)](https://www.legislation.gov.uk/eur/2016/679/article/28)also requires a processor contract. Its terms include acting only on the firm’s documented instructions, confidentiality, security, conditions for using other processors, help with data subject requests and audits, and, “at the choice of the controller”, deleting or returning all the personal data when the service ends. The [UK GDPR Article 28(3) processor contract](https://vexralabs.com/insights/uk-gdpr-article-28-processor-contract) guide lists every clause the two contracts share.

FG16/5 adds five exit points a firm should cover, which usually end up in the agreement:

- exit plans and termination arrangements that are understood, documented and fully tested;
- knowing how it would move to another supplier and keep the business running;
- a specific obligation on the supplier to co-operate fully with the firm and any new supplier;
- knowing how it would remove data from the supplier’s systems on exit;
- monitoring concentration risk and planning for the supplier’s failure.

## When should the FCA be notified?

A firm should give the FCA notice of “entering into, or significantly changing, a material outsourcing arrangement” ([SUP 15.3.8G(1)(e)](https://www.handbook.fca.org.uk/handbook/SUP/15/3.html)). That guidance explains Principle 11, which requires a firm to deal with its regulators openly and to disclose anything the FCA would reasonably expect notice of (SUP 15.3.7G).

Material outsourcing, as FG16/5 paragraph 3.6 quotes the Handbook definition, means outsourcing services of such importance that weakness or failure would cast serious doubt on the firm’s continuing satisfaction of the threshold conditions or compliance with the Principles for Businesses. SUP 15 applies to every firm, with exceptions only for ICVCs and the Society ([SUP 15.1.1G](https://www.handbook.fca.org.uk/handbook/SUP/15/1.html)).

SYSC 8.1.12G points to the same guidance: a firm should notify the FCA when it intends to rely on a third party for critical or important operational functions. Table B shows 8.1.12G as not applicable to MiFID optional exemption firms, but SUP 15.3.8G still applies to them. The FCA expects firms to discuss a matter early, “before making any internal or external commitments” (SUP 15.3.9G). Notice can be oral or written, and should be written if the matter is complex (SUP 15.3.10G).

## What changes on 18 March 2027?

New FCA rules on reporting operational incidents and material third-party arrangements come into force on **18 March 2027**. The FCA published them in [policy statement PS26/2](https://www.fca.org.uk/publications/policy-statements/ps26-2-operational-incident-third-party-reporting) on 18 March 2026, and SYSC 8.1 and SUP 15.3 both show future versions dated 18 March 2027.

**Diagram: FCA outsourcing guidance and reporting dates.** July 2016: the FCA publishes FG16/5, its guidance on outsourcing to the cloud and other third-party IT services. 23 October 2025: SYSC 8.1 is last updated. 18 March 2026: the FCA publishes PS26/2 on operational incident and third-party reporting. 18 March 2027: the PS26/2 rules come into force.

*Until 18 March 2027, SUP 15.3.8G is the notification route for material outsourcing.*

The third-party reporting rules define a material third-party arrangement, require notice of new or significantly changed ones, and require an annual register. They apply to nine groups:

- enhanced scope Senior Managers and Certification Regime (SM&CR) firms;
- banks;
- designated investment firms;
- building societies;
- Solvency II firms;
- Client Assets Sourcebook (CASS) large firms;
- UK Recognised Investment Exchanges (RIEs);
- authorised electronic money institutions or authorised payment institutions;
- consolidated tape providers.

The operational incident reporting rules apply more widely, to all firms with a Part 4A permission, payment service providers, UK RIEs, registered trade repositories and registered credit rating agencies. The FCA says many of the incidents reported to it originate at third parties. We will re-check this section after 18 March 2027.

## How should a firm assess a small supplier?

Apply the same twelve conditions, scaled to the risk: SYSC 1 Annex 1 3.3R(1)(b) and 3.2CR(1)(b) ask for proportionate application. Size changes the questions under condition (1), capacity, and condition (11), disaster recovery, more than any other.

- Ask who else can run the system if one person is unavailable.
- Ask where code, data and backups are held, and in which country; FG16/5 suggests agreeing a data residency policy with the supplier.
- Ask whose name the hosting, code repository and integration accounts are in.
- Ask for a written exit plan before signing, not after.

A firm that owns its code, data and accounts finds condition (12), continuity on exit, much easier to meet. Ownership does not replace the other eleven conditions.

## How does VexraLabs answer these checks?

We answer a firm’s due-diligence questionnaire in full and will provide a data processing agreement before work starts. We are a two-person team in Islamabad, so assess us as you would any small supplier. Access from Pakistan is a restricted transfer under UK GDPR, so we will also provide the UK International Data Transfer Agreement (IDTA) alongside the data processing agreement. For advice firms we build on official APIs and the firm’s own accounts.

SYSC 8 is one of the rules covered in [software and AI for advice firms under Consumer Duty](https://vexralabs.com/insights/software-ai-advice-firms), the guide this post sits under, and [software for financial advisers](https://vexralabs.com/financial-advisers) describes what we build. A supplier that hosts client files holds the records governed by [how long financial advisers must keep records](https://vexralabs.com/insights/record-keeping-financial-advisers), so the exit plan needs to cover them too.

Not legal advice

This guide summarises SYSC 8.1, SYSC 1 Annex 1, SUP 15.3, FG16/5 and PS26/2 as at the date checked. Which column applies, and whether a function is critical or important or an arrangement is material, depends on your firm; your compliance person or adviser decides.

## Frequently asked questions

### Does SYSC 8 apply to small advice firms?

Yes, mostly as guidance applied proportionately. For firms in Column B of SYSC 1 Annex 1, SYSC 8.1.6R is still a rule: the firm remains fully responsible for its obligations when it outsources a critical or important function. MiFID optional exemption firms follow Table B, where SYSC 8.1.1R and 8.1.6-AR are rules.

### Is a SaaS or cloud system outsourcing under FCA rules?

The FCA's guidance FG16/5 says that where a third party delivers services on behalf of a regulated firm, including a cloud provider, this is considered outsourcing. How much of SYSC 8 applies depends on whether the function is critical or important (SYSC 8.1.4R).

### Do we have to tell the FCA about a new software supplier?

A firm should give the FCA notice of entering into, or significantly changing, a material outsourcing arrangement (SUP 15.3.8G(1)(e)), ideally before making commitments (SUP 15.3.9G). A supplier that is not material does not need this notice.

### What contract terms does SYSC 8 expect?

A written agreement that keeps the firm's instruction, termination, information, inspection and access rights, and allows sub-outsourcing only with the firm's written consent (SYSC 8.1.9R). The firm should be able to terminate with immediate effect when that is in its clients' interest (SYSC 8.1.8R(7)).

### Do the March 2027 third-party reporting rules apply to advice firms?

PS26/2's third-party reporting rules apply to nine named groups, including enhanced scope SM&CR firms, banks and CASS large firms, from 18 March 2027. Its operational incident reporting rules apply to all firms with a Part 4A permission.

## Sources

1. [FCA Handbook, SYSC 8.1 General outsourcing requirements (last updated 23 October 2025)](https://www.handbook.fca.org.uk/handbook/SYSC/8/1.html)
2. [FCA Handbook, SYSC 1 Annex 1 Detailed application of SYSC, Part 3 and Tables A and B](https://www.handbook.fca.org.uk/handbook/SYSC/1/Annex1.html)
3. [FCA Handbook, SUP 15.3 General notification requirements, 15.3.7G to 15.3.10G](https://www.handbook.fca.org.uk/handbook/SUP/15/3.html)
4. [FCA Handbook, SUP 15.1 Application, 15.1.1G](https://www.handbook.fca.org.uk/handbook/SUP/15/1.html)
5. [FCA Handbook, PERG 13.5 Exemptions from the definition of investment firm, Q48 and Q49](https://www.handbook.fca.org.uk/handbook/PERG/13/5.html)
6. [FCA, FG16/5 Guidance for firms outsourcing to the cloud and other third-party IT services (PDF)](https://www.fca.org.uk/publication/finalised-guidance/fg16-5.pdf)
7. [FCA, PS26/2 Operational incident and third party reporting (18 March 2026)](https://www.fca.org.uk/publications/policy-statements/ps26-2-operational-incident-third-party-reporting)
8. [UK GDPR Article 28 (processors), legislation.gov.uk](https://www.legislation.gov.uk/eur/2016/679/article/28)
