Bridging the Gap: What Moving From Regulator to Regulated Teaches Us About TPRM
Third Party Therapy Podcast — featuring Dharminder Mehmi, third party risk specialist, Legal & General
Few people in third party risk management (TPRM) have sat on both sides of the regulatory relationship. In this episode of Third Party Therapy, host Mike Day speaks with Dharminder Mehmi, who spent around 21 years at the FCA and its predecessor — including several years in specialist technology resilience and cyber roles — before moving into industry, first at Virgin Money and now at Legal & General. All views shared are personal and don't represent any employer or institution.
## Twin Peaks: PRA and FCA, What's the Difference
Dharminder explains the UK's "Twin Peaks" regulatory model, created after the single Financial Services Authority was split in the wake of the financial crisis. The Prudential Regulation Authority (PRA) covers banks, building societies, insurers and a small number of PRA-designated investment firms, focused on safety and soundness — principally, can depositors and policyholders be paid when they need to be. The Financial Conduct Authority (FCA) covers conduct for all regulated financial services firms, and is the sole prudential regulator for firms outside the PRA's remit, such as standalone asset managers. Its objectives centre on consumer protection, market integrity, and competition.
## Proportionality: Same Rules, Different Expectations by Size
Both regulators apply their requirements proportionately. The largest, most systemically significant firms are expected to meet the "gold standard" of market practice; smaller firms face less stringent expectations, though they remain subject to the same underlying rules.
## How Regulators Are Structured
Supervision at the FCA is organised by sector specialism — retail banking, wholesale and investment banking, payment services, asset management, life insurance and so on — supplemented by cross-cutting specialist teams (client assets, prudential, technology resilience and cyber) who get pulled into supervisory conversations as needed. For complex groups spanning multiple regulated entities, a "group supervision" model applies, led by whichever part of the business is most significant, drawing in other specialist teams as required. Dharminder notes that specialists in areas like technology resilience get genuine cross-firm visibility — seeing how, say, a major retail bank and a major investment firm each approach the same underlying problem — which feeds directly into what "good practice" looks like across the industry.
## Crossing the Floor: What Moving From FCA to Industry Revealed
Dharminder describes the move from regulator to practitioner as "refreshing" and an "eye opener" in equal measure. At the regulator, firms present their most polished, C-suite-level version of their controls; inside a regulated firm, by contrast, "you've got the bonnet open" with no room to hide. Virgin Money specifically hired him, he says, for his insider knowledge of what the regulator considers good practice — knowledge he could then apply directly to TPRM, and to broader transformation programmes such as mortgage technology initiatives.
## From Outsourcing to Materiality: The Regulatory Patchwork
Dharminder traces how the UK's rules have evolved. The FCA's requirements sit in SYSC 8, which he describes as relatively high-level and light on detail around exit planning or materiality assessment, and apply mainly to material outsourcing specifically. The PRA's outsourcing and third party risk requirements, introduced in March 2021, are more prescriptive and better aligned to the full third party risk lifecycle — plan, evaluate, select, contract, onboard, manage and monitor, exit. Critically, Dharminder notes that in practice, firms quickly stopped worrying much about whether an arrangement technically counted as "outsourcing" at all, since the real driver became materiality — the same rigour now typically applies to material third party arrangements whether or not they meet the formal outsourcing definition. DORA, in his view, draws together the best of the PRA's resilience-focused approach, the UK's operational resilience regime, and elements of the emerging Critical Third Party regime, into a single EU-wide framework — which, given the number of member states involved, helps explain why it took years to finalise before going live in January 2025.
## Critical Third Parties: A New Kind of Oversight
The UK's Critical Third Party (CTP) regime gives regulators limited direct oversight over a small number of systemically significant technology providers, without diluting any firm's own due diligence obligations. Dharminder's sense, from industry conversations at events such as Deloitte roundtables and CeFPro conferences, is that the firms likely to be designated already operate to a standard broadly in line with what regulators will expect — the value lies less in forcing improvement and more in giving regulators a faster, more direct line of sight into systemic concentration risk, rather than needing multiple financial institutions to each independently investigate the same provider after an incident.
## The Horizon Risks: AI and Quantum
Looking ahead, Dharminder flags that none of the current regulatory frameworks directly address generative or agentic AI in detail, even as the EU AI Act and FCA sandboxing initiatives explore the space. He expects TPRM programmes to be increasingly challenged by both AI's rapid evolution and longer-term developments such as quantum computing, alongside the continued risk of supply-chain shocks nobody saw coming — citing the July 2024 CrowdStrike outage as a reminder that genuinely global disruption can originate from a vendor most firms would never have flagged as "critical."
## The One Area Still Lagging: Fourth Party Visibility
Asked where the industry still has the furthest to go, Dharminder points squarely at supply chain and fourth party visibility. The CrowdStrike outage disrupted systems worldwide within hours, and many affected firms only then discovered how deeply embedded a subcontractor they'd never classified as material actually was in their own technology stack. His recommendation: push third parties for genuine visibility into their own subcontractors, embed contractual rights to be notified of material subcontractor changes, and give senior management clear visibility of concentration risk — for example, how much of the technology estate ultimately rolls up to a small number of major cloud providers.
## Lessons Learned: TSB and Intra-Group Risk
Dharminder's clearest cautionary example is the TSB migration incident of 2018, where the enforcement notice found at its root a failure to apply sufficient rigour to an intra-group service provider. His point: firms are often diligent about third parties like IBM or a custodian bank, but can overlook that an intra-group service company (common in UK ring-fenced banking groups) should, under the rules, be treated with no less scrutiny than an external provider. He also flags that firms operating across multiple jurisdictions need to be alert to third party and resilience regulation beyond the UK — even a small overseas office can bring additional, sometimes less familiar, local requirements into scope.
## Getting Started: The Basics for Newcomers
For anyone new to TPRM in a regulated environment, Dharminder's starting checklist is straightforward: a clear policy for managing third party arrangements; a consistent risk segmentation approach (material/high/medium/low or equivalent); due diligence and review frequency genuinely proportionate to that segmentation; documented exit and contingency plans for services supporting important business services; and increasingly, genuine testing of those exit plans with the third party involved — not just a desktop exercise, but active testing with providers such as custodian banks or middle-office partners, reflecting the level of rigour now expected of larger, more sophisticated firms.
---
**Listen to the full episode of Third Party Therapy, produced in association with CeFPro, on Apple Podcasts, Spotify, Amazon Music, Audacy and YouTube, or visit [thirdpartytherapy.com](https://thirdpartytherapy.com) to subscribe to the mailing list.**
---
### Tags
#ThirdPartyTherapy #TPRM #FinancialServicesRegulation #DORA #PRARegulation #FCARegulation #CriticalThirdParty #OperationalResilience #ThirdPartyRiskManagement #IntraGroupRisk #SupplyChainRisk #CrowdStrike #TSB #RegulatoryCompliance #RiskManagementPodcast #WhatIsTheDifferenceBetweenPRAAndFCA #HowDoTPRMRegulationsWork #TPRMPodcast


