Share with us a complex technology or change challenge - we'll take it from there.

Green Dolphin (TCCR) Limited
Green Dolphin (TCCR) Limited
  • Home
  • Subscribe
  • Our Story
  • Outcomes Delivered
    • Client
    • Community
    • Client Feedback
  • Services
    • Overview
    • Change Assurance
    • Third Party Risk
    • Internal Audit and Risk
    • Technology and Cyber Risk
    • SWIFT Compliance
    • AI Governance and Control
    • Scenario Testing
  • Team
    • Senior Delivery Team
    • Flex Careers
  • Shareable Tools
    • Operational Risk Radar
    • SWIFT CSP Readiness
    • Supplier Due Diligence
    • Change Risk Scorecard
  • Blogs and Insights
  • Coffee in the Camper
  • Contact Us

Supplier Due Diligence Tool

Supplier due diligence, before the regulator does it for you

Supplier due diligence, before the regulator does it for you

The new third-party reporting rules, PRA PS7/26 and FCA PS26/2, take effect on 18 March 2027. Banks and building societies will report a register of their material third-party arrangements every year. They will also notify the regulators before entering into, or significantly changing, one. The question is no longer whether you have a register. It is whether you can show you understand what is on it.


You may be choosing a new critical supplier or reviewing one you already run. Either way, the question is the same: would this arrangement survive the scrutiny that is coming?


Fifteen minutes to find out. Talk to us if you want the evidence-based version.


What the survey gives you

One supplier, thirty-seven questions and an instant report you can read as a board member, risk lead, third-party risk manager or technology lead. It gives you:

  • Two separate numbers: where the arrangement stands today, and how ready you are for 18 March 2027
  • A domain-by-domain read against a target set by materiality, with the fastest route to close each gap
  • The three priority gaps, each with an owner, a date and the evidence an assessor will ask for
  • The strengths to put in front of your board
  • The questions to take into your next board and risk committee meetings
  • What it means for your wider third-party programme

Free to use. No sign-up. Your answers stay in your browser unless you choose to send them to us.


Why this matters now

Third parties sit behind a large share of operational incidents. In 2025, 27% of incidents reported to the FCA were attributed to a third-party issue, and 37% of those were cyber-related.


Expectations have moved with them. From 18 March 2027 firms must keep and report a register of material arrangements, notify changes in advance, and make a first incident report within 24 hours. The critical third parties regime is live. Since 13 July 2026 the Bank of England, PRA and FCA have overseen four designated cloud providers. That oversight complements your own obligations; it does not replace them.


Being ready takes months, not weeks. Start early and the work runs on your timetable, not the regulator's.


The questions the survey helps you answer

  • Are our material arrangements correctly classified, and would the regulator agree?
  • Do our contracts give audit rights, sub-contractor visibility and enforceable exit?
  • Have we mapped fourth-party dependencies, or are we exposed to suppliers we have never assessed?
  • Would our exit plans hold under stress, with a hostile or insolvent supplier?
  • Would this supplier tell us about an incident fast enough for us to report within 24 hours?
  • Is cyber posture monitored continuously, or checked once a year?
  • Can the accountable senior manager evidence their reasonable steps?


If you want the evidence-based version

The survey shows you where to look. A Health Check does the looking. Supplier documentation and onsite reviews start at £3,750. They are senior-led, carried out with audit discipline and worked jointly with your team. Use one for due diligence on a supplier you are choosing, or ongoing due diligence on the ones you already run. You get:

  • Real evidence, not self-reported scores: your contracts, register entries, sub-processor lists, exit plans, MI packs and board minutes
  • Calibration to your size, including building society proportionality and the Strong and Simple regime
  • Concentration and fourth-party mapping to surface hidden exposures
  • Stressed exit tested against a supplier that will not co-operate
  • A benchmark against PS7/26, PS26/2, SS2/21, SS1/21, SS1/26 and FG16/5
  • A board-ready report framed around senior manager accountability
  • Coaching for senior managers and NEDs on the questions to ask and the MI to demand

We introduce this at the end of your results. You can also email info@greendolphintccr.com

Start Your Assessment

Assess one of your suppliers to understand where you stand against current expectations. 


Access this latest innovation and be part of our inner circle Green Dolphin community who gets priority access and information👇🏼

Start

© Green Dolphin (TCCR) Limited
Company registered in England and Wales (NO.16855006)


NCSC Cyber Essentials Certified 2026 (No.8fe63bb4-be60-4c2a-81f7-8cad1848de4d)


Good Business Charter Accredited 2026


VAT Registration 513 0298 23


All rights reserved.

Powered by

  • Subscribe
  • LinkedIn Page
  • Policies
  • Trustpilot Reviews
  • Contact Us
  • About Us

This website uses cookies.

We use cookies to analyze website traffic and optimize your website experience. By accepting our use of cookies, your data will be aggregated with all other user data.

DeclineAccept