Managing your supplier risk isn't a deadline. It's about your resilience
Wed, 29th Jul 2026 (Today)
The UK FinTech sector has spent the last decade building an enviable reputation for moving fast. Faster than the banks. Faster than the regulators. Faster, sometimes, than common sense. That speed has been largely a good thing, it has produced genuinely transformative products, pulled millions of people into better financial services, and made London one of the most important FinTech hubs in the world.
But speed has a shadow. And in 2026, that shadow has a name: DORA.
The Digital Operational Resilience Act (DORA) came into full effect in January 2025. Across financial institutions, this meant accountability for managing third party risk remained on the financial institution themselves. However, the response has been fairly predictable. Compliance teams were mobilised. Questionnaires were sent to key ICT suppliers. Gaps were documented, roadmaps were written, and boxes were ticked. For many organisations, particularly the mid-tier banks, insurers and FinTechs that make up the UK's financial services backbone, the job is now considered largely done.
Sadly, it isn't; I'd say it is far from done.
The band-aid problem
I regularly see, through working with regulated businesses across South Africa and now the UK, that organisations have become extraordinarily good at the 'ticking the compliance box' of third-party risk management. They have the policies. They have the questionnaires. They have the annual review cycle and the risk rating spreadsheet. What they don't frequently have is a genuine understanding of what their supplier ecosystem actually looks like, what data is flowing where, what suppliers are connected to their environment and what would happen if a critical third party failed at 9am on a Tuesday.
DORA was designed precisely to close this gap. The regulation's third-party oversight requirements aren't a new compliance burden; they're a forcing function. For the first time, regulators are demanding that financial institutions demonstrate they actually understand their ICT dependencies, not just that they've asked their suppliers to fill in a form. The register of information requirements alone, mapping every ICT service, every contractual relationship, every concentration risk, is more demanding than anything the sector has faced before.
For UK FinTechs, this is pointed. The typical FinTech stack is a marvel of third-party integration: cloud infrastructure, payment rails, KYC providers, fraud tools, data aggregators. Every API connection is a dependency. Every dependency is a risk. Most FinTechs can tell you exactly how their product works. Far fewer can tell you with any precision what their exposure looks like if one of those dependencies goes down, is breached, or is acquired by someone they'd rather not be doing business with.
The opportunity hiding inside the regulation
I think what gets lost in the compliance conversation is that the organisations that treat regulations such as DORA seriously, not as a deadline to survive but as a framework to actually use, come out the other side with something of real value.
They understand their supply chain. They have contractual protections that actually reflect the risk they're carrying. They have incident response plans that have been tested and can actually be used if a real incident occurs. And they have a story to tell totheir own clients, partners and regulators: one that is independently verifiable, not just asserted.
This matters enormously in the UK FinTech context, where the race to partner with tier-one banks and institutional clients is intensifying. The question those institutions are increasingly asking is not just "what do you do?" but "can we trust you with our customers' data, our operational continuity, our regulatory exposure?" A FinTech that can answer that question with evidence - with a DORA-aligned third-party register, with documented resilience testing, with ISO 27001 or equivalent certification - is a different proposition from one that cannot.
What to do now
The enforcement picture is hardening. Regulators spent much of 2025 in education and remediation mode. That posture is shifting. Firms that treated the January 2025 deadline as the finish line are going to find it was just the start-line, in recent news terms, they only just qualified for the London Marathon - they didn't just win it as their LinkedIn post might suggest.
For UK FinTechs, the practical steps are not complicated, but they do require genuine commitment rather than a compliance project. Map your ICT dependencies, not at a high level, but in full. Understand which of your third parties are critical to your operational continuity and which represent concentration risk. Review your contractual arrangements against the DORA requirements, not just against what you agreed two years ago. And test your incident response, not in a workshop, but in a realistic scenario that actually stresses the system.
None of this is beyond any well-run FinTech. But it does require treating DORA and any other key regulation as a management priority, not a compliance one.
The regulation is not the problem. The band-aid approach to it is.