Third-party risk, handled with clarity and care. See how Green Dolphin helps.→
Sample report · composite supplier · illustrative answers scored by the live engine
Critical Supplier Survey · Free · July 2026 edition

Would this supplier survive the scrutiny that is coming?

You would not lend against a property without a survey. This is the survey for the suppliers your services stand on: one arrangement, thirty-seven questions, two honest numbers.

Updated July 2026
See a sample report → 15 min · no login · answers stay in your browser
Designated Critical Third Parties · 10 Jul 2026
AWS Google Cloud Microsoft Oracle joint Bank · PRA · FCA oversight AWS Google Cloud Microsoft Oracle firms remain responsible for their own arrangements
The clock this survey is set against

Your first PS7/26 register submission window opens 18 March 2027.

The work that has to be substantially complete before then: contract changes, fourth-party visibility, exit testing, governance uplift. The survey tells you which of it applies to this supplier.

0 days of runway 18 March 2027 is when the first PS7/26 register submission window opens, per the PRA and FCA policy statements published in March 2026. The count runs from your device’s clock and updates on every visit. days until the first PS7/26 register submission
PS7/26 publishedMar 2026 CTP designations10 Jul 2026 Today Register dry runAutumn 2026 Submission window18 Mar 2027
Every question anchored to
Two numbers, two different questions

Where the arrangement sits today. How ready you are for what is coming.

Number one · supplier posture

Where this arrangement sits today

Governance, contracts, concentration, resilience, exit, cyber and monitoring: the state of the relationship as it stands, scored across seven domains and weighted the way a supervisor would weight them.

Number two · regulatory readiness

How prepared you are for 18 March 2027

The forward-looking test: register readiness, the July Critical Third Party designations, incident-clock alignment, the renewals falling before the deadline, and whether anyone owns the horizon.

One survey, four documents

Built for the room you sit in

The report reshapes for your seat at the table, and each lens prints as its own pack. Tap a seat to open the sample report in that lens.

Sample report · composite supplier Alder Originate (composite) 63/100posture today 33/100readiness · Mar 2027 Static today · projected Assured, if 3 priority actions complete · calibrated to firm size See it scored →
Why now

The ground moved this month

When the same four names sit behind half the sector, strong controls of your own can still miss the point. On 10 July, HM Treasury designated AWS, Google Cloud, Microsoft and Oracle as the first Critical Third Parties, under joint Bank, PRA and FCA oversight from 13 July. Oversight of them does not move accountability for your own arrangements.

The supervisory question has changed shape. It is no longer "do you have a register" but "can you prove you understand and manage what is on it". The gap between those two questions is where findings are written.

4Critical Third Parties designated
AWS, Google, Microsoft, Oracle
10 Jul 2026
1stSMF18 fine for outsourcing
oversight failure set the bar
2024
803hours of unplanned outages,
much of it third-party
TSC, 2025
Mar 2026PS7/26 & PS26/2 published
10 Jul 2026First CTPs designated
Today247 days of runway
18 Mar 2027First register submission

Firms remain responsible for their own third-party arrangements. Oversight of the hyperscalers does not move that accountability. Sources: HM Treasury, PRA PS7/26, FCA PS26/2, Treasury Select Committee.

The wider picture

This survey reads one supplier. Our Digital Risk Radar reads the sector it sits inside: eight digital risks, every claim cited to primary sources, refreshed quarterly.

Open the Radar →
Questions worth asking

What the survey helps you answer

01Can we evidence that this arrangement is classified correctly, to the standard the new register will expose?
02Do we know where the newly designated Critical Third Parties sit in this supplier's delivery chain?
03Would our exit plan survive a supplier that stops co-operating, not just one that leaves politely?
04Which of this supplier's contract renewals fall before 18 March 2027, and what has to be inserted at each one?
05If this supplier had a reportable incident at 02:00 on a Sunday, would we meet our regulatory clock?
Client modules · unlocked on engagement

Where the survey stops, the modules begin

The free survey is self-reported by design. For material arrangements, clients unlock deeper analyses run with our team on your actual evidence. Each one appears against your results at the end of the survey.

Unlocked means we do the work with you. These are senior-led analyses delivered alongside your team as part of a Health Check or standalone. Not software, no licences, no per-seat pricing: scoped and priced per engagement.

What this is not
×
Not advice. It is a structured self-assessment built to open better board and supplier conversations, not to close them for you.
×
Not a regulatory submission. PS7/26 requires a register submitted through RegData. This survey helps you prepare for that; it is not that.
×
Not an independent assessment. It scores what you tell it. It does not test evidence, read contracts or interview your supplier. It shows you where the looking should start.
×
Not a data grab. No login. Your answers stay in this browser unless you choose to send them to us at the end.
Paul O’Leary

This survey came out of the same boardrooms as our Digital Risk Radar. Boards kept asking two questions in the same breath: how solid is this particular supplier, and are we ready for the rules landing in March. Those are different questions, and tools that blur them produce numbers nobody trusts. So we built one that keeps them apart, anchored every question to a primary source, and kept it free and login-less because the point was never to capture anyone. If it helps your next risk committee open with two clear numbers instead of one vague feeling, it has done its job.

Paul O'LearyGreen Dolphin (TCCR) · info@greendolphintccr.com

Common questions
Is this a PS7/26 or PS26/2 submission?›
No. Those policy statements require a register of material arrangements submitted via RegData from 18 March 2027. This survey gives you a structured view of one arrangement so you can prepare for that with confidence. It is not a regulatory return.
How long does it take?›
Around 15 minutes per supplier, depending on how much you already know. You can pause at any point; your answers stay in this browser and the survey resumes where you left off.
Where do my answers go?›
Nowhere, unless you choose otherwise. Answers are held in your browser's local storage. They are only sent to info@greendolphintccr.com if you complete the optional contact form at the end of your report.
Can I assess more than one supplier?›
Yes. After your first report you can run the survey again for another arrangement; your firm-size calibration is remembered. We suggest your top three to five most material arrangements before March 2027.
How is this different from a Green Dolphin Health Check?›
The free survey shows you where to look. The three-day Health Check does the looking: evidence-based, senior-led, working with your team on your actual contracts, register entries, exit plans and Board minutes, producing a report your Board, internal audit and supervisor can rely on.
How is it scored?›
Every question is answered against published anchors: 2 for evidenced and current, 1 for partial or ageing, 0 for absent, with "don't know" tracked separately because unknowns carry their own risk. Domains are weighted the way a supervisor would weight them (contracts, exit and materiality carry more), and each domain's target is set by the arrangement's materiality, not a one-size bar. The report shows the anchor behind every mark, so nothing in it is a black box.
What is it anchored to?›
FCA PS26/2, PRA PS7/26, PRA SS2/21, PRA SS1/21, FCA FG16/5, the Critical Third Parties regime under FSMA 2023 including the 10 July 2026 designations, the FSB Toolkit (2023), Basel Committee TPRM Principles, NIST SP 800-161r1, ISO/IEC 27036, NCSC guidance, UK GDPR and the ICO Accountability Framework. Every question shows its anchor as you answer.
Step 1 of 2 · the arrangement
Before the survey begins

Tell us what we are surveying

A surveyor asks what the building is used for before opening a single door. Three details calibrate everything that follows.

Used only to label your report. Stays in this browser unless you opt in at the end.

✓

Please name the supplier to continue.

✓
Important Business Services are the services which, if disrupted, could cause intolerable harm to your customers or to market integrity. Defined under PRA SS1/21 and FCA SYSC 15A; most firms have identified between five and fifteen.

Your best current view. If the mapping is unclear, that becomes a finding, not a problem.

✓
✓

If you know it. Renewals before the submission window are the cheapest place to fix contract gaps.

Please choose the closest fit to continue.

The PS26/2 and PS7/26 test: could disruption to this arrangement materially harm your safety and soundness, or the continuity of an Important Business Service? If yes, it is material, whatever the contract value. The register regime applies to material arrangements, and intragroup counts: a service from a group company is still a third-party arrangement under PS7/26.

The report will challenge this where your answers suggest it should be different.

Please choose a tier to continue.

0 of 5 confirmed Supplier name, firm and tier are needed to begin. Answers are saved in this browser only, on this device. Start again clears them.
Step 2 of 2 · surveying
0 of 0 answered · 0%
Green Dolphin · Critical Supplier SurveyEdition 2026.2 Scored 0 / 1 / 2 against published anchors, weighted by materiality. A self-assessment against supervisory expectations: not advice, and not a substitute for the firm's own risk assessment.

Reading this as

This is a self-assessment, not an independent assurance review. It reflects what you told it. It has not tested evidence, read contracts or interviewed the supplier. Use it to decide where the independent looking should start.
The two numbers
Supplier posture · today A weighted score across domains A to G. In place scores 2, partial scores 1, not in place and don’t know score 0. Domain weights follow supervisory emphasis: materiality, contracts, and resilience and exit carry 1.2.
0/100

Regulatory readiness · 18 March 2027 Scored from the Horizon domain plus the regulation-dated questions A3, A5 and E5, on the same 0 to 2 scale. It reads your preparedness for the register and incident reporting regime that begins on 18 March 2027.
0/100

AWARE ASSURED EXPOSED STATIC SUPPLIER POSTURE TODAY READINESS FOR MARCH 2027 GAPS CLOSED LAST RUN THIS ARRANGEMENT

Solid marker: today. Dashed: where closing the three priority gaps takes it, on our read.

Thresholds sit at 60 on both axes. Assured: strong on both counts. Static: strong today, unprepared for what is coming. Aware: sighted on what is coming, weak today. Exposed: work needed on both, with a deadline attached to one of them.
AssuredStrong today and sighted on March 2027. The task is keeping evidence current.
StaticSolid today, unprepared for the new regime. Strong is not the same as ready.
AwareSighted on what is coming, but today’s arrangement would not withstand scrutiny yet.
ExposedWork needed on both axes, and one of them has a regulatory deadline attached.
Our read of your answers
Domain by domain

Where the marks came from, and the target to reach

The notch on each track is the target for an arrangement of this materiality, on our judgement. Tap a row for the fastest route to it.

Where you are Target for this arrangementColour: distance to targetTap any row: the fastest route to target
The three gaps that matter most

Where a supervisor or auditor would start

Ranked by domain weight and answer severity. Each opens into what good looks like and the evidence an independent assessor would ask for.

What you already have

The foundations worth surfacing

Answers marked in place: confirmed strengths to put in front of your Board, audit committee or supervisor.

Flagged: don't know

On a material arrangement, a "don't know" is itself a finding. The first remediation step is to establish the answer.

    Beyond this supplier

    What these answers suggest about the wider arrangement

    A gap on one supplier is usually a gap in the machinery that manages all of them. Each numbered dot is plotted by the effort to build and the value it returns; the list alongside is the key. Tap a dot to jump to its rationale.

    Read these as prompts, not findings: one supplier is one data point. In our experience, the pattern usually holds across the register.

    Questions worth asking

    Take these into your next meetings

    Two registers for two rooms. Pick the room.

    Client modules · unlocked on engagement

    The deeper look this arrangement can have

    Each module is a senior-led analysis run with your team on your actual evidence. Tap one and we will pick the conversation up from there.

    From self-assessment to evidence

    Want help reviewing a particular supplier?

    The survey shows where to look; a review does the looking. Supplier documentation and onsite reviews start at £3,750, senior-led, with audit discipline. Use one to support your own RFP due diligence on a supplier you are choosing, or ongoing due diligence on the most critical suppliers you already run. We work on actual contracts, register entries, sub-processor lists, exit plans, MI packs and Board minutes, not self-reported scores, and we never take referrals from the suppliers we assess.

    • Evidence-based, calibrated for building society proportionality
    • Concentration and nth-party mapping across your material arrangements
    • Stressed exit credibility, tested against an uncooperative supplier
    • Board-ready report with SMF-level accountability framing
    • Assurance over how well TPRM is embedded across your three lines of defence, from policy to practice
    • Coaching for SMFs and NEDs on the questions and MI to demand

    Please enter a valid email address.

    Optional. Sends your survey context and scores so we arrive prepared. No mailing list, no sequences: one human reading what you send. We reply within one working day.

    ✓

    Thanks. We will be in touch.

    Your details are with us and we will reply within one working day. Print or save this report for your records in the meantime.

    What to do next
    1. Take the lowest-scoring high-weight gap above and start remediation this week. The clock strip at the top of this page is not decorative.
    2. Share this report with your CRO, COO or Head of Internal Audit. The board questions give them a ready-made opening.
    3. Run it a second time, independently, from the second line. Where the relationship owner’s answers and risk’s answers diverge is itself management information.
    4. Run the survey for your other most material suppliers. The register obligation covers all of them, not just this one.
    5. Put the supplier picture in its sector context. The Digital Risk Radar at radar.greendolphintccr.com shows where the pressure sits across the sector this quarter, cited to primary sources.
    6. If you want the independent version of this picture, talk to us about a Health Check, including assurance over how well TPRM is embedded across your three lines of defence. Earlier scoping means more runway.
    Your portfolio

    Every supplier you have assessed, one picture

    Latest run per supplier, plotted together. Numbered dots are keyed to the list; tap a name to open that supplier's report.

    15 min · no login Sample
    Composite · what firms are asking suppliers now Run the free survey →
    The people behind the survey
    Paul O’Leary
    Paul O’Leary
    Founder & Director

    Questions, or want this brought to your board?

    Contact us →