Sample report · composite supplier · illustrative answers scored by the live engine
Critical Supplier Survey · Free · July 2026 edition
Would this supplier survive the scrutiny that is coming?
You would not lend against a property without a survey. This is the survey for the suppliers your services stand on: one arrangement, thirty-seven questions, two honest numbers.
The instrument · two axesIllustrative · your arrangement plots here
Designated Critical Third Parties · 10 Jul 2026
AWSGoogle CloudMicrosoftOraclejoint Bank · PRA · FCA oversightAWSGoogle CloudMicrosoftOraclefirms remain responsible for their own arrangements
AWSGoogle CloudMicrosoftOraclejoint Bank · PRA · FCA oversightAWSGoogle CloudMicrosoftOraclefirms remain responsible for their own arrangements
The clock this survey is set against
Your first PS7/26 register submission window opens 18 March 2027.
The work that has to be substantially complete before then: contract changes, fourth-party visibility, exit testing, governance uplift. The survey tells you which of it applies to this supplier.
0days of runway18 March 2027 is when the first PS7/26 register submission window opens, per the PRA and FCA policy statements published in March 2026. The count runs from your device’s clock and updates on every visit.days until the first PS7/26 register submission
PRA PS7/26FCA PS26/2Bank of EnglandSS2/21SS1/21FG16/5CTP regime · FSMA 2023FSB ToolkitBasel TPRM PrinciplesStrong & SimpleUK GDPR Art 28NISTISO 27001PRA PS7/26FCA PS26/2Bank of EnglandSS2/21SS1/21FG16/5CTP regime · FSMA 2023FSB ToolkitBasel TPRM PrinciplesStrong & SimpleUK GDPR Art 28NISTISO 27001
Two numbers, two different questions
Where the arrangement sits today. How ready you are for what is coming.
Number one · supplier posture
Where this arrangement sits today
Governance, contracts, concentration, resilience, exit, cyber and monitoring: the state of the relationship as it stands, scored across seven domains and weighted the way a supervisor would weight them.
Number two · regulatory readiness
How prepared you are for 18 March 2027
The forward-looking test: register readiness, the July Critical Third Party designations, incident-clock alignment, the renewals falling before the deadline, and whether anyone owns the horizon.
One survey, four documents
Built for the room you sit in
The report reshapes for your seat at the table, and each lens prints as its own pack. Tap a seat to open the sample report in that lens.
When the same four names sit behind half the sector, strong controls of your own can still miss the point. On 10 July, HM Treasury designated AWS, Google Cloud, Microsoft and Oracle as the first Critical Third Parties, under joint Bank, PRA and FCA oversight from 13 July. Oversight of them does not move accountability for your own arrangements.
The supervisory question has changed shape. It is no longer "do you have a register" but "can you prove you understand and manage what is on it". The gap between those two questions is where findings are written.
4Critical Third Parties designated AWS, Google, Microsoft, Oracle10 Jul 2026
1stSMF18 fine for outsourcing oversight failure set the bar2024
803hours of unplanned outages, much of it third-partyTSC, 2025
Mar 2026PS7/26 & PS26/2 published
10 Jul 2026First CTPs designated
Today247 days of runway
18 Mar 2027First register submission
Firms remain responsible for their own third-party arrangements. Oversight of the hyperscalers does not move that accountability. Sources: HM Treasury, PRA PS7/26, FCA PS26/2, Treasury Select Committee.
The wider picture
This survey reads one supplier. Our Digital Risk Radar reads the sector it sits inside: eight digital risks, every claim cited to primary sources, refreshed quarterly.
01Can we evidence that this arrangement is classified correctly, to the standard the new register will expose?
02Do we know where the newly designated Critical Third Parties sit in this supplier's delivery chain?
03Would our exit plan survive a supplier that stops co-operating, not just one that leaves politely?
04Which of this supplier's contract renewals fall before 18 March 2027, and what has to be inserted at each one?
05If this supplier had a reportable incident at 02:00 on a Sunday, would we meet our regulatory clock?
Client modules · unlocked on engagement
Where the survey stops, the modules begin
The free survey is self-reported by design. For material arrangements, clients unlock deeper analyses run with our team on your actual evidence. Each one appears against your results at the end of the survey.
Unlocked means we do the work with you. These are senior-led analyses delivered alongside your team as part of a Health Check or standalone. Not software, no licences, no per-seat pricing: scoped and priced per engagement.
What this is not
×
Not advice. It is a structured self-assessment built to open better board and supplier conversations, not to close them for you.
×
Not a regulatory submission. PS7/26 requires a register submitted through RegData. This survey helps you prepare for that; it is not that.
×
Not an independent assessment. It scores what you tell it. It does not test evidence, read contracts or interview your supplier. It shows you where the looking should start.
×
Not a data grab. No login. Your answers stay in this browser unless you choose to send them to us at the end.
This survey came out of the same boardrooms as our Digital Risk Radar. Boards kept asking two questions in the same breath: how solid is this particular supplier, and are we ready for the rules landing in March. Those are different questions, and tools that blur them produce numbers nobody trusts. So we built one that keeps them apart, anchored every question to a primary source, and kept it free and login-less because the point was never to capture anyone. If it helps your next risk committee open with two clear numbers instead of one vague feeling, it has done its job.
Paul O'LearyGreen Dolphin (TCCR) · info@greendolphintccr.com
Common questions
Is this a PS7/26 or PS26/2 submission?›
No. Those policy statements require a register of material arrangements submitted via RegData from 18 March 2027. This survey gives you a structured view of one arrangement so you can prepare for that with confidence. It is not a regulatory return.
How long does it take?›
Around 15 minutes per supplier, depending on how much you already know. You can pause at any point; your answers stay in this browser and the survey resumes where you left off.
Where do my answers go?›
Nowhere, unless you choose otherwise. Answers are held in your browser's local storage. They are only sent to info@greendolphintccr.com if you complete the optional contact form at the end of your report.
Can I assess more than one supplier?›
Yes. After your first report you can run the survey again for another arrangement; your firm-size calibration is remembered. We suggest your top three to five most material arrangements before March 2027.
How is this different from a Green Dolphin Health Check?›
The free survey shows you where to look. The three-day Health Check does the looking: evidence-based, senior-led, working with your team on your actual contracts, register entries, exit plans and Board minutes, producing a report your Board, internal audit and supervisor can rely on.
How is it scored?›
Every question is answered against published anchors: 2 for evidenced and current, 1 for partial or ageing, 0 for absent, with "don't know" tracked separately because unknowns carry their own risk. Domains are weighted the way a supervisor would weight them (contracts, exit and materiality carry more), and each domain's target is set by the arrangement's materiality, not a one-size bar. The report shows the anchor behind every mark, so nothing in it is a black box.
What is it anchored to?›
FCA PS26/2, PRA PS7/26, PRA SS2/21, PRA SS1/21, FCA FG16/5, the Critical Third Parties regime under FSMA 2023 including the 10 July 2026 designations, the FSB Toolkit (2023), Basel Committee TPRM Principles, NIST SP 800-161r1, ISO/IEC 27036, NCSC guidance, UK GDPR and the ICO Accountability Framework. Every question shows its anchor as you answer.
Step 1 of 2 · the arrangement
Before the survey begins
Tell us what we are surveying
A surveyor asks what the building is used for before opening a single door. Three details calibrate everything that follows.
Used only to label your report. Stays in this browser unless you opt in at the end.
✓
Please name the supplier to continue.
✓
Important Business Services are the services which, if disrupted, could cause intolerable harm to your customers or to market integrity. Defined under PRA SS1/21 and FCA SYSC 15A; most firms have identified between five and fifteen.
Your best current view. If the mapping is unclear, that becomes a finding, not a problem.
✓
✓
If you know it. Renewals before the submission window are the cheapest place to fix contract gaps.
Please choose the closest fit to continue.
The PS26/2 and PS7/26 test: could disruption to this arrangement materially harm your safety and soundness, or the continuity of an Important Business Service? If yes, it is material, whatever the contract value. The register regime applies to material arrangements, and intragroup counts: a service from a group company is still a third-party arrangement under PS7/26.
The report will challenge this where your answers suggest it should be different.
Please choose a tier to continue.
0 of 5 confirmedSupplier name, firm and tier are needed to begin.Answers are saved in this browser only, on this device. Start again clears them.
Step 2 of 2 · surveying
0 of 0 answered · 0%
Green Dolphin · Critical Supplier SurveyEdition 2026.2Scored 0 / 1 / 2 against published anchors, weighted by materiality. A self-assessment against supervisory expectations: not advice, and not a substitute for the firm's own risk assessment.
Reading this as
This is a self-assessment, not an independent assurance review. It reflects what you told it. It has not tested evidence, read contracts or interviewed the supplier. Use it to decide where the independent looking should start.
The two numbers
Supplier posture · todayA weighted score across domains A to G. In place scores 2, partial scores 1, not in place and don’t know score 0. Domain weights follow supervisory emphasis: materiality, contracts, and resilience and exit carry 1.2.
0/100
Regulatory readiness · 18 March 2027Scored from the Horizon domain plus the regulation-dated questions A3, A5 and E5, on the same 0 to 2 scale. It reads your preparedness for the register and incident reporting regime that begins on 18 March 2027.
0/100
Solid marker: today. Dashed: where closing the three priority gaps takes it, on our read.
Thresholds sit at 60 on both axes. Assured: strong on both counts. Static: strong today, unprepared for what is coming. Aware: sighted on what is coming, weak today. Exposed: work needed on both, with a deadline attached to one of them.
AssuredStrong today and sighted on March 2027. The task is keeping evidence current.
StaticSolid today, unprepared for the new regime. Strong is not the same as ready.
AwareSighted on what is coming, but today’s arrangement would not withstand scrutiny yet.
ExposedWork needed on both axes, and one of them has a regulatory deadline attached.
Our read of your answersDomain by domain
Where the marks came from, and the target to reach
The notch on each track is the target for an arrangement of this materiality, on our judgement. Tap a row for the fastest route to it.
Where you are Target for this arrangementColour: distance to targetTap any row: the fastest route to target
The three gaps that matter most
Where a supervisor or auditor would start
Ranked by domain weight and answer severity. Each opens into what good looks like and the evidence an independent assessor would ask for.
What you already have
The foundations worth surfacing
Answers marked in place: confirmed strengths to put in front of your Board, audit committee or supervisor.
Flagged: don't know
On a material arrangement, a "don't know" is itself a finding. The first remediation step is to establish the answer.
Beyond this supplier
What these answers suggest about the wider arrangement
A gap on one supplier is usually a gap in the machinery that manages all of them. Each numbered dot is plotted by the effort to build and the value it returns; the list alongside is the key. Tap a dot to jump to its rationale.
Read these as prompts, not findings: one supplier is one data point. In our experience, the pattern usually holds across the register.
Questions worth asking
Take these into your next meetings
Two registers for two rooms. Pick the room.
Client modules · unlocked on engagement
The deeper look this arrangement can have
Each module is a senior-led analysis run with your team on your actual evidence. Tap one and we will pick the conversation up from there.
From self-assessment to evidence
Want help reviewing a particular supplier?
The survey shows where to look; a review does the looking. Supplier documentation and onsite reviews start at £3,750, senior-led, with audit discipline. Use one to support your own RFP due diligence on a supplier you are choosing, or ongoing due diligence on the most critical suppliers you already run. We work on actual contracts, register entries, sub-processor lists, exit plans, MI packs and Board minutes, not self-reported scores, and we never take referrals from the suppliers we assess.
Evidence-based, calibrated for building society proportionality
Concentration and nth-party mapping across your material arrangements
Stressed exit credibility, tested against an uncooperative supplier
Board-ready report with SMF-level accountability framing
Assurance over how well TPRM is embedded across your three lines of defence, from policy to practice
Coaching for SMFs and NEDs on the questions and MI to demand
✓
Thanks. We will be in touch.
Your details are with us and we will reply within one working day. Print or save this report for your records in the meantime.
What to do next
Take the lowest-scoring high-weight gap above and start remediation this week. The clock strip at the top of this page is not decorative.
Share this report with your CRO, COO or Head of Internal Audit. The board questions give them a ready-made opening.
Run it a second time, independently, from the second line. Where the relationship owner’s answers and risk’s answers diverge is itself management information.
Run the survey for your other most material suppliers. The register obligation covers all of them, not just this one.
Put the supplier picture in its sector context. The Digital Risk Radar at radar.greendolphintccr.com shows where the pressure sits across the sector this quarter, cited to primary sources.
If you want the independent version of this picture, talk to us about a Health Check, including assurance over how well TPRM is embedded across your three lines of defence. Earlier scoping means more runway.
Your portfolio
Every supplier you have assessed, one picture
Latest run per supplier, plotted together. Numbered dots are keyed to the list; tap a name to open that supplier's report.