Third-party register
Operational resilience register — vendors providing material services to the firm. UK firms: FCA SS1/21 / SYSC 8 third-party arrangements. AU firms: APRA CPS 230 critical service providers.
| Vendor | Service | Criticality | RTO / RPO (h) | Jurisdiction | Impact tolerance |
|---|---|---|---|---|---|
| AJ Bell | Custodian platform — SIPP for drawdown phase | critical | 4 / 1 | uk | Drawdown clients unable to transact; manual valuation path required. |
| AWS | Compute & storage (eu-west-2 production region) | critical | 4 / 1 | uk | Full service outage; DR plan invoked. |
| AWS | Compute & storage (ap-southeast-2 production region) | critical | 4 / 1 | au | Full service outage; DR plan invoked. |
| ComplyAdvantage | AML screening, PEP/sanctions | critical | 8 / 1 | uk | AML gate blocks advice; tolerable for short outages with monitoring. |
| Cynopsis | AML screening — AU sanctions/PEP/adverse media | critical | 8 / 1 | au | AML gate blocks SoA finalisation; tolerable for short outages with monitoring. |
| FrankieOne | IDV/AML — DVS/FVS adapter for AU client onboarding | critical | 4 / 1 | au | Client onboarding blocked while down; manual 100-point ID checklist path available. |
| HUB24 | Custodian platform — wrap accounts, super, pension | critical | 4 / 1 | au | Active client positions unavailable; halt new applications. |
| Netwealth | Custodian platform — wrap accounts, super, pension | critical | 4 / 1 | au | Active client positions unavailable; halt new applications. |
| Sumsub | IDV — client identification & verification | critical | 4 / 1 | uk | Onboarding blocked if down; queue manual review for IDV-pending cases. |
| Transact | Custodian platform — wraps, SIPP, GIA | critical | 4 / 1 | uk | Active client positions unavailable; halt new applications. |
| WorkOS | Authentication / SSO / directory | critical | 4 / 1 | uk | Sign-in blocked; existing sessions continue until expiry. |
| AWS Bedrock | LLM inference (Claude family) | high | 12 / 0 | uk | Generators degrade to template-only mode; advisers can still progress cases manually. |
| AWS Bedrock | LLM inference cross-region (Claude family) | high | 12 / 0 | au | Generators degrade to template-only mode; advisers can still progress cases manually. |
| DocuSign | Qualified electronic signatures | high | 12 / 1 | uk | Suitability reports cannot be e-signed; defer to next business day if outage extends. |
| Twilio | SMS — client communications + MFA codes | medium | 24 / 1 | au | SMS MFA falls back to TOTP; client SMS reminders delayed. |