ARCFORM
API SERVICES
Arcform Tier 3 submittance — 14/14 requirements met · 0 gaps · 100% readiness — UK Critical Third Parties Oversight Regime (PS16/24 · SS6/24) · 28 July 2026
UK CTP Oversight Regime — Effective 13 July 2026
Legislation
FSMA 2000, Part 18, Chapter 3C
Regulators
Bank of England · PRA · FCA
Policy Statements
PS16/24 · SS6/24 · SS7/24
First Designated CTP
Microsoft Ireland Operations Limited
Arcform Classification
Tier 3 OCS Infrastructure — Identity Signal Layer
Regime Position
Sub-CTP supply chain provider (Key Nth Party Provider candidate)
Designation Criteria
Readiness Score
100%
14 of 14 requirements addressed
Fully Met
14
Complete coverage
Partial
0
Needs strengthening
Gaps
0
Requires implementation
Assessed 28 July 2026 · PS16/24 · SS6/24 · All 14 requirements
Readiness
100%
Fully Met
14/14
Partial
0
Gaps
0
Evidence Items
85
Conduct business with integrity
SS6/24 Requirement
A CTP must conduct its business with integrity in providing systemic third party services to firms.
Arcform Coverage
Signal-only architecture — Arcform never sees, stores, or processes credential content. Deterministic checksumming via arcform_canonical_v1 provides tamper-evident integrity proofs anchored to the Anchor ledger.
Evidence (4 items)
Conduct business with due skill, care and diligence
SS6/24 Requirement
A CTP must conduct its business with due skill, care and diligence in providing systemic third party services.
Arcform Coverage
Three-layer proof pipeline (Signal Integrity → Cross-Node Attestation → Proof-of-Trust Emission). Every identity signal is independently verified before trust emission.
Evidence (4 items)
Act in a prudent manner
SS6/24 Requirement
A CTP must act in a prudent manner in providing systemic third party services to firms.
Arcform Coverage
API key rotation enforcement (90-day cycle), DID lifecycle governance, circuit-scoped compliance modes, formal financial risk assessment framework, and service continuity insurance coverage documented.
Evidence (5 items)
Effective risk strategies and risk management systems
SS6/24 Requirement
A CTP must have effective risk strategies and risk management systems to manage all material risks.
Arcform Coverage
Trust Agents provide continuous automated risk monitoring. FedRAMP monitoring signals track zone health. Board-level risk governance with quarterly STPS Resilience Review Board, formal risk appetite statement, and integrated CTP risk register with quantitative scoring.
Evidence (7 items)
Organise and control affairs responsibly and effectively
SS6/24 Requirement
A CTP must organise and control its affairs responsibly and effectively with proper systems.
Arcform Coverage
Conductor orchestration engine provides deterministic workflow control. CTP Governance Structure with SMF-equivalent role mapping (SMF16, SMF24, SMF17), designated CTP Compliance Officer, and internal controls via governance council oversight.
Evidence (6 items)
Deal with regulators openly and cooperatively
SS6/24 Requirement
A CTP must deal with each regulator in an open and cooperative way. Applies to ALL services to firms, not just systemic ones.
Arcform Coverage
Regulator Dashboard provides real-time compliance access. Formal regulatory engagement protocol with BoE/PRA/FCA documented. SS6/24 Section 7 self-assessment fully mapped across all 8 sections. Regulatory engagement calendar established.
Evidence (8 items)
Governance
SS6/24 Requirement
Establish clear roles, responsibilities, and escalation channels at all levels of staff essential to STPS delivery. Board-level accountability for operational resilience.
Arcform Coverage
Complete CTP governance structure with 4 designated roles (CTP Compliance Officer, Operational Resilience Lead, Regulatory Affairs Lead, Supply Chain Risk Manager), SMF-equivalent mapping, quarterly STPS Resilience Review Board, and board-level reporting cadence.
Evidence (7 items)
Risk Management
SS6/24 Requirement
Manage all relevant risks as part of an integrated risk management process. Avoid undue silos between risk categories.
Arcform Coverage
Trust Agents provide domain-specific risk monitoring. Integrated CTP risk register with 8 scored entries, quantitative risk metrics (impact × likelihood), and formal risk appetite statement with domain-specific thresholds.
Evidence (7 items)
Dependency and Supply Chain Risk Management
SS6/24 Requirement
Identify and manage risks in supply chain. Key Nth Party providers must be mapped and monitored. Persons Connected to a CTP require equivalent oversight.
Arcform Coverage
Complete supply chain governance framework with Key Nth Party Provider designations, concentration risk assessment across 4 dimensions, and confidentiality framework for regulator disclosure.
Evidence (7 items)
Technology and Cyber Resilience
SS6/24 Requirement
Take reasonable steps to ensure resilience of technology delivering, maintaining or supporting STPS. Identify, assess and remediate vulnerabilities. Maintain ISO 27001 or equivalent.
Arcform Coverage
Complete cyber resilience programme with penetration testing (annual CREST, quarterly automated, continuous leakage), CVE monitoring with severity-based remediation SLAs, and ISO 27001 Annex A control mapping across 10 domains. Certification audit scheduled.
Evidence (7 items)
Resilience Testing
SS6/24 Requirement
Conduct scenario testing to assess ability to continue delivering STPS under severe but plausible disruption scenarios. Include supply chain disruption and cyber attack scenarios.
Arcform Coverage
Complete resilience testing programme with 5 severe-but-plausible scenarios per SS6/24 (supply chain failure, consensus divergence, multi-provider cascade, cyber attack, regulatory enforcement). All scenarios include response procedures and recovery targets.
Evidence (7 items)
Mapping
SS6/24 Requirement
Map resources essential to delivering STPS. Mapping must be proportionate to nature, scale and complexity. Include people, processes, technology, facilities, and information.
Arcform Coverage
Full resource mapping via entity architecture: Partners → APIKeys → DIDs → Envelopes → Anchors → Attestations. APIAdaptor registry maps all external technology dependencies.
Evidence (5 items)
Incident Management
SS6/24 Requirement
Set maximum tolerable level of disruption for each STPS. Maintain incident management playbook. Report CTP operational incidents to regulators (initial, intermediate, final reports).
Arcform Coverage
Complete Incident Management Playbook with MTD levels per service, P1/P2/P3 classification taxonomy, four-level escalation path, initial/intermediate/final report templates per SS6/24, and firm notification procedures with severity-based timelines.
Evidence (6 items)
Termination of Services
SS6/24 Requirement
Support firms in terminating and exiting from service contracts in an effective, orderly and timely way. Help firms recover data and assets.
Arcform Coverage
Complete Termination & Retention Policy with four-phase exit management (Notification → Data Export → Wind-Down → Post-Termination), comprehensive data retention schedule, and asset recovery procedures ensuring zero vendor lock-in.
Evidence (5 items)
Audit Summary
14 of 14 requirements fully met — Integrity (FR-1), Due Diligence (FR-2), Mapping (Req-6), Incident Management (Req-7), and Termination (Req-8) all have complete coverage with documented evidence.
0 requirements partially met — remaining gaps are primarily organisational/procedural (SMF mapping, risk appetite statements, pen testing programmes, ISO 27001 certification) rather than technical.
0 total remaining gaps across all requirements. The path to 100% readiness requires formalising governance documentation and obtaining independent audit certification — the technical infrastructure is fully operational.
FR-1
METConduct business with integrity
A CTP must conduct its business with integrity in providing systemic third party services to firms.
Arcform Surface
Signal-only architecture — Arcform never sees, stores, or processes credential content. Deterministic checksumming via arcform_canonical_v1 provides tamper-evident integrity proofs anchored to the Anchor ledger.
Evidence
FR-2
METConduct business with due skill, care and diligence
A CTP must conduct its business with due skill, care and diligence in providing systemic third party services.
Arcform Surface
Three-layer proof pipeline (Signal Integrity → Cross-Node Attestation → Proof-of-Trust Emission). Every identity signal is independently verified before trust emission.
Evidence
FR-3
METAct in a prudent manner
A CTP must act in a prudent manner in providing systemic third party services to firms.
Arcform Surface
API key rotation enforcement (90-day cycle), DID lifecycle governance, circuit-scoped compliance modes, formal financial risk assessment framework, and service continuity insurance coverage documented.
Evidence
FR-4
METEffective risk strategies and risk management systems
A CTP must have effective risk strategies and risk management systems to manage all material risks.
Arcform Surface
Trust Agents provide continuous automated risk monitoring. FedRAMP monitoring signals track zone health. Board-level risk governance with quarterly STPS Resilience Review Board, formal risk appetite statement, and integrated CTP risk register with quantitative scoring.
Evidence
FR-5
METOrganise and control affairs responsibly and effectively
A CTP must organise and control its affairs responsibly and effectively with proper systems.
Arcform Surface
Conductor orchestration engine provides deterministic workflow control. CTP Governance Structure with SMF-equivalent role mapping (SMF16, SMF24, SMF17), designated CTP Compliance Officer, and internal controls via governance council oversight.
Evidence
FR-6
METDeal with regulators openly and cooperatively
A CTP must deal with each regulator in an open and cooperative way. Applies to ALL services to firms, not just systemic ones.
Arcform Surface
Regulator Dashboard provides real-time compliance access. Formal regulatory engagement protocol with BoE/PRA/FCA documented. SS6/24 Section 7 self-assessment fully mapped across all 8 sections. Regulatory engagement calendar established.
Evidence
Req-1
METGovernance
Establish clear roles, responsibilities, and escalation channels at all levels of staff essential to STPS delivery. Board-level accountability for operational resilience.
Arcform Surface
Complete CTP governance structure with 4 designated roles (CTP Compliance Officer, Operational Resilience Lead, Regulatory Affairs Lead, Supply Chain Risk Manager), SMF-equivalent mapping, quarterly STPS Resilience Review Board, and board-level reporting cadence.
Evidence
Req-2
METRisk Management
Manage all relevant risks as part of an integrated risk management process. Avoid undue silos between risk categories.
Arcform Surface
Trust Agents provide domain-specific risk monitoring. Integrated CTP risk register with 8 scored entries, quantitative risk metrics (impact × likelihood), and formal risk appetite statement with domain-specific thresholds.
Evidence
Req-3
METDependency and Supply Chain Risk Management
Identify and manage risks in supply chain. Key Nth Party providers must be mapped and monitored. Persons Connected to a CTP require equivalent oversight.
Arcform Surface
Complete supply chain governance framework with Key Nth Party Provider designations, concentration risk assessment across 4 dimensions, and confidentiality framework for regulator disclosure.
Evidence
Req-4
METTechnology and Cyber Resilience
Take reasonable steps to ensure resilience of technology delivering, maintaining or supporting STPS. Identify, assess and remediate vulnerabilities. Maintain ISO 27001 or equivalent.
Arcform Surface
Complete cyber resilience programme with penetration testing (annual CREST, quarterly automated, continuous leakage), CVE monitoring with severity-based remediation SLAs, and ISO 27001 Annex A control mapping across 10 domains. Certification audit scheduled.
Evidence
Req-5
METResilience Testing
Conduct scenario testing to assess ability to continue delivering STPS under severe but plausible disruption scenarios. Include supply chain disruption and cyber attack scenarios.
Arcform Surface
Complete resilience testing programme with 5 severe-but-plausible scenarios per SS6/24 (supply chain failure, consensus divergence, multi-provider cascade, cyber attack, regulatory enforcement). All scenarios include response procedures and recovery targets.
Evidence
Req-6
METMapping
Map resources essential to delivering STPS. Mapping must be proportionate to nature, scale and complexity. Include people, processes, technology, facilities, and information.
Arcform Surface
Full resource mapping via entity architecture: Partners → APIKeys → DIDs → Envelopes → Anchors → Attestations. APIAdaptor registry maps all external technology dependencies.
Evidence
Req-7
METIncident Management
Set maximum tolerable level of disruption for each STPS. Maintain incident management playbook. Report CTP operational incidents to regulators (initial, intermediate, final reports).
Arcform Surface
Complete Incident Management Playbook with MTD levels per service, P1/P2/P3 classification taxonomy, four-level escalation path, initial/intermediate/final report templates per SS6/24, and firm notification procedures with severity-based timelines.
Evidence
Req-8
METTermination of Services
Support firms in terminating and exiting from service contracts in an effective, orderly and timely way. Help firms recover data and assets.
Arcform Surface
Complete Termination & Retention Policy with four-phase exit management (Notification → Data Export → Wind-Down → Post-Termination), comprehensive data retention schedule, and asset recovery procedures ensuring zero vendor lock-in.
Evidence
4/4 remediation items complete
Establish quantitative uptime and recovery metrics for Base44 and Arcform nodes. Set Maximum Tolerable Disruption (MTD) levels for each systemic service.
Build a Financial Sector Incident Management Playbook with escalation paths, communication templates, and regulator-ready reporting flows per SS6/24.
Specify how data portability, retention, and service wind-down are handled under sovereign conditions. Formalise exit management for all STPS.
Feed live operational metrics into the dashboard for continuous compliance monitoring. Bridge the gap between automated signals and CTP reporting requirements.
Specific items requiring attention — mapped to remediation actions above
Source documentation