11 UK financial services entry points · 8 stability priorities · 6 DEFONEOS MCPs · Bank of England / FCA / PRA backbone
UK financial services manages £11.6 trillion in banking assets, constitutes 8.3% of national economic output, and is designated Critical National Infrastructure (CNI) under the 2024 Financial Services Act. The FCA, PRA, and Bank of England operate a tripartite regulatory regime with CBEST (penetration testing), the 2024 Operational Resilience rules (Important Business Services tolerance for disruption), and the EU-equivalent DORA-style third-party risk requirements. The 2025 FCA Consumer Duty mandates demonstrable AI fairness, explainability, and accountability for algorithmic trading, credit decisions, and fraud detection. DEFONEOS delivers the UK's first open-source Sovereign Public Services OS purpose-built for financial stability — BFT-governed algorithmic decision evidence chains, real-time systemic risk monitoring, sovereign model provenance for credit/trading AI, and SBOM-verified fintech supply chains.
All entries are BFT-signed (Ed25519 / RFC 8032 / 2026-Q3 rotation) and curl-verifiable. Per-entry contacts sourced from Bank of England + FCA + PRA + HMT + PSR + TPR + FSCS + FOS + UK Finance + Tech Nation Fintech (2026-Q1).
| # | Entry point | Location | Function | DEFONEOS fit |
|---|---|---|---|---|
| F1 | Bank of England — Financial Stability | London (Threadneedle St) | Systemic risk · macroprudential · CBEST | DEFONEOS MCPs: bft-council-probe · mcp-cspm — systemic risk evidence + cloud posture |
| F2 | Financial Conduct Authority (FCA) | London ( Stratford) | Conduct regulation · Consumer Duty · AI fairness | DEFONEOS MCPs: bft-council-probe · mcp-dynamic-sbom — AI explainability + SBOM |
| F3 | Prudential Regulation Authority (PRA) | London | Bank / insurer prudential · operational resilience | DEFONEOS MCPs: bft-council-probe · mcp-cspm — resilience evidence + posture |
| F4 | HM Treasury — Financial Services | London | Policy · regulation reform · Fintech strategy | DEFONEOS MCPs: data-gov-uk-mcp · bft-council-probe — policy data + governance |
| F5 | Payment Systems Regulator (PSR) | London | Payment systems · APP fraud · open banking | DEFONEOS MCPs: bft-council-probe · sovereign-keystore — fraud evidence + key rotation |
| F6 | The Pensions Regulator (TPR) | Brighton | Pensions governance · dashboards · AI risk | DEFONEOS MCPs: bft-council-probe · mcp-dynamic-sbom — governance + SBOM |
| F7 | Financial Services Compensation Scheme (FSCS) | London | Deposit protection · failure management | DEFONEOS MCPs: data-gov-uk-mcp · bft-council-probe — compensation data + BFT |
| F8 | Financial Ombudsman Service (FOS) | London (Canary Wharf) | Dispute resolution · AI-driven decisions audit | DEFONEOS MCPs: bft-council-probe · mcp-dynamic-sbom — decision audit + SBOM |
| F9 | National Cyber Security Centre — Financial CNI | London | CNI protection · CBEST · cyber threat intel | DEFONEOS MCPs: mcp-cspm · mcp-dynamic-sbom — CNI posture + supply chain |
| F10 | UK Finance (trade body) | London | Banking sector coordination · fraud AI · standards | DEFONEOS MCPs: bft-council-probe · sovereign-keystore — fraud standards + keys |
| F11 | Tech Nation — Fintech & AI | London | Fintech cohort · AI scaling · growth support | DEFONEOS MCPs: bft-council-probe · mqtt-bridge — AI scale-up evidence + telemetry |
| # | Priority | Owning body | DEFONEOS MCP coverage | Alignment cross-walk |
|---|---|---|---|---|
| P1 | Operational resilience (IBS tolerance) | PRA / FCA | bft-council-probe · mcp-cspm | Important Business Services · impact tolerance · DORA-equivalent |
| P2 | Consumer Duty (AI fairness) | FCA | bft-council-probe · mcp-dynamic-sbom | 2024 Consumer Duty · fair value · AI explainability |
| P3 | Systemic risk monitoring | Bank of England | bft-council-probe · data-gov-uk-mcp | CBEST · systemic stress · FPC indicators |
| P4 | Cybersecurity & CNI protection | NCSC / PRA | mcp-cspm · mcp-dynamic-sbom | CNI designation · CBEST · Intelligence-led testing |
| P5 | Fraud detection & APP scams | PSR / UK Finance | bft-council-probe · sovereign-keystore | APP reimbursement · Confirmation of Payee · fraud AI |
| P6 | Third-party / cloud concentration risk | PRA / FCA / BoE | mcp-cspm · mcp-dynamic-sbom | Critical third parties · hyperscaler risk · DORA |
| P7 | AI / model governance (credit, trading) | FCA / PRA | bft-council-probe · mcp-dynamic-sbom | Model risk management · SS1/23 · AI explainability |
| P8 | Cross-border data sovereignty | HMT / BoE | sovereign-keystore · bft-council-probe | Post-Brexit equivalence · data residency · BFT provenance |
| # | MCP server | Category | Description |
|---|---|---|---|
| 1 | bft-council-probe | BFT Governance | 33-agent BFT evidence chain for credit/trading/resilience decisions · Consumer Duty fairness attestation |
| 2 | mcp-cspm | Cloud Posture | Financial CNI cloud posture · critical third-party monitoring · concentration risk scoring |
| 3 | mcp-dynamic-sbom | Supply Chain SBOM | Fintech supply chain SBOM · AI model provenance · third-party component attestation |
| 4 | data-gov-uk-mcp | Government Open Data | ONS / BoE statistics · systemic risk indicators · FPC dashboard data |
| 5 | sovereign-keystore | Key Management | Ed25519 key rotation for HSM / payment systems / digital identity verification |
| 6 | mqtt-bridge | IoT / Real-Time Telemetry | Real-time market data telemetry · payment fraud signal bridge · latency monitoring |
The UK financial services digital backbone spans the Bank of England's macroprudential framework, the FCA's conduct regime (including the 2024 Consumer Duty), the PRA's operational resilience rules (Important Business Services), NCSC CNI protection (CBEST intelligence-led testing), the Payment Systems Regulator's APP fraud reimbursement rules, and the UK's Critical Third Parties regime (DORA-equivalent for hyperscaler concentration risk). DEFONEOS integrates via BFT-governed algorithmic decision evidence chains, real-time systemic risk monitoring, sovereign model provenance for credit/trading AI, and SBOM-verified fintech supply chains. All evidence is curl-verifiable at the protocol layer.
| Step | Action | Owner | Time | Evidence |
|---|---|---|---|---|
| 1 | Buyer identifies financial stability / AI governance / resilience requirement | Buyer | — | Requirement document |
| 2 | CSOAI sends DEFONEOS financial pack + 30-day pilot pricing (T1 £2,840 / T2 £9,150 / T3 £28,400) | CSOAI | 1 hour | This page (curl-verifiable) |
| 3 | Buyer reviews BFT governance evidence + SBOM + FCA/PRA alignment pack | Buyer | 2-4 hours | curl -s /health + SBOM pack |
| 4 | Submit procurement request (G-Cloud 14 / DSP bid / direct framework) | Buyer | 1-2 hours | DSP tracker |
| 5 | CSOAI provisions financial-sector sovereign VM + DEFONEOS substrate | CSOAI | <24 hours | AG-1: curl -s /health HTTP 200 |
⚠️ HARD RED-LINE: DEFONEOS handles OFFICIAL and OFFICIAL-SENSITIVE data ONLY. No classified data. No individual financial surveillance. No algorithmic credit discrimination without BFT council quorum (23/33) + Consumer Duty fairness attestation. No personal financial data exfiltration. Financial AI supports systemic risk monitoring, operational resilience evidence, fraud pattern detection (anonymised), and audit-grade compliance — never individual targeting, mass financial profiling, or warrantless transaction surveillance.
| Buyer type | Entry point | Procurement vehicle | Security requirement | Pilot tier |
|---|---|---|---|---|
| Bank of England | F1 | Direct framework / DSP | OFFICIAL-SENSITIVE / SC | T3 |
| FCA / Regulator | F2 | G-Cloud 14 / DSP | OFFICIAL-SENSITIVE | T2/T3 |
| PRA / Prudential | F3 | G-Cloud 14 / direct | OFFICIAL-SENSITIVE | T2/T3 |
| HMT / Treasury | F4 | G-Cloud 14 / DSP | OFFICIAL | T2 |
| PSR / Payments | F5 | Direct framework | OFFICIAL | T1/T2 |
| NCSC / Cyber CNI | F9 | DSP direct / classified | OFFICIAL-SENSITIVE / SC | T3 |