Third-party and outsourcing resilience: the supplier failures that can stop a football club cold
Identifying important business services, setting tolerances for their disruption, and mapping who delivers them are three disciplines a club can complete largely through its own effort. The fourth is harder, because it requires the club to hold a third party to a standard the club does not control. Financial services firms have a specific regulatory framework for exactly this problem. Football clubs, for the most part, do not -- and it shows.
This article is the fifth in our series on Operational Resilience for Football clubs. You can find other articles in this series here.
The framework alongside PS21/3 that football has largely missed
The previous article in this series introduced the FCA's principle that outsourcing the delivery of a service does not outsource the responsibility for its resilience. That principle is not merely a general observation drawn from PS21/3 -- it sits within a specific, detailed regulatory framework built for exactly this purpose. The Prudential Regulation Authority's Supervisory Statement SS2/21, Outsourcing and third party risk management, sits alongside PS21/3 and works with the FCA's own outsourcing rules under SYSC 8 to set out precisely what financial services firms are expected to do with their critical suppliers: conduct proper due diligence before onboarding them, maintain contracts that specifically address business continuity and exit arrangements, assess the materiality of each relationship on an ongoing basis, and understand concentration risk where multiple parts of the firm -- or, in aggregate across the sector, multiple firms -- depend on the same provider.
Nothing in English football requires clubs to do any of this. That absence of a mandatory framework is precisely why this is football's biggest blind spot in the entire operational resilience discipline: not because the risk is smaller than in financial services, but because no external pressure has yet forced clubs to build the muscle for managing it. The previous article in this series established how concentrated football's supplier market actually is -- a small number of stewarding, catering and ticketing technology providers serving much of the league at once. This article addresses what a club should actually be doing about that concentration, using the same rigour the FCA and PRA now require of banks.
What supplier failure actually looks like and why it is not hypothetical
It is worth being precise about the kind of failure this discipline is designed to guard against, because it is easy to underestimate until it has been seen in practice elsewhere in professional sport. Two documented, dated incidents -- both from American sport rather than English football, but directly illustrative of the mechanics involved -- make the risk concrete.
In October 2025, a major cloud infrastructure outage at Amazon Web Services disrupted a wide range of unrelated online services simultaneously, including digital ticketing access for fans attending an NFL Monday Night Football fixture at Ford Field. Supporters who had valid tickets stored in their phones found they could not display the barcode needed to enter, because the underlying cloud infrastructure their ticketing app depended on had failed -- a failure that had nothing to do with football, the venue, or the ticketing provider's own football-specific systems, and everything to do with a single piece of shared infrastructure that a huge number of unrelated services around the world also happened to depend on.
In September 2022, a fault at Paciolan -- at the time the largest primary ticketing provider in US college athletics, serving roughly three-quarters of the major Power Five conference programmes -- disrupted digital ticket access simultaneously at multiple universities on the same Saturday, including Nebraska, Oklahoma, Georgia Tech, Pittsburgh, UCLA, Wisconsin, Michigan and Cincinnati. A single provider's technical fault became a shared operational crisis across a large proportion of a sector's biggest fixtures on the same afternoon, and the secondary ticketing marketplace StubHub was forced to suspend sales entirely until the issue was resolved.
Neither incident happened at an English football club, and neither is cited here as evidence that it will. They are cited because they are real, documented, dated events that demonstrate precisely the mechanism this article is concerned with: a single third-party failure -- one that has nothing to do with football specifically -- disrupting access-control services at multiple, unrelated sporting organisations at the same time, on the same day, because those organisations shared a dependency none of them had individually assessed as a systemic risk.
Neither incident happened to an English club. Both illustrate exactly the mechanism English football's own concentrated supplier market creates -- and has not yet been tested against.
The four elements of genuine supplier resilience
Translating the SS2/21 discipline into a football context produces four practical requirements, none of which most clubs currently meet in full for their most critical suppliers.
Due diligence before onboarding, not after a problem occurs. Before a club engages a critical supplier -- for ticketing, payments, data processing, catering, stewarding, medical services or, increasingly, core IT infrastructure -- it should assess that supplier's own resilience posture as part of the selection process, not discover it retrospectively when something goes wrong. This means asking the supplier directly what their own continuity and disaster recovery arrangements look like, what happens to the club's service if the supplier's own critical infrastructure fails, and how many other organisations -- across football and beyond -- depend on the same underlying systems.
Contractual provisions that actually address resilience, not just service quality. A great many supplier contracts in football govern price, service levels and performance metrics in granular detail, while saying almost nothing about what happens under serious disruption. SS2/21 requires financial services firms to build specific continuity and exit provisions into material outsourcing contracts as standard practice. A football club's equivalent discipline should ask: does this contract specify what the supplier must do in the event of a serious outage? Does it require the supplier to notify the club promptly, and to what standard? Does it give the club any right to audit or test the supplier's own continuity claims, rather than simply taking them on trust?
Testing supplier continuity arrangements, not just assuming they exist. This is the element most consistently missing in football, and it is the direct analogue of the scenario testing this series will address in its next article. A club that has never actually tested what happens if a critical supplier's system fails during a live matchday -- rather than simply trusting the supplier's own assurance that it "has a plan" -- does not know whether that plan works. The Paciolan incident above is instructive precisely because it affected clients who, in most cases, would have assumed their ticketing provider's infrastructure was robust until the moment it demonstrably was not.
Substitutability and exit planning for every critical supplier. The hardest and most neglected element. For each supplier supporting an important business service, a club should be able to answer a specific question: if this supplier failed entirely, tomorrow, what would the club actually do? A genuine answer requires knowing whether a realistic alternative supplier exists, how quickly it could be engaged, what manual fallback process could bridge the gap in the meantime, and whether that fallback has ever actually been tested rather than simply described in a document. A club that cannot answer this question for a critical supplier has not achieved substitutability -- it has a single point of failure with a contract attached.
Why exit planning is the discipline clubs find hardest to prioritise
Exit planning is uncomfortable in a way the other three elements are not, because it requires the club to actively plan for the failure of a relationship it is currently relying on and, in most cases, satisfied with. It can feel like disloyalty to a supplier that has served the club well for years, or like an unnecessary cost for a risk that has never yet materialised.
The concentration risk identified in the previous article in this series is exactly why that instinct needs to be resisted. A supplier\'s own quality of service to the club is not the same question as that supplier\'s structural resilience to a failure that originates entirely outside its control -- a cloud outage, a cyberattack, an insolvency in its own supply chain. The Ford Field and Paciolan incidents did not happen because those ticketing providers were poor at their jobs. They happened because a dependency none of the affected organisations had individually stress-tested turned out, on one specific day, to be a shared and simultaneous point of failure.
Where this sits in the governance structure
Supplier resilience due diligence, contract review and exit planning should not sit exclusively within procurement, for the same reason mapping should not sit exclusively there either: the question being asked -- what happens to our important business service if this supplier fails -- is a board-level risk question, not a commercial negotiation. A club's approach to its most critical suppliers should be reviewed with the same seniority and the same rigour as any other material risk on the board's own register, precisely because a supplier failure lands on the club's own supporters, players and staff regardless of whose name is on the contract.
This does not mean every supplier relationship warrants this level of scrutiny. Proportionality matters, and the discipline should be applied in line with the materiality of the service the supplier supports -- a club's important business services, identified through the method set out earlier in this series, are the natural starting point for deciding which suppliers genuinely warrant this depth of assessment.
The next article in this series addresses the discipline that ultimately proves whether any of this work -- important business services, impact tolerances, mapping and supplier resilience -- actually holds up: how to design and run scenario testing against severe but plausible disruption, including the disruption of a critical third-party supplier itself.
Most clubs have never asked their critical suppliers the questions a genuinely resilient organisation would ask before something goes wrong.
Lagom Sports Compliance works with football clubs across governance, risk, compliance and operational resilience. If your club has not yet applied genuine resilience due diligence to its most critical suppliers, we would welcome a conversation about what that process looks like for your club.
Frequently asked questions: third-party and outsourcing resilience for football clubs
-
Supplier resilience due diligence is the process of assessing a critical third-party supplier's own ability to withstand serious disruption before, and throughout, the club's relationship with them -- as distinct from assessing their price, service quality or performance metrics alone. It involves understanding the supplier's own continuity and disaster recovery arrangements, what happens to the club's service if the supplier's own critical infrastructure fails, and how many other organisations depend on the same underlying systems, which speaks directly to concentration risk.
-
No. This is a foundational principle in UK financial services regulation, set out clearly in the PRA's Supervisory Statement SS2/21 alongside the FCA's operational resilience framework under PS21/3: outsourcing the delivery of a function does not outsource accountability for its resilience. If a critical supplier fails, the resulting harm still lands on the organisation's own customers or, in a football context, its own supporters, players and staff -- and the organisation remains responsible for having assessed and planned for that risk, regardless of whose infrastructure actually failed.
-
Exit planning means being able to answer, in concrete terms, what the club would actually do if a critical supplier failed entirely -- whether a realistic alternative supplier exists, how quickly it could be engaged, what manual fallback process could bridge any gap, and whether that fallback has genuinely been tested rather than simply documented. A club that cannot answer this question for a critical supplier has, in practice, a single point of failure rather than a managed risk.
-
Yes, and there are documented, dated examples that illustrate the underlying mechanism clearly. In October 2025, a cloud infrastructure outage at Amazon Web Services disrupted digital ticket access for fans at an NFL fixture, because the ticketing app depended on cloud infrastructure that also served a huge range of unrelated services worldwide. In September 2022, a fault at Paciolan, then the largest primary ticketing provider in US college athletics, disrupted digital ticket access simultaneously at multiple major university athletic programmes on the same Saturday, forcing the secondary marketplace StubHub to suspend sales. Neither incident involved an English football club, but both demonstrate how a single third-party failure can create simultaneous disruption across multiple, otherwise unrelated organisations that share the same underlying dependency.
-
The question at the heart of supplier resilience -- what happens to a critical service if this supplier fails -- is a governance and risk question, not a commercial negotiation. Procurement functions are typically focused on price, service quality and contract terms, which is appropriate for their remit, but does not systematically address whether a genuine, tested fallback exists if the relationship fails. Because the consequences of a critical supplier failure ultimately land on the club's own stakeholders regardless of where the underlying fault originated, the assessment of that risk should sit at the same governance level as any other material risk on the club's own risk register.
-
Proportionality matters -- not every supplier relationship warrants the same depth of scrutiny. The suppliers that should be prioritised are those supporting a club's important business services: the small number of genuinely critical activities, such as matchday ticketing and access control, payment processing, player registration systems, and core financial reporting infrastructure, whose disruption would cause serious harm. A club that has already identified its important business services, as set out earlier in this series, has the natural starting point for deciding which supplier relationships require this level of assessment.