UK Regulators Designate Four Cloud Providers for Critical Third-Party Oversight
Key Takeaways
- 01HM Treasury has designated AWS, Google Cloud, Microsoft and Oracle as the first Critical Third Parties, with joint Bank of England, PRA and FCA oversight starting on 13 July 2026.
- 02The regime is intended to reduce the risk that disruption at a major technology provider spreads across the UK financial system.
- 03Designated providers must manage risks to critical services and communicate promptly with regulators and affected financial-sector customers during major incidents.
- 04The oversight powers arise from FSMA 2000 as amended by the Financial Services and Markets Act 2023, and the CTP rules apply once HM Treasury makes a designation.
HM Treasury has designated Amazon Web Services, Google Cloud, Microsoft and Oracle as the first Critical Third Parties (CTPs) to the UK financial sector. The Bank of England, Prudential Regulation Authority (PRA) and Financial Conduct Authority (FCA) will begin jointly overseeing them on 13 July 2026.
The regime aims to strengthen the operational resilience of services that are critical to UK regulated firms and financial market infrastructures. It addresses the risk that a serious disruption at a major technology provider could spread across multiple financial institutions and affect the wider financial system.
The designated companies are Amazon Web Services EMEA SARL, Google Cloud EMEA Limited, Microsoft Ireland Operations Ltd and Oracle Corporation UK Limited. The regulators’ oversight will focus on the resilience of the critical services these providers supply to the UK financial sector, using a proportionate approach.
CTPs must identify and manage risks to their critical services and maintain open, timely communication with regulators and their financial-sector customers, particularly during major incidents. The three regulators will also work with the providers on system-level risks—risks that may affect multiple firms at once.
The Bank, PRA and FCA received these oversight powers under the Financial Services and Markets Act 2000, as amended by the Financial Services and Markets Act 2023. The regulators published final CTP rules and policy in November 2024; those rules took effect on 1 January 2025 and apply to a provider once HM Treasury designates it. For UK financial firms that rely on the four providers, the designation increases regulatory attention on the continuity and incident management of those providers’ critical services.