Since 13 July 2026, the Bank of England, the Prudential Regulation Authority and the Financial Conduct Authority have jointly overseen four cloud and technology providers as critical third parties to the UK financial sector — Amazon Web Services EMEA SARL, Google Cloud EMEA Limited, Microsoft Ireland Operations Limited and Oracle Corporation UK Limited. HM Treasury announced the designations on 10 July 2026, the first ever made under powers created by the Financial Services and Markets Act 2023, and they took legal effect the following Monday through The Critical Third Parties (Designation) Regulations 2026.
For the first time, UK financial regulators can set enforceable requirements directly on the cloud providers themselves — resilience testing, incident reporting, information gathering — rather than reaching them only through the outsourcing rules that bind banks, insurers and fintechs. That is the half of the story most coverage will lead with, and it is genuinely new.
The other half is the one procurement and compliance teams will get asked about within the year, and it points the opposite way: the regime removes nothing from regulated firms. The Bank of England's own release states that the new oversight "complements, but does not replace" the existing outsourcing and operational resilience rules, and that firms "remain responsible for managing their own third-party arrangements including due diligence, risk management and contingency planning". A fintech cannot point at the CTP regime as its own compliance. This article sets out what the regime is, what it changes, what it deliberately leaves alone, and what a UK financial firm — or the MSP serving one — should actually do about it.
What is a critical third party designation?
A critical third party (CTP) designation is a decision by HM Treasury that a service provider matters so much to the UK financial system that the services it supplies to that system need direct regulatory oversight. The Bank of England describes CTPs as "technology and other service providers whose services underpin the UK financial system". The legal machinery comes from the Financial Services and Markets Act 2023, which amended the Financial Services and Markets Act 2000 to give the Bank, the PRA and the FCA new powers over designated providers — the measures now sit in Chapter 3C of Part 18 of FSMA 2000.
The statutory test is narrow. Under section 312L of FSMA, HM Treasury may designate a third party only where, in its opinion, a failure in, or disruption to, the services the third party provides to financial firms could threaten the stability of, or confidence in, the UK financial system. HM Treasury makes the decision following consultation with the provider and the three regulators, generally on the regulators' recommendation, and describes its approach as risk-based and proportionate. Designation happens by statutory instrument — for the first four providers, The Critical Third Parties (Designation) Regulations 2026 (SI 2026/777).
Two boundaries are written into the regime and worth stating plainly. First, oversight applies only to the services a designated entity provides to the financial sector — HM Treasury's notes state that it covers "the systemic services provided to the financial sector, not firms' wider operations". The regulators are not supervising a hyperscaler's consumer businesses. Second, designation is not authorisation. The Bank of England is explicit that being designated under this regime is not the same as being authorised by the regulators; no one has approved or endorsed these providers, and designation says nothing about quality. It says only that the UK financial system now depends on them.
The regime is also open-ended. HM Treasury calls it "a rolling regime", states there is no statutory limit on the number of critical third parties that may be designated, and says further designations may follow where providers meet the statutory criteria.
Which cloud providers are designated, and from when?
Four entities are designated as critical third parties, all with effect from 13 July 2026, listed in regulation 2 of SI 2026/777: Amazon Web Services EMEA SARL, Google Cloud EMEA Limited, Microsoft Ireland Operations Limited and Oracle Corporation UK Limited. The Bank, the PRA and the FCA began joint oversight of the four on that date.
Note what the instrument actually names. The designations attach to specific legal entities — the contracting companies through which these providers serve customers in the region — not to the global brands or their US parents. Three of the four are not UK-registered companies at all, which the regime anticipates: the Bank of England's guidance notes that designated CTPs may be located outside the UK, and the oversight follows the services provided to UK financial firms rather than the location of the entity providing them. For a compliance team, the practical consequence is that supplier registers need checking against these exact entity names, not against "AWS" or "Microsoft" as a brand.
Oracle's inclusion alongside the three largest hyperscalers is itself a data point. HM Treasury does not publish a provider-by-provider rationale beyond the statutory test, so the designation is best read at face value: in the Treasury's assessment, disruption to Oracle Corporation UK Limited's services to the financial sector could threaten the stability of, or confidence in, the UK financial system. Kevin Kimber, Oracle's Senior Vice President and General Manager for UK and Ireland, said: "Oracle supports the UK Government's important objective of enhancing the operational resilience of the UK financial sector."
All four providers responded publicly and cooperatively to the announcement. Microsoft's Freddy Dezeure said the designation "marks a new chapter" in its UK relationship and that Microsoft "remains fully committed to complying with the relevant oversight requirements". AWS's Michael Jefferson said AWS "will comply with all applicable regulations". A Google Cloud spokesperson said the framework "can enhance the long-term resilience of the UK's financial ecosystem and increase understanding, transparency, and trust between all parties". Economic Secretary to the Treasury Rachel Blake MP framed the designations as protective: "We are a world-leading financial centre, and maintaining trust in our financial system is essential to its success."
What can the regulators now require directly of the providers?
The regulators can now make rules that bind a designated provider, gather information from it, commission independent skilled-person reviews of it, and take enforcement action against it — powers that previously stopped at the regulated firm. Until 13 July 2026, the financial regulators could shape cloud provider behaviour only indirectly: outsourcing rules such as the PRA's supervisory statement SS2/21 told banks and insurers what to demand of their providers by contract, but the providers themselves owed the regulators nothing. The Financial Services and Markets Act now gives the Bank, the PRA and the FCA rule-making, information-gathering and enforcement powers over CTPs in connection with the systemic services they provide — and the information-gathering power in section 312P extends beyond the designated entity to "persons connected" with it, including other companies in its group.
The rulebook was written in advance. The regulators published their final CTP rules in November 2024 in policy statement PS16/24, together with supervisory statement SS6/24 on how CTPs should comply and SS7/24 on skilled-person reviews. The rules took effect on 1 January 2025 and sat dormant, applying to no one, until the first designations landed. They apply to a designated CTP from the date its designation takes effect, with transitional periods for some requirements — set out in section 12 of SS6/24 — running from that same date.
What the rules contain, in outline:
- Six CTP Fundamental Rules — high-level obligations modelled on the PRA's Fundamental Rules for firms. Rules 1 to 5 apply to a CTP's systemic third party services; Rule 6, which requires a CTP to "deal with each regulator in an open and cooperative way" and to disclose anything of which the regulators would reasonably expect notice, applies across all services the CTP provides to firms.
- Eight Operational Risk and Resilience Requirements covering governance, risk management, dependency and supply chain risk management, technology and cyber resilience, change management, mapping, incident management, and termination of services.
- An assurance layer. A newly designated CTP must submit an interim self-assessment to the regulators within three months of designation — on the current clock, that falls due in October 2026 — and annually thereafter, with a summary shared with the firms it serves. It must regularly test its ability to keep material services running in severe but plausible scenarios, and run incident management playbook exercises annually with a representative sample of the firms relying on it. The regulators can also commission skilled-person reviews, and PS16/24 records their expectation that CTPs adopt a "transparency by default" approach to sharing relevant findings with firms.
- Incident reporting. A CTP must report operational incidents in three phases — initial, intermediate and final reports — to the regulators and to the firms whose services are affected.
The incident reporting duty is the one to watch, because it addresses a documented problem. PS16/24 cites the FCA's lessons-learnt note on the CrowdStrike outage, which recorded that third-party related issues were the leading cause of operational incidents reported to the FCA between 2022 and 2023. Sarah Breeden, the Bank of England's Deputy Governor for Financial Stability, put the systemic case directly: "As critical third parties become increasingly embedded in the operations of financial institutions, they can introduce new forms of systemic risk. Our proportionate approach to overseeing these providers will ensure that these dependencies are managed in a way that safeguards financial stability." FCA chief executive Nikhil Rathi made the concentration point: "when the same providers serve thousands of firms, a single failure can reverberate across the financial system".
What does the CTP regime not change for regulated firms?
The CTP regime removes no obligation from any regulated firm — that is stated in the primary documents, not inferred. The Bank of England's release says the regime "complements, but does not replace, existing outsourcing and operational resilience rules for regulated firms who remain responsible for managing their own third-party arrangements including due diligence, risk management and contingency planning". HM Treasury's notes to editors close on the same point: "Financial firms remain responsible for managing risks arising from their third-party suppliers."
In practice that means every answer a firm gave its supervisor or auditor last year still has to hold this year. The PRA's outsourcing and third party risk management expectations in SS2/21 continue to apply to banks and insurers. The FCA's outsourcing requirements continue to apply to solo-regulated firms, including payments and e-money businesses. And the FCA's operational resilience regime, which required in-scope firms by 31 March 2025 to be able to keep important business services within impact tolerances, binds exactly as it did before 13 July — the FCA restates that deadline as a standing obligation on its operational resilience pages.
So a fintech that answers a due diligence questionnaire with "our cloud provider is a designated critical third party" has answered a different question from the one asked. Designation gives the regulators a direct line to the provider; it does not transfer the firm's accountability for exit plans, substitutability analysis, contract terms or contingency arrangements — the same disciplines that apply to backup and disaster recovery planning at any scale. The regulators designed the regime this way deliberately, and both the Bank and the Treasury said so on the day.
The dates that matter
| Date | What happened, or happens |
|---|---|
| November 2024 | Regulators publish final CTP rules (PS16/24), SS6/24 and SS7/24 |
| 1 January 2025 | CTP rules take legal effect — no CTPs yet designated |
| 31 March 2025 | FCA deadline for in-scope firms to operate important business services within impact tolerances |
| January 2026 | UK regulators and European Supervisory Authorities sign a memorandum of understanding on CTP oversight cooperation |
| 18 March 2026 | PRA publishes PS7/26 on operational incident and third-party reporting by firms |
| 10 July 2026 | HM Treasury announces the first four CTP designations |
| 13 July 2026 | Designations take effect; Bank, PRA and FCA oversight begins |
| October 2026 | Interim self-assessments from the four CTPs fall due, three months from designation |
| 18 March 2027 | Firm-side operational incident and material third-party reporting rules take effect |
What should a UK fintech, insurer or payments firm do differently?
The honest answer is a short list of unhurried, specific actions — the regime asks nothing new of regulated firms, so the work is about using what it creates. Four things are worth doing this quarter rather than eventually.
Map the designated entities in your supply chain, by legal name. Check your outsourcing register and material contracts for the four designated entities — Amazon Web Services EMEA SARL, Google Cloud EMEA Limited, Microsoft Ireland Operations Limited, Oracle Corporation UK Limited — and note where a designated service sits beneath a SaaS product you buy rather than in a direct contract. The mapping discipline is the same one that serves UK GDPR Article 30 records: entity names, service names, what depends on what. If your contract is with a different group company than the designated one, record that too — the designation follows the named entity.
Watch the incident reporting obligation mature, and plumb it in. From designation, a CTP must report operational incidents to the regulators and to affected firms in initial, intermediate and final phases. Ask your provider, through your account team, how CTP incident reports will reach your firm, and fold that channel into your incident response runbooks. Then note the mirror obligation coming your way: from 18 March 2027, under PS7/26, banks, insurers and larger credit unions must report their own operational incidents through a standardised, phased report — and the PRA has said that when an incident occurs at a CTP it expects reports from both the CTP and affected firms, each with its own view of the event. Your account of a cloud outage will be read alongside your provider's.
Use the new artefacts at renewal. The regime creates documents that did not exist before: an annual CTP self-assessment with a summary shared with customer firms, results of scenario testing, playbook exercises run jointly with firms, and a supervisory expectation of "transparency by default" about relevant findings. A procurement team renegotiating a cloud or managed service contract now has specific, named artefacts to request rather than a generic assurances clause — and a provider that supplies them to the regulators will find it hard to argue they cannot be summarised for a customer.
Do not rewrite your compliance narrative. Nothing about your firm's own obligations has moved, so resist any internal suggestion that CTP designation de-risks concentration on a single provider. The concentration question remains live and remains yours — two thirds of UK IT leaders say they would switch cloud provider to regain sovereignty, and the practical work of comparing providers on UK terms, as in our AWS and Azure UK compliance comparison, is unchanged by the regime.
What does the CTP regime mean for an MSP serving financial clients?
The regime reaches the cloud provider, not the MSP. No managed service provider is designated, and the obligations described above fall on the four named entities and on regulated firms — an MSP's duties continue to arrive the way they always have, through its clients' outsourcing rules and contracts: SS2/21 expectations flowed down from PRA-regulated clients, FCA outsourcing requirements flowed down from solo-regulated ones. An MSP running multi-vendor arrangements for mid-market clients will recognise the position: in the middle of the mapped supply chain, carrying obligations by contract rather than by designation.
Three things in the regime are still worth an MSP's attention. First, the designation pipeline now runs on data your clients file about you. PS7/26 requires PRA-regulated firms to maintain and submit a standardised register of material third-party arrangements — firms have until March 2027 before the requirements come into force — and the PRA has said this register data will help inform future CTP designation recommendations to HM Treasury. With a rolling regime and no statutory limit on designations, the register your clients complete is the dataset from which the next round of critical third parties gets recommended.
Second, expect CTP questions from clients. Financial firms mapping the four designated entities through their supply chains will ask their MSP where designated services sit inside what the MSP runs for them — which workloads are on which designated entity's platform, and what the MSP's own contingency position is. Having that answer prepared, by client and by service, is cheap now and awkward under time pressure.
Third, know the term "Key Nth Party provider". The CTP rules' supply chain requirement applies most strongly to persons in a CTP's own supply chain who are essential to delivering a systemic service — the rules call these Key Nth Party providers. Most MSPs sit on the firm's side of the chain, not the cloud provider's, and are untouched by that provision; an MSP that is actually part of a designated provider's delivery chain for financial sector services is in different territory and should read SS6/24 directly.
How does the UK regime sit alongside the EU's DORA?
The UK regime has a deliberate international dimension, because the designated entities serve more than one jurisdiction and answer to more than one regulator. The Bank of England notes that CTPs may also be regulated under similar regimes elsewhere, naming the EU's Digital Operational Resilience Act (DORA), and says UK CTP oversight has been designed to be compatible with similar approaches in other jurisdictions where appropriate.
In January 2026, the UK regulators and the European Supervisory Authorities signed a memorandum of understanding to support coordination and information sharing on the oversight of critical third parties. For a UK firm that is part of an EU group, or an MSP serving clients on both sides, the practical reading is that the two regimes are meant to be answered once each rather than fought twice — though each keeps its own designations, rules and reporting, and nothing in the MoU merges them.
Sources
This article is reported from primary documents. The designation facts come from HM Treasury's press release of 10 July 2026, the Bank of England's news release of the same date, and The Critical Third Parties (Designation) Regulations 2026 (SI 2026/777) on legislation.gov.uk. The regime's obligations are drawn from the regulators' policy statement PS16/24 and supervisory statements SS6/24 and SS7/24 (November 2024), the Bank of England's critical third parties pages, and Chapter 3C of Part 18 of the Financial Services and Markets Act 2000 as amended by the Financial Services and Markets Act 2023. The firm-side reporting picture comes from the PRA's PS7/26 (March 2026) and SS2/21, and the operational resilience deadline from the FCA's operational resilience pages. All regulator and vendor quotations are taken verbatim from the 10 July 2026 releases.