The Bank of England Now Oversees Your Cloud Provider

The Bank of England Now Oversees Your Cloud Provider

16 min read

HM Treasury designated Amazon Web Services EMEA SARL, Google Cloud EMEA Limited, Microsoft Ireland Operations Limited and Oracle Corporation UK Limited as critical third parties, effective 13 July 2026 under the Financial Services and Markets Act 2023 regime. The Bank of England, PRA and FCA can now set requirements directly on the providers, including scenario testing, phased incident reporting to regulators and affected firms, self-assessments and skilled-person reviews. The piece explains the designation criteria, the obligations and their timeline, and the point the primary documents state plainly but commentary will miss, that regulated firms keep every outsourcing and operational resilience obligation they already had. It closes with practical steps for fintechs, insurers, payments firms and the MSPs serving them.

Daniel Thomas
Written by Daniel Thomas

Since 13 July 2026, the Bank of England, the Prudential Regulation Authority and the Financial Conduct Authority have jointly overseen four cloud and technology providers as critical third parties to the UK financial sector — Amazon Web Services EMEA SARL, Google Cloud EMEA Limited, Microsoft Ireland Operations Limited and Oracle Corporation UK Limited. HM Treasury announced the designations on 10 July 2026, the first ever made under powers created by the Financial Services and Markets Act 2023, and they took legal effect the following Monday through The Critical Third Parties (Designation) Regulations 2026.

For the first time, UK financial regulators can set enforceable requirements directly on the cloud providers themselves — resilience testing, incident reporting, information gathering — rather than reaching them only through the outsourcing rules that bind banks, insurers and fintechs. That is the half of the story most coverage will lead with, and it is genuinely new.

The other half is the one procurement and compliance teams will get asked about within the year, and it points the opposite way: the regime removes nothing from regulated firms. The Bank of England's own release states that the new oversight "complements, but does not replace" the existing outsourcing and operational resilience rules, and that firms "remain responsible for managing their own third-party arrangements including due diligence, risk management and contingency planning". A fintech cannot point at the CTP regime as its own compliance. This article sets out what the regime is, what it changes, what it deliberately leaves alone, and what a UK financial firm — or the MSP serving one — should actually do about it.

What is a critical third party designation?

A critical third party (CTP) designation is a decision by HM Treasury that a service provider matters so much to the UK financial system that the services it supplies to that system need direct regulatory oversight. The Bank of England describes CTPs as "technology and other service providers whose services underpin the UK financial system". The legal machinery comes from the Financial Services and Markets Act 2023, which amended the Financial Services and Markets Act 2000 to give the Bank, the PRA and the FCA new powers over designated providers — the measures now sit in Chapter 3C of Part 18 of FSMA 2000.

The statutory test is narrow. Under section 312L of FSMA, HM Treasury may designate a third party only where, in its opinion, a failure in, or disruption to, the services the third party provides to financial firms could threaten the stability of, or confidence in, the UK financial system. HM Treasury makes the decision following consultation with the provider and the three regulators, generally on the regulators' recommendation, and describes its approach as risk-based and proportionate. Designation happens by statutory instrument — for the first four providers, The Critical Third Parties (Designation) Regulations 2026 (SI 2026/777).

Two boundaries are written into the regime and worth stating plainly. First, oversight applies only to the services a designated entity provides to the financial sector — HM Treasury's notes state that it covers "the systemic services provided to the financial sector, not firms' wider operations". The regulators are not supervising a hyperscaler's consumer businesses. Second, designation is not authorisation. The Bank of England is explicit that being designated under this regime is not the same as being authorised by the regulators; no one has approved or endorsed these providers, and designation says nothing about quality. It says only that the UK financial system now depends on them.

The regime is also open-ended. HM Treasury calls it "a rolling regime", states there is no statutory limit on the number of critical third parties that may be designated, and says further designations may follow where providers meet the statutory criteria.

Which cloud providers are designated, and from when?

Four entities are designated as critical third parties, all with effect from 13 July 2026, listed in regulation 2 of SI 2026/777: Amazon Web Services EMEA SARL, Google Cloud EMEA Limited, Microsoft Ireland Operations Limited and Oracle Corporation UK Limited. The Bank, the PRA and the FCA began joint oversight of the four on that date.

Note what the instrument actually names. The designations attach to specific legal entities — the contracting companies through which these providers serve customers in the region — not to the global brands or their US parents. Three of the four are not UK-registered companies at all, which the regime anticipates: the Bank of England's guidance notes that designated CTPs may be located outside the UK, and the oversight follows the services provided to UK financial firms rather than the location of the entity providing them. For a compliance team, the practical consequence is that supplier registers need checking against these exact entity names, not against "AWS" or "Microsoft" as a brand.

Oracle's inclusion alongside the three largest hyperscalers is itself a data point. HM Treasury does not publish a provider-by-provider rationale beyond the statutory test, so the designation is best read at face value: in the Treasury's assessment, disruption to Oracle Corporation UK Limited's services to the financial sector could threaten the stability of, or confidence in, the UK financial system. Kevin Kimber, Oracle's Senior Vice President and General Manager for UK and Ireland, said: "Oracle supports the UK Government's important objective of enhancing the operational resilience of the UK financial sector."

All four providers responded publicly and cooperatively to the announcement. Microsoft's Freddy Dezeure said the designation "marks a new chapter" in its UK relationship and that Microsoft "remains fully committed to complying with the relevant oversight requirements". AWS's Michael Jefferson said AWS "will comply with all applicable regulations". A Google Cloud spokesperson said the framework "can enhance the long-term resilience of the UK's financial ecosystem and increase understanding, transparency, and trust between all parties". Economic Secretary to the Treasury Rachel Blake MP framed the designations as protective: "We are a world-leading financial centre, and maintaining trust in our financial system is essential to its success."

What can the regulators now require directly of the providers?

The regulators can now make rules that bind a designated provider, gather information from it, commission independent skilled-person reviews of it, and take enforcement action against it — powers that previously stopped at the regulated firm. Until 13 July 2026, the financial regulators could shape cloud provider behaviour only indirectly: outsourcing rules such as the PRA's supervisory statement SS2/21 told banks and insurers what to demand of their providers by contract, but the providers themselves owed the regulators nothing. The Financial Services and Markets Act now gives the Bank, the PRA and the FCA rule-making, information-gathering and enforcement powers over CTPs in connection with the systemic services they provide — and the information-gathering power in section 312P extends beyond the designated entity to "persons connected" with it, including other companies in its group.

The rulebook was written in advance. The regulators published their final CTP rules in November 2024 in policy statement PS16/24, together with supervisory statement SS6/24 on how CTPs should comply and SS7/24 on skilled-person reviews. The rules took effect on 1 January 2025 and sat dormant, applying to no one, until the first designations landed. They apply to a designated CTP from the date its designation takes effect, with transitional periods for some requirements — set out in section 12 of SS6/24 — running from that same date.

What the rules contain, in outline:

  • Six CTP Fundamental Rules — high-level obligations modelled on the PRA's Fundamental Rules for firms. Rules 1 to 5 apply to a CTP's systemic third party services; Rule 6, which requires a CTP to "deal with each regulator in an open and cooperative way" and to disclose anything of which the regulators would reasonably expect notice, applies across all services the CTP provides to firms.
  • Eight Operational Risk and Resilience Requirements covering governance, risk management, dependency and supply chain risk management, technology and cyber resilience, change management, mapping, incident management, and termination of services.
  • An assurance layer. A newly designated CTP must submit an interim self-assessment to the regulators within three months of designation — on the current clock, that falls due in October 2026 — and annually thereafter, with a summary shared with the firms it serves. It must regularly test its ability to keep material services running in severe but plausible scenarios, and run incident management playbook exercises annually with a representative sample of the firms relying on it. The regulators can also commission skilled-person reviews, and PS16/24 records their expectation that CTPs adopt a "transparency by default" approach to sharing relevant findings with firms.
  • Incident reporting. A CTP must report operational incidents in three phases — initial, intermediate and final reports — to the regulators and to the firms whose services are affected.

The incident reporting duty is the one to watch, because it addresses a documented problem. PS16/24 cites the FCA's lessons-learnt note on the CrowdStrike outage, which recorded that third-party related issues were the leading cause of operational incidents reported to the FCA between 2022 and 2023. Sarah Breeden, the Bank of England's Deputy Governor for Financial Stability, put the systemic case directly: "As critical third parties become increasingly embedded in the operations of financial institutions, they can introduce new forms of systemic risk. Our proportionate approach to overseeing these providers will ensure that these dependencies are managed in a way that safeguards financial stability." FCA chief executive Nikhil Rathi made the concentration point: "when the same providers serve thousands of firms, a single failure can reverberate across the financial system".

What does the CTP regime not change for regulated firms?

The CTP regime removes no obligation from any regulated firm — that is stated in the primary documents, not inferred. The Bank of England's release says the regime "complements, but does not replace, existing outsourcing and operational resilience rules for regulated firms who remain responsible for managing their own third-party arrangements including due diligence, risk management and contingency planning". HM Treasury's notes to editors close on the same point: "Financial firms remain responsible for managing risks arising from their third-party suppliers."

In practice that means every answer a firm gave its supervisor or auditor last year still has to hold this year. The PRA's outsourcing and third party risk management expectations in SS2/21 continue to apply to banks and insurers. The FCA's outsourcing requirements continue to apply to solo-regulated firms, including payments and e-money businesses. And the FCA's operational resilience regime, which required in-scope firms by 31 March 2025 to be able to keep important business services within impact tolerances, binds exactly as it did before 13 July — the FCA restates that deadline as a standing obligation on its operational resilience pages.

So a fintech that answers a due diligence questionnaire with "our cloud provider is a designated critical third party" has answered a different question from the one asked. Designation gives the regulators a direct line to the provider; it does not transfer the firm's accountability for exit plans, substitutability analysis, contract terms or contingency arrangements — the same disciplines that apply to backup and disaster recovery planning at any scale. The regulators designed the regime this way deliberately, and both the Bank and the Treasury said so on the day.

The dates that matter

DateWhat happened, or happens
November 2024Regulators publish final CTP rules (PS16/24), SS6/24 and SS7/24
1 January 2025CTP rules take legal effect — no CTPs yet designated
31 March 2025FCA deadline for in-scope firms to operate important business services within impact tolerances
January 2026UK regulators and European Supervisory Authorities sign a memorandum of understanding on CTP oversight cooperation
18 March 2026PRA publishes PS7/26 on operational incident and third-party reporting by firms
10 July 2026HM Treasury announces the first four CTP designations
13 July 2026Designations take effect; Bank, PRA and FCA oversight begins
October 2026Interim self-assessments from the four CTPs fall due, three months from designation
18 March 2027Firm-side operational incident and material third-party reporting rules take effect

What should a UK fintech, insurer or payments firm do differently?

The honest answer is a short list of unhurried, specific actions — the regime asks nothing new of regulated firms, so the work is about using what it creates. Four things are worth doing this quarter rather than eventually.

Map the designated entities in your supply chain, by legal name. Check your outsourcing register and material contracts for the four designated entities — Amazon Web Services EMEA SARL, Google Cloud EMEA Limited, Microsoft Ireland Operations Limited, Oracle Corporation UK Limited — and note where a designated service sits beneath a SaaS product you buy rather than in a direct contract. The mapping discipline is the same one that serves UK GDPR Article 30 records: entity names, service names, what depends on what. If your contract is with a different group company than the designated one, record that too — the designation follows the named entity.

Watch the incident reporting obligation mature, and plumb it in. From designation, a CTP must report operational incidents to the regulators and to affected firms in initial, intermediate and final phases. Ask your provider, through your account team, how CTP incident reports will reach your firm, and fold that channel into your incident response runbooks. Then note the mirror obligation coming your way: from 18 March 2027, under PS7/26, banks, insurers and larger credit unions must report their own operational incidents through a standardised, phased report — and the PRA has said that when an incident occurs at a CTP it expects reports from both the CTP and affected firms, each with its own view of the event. Your account of a cloud outage will be read alongside your provider's.

Use the new artefacts at renewal. The regime creates documents that did not exist before: an annual CTP self-assessment with a summary shared with customer firms, results of scenario testing, playbook exercises run jointly with firms, and a supervisory expectation of "transparency by default" about relevant findings. A procurement team renegotiating a cloud or managed service contract now has specific, named artefacts to request rather than a generic assurances clause — and a provider that supplies them to the regulators will find it hard to argue they cannot be summarised for a customer.

Do not rewrite your compliance narrative. Nothing about your firm's own obligations has moved, so resist any internal suggestion that CTP designation de-risks concentration on a single provider. The concentration question remains live and remains yours — two thirds of UK IT leaders say they would switch cloud provider to regain sovereignty, and the practical work of comparing providers on UK terms, as in our AWS and Azure UK compliance comparison, is unchanged by the regime.

What does the CTP regime mean for an MSP serving financial clients?

The regime reaches the cloud provider, not the MSP. No managed service provider is designated, and the obligations described above fall on the four named entities and on regulated firms — an MSP's duties continue to arrive the way they always have, through its clients' outsourcing rules and contracts: SS2/21 expectations flowed down from PRA-regulated clients, FCA outsourcing requirements flowed down from solo-regulated ones. An MSP running multi-vendor arrangements for mid-market clients will recognise the position: in the middle of the mapped supply chain, carrying obligations by contract rather than by designation.

Three things in the regime are still worth an MSP's attention. First, the designation pipeline now runs on data your clients file about you. PS7/26 requires PRA-regulated firms to maintain and submit a standardised register of material third-party arrangements — firms have until March 2027 before the requirements come into force — and the PRA has said this register data will help inform future CTP designation recommendations to HM Treasury. With a rolling regime and no statutory limit on designations, the register your clients complete is the dataset from which the next round of critical third parties gets recommended.

Second, expect CTP questions from clients. Financial firms mapping the four designated entities through their supply chains will ask their MSP where designated services sit inside what the MSP runs for them — which workloads are on which designated entity's platform, and what the MSP's own contingency position is. Having that answer prepared, by client and by service, is cheap now and awkward under time pressure.

Third, know the term "Key Nth Party provider". The CTP rules' supply chain requirement applies most strongly to persons in a CTP's own supply chain who are essential to delivering a systemic service — the rules call these Key Nth Party providers. Most MSPs sit on the firm's side of the chain, not the cloud provider's, and are untouched by that provision; an MSP that is actually part of a designated provider's delivery chain for financial sector services is in different territory and should read SS6/24 directly.

How does the UK regime sit alongside the EU's DORA?

The UK regime has a deliberate international dimension, because the designated entities serve more than one jurisdiction and answer to more than one regulator. The Bank of England notes that CTPs may also be regulated under similar regimes elsewhere, naming the EU's Digital Operational Resilience Act (DORA), and says UK CTP oversight has been designed to be compatible with similar approaches in other jurisdictions where appropriate.

In January 2026, the UK regulators and the European Supervisory Authorities signed a memorandum of understanding to support coordination and information sharing on the oversight of critical third parties. For a UK firm that is part of an EU group, or an MSP serving clients on both sides, the practical reading is that the two regimes are meant to be answered once each rather than fought twice — though each keeps its own designations, rules and reporting, and nothing in the MoU merges them.

Sources

This article is reported from primary documents. The designation facts come from HM Treasury's press release of 10 July 2026, the Bank of England's news release of the same date, and The Critical Third Parties (Designation) Regulations 2026 (SI 2026/777) on legislation.gov.uk. The regime's obligations are drawn from the regulators' policy statement PS16/24 and supervisory statements SS6/24 and SS7/24 (November 2024), the Bank of England's critical third parties pages, and Chapter 3C of Part 18 of the Financial Services and Markets Act 2000 as amended by the Financial Services and Markets Act 2023. The firm-side reporting picture comes from the PRA's PS7/26 (March 2026) and SS2/21, and the operational resilience deadline from the FCA's operational resilience pages. All regulator and vendor quotations are taken verbatim from the 10 July 2026 releases.

Frequently Asked Questions

What is the UK critical third party regime?

The critical third party (CTP) regime lets UK financial regulators directly oversee service providers whose failure could threaten the stability of, or confidence in, the UK financial system. Created by the Financial Services and Markets Act 2023, it gives the Bank of England, the PRA and the FCA powers to make rules for, gather information from, and take enforcement action against providers designated by HM Treasury. Oversight covers only the systemic services those providers supply to the financial sector, not their wider operations.

Which cloud providers are designated as critical third parties in the UK?

Four entities are designated: Amazon Web Services EMEA SARL, Google Cloud EMEA Limited, Microsoft Ireland Operations Limited and Oracle Corporation UK Limited. The designations were announced by HM Treasury on 10 July 2026 and took effect on 13 July 2026 through The Critical Third Parties (Designation) Regulations 2026. The designations name specific legal entities rather than global brands, so supplier registers should be checked against the exact entity names.

When did the CTP designations take effect?

The designations took effect on 13 July 2026, and the Bank of England, PRA and FCA began joint oversight of the four providers on that date. The rules the providers must meet were published earlier, in November 2024 in policy statement PS16/24, and took legal effect on 1 January 2025, but applied to no one until HM Treasury made the first designations. Some requirements carry transitional periods running from the designation date, set out in section 12 of supervisory statement SS6/24.

Does designation mean the Bank of England has approved these cloud providers?

No. The Bank of England states explicitly that designation under the CTP regime is not the same as authorisation by the regulators. Designation is a judgement about dependency, not quality: HM Treasury may only designate a provider where failure or disruption of its services to financial firms could threaten the stability of, or confidence in, the UK financial system. It is not an endorsement, a certification, or a compliance badge a customer can rely on.

Does the CTP regime reduce a regulated firm's own compliance obligations?

No, and the primary documents say so directly. The Bank of England states the regime "complements, but does not replace" existing outsourcing and operational resilience rules, and that firms remain responsible for their own third-party arrangements, including due diligence, risk management and contingency planning. HM Treasury adds that financial firms remain responsible for managing risks from their third-party suppliers. Exit plans, impact tolerances and outsourcing registers all continue exactly as before.

What does a designated critical third party actually have to do?

A designated CTP must comply with six Fundamental Rules and eight Operational Risk and Resilience Requirements covering governance, risk management, supply chain risk, technology and cyber resilience, change management, mapping, incident management and termination of services. It must submit an interim self-assessment within three months of designation and annually thereafter, test its services against severe but plausible scenarios, run annual incident management exercises with a sample of firms, and report operational incidents to regulators and affected firms in initial, intermediate and final phases.

Who decides which companies become critical third parties?

HM Treasury decides, generally on the recommendation of the Bank of England, the PRA and the FCA, and after consulting the provider. The statutory test in section 312L of the Financial Services and Markets Act 2000 allows designation only where, in HM Treasury's opinion, failure or disruption of the provider's services to financial firms could threaten the stability of, or confidence in, the UK financial system. Designation is made by statutory instrument, and HM Treasury can also de-designate providers.

Will more companies be designated as critical third parties?

Possibly. HM Treasury describes the CTP regime as rolling, confirms there is no statutory limit on the number of designations, and says further providers may be designated where they meet the statutory criteria. The data pipeline for future designations is being built now: under PS7/26, PRA-regulated firms must submit standardised registers of material third-party arrangements, and the PRA has said this register data will help inform future designation recommendations to HM Treasury.

Does the CTP regime apply to MSPs serving financial firms?

Not directly. No MSP is designated, and the regime's obligations fall on the four named cloud entities and on regulated firms. An MSP's duties continue to arrive through its clients' outsourcing rules and contracts, as they always have. MSPs should still expect client questions about where designated services sit in what they run, and should know that clients' material third-party registers, which will record MSP arrangements, feed the data the PRA uses to recommend future designations.

How does the UK CTP regime relate to the EU's DORA?

They are parallel regimes designed to be compatible. The Bank of England notes that CTPs may also be regulated under similar frameworks elsewhere, naming the EU's Digital Operational Resilience Act, and says UK oversight was designed for compatibility with other jurisdictions where appropriate. In January 2026 the UK regulators and the European Supervisory Authorities signed a memorandum of understanding on coordination and information sharing over CTP oversight. Each regime keeps its own designations, rules and reporting.