UK regulators tighten oversight of major cloud providers

The UK’s financial regulators have begun direct oversight of major cloud providers under a new regime designed to address systemic risks in financial technology.
The Critical Third Parties (CTPs) framework, established under the Financial Services and Markets Act, officially launched on Monday, July 13, 2026. The Bank of England, Prudential Regulation Authority (PRA), and Financial Conduct Authority (FCA) will now jointly supervise four global technology firms designated as the first CTPs: Microsoft Ireland Operations Ltd, Amazon Web Services (AWS), Google Cloud, and Oracle. The designation was formalized by HM Treasury following a formal order.
The move reflects growing concerns over concentrated risk in financial infrastructure. Over 65% of UK firms rely on a small group of cloud providers for core operations, according to the Bank of England. Disruptions in 2023, including the CrowdStrike outage and Microsoft Azure incidents, demonstrated how quickly a single failure could paralyze banking, payments, and critical services worldwide.
Sarah Breeden, Deputy Governor for Financial Stability at the Bank of England, warned that as these third parties become more embedded in financial operations, they introduce new systemic risks. “Our proportionate approach to overseeing these providers will ensure that these dependencies are managed in a way that safeguards financial stability,” she said. Nikhil Rathi, Chief Executive of the FCA, echoed the risk of market concentration: “Critical third parties provide essential services which support innovation and growth. At the same time, when the same providers serve thousands of firms, a single failure can reverberate across the financial system. Operationalising this regime strengthens our ability to tackle those risks and improve overall resilience.”
The new regime does not turn these firms into regulated financial entities. Instead, it imposes three key obligations: managing operational risks, maintaining real-time communication with regulators during incidents, and adhering to strict conduct rules, including incident reporting and orderly contract termination.
This approach aligns with, but is narrower than, the European Union’s Digital Operational Resilience Act (DORA), which applies to a broader set of providers. The UK’s focus on four firms reflects its targeted approach to systemic risk.
For financial firms, the change means no reduction in existing compliance requirements. Banks and fintechs remain fully responsible for their cloud architectures, due diligence, and disaster recovery plans. However, the new regime will demand greater transparency from providers, including updated disclosure protocols and formalized communication during outages.
