The decision marks an important change in the way systemic technology risk is regulated. Instead of relying exclusively on banks, insurers and other financial institutions to manage their suppliers, UK authorities will now supervise the resilience of certain cloud and technology services directly at provider level.
The first designations take effect on 13 July 2026 and apply to Amazon Web Services EMEA SARL, Google Cloud EMEA Limited, Microsoft Ireland Operations Limited and Oracle Corporation UK Limited. Regulatory oversight will be limited to services considered systemic to the UK financial sector rather than extending across the providers’ entire global operations.
Financial institutions have traditionally remained responsible for evaluating cloud providers, negotiating contractual protections, monitoring service performance and maintaining contingency arrangements. That responsibility remains in place. However, the new regime addresses a limitation of the traditional outsourcing model: an individual bank can assess its own dependency on a provider, but it cannot independently evaluate the consequences of thousands of institutions depending on the same infrastructure.
The UK authorities are therefore treating concentrated technology dependency as a potential financial-stability issue. A major disruption affecting one widely used provider could simultaneously interrupt payment services, banking platforms, insurance operations, trading systems and other critical functions. The problem is not necessarily that any single institution has managed its supplier poorly. It is that multiple institutions may share the same underlying point of failure.
The FCA, Bank of England and PRA have said that a failure affecting one of the designated providers could spread across firms and markets and affect services used by millions of consumers and businesses. This makes the new framework structurally different from conventional third-party risk management. Its primary focus is not only the bilateral relationship between a financial institution and its supplier, but the systemic risk created when critical services become concentrated among a small number of providers.
Under the Critical Third Parties regime, the three UK regulators will jointly oversee the resilience of the designated providers’ relevant services. The authorities will be able to collect information, assess operational resilience and require providers to address weaknesses affecting the continuity of critical financial services. They may also establish and enforce provider-specific requirements where necessary.
The framework requires designated providers to identify and manage risks to their critical services and maintain timely communication with regulators and affected financial institutions, particularly during major incidents. The rules also provide for regular assurance, resilience testing and reporting of serious operational disruptions.
This gives the Bank of England, the PRA and the FCA a much more direct line of sight into the condition of major technology providers. Regulators will no longer have to reconstruct the resilience of a cloud or infrastructure provider mainly through information collected separately from its financial-sector customers.
The new powers should also make system-wide resilience exercises more meaningful. Rather than asking individual institutions whether they have tested their own recovery arrangements, regulators can examine whether the underlying service provider can withstand, contain and recover from disruption affecting multiple customers at the same time.
The framework is based on powers introduced through the Financial Services and Markets Act 2023. The detailed rules entered into force on 1 January 2025 but could only become operational for an individual provider after formal designation by HM Treasury. The announcements made on 10 July therefore move the regime from regulatory preparation into active supervision.
The designation of the four providers does not transfer accountability away from banks, insurers, investment firms or financial-market infrastructure operators. UK regulators have made clear that the regime complements rather than replaces existing outsourcing and operational-resilience obligations.
Financial institutions must continue to conduct due diligence, manage contractual and operational risks, understand dependencies, develop contingency plans and maintain their own ability to continue important business services during disruption. Direct oversight of AWS, Microsoft, Google Cloud or Oracle should not be interpreted as a regulatory assurance that using those services is automatically safe.
Nor does designation remove the need to evaluate service architecture, subcontracting chains, geographical dependencies, data portability, exit options and recovery arrangements. Direct supervision addresses risk at provider and financial-system level. It does not resolve the specific resilience weaknesses of each institution.
In practice, firms may face greater scrutiny over whether their own risk assessments are consistent with information emerging from the new supervisory process. Regulators could reasonably expect boards to demonstrate that they understand which important business services depend on designated providers and what would happen if those services became unavailable for an extended period.
The four initial designations also reveal how the UK authorities view technology concentration. AWS, Google Cloud, Microsoft and Oracle are not being designated because of a particular publicly disclosed security failure. They are being brought into the regime because the scale and importance of the services they provide mean that disruption could affect financial stability or confidence in the UK financial system.
That is a significant regulatory signal. Cloud concentration has often been discussed as a procurement, competition or vendor-management issue. The UK framework now places it firmly within operational resilience and financial stability.
The authorities are not seeking to discourage cloud adoption. Cloud platforms remain essential to modernisation, scalability and financial-sector innovation. The regulatory objective is instead to reduce the possibility that the efficiency gained from shared infrastructure creates an unmanaged common dependency.
The central policy question is therefore no longer whether financial institutions should use cloud services. It is whether the financial system can retain sufficient resilience when many important services rely on a limited group of technology providers.
The UK regime also places the country closer to the European Union’s approach under the Digital Operational Resilience Act. DORA establishes direct oversight of critical ICT third-party providers serving the EU financial sector. Although the legal structures are not identical, both models recognise that supervising financial institutions alone is insufficient when systemic operational dependencies sit outside the regulated financial perimeter.
In January 2026, the UK regulators signed a memorandum of understanding with the European Supervisory Authorities to coordinate oversight and exchange information concerning providers that may fall under both the UK framework and DORA. The arrangement covers cooperation during incidents such as cyberattacks and power outages and is intended to reduce unnecessary duplication.
This coordination will be important because the designated companies provide services across borders. A large-scale outage or cyber incident is unlikely to remain confined to a single jurisdiction. For multinational financial groups, the emergence of parallel UK and EU regimes may improve regulatory visibility but will also increase expectations for consistent mapping of technology dependencies across legal entities and countries
.
The immediate regulatory obligations fall primarily on the four designated providers, but the announcement should trigger action across the financial sector. Financial institutions should identify which important business services depend directly or indirectly on AWS, Google Cloud, Microsoft or Oracle. This analysis should extend beyond named cloud contracts to include software-as-a-service platforms, managed service providers and other suppliers that themselves rely on the designated infrastructure.
Boards should also review whether concentration-risk reporting provides a sufficiently clear picture of common dependencies. A list of suppliers is not enough. Decision-makers need to understand where different business processes ultimately converge on the same provider, region, identity service, management platform or recovery environment.
Exit planning also requires renewed attention. The ability to terminate a contract is not the same as the operational ability to migrate a critical service. Realistic exit strategies must account for data transfer, application redesign, specialist skills, replacement capacity, security validation and the time required to move complex workloads.
Resilience exercises should also test prolonged and multi-service disruption rather than assume that cloud availability will be restored within standard contractual targets. Scenarios should consider the failure of a shared identity platform, control plane, regional service, security function or connectivity layer affecting several business services simultaneously.
The UK’s first Critical Third Party designations are therefore more than a new set of rules for four technology companies. They show that the regulatory perimeter is expanding to follow operational dependency. When a technology provider becomes sufficiently important to the functioning of a regulated sector, authorities may no longer be satisfied with supervising it indirectly through customer contracts and supplier questionnaires.
