UK · technology

UK Regulators Begin Direct Oversight of Major Cloud Providers Supporting Financial Services

AWS, Google Cloud, Microsoft and Oracle have become the first technology providers placed under the United Kingdom's new Critical Third Parties oversight regime.

Published Jul 21, 2026, 9:45 AMLast updated Jul 21, 2026, 9:45 AM
UK Regulators Begin Direct Oversight of Major Cloud Providers Supporting Financial Services — UK · technology

LONDON — UK financial regulators have begun directly overseeing four major technology and cloud-service companies whose systems support banks, insurers and other financial institutions.

The Bank of England, Prudential Regulation Authority and Financial Conduct Authority started supervising the first designated Critical Third Parties on 13 July 2026.

HM Treasury designated Amazon Web Services EMEA, Google Cloud EMEA, Microsoft Ireland Operations and Oracle Corporation UK under the new regime.

Critical Third Parties are external companies whose services have become sufficiently important to the financial system that a serious outage, cyber incident or operational failure could affect numerous regulated firms simultaneously.

Many banks, insurers and financial-market businesses rely on a relatively small number of technology providers for cloud storage, computing infrastructure, data management and other essential services.

Regulators are concerned that concentration among a few major providers could create system-wide risk. A disruption affecting one widely used platform could interfere with financial services used by millions of consumers and businesses.

Under the new framework, regulators will focus on the resilience of the critical services these companies provide. Designated providers will be expected to identify and manage risks, conduct resilience testing and maintain timely communication with regulators and financial firms during serious incidents.

The regime is intended to improve coordination and information sharing across the financial sector. It will also allow regulators to examine risks that may not be visible when individual banks or insurers assess their own outsourcing arrangements separately.

Designation as a Critical Third Party does not mean that the companies have been authorised as banks or financial institutions. Regulatory oversight is limited to the resilience of services supplied to the UK financial sector.

The new system also does not remove responsibility from financial institutions. Banks, insurers and investment firms must still assess their suppliers, maintain contingency plans and ensure they can continue providing important services during disruption.

UK regulators have also established cooperation arrangements with European authorities, recognising that major cloud and technology companies often serve financial institutions across several jurisdictions.

The regime reflects the growing dependence of modern finance on external digital infrastructure. Cloud services can support innovation and efficiency, but heavy reliance on a small group of suppliers requires stronger planning for outages, cyber-attacks and other operational emergencies.

Related
We use essential cookies to run the site. Analytics and personalisation are off by default. See our privacy policy.