What changed on 13 July
The Bank of England, Prudential Regulation Authority and Financial Conduct Authority have begun jointly overseeing the first providers designated as Critical Third Parties to the UK financial sector. The four named entities are Amazon Web Services EMEA SARL, Google Cloud EMEA Limited, Microsoft Ireland Operations Limited and Oracle Corporation UK Limited. HM Treasury made the designations after the regulators’ rules took effect in January 2025. This is direct oversight of the resilience of specified critical services; it is not general authorisation of the companies or regulation of every product they sell.
Why concentration matters
Cloud platforms let financial firms obtain resilient infrastructure and specialised services without building everything themselves. The systemic concern appears when many banks, insurers, payment systems or market infrastructures depend on the same supplier. A cyber-attack, power failure or operational error could then interrupt several institutions at once. The new regime gives regulators a view across individual contracts and is intended to reduce the chance that one provider incident spreads through services used by British consumers and businesses.
What the providers must do
Once designated, a Critical Third Party must provide assurance, information and notifications to the regulators, take part in resilience testing and scenario exercises, and report major incidents affecting its critical services. The rules are outcomes-focused: providers must identify and manage risks, communicate promptly and show that important services can withstand and recover from disruption. Regulators can gather information and enforce requirements, while HM Treasury retains responsibility for future designations and de-designations.
What financial firms should do now
Designation does not transfer accountability away from a bank, insurer or financial market infrastructure. Existing outsourcing and operational-resilience duties still apply, including due diligence, risk management and contingency planning. In practice, firms need an accurate map of which important business services depend on each cloud component, tested recovery assumptions and incident contacts that work across organisational boundaries. Multi-cloud branding is not enough if two supposedly separate services share an identity system, network path or operational team. The useful test is whether the institution can keep an important service within its impact tolerance when a dependency fails.
UK TECH TRENDIndependent analysis for the British technology market.
Continue to all articles
