AWS, Google Cloud, Microsoft and Oracle come under UK regulatory oversight from 13 July as CTP regime goes live

The Bank of England, PRA and FCA began supervising the UK's first Critical Third Parties on 13 July 2026. If your firm runs on any of the four designated cloud providers, here is what the regime means for you.

AWS, Google Cloud, Microsoft and Oracle come under UK regulatory oversight from 13 July as CTP regime goes live
Illustration: AI-generated

Worth reviewing for any regulated firm using cloud infrastructure from any of the four designated providers. No immediate action is required, but the boundary between your obligations and the new regime is worth understanding.

The Bank of England, PRA and FCA began overseeing the UK's first Critical Third Parties (CTPs) on 13 July 2026, following designation by HM Treasury. The four providers named are Amazon Web Services EMEA SARL, Google Cloud EMEA Limited, Microsoft Ireland Operations Ltd, and Oracle Corporation UK Limited.

The rationale is concentration risk: enough firms depend on these four providers that a serious outage at any one of them could ripple across the sector simultaneously, potentially affecting UK financial stability and services used by millions of consumers and businesses. The legal basis is the Financial Services and Markets Act 2000 (FSMA 2000) as amended by the Financial Services and Markets Act 2023 (FSMA 2023), which gave the three regulators new powers to oversee critical third parties. The final rules came into effect on 1 January 2025 and apply immediately upon HM Treasury designation.

One distinction is worth stating clearly: designation is not authorisation. The regulators are not approving these providers to operate; they are supervising the resilience of the specific services those providers supply to UK financial firms. The scope is deliberately narrow.

The regime does not lift any of your existing obligations. Your outsourcing rules, due diligence requirements, and contingency planning remain yours. The CTP framework sits alongside your operational resilience duties, not instead of them.

For the designated providers, the core obligations are to identify and manage risks to the services they supply to UK financial firms, and to keep regulators and client firms informed promptly, especially when something goes wrong.

The regulators have signed a Memorandum of Understanding with EU counterparts to support coordination and information sharing, recognising that the four providers are likely subject to the EU's Digital Operational Resilience Act (DORA) as well. HM Treasury holds sole responsibility for designating and de-designating CTPs, generally acting on recommendations from the regulators. Further designations are expected as the regime evolves, though no timeline or criteria for the next round have been published.

The Bank of England's Financial Stability Report (7 July 2026) identified that rapid advances in frontier AI have increased financial stability risks related to cyber and operational resilience. The Mills Review (6 July 2026) separately noted that firms remain accountable for outcomes where AI or cloud capabilities are supplied by third parties, and that governance cannot be outsourced.

If your outsourcing and third-party risk arrangements are already current, this is a framework to understand rather than a trigger for immediate change. If you have not mapped your cloud provider dependencies recently, now is a reasonable moment to do so.

Sources