New Oversight for Cloud Service Providers in the UK Financial Sector
In a significant move to bolster the resilience of the UK’s financial system, four prominent global cloud service providers will soon be placed under a direct regulatory framework. This initiative aims to enhance the reliability of critical services that millions of businesses and individuals depend on daily.
As the reliance of banks, insurers, and financial market infrastructures on cloud services intensifies, the potential for disruption from a major supplier poses risks that could cascade across multiple firms. Such disruptions could adversely affect the services that customers rely upon. To mitigate these threats, the UK Government has designated four major cloud service and technology providers as Critical Third Parties (CTPs).
Collaboration Among Financial Regulators
This designation enables collaborative oversight involving the Bank of England, the Prudential Regulation Authority, and the Financial Conduct Authority. By working together, these regulatory bodies will oversee the essential services provided by these firms to the financial sector. This joint effort aims to diminish the likelihood of widespread disruptions while enhancing cooperation across the financial services landscape.
The designated CTPs will be subject to comprehensive scrutiny by UK financial regulators to ensure they maintain robust protocols for identifying, managing, and recovering from operational disruptions that could impact critical services in the financial sector. Through this new regulatory regime, regulators will have the authority to gather data, evaluate resilience, and collaborate with third parties to address potential risks to the continuity of vital services. This may include the development and enforcement of specific rules tailored to CTPs when necessary.
Government’s Commitment to Financial Stability
Rachel Blake MP, the Economic Secretary to the Treasury and City Minister, emphasised the importance of maintaining trust in the UK’s financial system. She stated that these designations are crucial for ensuring the resilience of critical services upon which financial firms rely, ultimately safeguarding consumers and businesses while fostering economic growth.
The government’s initiative marks a pivotal step in reinforcing the UK’s financial system’s resilience. A stable and secure financial environment is deemed essential for promoting economic growth. By enhancing oversight of critical services and improving collaboration with third-party providers, the government aims to protect financial stability, bolster confidence, and create a conducive atmosphere for investment and innovation.
Designated Cloud Service Providers
The following firms will be officially designated as Critical Third Parties starting from 13 July 2026:
- Microsoft Ireland Operations Limited
- Google Cloud EMEA Limited
- Amazon Web Services EMEA SARL
- Oracle Corporation UK Limited
This designation comes after a thorough period of evidence gathering and collaboration with the relevant third parties.
Industry Responses to Regulatory Changes
Freddy Dezeure, Deputy Chief Information Security Officer for Europe at Microsoft, expressed the company’s long-standing commitment to supporting UK government agencies and enhancing the resilience of the digital ecosystem. He noted that the designation of Microsoft Ireland Operations as a critical third party signifies an evolution in their partnership with the UK government.
A spokesperson for Google Cloud reiterated their commitment to ensuring operational resilience within the UK financial sector, expressing confidence that the new CTP framework will foster long-term resilience and improve understanding and trust among all stakeholders in the financial ecosystem.
Michael Jefferson, Head of Financial Services Public Policy EMEA at AWS, affirmed their dedication to adhering to UK regulations while assisting customers in achieving their operational resilience goals. Similarly, Kevin Kimber, Senior Vice President and General Manager for UK&I at Oracle, highlighted their commitment to working closely with regulators to enhance operational resilience and support government initiatives aimed at driving innovation and economic growth.
Framework and Future Designations
The Critical Third Parties regime was established through the Financial Services and Markets Act 2023, which aims to fortify the operational resilience of the UK financial system. The decisions regarding designations are made by HM Treasury following consultations with third parties, including the Bank of England, Prudential Regulation Authority, and Financial Conduct Authority.
It is important to note that this regulatory oversight pertains solely to the systemic services provided to the financial sector, and not the broader operations of these firms. There is no statutory cap on the number of Critical Third Parties that may be designated, and HM Treasury adopts a risk-based and proportionate approach to ensure that only the most crucial third-party providers enter the regime. Future designations may occur where suppliers meet the necessary statutory criteria, particularly where disruptions could threaten UK financial stability or public confidence in the financial system.
Ultimately, financial firms will retain responsibility for managing risks associated with their third-party suppliers, even as the regulatory environment evolves to strengthen the foundations of the financial sector.
