By This Hour Finance Desk

UK financial regulators are scheduled to begin direct oversight of four major cloud and technology suppliers whose services support banks, insurers, market infrastructure and other financial firms. The move follows HM Treasury’s designation of Amazon Web Services EMEA SARL, Google Cloud EMEA Limited, Microsoft Ireland Operations Ltd and Oracle Corporation UK Limited as the first Critical Third Parties.

The Bank of England, Prudential Regulation Authority and Financial Conduct Authority are due to start the joint supervision on 13 July 2026. The new regime is intended to address a concentrated operational risk: disruption at a provider used by many financial businesses could affect numerous firms or markets at once, rather than remaining an isolated technology problem inside one institution.

For the companies designated, the change is not an authorisation to conduct regulated financial activity. It instead brings the resilience of specified services supplied to UK financial firms within a purpose-built supervisory framework. For the financial sector, it adds oversight at a point in the supply chain that has become deeply embedded in day-to-day operations, while leaving regulated firms responsible for the choices and controls around their own outsourcing arrangements.

Four providers enter a new supervisory perimeter

HM Treasury has responsibility for deciding which third-party suppliers fall within the Critical Third Party regime. Its initial group comprises the European and UK legal entities connected to Amazon Web Services, Google Cloud, Microsoft and Oracle, rather than a blanket designation of every service or activity associated with those global corporate groups.

The boundaries matter. The oversight described by the regulators is confined to the resilience of critical services provided to UK financial firms. A designation therefore does not mean that the designated entity has been authorised by the Bank, PRA or FCA, and it does not convert the cloud suppliers into financial institutions. The regime focuses on a specific channel through which technology failures, operational weaknesses or incident-management problems could transmit across the financial system.

That focus reflects the way shared providers can create a common dependency. A financial firm may have safeguards for its own systems, but a service interruption at a supplier used across the sector can pose a broader problem. The Bank’s account of the policy says such disruption could reach multiple firms or markets simultaneously and affect services used by consumers and businesses. The objective is to reduce the possibility that a failure in a critical outsourced service spreads through the UK system.

The designation process is also not presented as fixed. Treasury can make future designations or remove a designation. The three regulators are expected to review periodically whether providers continue to meet the relevant criteria, generally making recommendations to Treasury, and to assess whether their own oversight approach is working effectively. That arrangement separates the formal decision to designate from the regulators’ continuing operational and supervisory role.

Resilience rather than financial authorisation is the core test

The Bank, PRA and FCA say they will supervise the designated providers together under a proportionate framework. Its central concern is whether the critical services supplied to the UK financial sector are resilient. The authorities plan to work with the providers on risks that arise at system level, where the effect on the sector may be greater than any single firm’s direct exposure appears to suggest.

Under the regime, Critical Third Parties are expected to identify and manage risks affecting their critical services. They must also keep communication open and timely with both the regulators and the firms dependent on their services, particularly during major incidents. In practical terms, the communication requirement places incident response alongside prevention: financial firms and public authorities need relevant information promptly when an important service is disrupted or under pressure.

The policy aim is coordination as much as scrutiny. Three financial authorities will be engaging with suppliers that may serve a wide range of regulated firms and financial market infrastructures. The approach described by the Bank is intended to improve information sharing across the sector and give the authorities a route to engage directly on dependencies that extend beyond the relationship between any one customer and its supplier.

For regulated firms, however, the new oversight does not transfer responsibility upward to the cloud provider or to the state. Existing outsourcing and operational-resilience requirements remain in place. Firms must still carry out due diligence, manage the risks in their third-party arrangements and prepare contingency plans. Direct supervision of a designated provider may provide a wider view of shared risks, but it is not described as a substitute for a firm’s own governance of its suppliers.

A framework prepared before the first designations

The authorities’ rules and policy for the Critical Third Party regime took effect on 1 January 2025. According to the Bank’s account, they apply to a provider as soon as Treasury designates it. The first designations therefore activate a framework that had already been set out, rather than establishing a wholly new set of requirements on the day oversight begins.

The legal basis lies in powers given to the Bank, PRA and FCA through amendments to the Financial Services and Markets Act 2000 made by the Financial Services and Markets Act 2023. The Bank says the regulators published final rules and policy in November 2024, as well as an approach to regulatory oversight and a supervisory statement intended to explain how designated providers should interpret and comply with the rules.

The timing supplied by the Bank is precise: its news release was published on 10 July 2026, Treasury’s initial designations were announced at that point, and the regulations and supervisory regime were due to begin on 13 July. This sequence indicates that designation is the trigger that puts a provider within the established framework, while the rules themselves had been in force since the start of 2025.

The authorities have also set the regime in an international context. The Bank notes that Critical Third Parties can be subject to comparable rules elsewhere, including the European Union’s Digital Operational Resilience Act. It says UK and EU regulators have signed a memorandum of understanding intended to support coordination and information sharing over the oversight of such providers. The supplied material does not specify how the UK framework will interact in individual cases with overseas supervision of any of the four companies.

The test will be in oversight and incident handling

The immediate consequence of Treasury’s action is a new line of engagement between the three UK regulators and the four designated entities. The broader consequences will depend on how the framework is applied to individual critical services, how providers evidence their management of relevant risks and how information flows during a major incident. The material does not detail particular resilience assessments, findings, enforcement action, service failures or remedial programmes involving any of the four providers.

It also does not identify further prospective designations, set a timetable for the next review of the designation criteria, or describe what specific steps the regulators might take in response to a future failure. Treasury retains the designation and de-designation decisions, while the regulators will continue to evaluate the criteria and their oversight model. That leaves the perimeter capable of changing as authorities consider additional dependencies within UK finance.

No current market prices, company financial results or investor reactions are contained in the supplied material, so no market response can be established from this announcement alone. Nor does designation itself state anything about the quality, security or commercial performance of each provider’s full range of products. It identifies the importance of certain services to the UK financial sector and subjects their resilience to the new oversight structure.

The underlying Bank of England release is primary documentation of the regulators’ stated plans and of the designations it attributes to HM Treasury. However, this report has not been independently corroborated. The available material is limited to that official account, and it does not include separate confirmation from Treasury, the four designated companies, affected financial firms or another independent source. The scheduled start date and the workings of the regime should therefore be read as reported by the Bank and subject to the scope and limitations it describes.

Sources