UK regulators place first Big Tech cloud providers under new financial oversight regime
From 13 July 2026 the Bank of England, the Prudential Regulation Authority and the Financial Conduct Authority will jointly supervise the United Kingdom’s first designated Critical Third Parties (CTPs). HM Treasury has named four global cloud providers – Amazon Web Services EMEA SARL, Google Cloud EMEA Limited, Microsoft Ireland Operations Ltd and Oracle Corporation UK Limited – as the inaugural CTPs. The new framework obliges these firms to identify, monitor and mitigate operational risks to the critical services they supply to banks, fintechs and asset managers, and to maintain real‑time communication with regulators during major incidents.
The regime does not make the cloud providers financial institutions; it adds a focused oversight layer aimed at reducing systemic concentration risk, complementing existing outsourcing and resilience rules. Deputy Governor Sarah Breeden of the Bank of England warned that “critical third parties can introduce new forms of systemic risk”, while FCA chief Nikhil Rathi said a single failure could “reverberate across the financial system”. The move aligns the UK with broader international trends such as the EU’s Digital Operational Resilience Act.