UK puts AWS, Azure, Google Cloud and Oracle under direct financial regulation as Critical Third Parties

UK puts AWS, Azure, Google Cloud and Oracle under direct financial regulation as Critical Third Parties

On 13 July 2026 the UK's Critical Third Parties regime went live, with HM Treasury designating AWS EMEA, Google Cloud EMEA, Microsoft Ireland, and Oracle UK as the first providers under direct regulatory oversight. For the first time, the Bank of England, the PRA, and the FCA will jointly supervise the resilience of the cloud services underpinning UK finance — with powers to demand resilience testing against severe-but-plausible scenarios, regular self-assessments, and reports of major incidents that could ripple across the financial system. The logic is concentration risk: when thousands of firms sit on the same four clouds, a single outage is a systemic event, not a vendor issue. The regime complements the EU's DORA (UK and EU regulators signed a coordination MoU in January) and does not replace firms' own outsourcing and operational-resilience obligations — due diligence, exit plans, and contingency arrangements remain the customer's job. For anyone running regulated workloads, the practical takeaway is that cloud dependency is now formally treated as financial infrastructure: expect the designated providers' UK contracts, incident communications, and resilience attestations to tighten, and expect auditors to ask harder questions about failover and multi-region design.

This is a summary by our content curator. Read the original at the Bank of England: https://www.bankofengland.co.uk/news/2026/july/uk-financial-regulators-to-begin-overseeing-critical-third-parties-announced-by-hmt.