Decoding the world of cybersecurity

Cloud providers enter UK finance resilience regime

UK financial regulators are now directly overseeing the first critical third parties, bringing major cloud providers inside a system-wide operational resilience framework.

Cloud providers enter UK finance resilience regime
Summary
  • AWS EMEA, Google Cloud EMEA, Microsoft Ireland Operations, and Oracle Corporation UK are the first designated critical third parties.
  • UK regulators say 27% of incidents reported to the FCA by firms in 2025 were attributed to third party issues, with 37% of those cyber-related.
  • The regime adds direct oversight of critical services while leaving financial firms responsible for their own outsourcing, contingency planning, and operational resilience duties.

The Financial Conduct Authority, Prudential Regulation Authority, and Bank of England have begun direct oversight of the first critical third parties to the UK financial sector, bringing major technology suppliers inside a system-wide resilience regime.

The first designated providers are Amazon Web Services EMEA SARL, Google Cloud EMEA Limited, Microsoft Ireland Operations Limited, and Oracle Corporation UK Limited. From 13 July 2026, the three regulators began jointly overseeing the critical services those providers supply to UK financial firms and financial market infrastructures.

The regime addresses the risk created when many regulated firms depend on the same technology, data, cloud, or operational service providers. The FCA and PRA said 27% of incidents reported by firms to the FCA in 2025 were attributed to third party issues, and 37% of those incidents were cyber-related.

Oversight is limited to the resilience of critical services supplied to the financial sector. It does not authorise or regulate every part of the designated providers’ business, and it does not replace the obligations that banks, insurers, payment firms, and other regulated firms already have for outsourcing, due diligence, risk management, and contingency planning.

The change still alters the accountability landscape. Until now, resilience duties have largely sat with regulated firms buying services from global technology providers with enormous bargaining power and operational scale. The new regime gives regulators a direct route into designated third parties, including expectations around risk management, testing, communication, and major incident coordination.

Cloud concentration is now inseparable from financial-sector cyber resilience. A major outage, control-plane failure, identity compromise, ransomware event, or serious misconfiguration at a common provider could affect many institutions at once. The 2024 CrowdStrike outage, although not a cyber attack, remains a useful reminder of how shared technology dependencies can disrupt services across sectors.

The UK approach also sits alongside the EU’s Digital Operational Resilience Act, which gives European supervisory authorities an oversight role for critical ICT third party service providers used by financial entities. Multinational firms and providers will need to manage overlapping expectations around evidence, testing, reporting, and incident coordination.

Financial firms will feel the effect through procurement, architecture, and resilience evidence. They need to understand which important business services depend on designated providers, what substitution options exist, how incident information will flow, and whether testing covers shared disruption rather than isolated service faults. Supplier assurance will need to show operational behaviour and recovery capability, not only contractual commitments.

The regime places cloud and technology providers inside the UK financial resilience perimeter. Regulated firms will still own their risk decisions, but those decisions will now sit within a supervisory model that recognises how concentrated digital infrastructure can affect the wider market.

×