Starting July 13, the Bank of England, the Prudential Regulation Authority and the Financial Conduct Authority begin direct oversight of four companies that have never held a banking licence and never taken a customer deposit: Amazon Web Services, Google Cloud, Microsoft and Oracle. The shift marks a structural change in how financial regulation works. For decades, regulators policed banks and let banks police their vendors through contracts. Now, for the first time, UK regulators can reach past the bank and intervene directly in the infrastructure the bank runs on.

From Contractual Risk to Direct Oversight

HM Treasury’s designation of the four cloud providers as Critical Third Parties (CTPs) activates a regime built under the Financial Services and Markets Act 2023, with final rules in force since January 2025. Until now, a bank’s relationship with its cloud vendor was governed entirely by outsourcing contracts and due diligence obligations sitting on the bank’s side of the relationship. If AWS had an outage, the regulator’s only lever was to lean on the bank, not on AWS.

That changes this week. The Bank of England, PRA and FCA can now assess the operational resilience of the designated providers directly, gather information from them, set resilience requirements and require regular self-assessments and incident reporting. Sarah Breeden, the Bank’s Deputy Governor for Financial Stability, framed the rationale plainly: “As critical third parties become increasingly embedded in the operations of financial institutions, they can introduce new forms of systemic risk.” Designation is not authorisation. The providers are not being turned into regulated financial firms. The oversight is scoped narrowly to the resilience of the specific services they supply to UK financial firms.

Advertisement

FinTech Your brand belongs here. Reach the decision-makers who read FinTech every day. Premium placements across the site and newsletter. Advertise with us

Why These Four, Why Now

The trigger is concentration, not any single incident. HM Treasury’s own analysis found that more than 65% of UK financial organisations rely on the same four infrastructure providers, and a joint Bank of England and FCA survey found that Amazon, Google and Microsoft alone account for 73% of cloud computing services supplied by named vendors to UK financial firms. That concentration means a single provider’s failure would no longer be one bank’s problem. It would be shared, simultaneously, across a large share of the sector, which is exactly the kind of systemic exposure the Bank of England exists to prevent.

FCA Chief Executive Nikhil Rathi put it in those terms: “A single failure can reverberate across the financial system,” and the new regime “strengthens our ability to tackle those risks.” Katharine Braddick, the Bank’s Deputy Governor for Prudential Regulation, added that “by bringing critical third parties into the scope of oversight, we are ensuring that the infrastructure underpinning UK financial services is robust.” HM Treasury retains sole authority to add further providers as it did with this first batch, and officials have signalled the scope will keep evolving.

The DORA Parallel

The UK is not moving alone. The EU’s Digital Operational Resilience Act created its own Critical ICT Third-Party Service Provider regime, and in November 2025 European Supervisory Authorities published a list of 19 designated providers, including AWS, Google Cloud and Microsoft alongside data centre operators and telecom firms. In January, the European Supervisory Authorities and UK regulators signed a Memorandum of Understanding to coordinate cross-border oversight of shared providers, an acknowledgment that AWS’s UK resilience and AWS’s EU resilience are, in practice, the same engineering problem viewed from two regulatory seats. Firms that have already mapped their vendor contracts for DORA will find the UK regime largely parallel in structure, if narrower in current scope.

Newsletter

Get the week's best tech coverage.

Free. Read by thousands of HR, tech, and business leaders.

What It Means for the Finance Leader

For a bank, payments firm or insurer’s CTO, CRO or head of vendor risk, the practical change is who else is now watching the same vendor. Resilience testing, incident reporting and self-assessment obligations that the designated providers must meet create a new source of information: regulatory findings a firm can reference when it renews its own outsourcing risk assessment, rather than relying solely on the vendor’s own attestations. Firms should expect the Bank of England and FCA to eventually publish thematic findings from CTP oversight, the way they already do for other supervised sectors, and should build a process for ingesting those findings into their own third-party risk frameworks. For firms using smaller or regional cloud providers not among the initial four, the designation list itself is worth tracking closely: further additions are explicitly anticipated.

The Concentration Paradox

The regime carries an irony its architects have acknowledged only indirectly. Google Cloud’s public response was notably cooperative, saying the framework, done well, “can enhance the long-term resilience of the UK’s financial ecosystem and increase understanding, transparency, and trust between all parties.” That comfort is easier for an incumbent to express than for a challenger. Once AWS, Google Cloud, Microsoft and Oracle are absorbing the compliance cost of direct regulatory oversight, smaller cloud providers face a materially higher bar to win financial-sector business, since a bank now has less regulatory cover when using an undesignated vendor. A regime built to reduce concentration risk may, over time, entrench the very concentration it targets.

What to Watch

Vendor risk teams should treat July 13 as a deadline for two things: confirming which of their critical vendors sit inside the initial CTP designation, and building a monitoring process for the resilience findings the Bank of England, PRA and FCA are now empowered to generate. The UK’s own regulatory approach to fintech risk is evolving in parallel on other fronts, including the FCA’s Mills Review of how existing rules apply to agentic AI in retail financial services, and firms should expect UK supervisors to keep extending direct oversight further up the technology stack rather than stopping at the cloud layer.

Source: Bank of England