En
← All articles

The UK places four cloud service providers under direct oversight of the financial system

From 13/7/2026, the UK's financial regulator began jointly supervising four cloud service providers deemed “critical third parties”. The line…

AuthorOpen Market Notes Research DeskTypeArticle

What happened

On 13/7, a new UK regulatory regime officially came into force. The UK Treasury designated Amazon Web Services EMEA, Google Cloud EMEA, Microsoft Ireland Operations and Oracle Corporation UK as “Critical Third Parties” (CTPs) to the financial system. The UK Financial Conduct Authority, the Prudential Regulation Authority and the Bank of England will jointly oversee the systemic services these companies provide to financial institutions and financial market infrastructure.

This is not about turning all cloud computing companies into bank-supervised entities. The regulatory scope is focused on services that, if disrupted, could affect multiple banks, insurance companies, trading platforms or market infrastructure at the same time. The regulators can collect information, conduct resilience assessments and work with providers to address risks affecting the continuity of critical services; when necessary, they can also develop and enforce rules applying to those critical services.

Why this matters

In the day-to-day operations of the financial industry, cloud services sit behind many “invisible” functions: data storage, trading systems, customer interfaces, risk calculations and back-office operations may all depend on the same group of technology providers across multiple organizations. Previously, oversight responsibility rested mainly with the financial institutions themselves, while cloud service providers were largely bound only indirectly through contracts, audits and vendor governance.

The UK’s new arrangement changes an important institutional assumption: if an incident at a technology company can spread to many financial institutions at once, then the service that company provides is no longer just an operational procurement issue for a single institution, but can become a financial stability issue. Earlier, UK financial regulators said that of the cyber incident reports received in 2025, more than 40% involved third parties; this shows that supply-chain risk is no longer a side topic but part of the resilience of the financial system.

For cloud service providers, direct oversight may mean higher requirements for disclosure, testing and emergency response coordination. For banks and trading infrastructure, it does not mean responsibility can be shifted to the regulator: financial firms must still manage third-party risk themselves and ensure they have fallback plans and recovery capabilities when services are disrupted. The more practical change is that, when selecting cloud providers, designing multi-cloud architectures and assessing concentration risk, financial institutions may need to incorporate regulatory requirements into long-term infrastructure decisions.

What to watch next

First, how regulators will define each provider’s “systemic services,” and how deeply resilience assessments will go. Second, whether the UK Treasury will continue expanding the list of critical third parties; the current regime does not set a fixed number, so more data, software or operations service providers could be added in the future. Third, whether this regime can be coordinated with cloud supervision rules in other financial centers. Cloud infrastructure itself crosses national borders, while the services, data and operational teams used by UK financial institutions are often spread across multiple jurisdictions; whether regulatory boundaries align with technological boundaries will determine the regime’s practical effectiveness.

The policy signal is clear: the core infrastructure of financial markets is expanding from traditional trading, clearing and payment networks to the computing and data networks of a small number of large technology groups. The next phase of supervision is not only about tracking who trades in the market, but also who keeps the market running.

Sources

Information only. No investment, legal, tax, or financial advice.