UK Regulators Launch Oversight of Tech Giants AWS, Google, Microsoft, and Oracle as Critical Third Parties
By Lauren Towner · 10 July 2026

Quick Summary
The UK’s financial regulators—the Bank of England, PRA, and FCA—will begin formal oversight of Critical Third Parties (CTPs) starting July 13, 2026. This regime targets systemic risks posed by major technology providers like AWS, Google, Microsoft, and Oracle to ensure the UK financial stability remains resilient against large-scale service disruptions.
How Does the New CTP Oversight Regime Protect the UK Financial System?
The Critical Third Parties regime addresses the systemic vulnerability created when thousands of financial firms rely on a handful of global technology providers. By designating Amazon Web Services, Google Cloud, Microsoft, and Oracle as CTPs, regulators can now directly monitor the resilience of the infrastructure underpinning the UK economy. This oversight is designed to prevent a single point of failure from triggering a market-wide disruption that could impact millions of consumers.
- Direct Regulatory Oversight: Regulators will now jointly supervise the resilience of services provided by designated tech giants.
- System-Level Risk Management: CTPs are required to identify and mitigate risks that could spread across the entire financial sector.
- Enhanced Communication: Providers must maintain open channels with regulators and clients during major technical incidents.
Which Companies Are Designated as Critical Third Parties?
HM Treasury has officially designated four global providers as the inaugural members of the CTP framework. These include Amazon Web Services EMEA SARL, Google Cloud EMEA Limited, Microsoft Ireland Operations Ltd, and Oracle Corporation UK Limited. These firms were selected because their services are so deeply embedded in UK finance that their failure would pose a significant threat to national financial stability.
- AWS EMEA SARL: A primary provider of cloud infrastructure for UK fintechs and banks.
- Google Cloud EMEA: Essential for data analytics and scalable financial applications.
- Microsoft Ireland: Critical for enterprise productivity and cloud-based banking core systems.
- Oracle UK: A cornerstone for database management and legacy system integration.
What Are the Responsibilities of Regulated Financial Firms?
While the regulators now oversee the tech providers directly, regulated financial firms remain legally responsible for their own operational resilience. This new regime complements existing rules rather than replacing them. Banks and insurers must continue to perform rigorous due diligence, manage their specific third-party risks, and maintain robust contingency planning for their own operations.
"As critical third parties become increasingly embedded in the operations of financial institutions, they can introduce new forms of systemic risk. Our proportionate approach to overseeing these providers will ensure that these dependencies are managed in a way that safeguards financial stability." said Sarah Breeden, Deputy Governor for Financial Stability at the Bank of England.
FF NEWS TAKE:
This move by the Bank of England and FCA is a massive shift in the regulatory landscape. For years, the "Big Tech" cloud providers operated in a regulatory grey area—essential to finance but not directly supervised. By designating Critical Third Parties, the UK is leading the way in acknowledging that cloud resilience is now synonymous with financial stability. It moves the needle by forcing transparency from tech giants who previously held all the cards.
Companies in this story: HM Treasury, Google Cloud EMEA Limited, Microsoft Ireland Operations Ltd, Amazon Web Services EMEA SARL, Prudential Regulation Authority, Bank of England, Oracle Corporation UK Limited, Financial Conduct Authority
People in this story: Nikhil Rathi, Sarah Breeden, Katharine Braddick