UK financial regulators to begin overseeing Critical Third Parties announced by Treasury
Executive Summary
The Bank of England, PRA and FCA will begin **direct, joint oversight of the first designated Critical Third Parties (CTPs) from 13 July 2026**, covering four major cloud and technology providers whose services underpin UK financial markets. This materially changes the operational resilience landscape: while regulated firms remain fully responsible for their own outsourcing and third‑party risk management, critical dependencies on AWS, Google Cloud, Microsoft and Oracle will now sit within a separate supervisory regime focused on system‑level resilience and incident management.
What Changed
- - A new CTP oversight regime becomes operational on 13 July 2026, under which the Bank of England, PRA and FCA will jointly supervise certain technology and service providers whose failure could threaten UK financial stability.
- HM Treasury has made the first formal CTP designations: Amazon Web Services EMEA SARL, Google Cloud EMEA Limited, Microsoft Ireland Operations Ltd and Oracle Corporation UK Limited.
- Designated CTPs must identify and manage risks to their critical services effectively, including governance, risk management and operational resilience arrangements specifically focused on services supporting UK financial firms and market infrastruct
- CTPs are required to maintain open, timely communication with regulators and with firms that rely on them, particularly during major incidents, implying strengthened incident reporting, information‑sharing and coordination obligations.
- The three regulators will jointly oversee CTPs under a proportionate regime focused on resilience of “critical services”, including assessing and mitigating system‑level risks and reducing the risk that disruption at a single provider spreads across
- Regulators will periodically review whether designated CTPs continue to meet the statutory designation criteria and may recommend further designations or de‑designations to HM Treasury.
Suggested Considerations
- Review and update the firm’s operational resilience framework, including impact tolerances and scenario testing, to explicitly incorporate systemic risk arising from reliance on the designated CTPs and potential correlated failures affecting multiple services or regions.
- Re‑assess outsourcing and third‑party risk management policies to ensure they clearly distinguish between obligations placed on regulated firms and those placed directly on CTPs, while maintaining robust due diligence, ongoing monitoring and exit strategies for all CTP‑hosted services.
- Engage with designated CTPs (through account management, risk and security channels) to understand their approach to compliance with the CTP regime, including incident reporting arrangements, resilience testing, communication protocols and any new assurance artifacts they plan to provide.
- Update board and senior management reporting so that reliance on designated CTPs, associated systemic risk and regulatory developments under the CTP regime are regularly monitored and discussed at appropriate governance forums (e.g. risk committee, operational resilience committee).
- Review major incident management and crisis communication playbooks to ensure they include specific escalation paths, contact points and joint incident handling procedures with designated CTPs and relevant regulators.
- Ensure contracts and service level agreements with the designated CTPs are reviewed for alignment with regulatory expectations (e.g. access to data, resilience commitments, testing, audit and information‑sharing), and consider negotiating amendments where material gaps exist.
Key Dates
Compliance Impact
Non‑compliance primarily affects regulated firms through weaknesses in operational resilience and third‑party risk management, rather than direct CTP rule breaches, but could result in supervisory findings, remediation programmes, restrictions on business growth and, in serious cases, enforcement action. For designated CTPs, failure to meet the regime’s requirements may trigger direct regulatory i
Who is Affected
References
AI-generated analysis. May contain errors or omissions — verify with the original FCA source before acting. Full disclaimer.
Summary
The Bank of England (the Bank), the Prudential Regulation Authority (PRA) and the FCA will start overseeing the first critical third parties (CTPs) on Monday 13 July 2026, following designation by the Treasury. CTPs are technology and other service providers whose services underpin the UK financial system. Today, the Treasury has announced its first designations of 4 global cloud services and technology providers: Amazon Web Services EMEA SARL, Google Cloud EMEA Limited, Microsoft Ireland Ope...