Live Updates

UK financial regulators to begin overseeing Critical Third Parties announced by Treasury

AI Analysis

Executive Summary

The Bank of England, PRA and FCA will begin **direct, joint oversight of the first designated Critical Third Parties (CTPs) from 13 July 2026**, covering four major cloud and technology providers whose services underpin UK financial markets. This materially changes the operational resilience landscape: while regulated firms remain fully responsible for their own outsourcing and third‑party risk management, critical dependencies on AWS, Google Cloud, Microsoft and Oracle will now sit within a separate supervisory regime focused on system‑level resilience and incident management.

What Changed

  • - A new CTP oversight regime becomes operational on 13 July 2026, under which the Bank of England, PRA and FCA will jointly supervise certain technology and service providers whose failure could threaten UK financial stability.
  • HM Treasury has made the first formal CTP designations: Amazon Web Services EMEA SARL, Google Cloud EMEA Limited, Microsoft Ireland Operations Ltd and Oracle Corporation UK Limited.
  • Designated CTPs must identify and manage risks to their critical services effectively, including governance, risk management and operational resilience arrangements specifically focused on services supporting UK financial firms and market infrastruct
  • CTPs are required to maintain open, timely communication with regulators and with firms that rely on them, particularly during major incidents, implying strengthened incident reporting, information‑sharing and coordination obligations.
  • The three regulators will jointly oversee CTPs under a proportionate regime focused on resilience of “critical services”, including assessing and mitigating system‑level risks and reducing the risk that disruption at a single provider spreads across
  • Regulators will periodically review whether designated CTPs continue to meet the statutory designation criteria and may recommend further designations or de‑designations to HM Treasury.

Suggested Considerations

  • Review and update the firm’s operational resilience framework, including impact tolerances and scenario testing, to explicitly incorporate systemic risk arising from reliance on the designated CTPs and potential correlated failures affecting multiple services or regions.
  • Re‑assess outsourcing and third‑party risk management policies to ensure they clearly distinguish between obligations placed on regulated firms and those placed directly on CTPs, while maintaining robust due diligence, ongoing monitoring and exit strategies for all CTP‑hosted services.
  • Engage with designated CTPs (through account management, risk and security channels) to understand their approach to compliance with the CTP regime, including incident reporting arrangements, resilience testing, communication protocols and any new assurance artifacts they plan to provide.
  • Update board and senior management reporting so that reliance on designated CTPs, associated systemic risk and regulatory developments under the CTP regime are regularly monitored and discussed at appropriate governance forums (e.g. risk committee, operational resilience committee).
  • Review major incident management and crisis communication playbooks to ensure they include specific escalation paths, contact points and joint incident handling procedures with designated CTPs and relevant regulators.
  • Ensure contracts and service level agreements with the designated CTPs are reviewed for alignment with regulatory expectations (e.g. access to data, resilience commitments, testing, audit and information‑sharing), and consider negotiating amendments where material gaps exist.

Key Dates

12 November 2024
- UK regulators publish final policy and supervisory materials setting out the CTP oversight regime, including Fundamental Rules and operational risk and resilience requirements
01 January 2025
- CTP rules and oversight regime take legal effect, but only apply once a provider is designated as a CTP
13 July 2026
- Regulations for CTP oversight come into effect for the first designated CTPs; Bank of England, PRA and FCA formally start supervising AWS EMEA, Google Cloud EMEA, Microsoft Ireland Operations and Oracle UK as CTPs

Compliance Impact

Non‑compliance primarily affects regulated firms through weaknesses in operational resilience and third‑party risk management, rather than direct CTP rule breaches, but could result in supervisory findings, remediation programmes, restrictions on business growth and, in serious cases, enforcement action. For designated CTPs, failure to meet the regime’s requirements may trigger direct regulatory i

Who is Affected

UK‑authorised banks and building societiesInvestment firms and securities dealers authorised by the FCA and/or PRAFinancial market infrastructures (FMIs)UK‑authorised insurers and reinsurersPayment institutions and e‑money firms regulated by the FCADesignated CTPs themselvesOther technology and outsourcing providers to the UK financial sector

AI-generated analysis. May contain errors or omissions — verify with the original FCA source before acting. Full disclaimer.

Summary

The Bank of England (the Bank), the Prudential Regulation Authority (PRA) and the FCA will start overseeing the first critical third parties (CTPs) on Monday 13 July 2026, following designation by the Treasury. CTPs are technology and other service providers whose services underpin the UK financial system. Today, the Treasury has announced its first designations of 4 global cloud services and technology providers: Amazon Web Services EMEA SARL, Google Cloud EMEA Limited, Microsoft Ireland Ope...

Relevant Firm Types

BankBroker DealerPayment ProviderAll Firms
View Original on FCA Back to Feed

Share this update