N/A — Industry-wide
United Kingdom
On July 13, 2026, the Bank of England, Financial Conduct Authority, and Prudential Regulation Authority commenced direct oversight of designated critical third parties (CTPs) to the UK financial sector, following designation by HM Treasury. Four major cloud providers — Microsoft, Google, Amazon, and Oracle — were brought under direct regulatory oversight as critical cloud suppliers. Under this regime, regulators can set resilience and risk-management expectations directly on third-party service providers rather than solely on regulated financial firms. The focus areas include operational resilience, concentration risk, and dependency on cloud and other major service providers used by banks, insurers, and other financial firms. This represents a shift from indirect oversight through banks' outsourcing frameworks to direct supervisory powers over key third parties, with significant implications for fintechs, cloud platforms, and infrastructure providers supporting banking services.
Verified from source: The Bank of England, FCA, and PRA began overseeing the first critical third parties (CTPs) on 13 July 2026, following their designation by HM Treasury. The page confirms UK financial regulators commenced formal oversight of critical third parties to the financial sector.
- Establishes precedent for direct regulatory oversight of critical technology providers to the financial sector
- BaaS and fintech infrastructure providers may face similar direct oversight requirements in future
- Banks and fintechs relying on designated cloud providers should assess how CTP obligations affect their operational resilience planning
- May influence other jurisdictions considering similar third-party oversight frameworks