UK regulators began overseeing the first four Critical Third Parties on 13 July 2026. AWS, Google Cloud, Microsoft and Oracle are now subject to resilience supervision focused on systemic risks to financial services.
HM Treasury Launches Critical Third Party Oversight Regime on 13 July 2026
From Monday, 13 July 2026, the Bank of England, the Prudential Regulation Authority (PRA) and the Financial Conduct Authority (FCA) formally began overseeing the first designated Critical Third Parties (CTPs) following their designation by HM Treasury (HMT). HM Treasury had previously announced the first designations on 10 July 2026 and introduced the Critical Third Parties (Designation) Regulations 2026.(Source: Bank of England, UK financial regulators to begin overseeing Critical Third Parties, published: 2026-07.)
Critical Third Parties are organisations that provide technology support and other services forming part of the underlying infrastructure of the UK financial system. HM Treasury explained that, because large numbers of financial firms depend on these services, an outage or failure could affect multiple firms or markets simultaneously, potentially disrupting UK financial stability and services used by millions of consumers and businesses.
First Four Global Cloud and Technology Providers Designated
The first designated entities announced by HM Treasury are four global cloud service and technology providers. The table below lists their registered legal entity names and the key dates on which they entered the oversight regime:
| Designated Entity (Registered Legal Entity) | Parent Company/Brand | Designation Announcement Date | Oversight Effective Date |
|---|---|---|---|
| Amazon Web Services EMEA SARL | Amazon Web Services (AWS) | 2026-07-10 | 2026-07-13 |
| Google Cloud EMEA Limited | Google Cloud | 2026-07-10 | 2026-07-13 |
| Microsoft Ireland Operations Ltd | Microsoft | 2026-07-10 | 2026-07-13 |
| Oracle Corporation UK Limited | Oracle | 2026-07-10 | 2026-07-13 |
HM Treasury said the three regulators would jointly oversee these Critical Third Parties for the first time under a newly established proportionate regulatory framework, focusing on the resilience of the critical services they provide to the UK financial sector. The regulators will work with the Critical Third Parties to address systemic risks and reduce the likelihood that service disruption spreads across the UK financial system.
Division of Responsibilities Between Regulators and Designated Entities
Critical Third Parties Must Identify Risks and Maintain Effective Communication
According to HM Treasury, the principal obligations imposed on Critical Third Parties under the regime include:
Effectively identifying and managing risks affecting their critical services;
Maintaining open and timely communication with regulators and the financial firms that depend on their services;
Ensuring that such communication is particularly timely during major incidents.
HM Treasury emphasised that the regime supplements existing outsourcing and operational resilience rules rather than replacing the requirements already applying to regulated firms. Regulated firms remain responsible for managing their own third-party arrangements, including:
Conducting due diligence on third-party suppliers;
Maintaining ongoing risk management;
Developing and maintaining contingency plans.
HM Treasury also clarified that designation under the regime does not constitute regulatory authorisation. The scope of oversight is limited to the resilience of services provided by the relevant entities to UK financial firms.(Source: Bank of England, UK financial regulators to begin overseeing Critical Third Parties, published: 2026-07, paragraphs concerning the scope of oversight and division of responsibilities.)
HM Treasury Is Responsible for Designation and De-Designation Decisions
HM Treasury is responsible for deciding which third-party service providers are designated as Critical Third Parties, as well as making any future designation or de-designation decisions, generally following recommendations from the regulators. The regulators will periodically review whether each Critical Third Party continues to meet the designation criteria, make recommendations to HM Treasury and assess the effectiveness of the oversight approach. HM Treasury said the scope of the regime would continue to expand as additional entities are designated.
Regulatory Leaders Explain the Objectives of the Regime
Three Authorities Emphasise Systemic Risk and Financial Stability
Sarah Breeden, Deputy Governor for Financial Stability at the Bank of England, explained the objectives of the regime:
“As Critical Third Parties become increasingly embedded in the operations of financial institutions, they may introduce new systemic risks. Applying proportionate oversight to these organisations will ensure that these dependencies are managed in a way that protects financial stability.”
Katharine Braddick, Deputy Governor and Chief Executive of the Prudential Regulation Authority, said that bringing Critical Third Parties within regulatory oversight would help ensure that the infrastructure supporting UK financial services was sufficiently resilient. This would safeguard UK financial stability and confidence while directly supporting the PRA’s objective of promoting the safety and soundness of regulated firms.
Nikhil Rathi, Chief Executive of the Financial Conduct Authority, noted that Critical Third Parties provide essential services supporting innovation and growth. However, when a single supplier provides services to thousands of firms, a failure at any one provider could have cascading effects across the financial system. He said implementing the regime would strengthen regulators’ ability to address these risks and improve overall resilience.
Legal Basis and International Coordination
Source of Regulatory Powers and Implementation Timeline
The legal basis for the oversight powers is the Financial Services and Markets Act 2000 (FSMA), as amended in 2023. The legislation granted the Bank of England, the Prudential Regulation Authority and the Financial Conduct Authority new powers to oversee Critical Third Parties and strengthen the resilience of the services they provide to regulated firms and financial market infrastructure. The implementation timeline was as follows:
In November 2024, the Financial Conduct Authority, the Bank of England and the Prudential Regulation Authority published the final rules and policies for the Critical Third Party regime;
On 1 January 2025, those rules and policies came into force and became applicable to Critical Third Parties immediately after designation by HM Treasury;
On 10 July 2026, HM Treasury announced the first four designated Critical Third Parties;
On 13 July 2026, the designations took effect and the three regulators began their joint oversight.
Coordination with the EU’s DORA and Similar Regimes
HM Treasury explained that Critical Third Parties may also be subject to similar oversight regimes in other jurisdictions, including the European Union’s Digital Operational Resilience Act (DORA). To support cross-border coordination and information sharing, the relevant regulators have signed memoranda of understanding concerning the oversight of Critical Third Parties.(Source: Bank of England, UK financial regulators to begin overseeing Critical Third Parties, published: 2026-07, paragraphs concerning FSMA and DORA.)
Frequently Asked Questions About the UK Critical Third Party Oversight Regime
When did the Critical Third Party oversight regime take effect?
HM Treasury announced the first designations on 10 July 2026, and the oversight regime formally took effect on Monday, 13 July 2026. It is jointly administered by the Bank of England, the Prudential Regulation Authority and the Financial Conduct Authority.
Which four organisations were included in the first designations?
The four organisations are Amazon Web Services EMEA SARL, Google Cloud EMEA Limited, Microsoft Ireland Operations Ltd and Oracle Corporation UK Limited. All four are global cloud service and technology providers.
What is a Critical Third Party?
A Critical Third Party is an organisation that provides technology support or other services forming part of the underlying infrastructure of the UK financial system. Because large numbers of financial firms depend on such services, an outage could affect multiple firms or markets simultaneously.
Does designation as a CTP constitute regulatory authorisation?
No. HM Treasury explained that designation under the regime does not constitute authorisation by a regulator. The scope of oversight is limited to the resilience of the services provided by the relevant entity to UK financial firms.
Does the regime remove financial firms’ own responsibilities?
No. The regime supplements existing outsourcing and operational resilience rules rather than replacing the requirements applying to regulated firms. Regulated firms remain responsible for their third-party arrangements, including due diligence, risk management and contingency planning.
What is the legal basis for the regime?
The legal basis is the Financial Services and Markets Act 2000, as amended in 2023. The legislation granted the Bank of England, the Prudential Regulation Authority and the Financial Conduct Authority new powers to oversee Critical Third Parties. The relevant final rules took effect on 1 January 2025.