📈 Markets | London, Edinburgh, Cardiff

MARKET PULSE UK

Decoding Markets for Everyone


UK Designates AWS, Google Cloud, Microsoft and Oracle as Critical Third Parties

HM Treasury has made The Critical Third Parties (Designation) Regulations 2026, naming Amazon Web Services EMEA SARL, Google Cloud EMEA Limited, Microsoft Ireland Operations Limited and Oracle Corporation UK Limited as critical third parties from Monday 13 July 2026. The legal text is brief, but the policy message is not: the Treasury now sees dependence on a handful of cloud providers as something that can threaten confidence in the UK financial system, not just an outsourcing issue for individual banks. (gov.uk) That matters because modern finance runs on rented computing power. Payments, customer log-ins, fraud checks, trading tools and back-office processing increasingly sit with outside providers. When HM Treasury warns that disruption at one of these suppliers could damage stability or confidence, it is really talking about the services households, investors and small firms use every day. (gov.uk)

The designation is aimed at one clear weakness: concentration. The Bank of England says the sector increasingly relies on a small number of third-party providers, creating the risk of a single point of failure across multiple firms and market infrastructure at the same time. The FCA puts it in similarly plain terms: if one major provider goes down, several firms or markets could be hit together. (bankofengland.co.uk) For retail investors, that could mean trading interruptions or delays in account access. For SME owners, it could mean payment bottlenecks, patchy access to banking platforms or problems with routine finance operations that depend on banks and insurers staying online. This is why cloud dependency has moved out of the server room and into the financial stability brief. (fca.org.uk)

From Monday 13 July 2026, the Bank of England, the Prudential Regulation Authority and the FCA will jointly oversee the critical services these firms provide to UK finance. According to the FCA and the Bank, the regime is designed to be proportionate. It focuses on the systemic services supplied to the financial sector, not the whole of each provider's global business. (fca.org.uk) Just as important is what the regime does not do. Designation is not the same as authorisation, and it does not let banks, insurers or payment firms off the hook for their own operational resilience and outsourcing duties. Financial firms still have to manage third-party risk themselves. The new oversight sits on top of that, rather than replacing it. (fca.org.uk)

The legal route for this was built in the Financial Services and Markets Act 2023. The explanatory notes to that Act say the problem was not a lack of concern but a lack of reach: regulators could place obligations on banks and other finance firms, yet had no matching powers over the outside companies providing some of the most important digital services. The Act changed that by allowing HM Treasury to designate critical third parties through secondary legislation. (legislation.gov.uk) Those same notes explain why ministers have chosen this route. A small number of providers are dominant, contractual pressure can be hard for individual firms to exert, and switching supplier is rarely quick once systems are deeply embedded. That helps explain why the first designations landed on AWS, Google Cloud, Microsoft and Oracle. This is not about novelty. It is about scale, dependency and what happens when too many institutions rely on the same technology base. (legislation.gov.uk)

As the FCA sets out, designated providers will be expected to identify and manage risks to the systemic services they supply and to keep regulators and client firms informed, especially during major incidents. The Bank of England adds that the authorities can gather information, assess resilience and, if needed, take enforcement action connected to those services. In the background sits a fairly clear message: if cloud providers want deep, long-running business with the finance sector, they also have to accept direct scrutiny. (fca.org.uk) There is a limit to the drama here. Monday will not bring an instant reshaping of market shares or a public row with Silicon Valley. The regime is built for supervision rather than spectacle. Even so, it changes the balance of accountability. When an outage or cyber incident hits, regulators will no longer be looking only at the bank on the front end; they will also have a formal line into the supplier behind the service. (fca.org.uk)

HM Treasury says the designations followed evidence gathering and collaborative engagement with the third parties, alongside consultation with the Bank of England, the PRA and the FCA. The government also describes the method as risk-based and proportionate, with room for further designations if other providers meet the statutory test in future. That suggests this first list should be read as the opening phase of a wider regime, not the final word. (gov.uk) For the providers themselves, the immediate effect is likely to be less about headlines and more about process: resilience evidence, regulatory dialogue, incident communication and a more formal supervisory relationship. For customers of banks and insurers, the hoped-for benefit is mundane in the best sense: fewer nasty surprises when the technology underneath financial services comes under pressure. That may not sound dramatic, but it is exactly what resilience policy is meant to deliver. (fca.org.uk)

For investors, SME owners and anyone who has ever found a banking app unavailable at the wrong moment, this is a reminder that financial stability now depends on more than capital ratios and interest rates. It also depends on data centres, software layers and a small group of suppliers that most customers never see. The Treasury's regulations do not solve concentration risk on their own, but they do acknowledge it plainly. (bankofengland.co.uk) The practical date to watch is Monday 13 July 2026, when the designations take effect and joint oversight begins. After that, the real test will be whether the regime improves transparency during incidents and pushes both finance firms and their biggest technology suppliers to show, rather than simply claim, that they can keep essential services running. (fca.org.uk)

← Back to Articles