The UK government has designated Amazon Web Services (AWS), Microsoft, Google Cloud, and Oracle as Critical Third Parties (CTPs) for the British financial sector. This move, announced by the UK Government, places the four cloud giants under a new regulatory regime overseen by the Bank of England, the Prudential Regulation Authority (PRA), and the Financial Conduct Authority (FCA) to prevent systemic financial instability caused by cloud outages.
Why the UK is Regulating Cloud Hyperscalers
The designation stems from the heavy reliance of UK financial institutions on cloud infrastructure to deliver essential services. According to the UK government, a significant disruption at a single major provider could impact multiple firms simultaneously, creating a “single point of failure” that threatens the stability of the national economy. By classifying these providers as CTPs, regulators can now directly oversee the services these companies provide to the financial sector.
Under this regime, the Bank of England and the FCA will collaborate to monitor critical services and reduce the risk of widespread operational failures. The government stated that this approach is “proportionate” and tailored to the specific role these technology providers play in the financial ecosystem.
New Compliance Requirements for AWS, Microsoft, Google, and Oracle
The four hyperscalers must now implement rigorous mechanisms to identify, manage, and recover from operational disruptions. The new regulatory framework grants authorities specific powers to ensure continuity, including:
- Information Gathering: Regulators can now formally collect data to assess the resilience of cloud services.
- Resilience Assessments: The PRA and FCA will evaluate the ability of these providers to maintain services during crises.
- Rulemaking Power: Authorities can draft and enforce specific rules for CTPs when necessary to address emerging risks.
In response to the designation, Microsoft, Google Cloud, AWS, and Oracle released a joint commitment to cooperate with British financial authorities. The companies stated they will focus on strengthening operational resilience and cybersecurity to support long-term stability and innovation within the UK’s financial landscape.
The Economic Stakes of Financial Cloud Resilience
Rachel Blake, the Secretary for the Treasury and Minister for the City, emphasized that maintaining trust in the UK’s financial system is essential for its success as a global financial hub. Blake stated that these designations protect consumers and businesses by ensuring that the critical services they rely on remain resilient, which in turn drives economic growth.

This move aligns with a broader global trend of “operational resilience” mandates. While the current designation targets the four largest providers, the UK government indicated that this is a progressive regime. Other technology providers may be designated as CTPs in the future if their systemic importance to the financial sector grows.
Comparison of Regulatory Oversight
| Feature | Previous State | Under CTP Designation |
|---|---|---|
| Oversight | Indirect (via the financial firms using the cloud) | Direct (Bank of England, PRA, and FCA) |
| Risk Management | Contractual SLAs between firm and provider | Regulated resilience and recovery mandates |
| Data Access | Limited to client-requested audits | Direct regulatory information gathering |
Frequently Asked Questions
Which companies are now Critical Third Parties in the UK?
Amazon Web Services (AWS), Microsoft, Google Cloud, and Oracle are the four initial companies designated as CTPs.
Who is supervising these cloud providers?
The oversight is a joint effort between the Bank of England, the Prudential Regulation Authority (PRA), and the Financial Conduct Authority (FCA).
Will other companies be added to this list?
Yes. The UK government has stated that the regime is progressive and other providers may be designated over time as necessary.
Worth a look