In a landmark move that takes effect Monday, July 13, 2026, the UK government has designated four of the world's largest cloud service providers — Microsoft, Google, Amazon Web Services, and Oracle — as Critical Third Parties (CTPs) to the financial sector, bringing them under direct regulatory oversight for the first time.

What Changes

The Bank of England, the Prudential Regulation Authority (PRA), and the Financial Conduct Authority (FCA) will jointly supervise the four technology giants under a new proportionate regime focused on the resilience of the services they provide to UK financial institutions.

The designated entities — Microsoft Ireland Operations Ltd, Google Cloud EMEA Ltd, Amazon Web Services EMEA SARL, and Oracle Corporation UK Ltd — will now be required to:

- Undergo regular resilience testing to ensure their systems can withstand cyber attacks and major disruptions - Conduct periodic self-assessments of their risk management practices - Report major incidents to regulators in a timely manner - Maintain open communication with both regulators and the financial firms that depend on their services

Why Now

Britain's financial sector has become increasingly reliant on a small number of cloud providers for everything from core banking systems to payment processing and data storage. While this concentration drives efficiency, it also creates systemic risk.

"As banks, insurers and financial market infrastructures become increasingly reliant on cloud services, disruption at a major supplier could affect multiple firms at the same time, potentially impacting services customers depend on," the government said in a statement.

Sarah Breeden, Deputy Governor for Financial Stability at the Bank of England, added: "As critical third parties become increasingly embedded in the operations of financial institutions, they can introduce new forms of systemic risk. Our proportionate approach to overseeing these providers will ensure that these dependencies are managed in a way that safeguards financial stability."

A Growing Global Trend

The UK's approach mirrors similar efforts in the European Union, which designated 19 technology and services firms under a comparable framework in November. However, the UK's initial focus on the four dominant cloud infrastructure providers is notably narrower and more targeted.

Google Cloud responded positively to the announcement, with a spokesperson saying: "With effective implementation and meaningful industry engagement, this new Critical Third Party framework can enhance the long-term resilience of the UK's financial ecosystem and increase understanding, transparency, and trust between all parties."

What It Means for Consumers

For everyday banking customers, the regime is designed to be invisible — its goal is to prevent disruptions before they happen. By holding cloud providers directly accountable for their resilience, UK regulators aim to reduce the risk of widespread banking outages, payment system failures, or data center incidents that could leave millions of customers unable to access their money.

HM Treasury is responsible for deciding which third-party providers are designated as CTPs, and the list may grow over time as further designations are considered.