Critical Third Parties: the cloud comes inside the regulatory perimeter
From 13 July 2026, the Bank of England, PRA and FCA jointly oversee Amazon Web Services, Google Cloud, Microsoft and Oracle as designated Critical Third Parties. For boards, the concentration risk they have long acknowledged in strategy papers now has a formal supervisory counterpart, and it does not shift accountability off the regulated firm.
Today, the Bank of England, the Prudential Regulation Authority and the Financial Conduct Authority begin joint oversight of the first Critical Third Parties (CTPs) designated by HM Treasury: Amazon Web Services EMEA SARL, Google Cloud EMEA Limited, Microsoft Ireland Operations Ltd, and Oracle Corporation UK Limited (FCA). The designation, announced on 10 July 2026, brings four suppliers that sit beneath most UK banks, insurers and market infrastructures into a common supervisory frame for the first time (HM Treasury).
A supervisory answer to a concentration problem
The policy logic is straightforward. As Nikhil Rathi, chief executive at the FCA, put it, "when the same providers serve thousands of firms, a single failure can reverberate across the financial system" (FCA). The regime gives regulators powers to gather information, assess resilience, and make and enforce CTP-specific rules where necessary (HM Treasury). What was previously a matter of contractual negotiation between a bank and a hyperscaler now has a public-law overlay, with three regulators coordinating on system-level risk rather than each firm managing its exposure in isolation.
Accountability does not move
The more consequential point for boards is what has not changed. The regulators are explicit that the CTP regime "complements, but does not replace, existing outsourcing and operational resilience rules for regulated firms who remain responsible for managing their own third-party arrangements including due diligence, risk management and contingency planning" (Bank of England). Firms cannot point upwards. If anything, direct supervisory contact with cloud providers will surface asymmetries between how a hyperscaler describes its resilience posture and how individual firms have documented dependencies in their impact tolerances. Expect supervisors to test whether those two pictures match.
Stakeholder dynamics shift
The commercial balance also moves. Katharine Braddick, deputy governor for prudential regulation and CEO of the PRA, framed the regime as ensuring "that the infrastructure underpinning UK financial services is robust enough to support UK financial stability" (FCA). In practice, that gives CIOs and COOs a supervisory reference point when negotiating with providers on incident communication, exit planning and substitutability. Sarah Breeden, deputy governor for financial stability, warned that CTPs "can introduce new forms of systemic risk" (Bank of England). Boards should read that as an instruction to stop treating cloud concentration as a technology issue owned two levels below the executive committee.
What senior leaders should do now
Three practical moves follow. First, reconcile the firm's mapped critical services against dependencies on the four named providers, and ensure the board pack states the exposure in plain terms rather than in vendor names. Second, revisit exit and stressed-exit assumptions: the presence of a CTP regime does not make substitution easier, and regulators will now have their own view of provider resilience against which to test firm assumptions. Third, treat the Treasury's list as a floor, not a ceiling. Designation criteria are set by government, and further providers, including payments and identity infrastructure, are plausible candidates in later rounds.
The cloud has been inside the perimeter operationally for a decade. From this week, it is inside it in law. The question for boards is whether their own governance has caught up.
Sources
What this reveals
The CTP designation exposes a common asymmetry: firms have described their cloud dependencies in impact tolerance documents and board papers using assumptions never tested against how the providers themselves characterise resilience. Boards may believe supervisory oversight of hyperscalers reduces their exposure, when in fact it creates a new evidential test — whether the firm's documented view of its critical dependencies matches what regulators now hear directly from AWS, Google, Microsoft and Oracle. Any divergence between those two pictures becomes visible for the first time, and accountability for reconciling it sits with the regulated firm, not the provider.
Questions accountable leaders should ask
- 01Have we tested whether our documented impact tolerances and dependency maps for cloud services match how our providers actually describe their own resilience posture and failure modes?
- 02If a supervisor compared our third-party risk assessment of a hyperscaler against what that hyperscaler tells the Bank of England, would the two accounts reconcile?
- 03Where in our operational resilience documentation are we relying on assumptions about provider behaviour that we have never independently validated?
- 04Who inside the firm is accountable for keeping our view of critical third-party dependencies current as the CTP regime generates new supervisory information?
- 05Has the board seen a candid assessment of concentration risk that goes beyond the strategy paper acknowledgement, or is our real exposure still described in reassuring terms?
What accountable leaders should do now
- 1Commission a reconciliation exercise between the firm's documented cloud dependencies, impact tolerances and contingency plans, and the resilience representations made publicly and contractually by each designated CTP the firm uses.
- 2Ask the CIO, COO and CRO jointly to identify the three assumptions about hyperscaler behaviour most likely to fail under supervisory scrutiny, and set a deadline for testing each.
- 3Refresh the board's view of concentration risk with specifics: which critical business services depend on which CTPs, what the substitutability position honestly is, and where the firm has been relying on provider assurances it has not verified.
- 4Establish a standing channel for interpreting signals from the new supervisory regime — expectations, information requests, and any CTP-specific rules — so the firm updates its own posture before supervisors ask why it has not.
- 5Review third-party contracts and exit plans against the accountability position the regulators have restated, and close any gap where the firm has been treating oversight of the provider as a substitute for its own resilience work.
Explore the practical guide
This guide shows how to test whether your board's view of stakeholder priorities matches what regulators and adjacent decision-makers will actually demand during review. After reading, you will know how to structure that test, where assumptions typically break, and how to use the findings without undermining the board.
Read the guideWhere internal confidence may exceed external evidence
Polar Insight helps leadership teams test critical assumptions against stakeholder, market, regulatory, and operational reality before risk compounds.
Explore Stakeholder ProximityRelated insights
The FPC's July warning: leverage, AI concentration, and a thinner margin for error
The Bank of England's Financial Policy Committee has flagged a sharper build-up of vulnerabilities across equity leverage, AI-driven market concentration, and cyber resilience, even as the UK system holds up. For senior leaders, the message is that the correlation of risks, not any single one, is what now demands board attention.
T+1 readiness splits the market: FCA signals action against laggards
With 14 months to the UK's move to T+1 securities settlement, the FCA has publicly warned that some firms are so far behind they may miss the October 2027 deadline. The regulator's willingness to name a readiness gap, and to hint at enforcement, changes the calculus for boards that have treated post-trade automation as an operational afterthought.
Scale-up Unit expands: the FCA picks its growth champions
The FCA has admitted five solo-regulated firms to its Scale-up Unit and published findings from a parallel 15-firm Early and High Growth Oversight pilot. For senior leaders, the signal is that regulatory proximity is now a competitive asset, and governance maturity is the price of entry.
Stakeholder Signals
Consequential developments in financial services and other regulated markets, with one implication for accountable leaders.
