Products Intelligence Pricing Methodology Contact
Cresthaven Analytics Intelligence Brief

UK FCA Regulatory Brief

July 10, 2026 · Financial Conduct Authority · EU

Bank of England, PRA, and FCA begin joint oversight of four designated cloud providers on 13 July 2026

The Bank of England, PRA, and FCA will begin oversight of the UK's first Critical Third Parties on 13 July 2026, following Treasury designation of Amazon Web Services EMEA SARL, Google Cloud EMEA Limited, Microsoft Ireland Operations Ltd, and Oracle Corporation UK Limited. The regime draws on powers granted by the Financial Services and Markets Act 2023 and applies immediately upon designation. Its focus is the operational resilience of services these providers supply to UK regulated firms and financial market infrastructures.

Active CTP oversight begins 13 July 2026 across all four designated providers simultaneously. Regulated firms that rely on AWS, Google Cloud, Microsoft, or Oracle for services to UK financial operations now sit within a tripartite supervisory perimeter focused on system-level resilience, without any reduction in their own outsourcing and operational resilience obligations. The regime's explicit design as an evolving framework, with Treasury retaining designation authority on regulator recommendation, places additional cloud and technology providers within scope of future designation. Firms with cross-border operations face parallel obligations under EU DORA for the same providers, coordinated through a formalized inter-authority information-sharing arrangement.

  • Immediate Obligations on Designated Providers: The four named cloud and technology providers must identify and manage risks to their critical services, maintain open communication with regulators, and engage promptly during major incidents. These obligations apply from 13 July 2026 under rules that came into force on 1 January 2025 and attach automatically upon Treasury designation.
  • Regulated Firms Retain Full Outsourcing Responsibility: The CTP regime does not replace existing outsourcing and operational resilience obligations on regulated firms. Banks, insurers, and investment firms remain accountable for due diligence, risk management, and contingency planning for their third-party arrangements, including those with the four designated CTPs.
  • Tripartite Supervisory Structure Introduces a New Coordination Layer: The Bank, PRA, and FCA will jointly supervise CTPs, a structure with no direct precedent in UK financial regulation. Regulated firms that rely on designated CTPs now interact with a supervisory layer sitting above their own regulators, with system-level risk as the explicit focus rather than firm-level compliance.
  • Treasury Holds Designation and De-designation Authority: The three regulators will periodically review whether CTPs continue to meet designation criteria and make recommendations to Treasury, which retains sole authority over designation decisions. The scope of the regime is explicitly described as continuing to evolve, signaling further designations are under active consideration.
  • Cross-Border Coordination with EU DORA Is Formalized: The regulators have signed a Memorandum of Understanding to coordinate information sharing on CTP oversight with counterparts overseeing the same providers under the EU's Digital Operational Resilience Act. Firms operating across UK and EU jurisdictions face parallel but distinct resilience obligations from the same cloud providers under two separate regulatory regimes.

- The 13 July 2026 commencement marks the first operational activation of CTP oversight powers under the Financial Services and Markets Act 2023. Final rules were published in November 2024 and took effect 1 January 2025; this date therefore represents the transition from rule-in-force to active supervision.

- The four designations cover the dominant hyperscale cloud providers serving UK financial services. From day one, the regime's initial perimeter captures a substantial share of cloud-dependent financial infrastructure.

- A formalized Memorandum of Understanding with EU counterparts on DORA coordination establishes a cross-border supervisory channel. No prior equivalent exists in UK operational resilience regulation.

HIGH — A binding supervisory regime activates on 13 July 2026 with sector-wide application: every UK regulated firm relying on the four designated cloud providers operates within a new tripartite oversight perimeter, and the regime's stated evolution signals further designations affecting additional firms.

effective — 2026-07-13

Monitor HM Treasury and the Bank of England, PRA, and FCA jointly for further CTP designation announcements and any supervisory findings or guidance issued under this regime as oversight becomes operational.

Financial Services and Markets Act 2000 as amended by Financial Services and Markets Act 2023 (CTP oversight powers); FCA, PRA, and Bank of England final CTP rules and policy (effective 1 January 2025); PRA Supervisory Statement on CTP expectations; FCA CTP oversight approach statement; HM Treasury CTP designation regulations (effective 13 July 2026); Regulation (EU) 2022/2554 (Digital Operational Resilience Act, DORA); Bank of England, PRA, and FCA Memorandum of Understanding on CTP cross-border coordination

www.fca.org.uk — Source ↗

This is a sample intelligence brief from Cresthaven Analytics. Live subscribers receive briefs like this on a daily or weekly cadence depending on tier.