The UK government has designated four global technology companies—Amazon, Google, Microsoft, and Oracle—as critical third-party providers. This decision brings their cloud services under direct oversight by financial regulators, effective from July 13, 2026.
The initiative addresses growing concerns over the financial industry’s heavy dependence on a handful of cloud infrastructure suppliers, where a single major disruption could cascade across multiple institutions and affect everyday services for millions of customers.
As banks, insurers, and financial market infrastructures increasingly turn to cloud computing for essential operations, the risks associated with concentrated reliance have come into sharper focus.
A widespread outage, cyber incident, or operational failure at one of these providers could simultaneously impact numerous firms, potentially undermining public confidence and economic activity.
By formalizing oversight, authorities aim to mitigate these systemic vulnerabilities and promote greater resilience across the sector.
The designated entities include specific UK or regional arms: Microsoft Ireland Operations Limited, Google Cloud EMEA Limited, Amazon Web Services EMEA SARL, and Oracle Corporation UK Limited. Joint supervision will fall to the Bank of England, the Prudential Regulation Authority, and the Financial Conduct Authority.
Regulators will have powers to collect information, evaluate resilience measures, conduct testing, require self-assessments, and enforce tailored rules where necessary.
Oversight will focus exclusively on services provided to the financial sector, leaving broader operations untouched.
Economic Secretary to the Treasury and City Minister Rachel Blake MP emphasized the importance of this step: maintaining trust in the UK’s world-leading financial center requires robust protections for the critical infrastructure that underpins it.
The designations support consumer and business protection while fostering conditions for long-term growth, innovation, and investment.
This targeted, proportionate approach forms part of a rolling regime, with potential for additional providers to be added if they meet statutory criteria for posing risks to financial stability.
The companies have expressed commitment to compliance and collaboration. Microsoft highlighted its long-standing partnership with UK authorities on cybersecurity and resilience.
Google Cloud stressed the potential for enhanced transparency and trust through effective implementation.
Amazon Web Services affirmed support for a proper financial system, while Oracle pledged close work with regulators to advance innovation and economic objectives.
This framework, established under the Financial Services and Markets Act 2023, marks a proactive response to evolving digital dependencies.
Financial firms retain primary responsibility for managing third-party risks, but the new regime introduces structured accountability for the most critical suppliers.
By enhancing oversight and cooperation, the UK seeks to safeguard its financial ecosystem against emerging threats in an increasingly cloud-dependent landscape.
The development underscores broader international trends, as regulators worldwide scrutinize technology providers’ roles in critical infrastructure. For the UK, it represents a balanced step toward securing digital foundations without stifling technological advancement.