Brief № 064 · Market
Critical cloud does not mean approved cloud
The UK's first Critical Third Parties are four cloud providers. Financial firms still own supplier due diligence, resilience and exit planning.
On this page
Four cloud providers have acquired a new regulatory label in UK finance. The useful first response is to remove that label from the supplier scorecard.
On 13 July 2026, Amazon Web Services EMEA SARL, Google Cloud EMEA Limited, Microsoft Ireland Operations Limited and Oracle Corporation UK Limited became the first Critical Third Parties under the UK’s financial-services regime. The Bank of England, Prudential Regulation Authority and Financial Conduct Authority can now oversee the resilience of the critical services those entities provide to the sector.
That is a material change at system level. It is not a purchasing recommendation. The regulators state the distinction unusually clearly: designation is not authorisation, does not make a provider inherently more resilient and does not make it better suited to a particular firm’s needs. Regulated firms still own their outsourcing and third-party arrangements.
For a smaller bank, insurer, lender, payments firm or regulated fintech, the designation creates a better information channel around concentrated infrastructure. It does not complete the firm’s due diligence. The practical job is to connect one named cloud service to one business process, one interruption tolerance and one credible recovery or exit route.
The legal entity matters
The four designations name legal entities, not consumer brands in the abstract. They also bring the systemic services supplied to UK financial firms under oversight, not every product sold by the wider corporate group in every market.
That boundary matters when a procurement file says only “Microsoft”, “AWS” or “Google”. A contract may be with a reseller, a different group entity or a managed-service provider that assembles several underlying services. An AI application may add a model host, vector database, identity service, observability vendor and data processor on top of the designated cloud.
The useful first line in the file is therefore factual:
contracting entity / exact service / region / reseller / material subcontractors
If that line is incomplete, the CTP label cannot repair it. Oversight of one entity’s critical services does not automatically extend to every component in the deployment chain.
The UK framework is designed around system-wide risk. HM Treasury designates a provider where disruption could threaten financial stability or confidence in the financial system. The three regulators then oversee the provider’s resilience for the relevant services. That helps with risks no single small firm can investigate alone. It does not answer whether a specific workload has the right retention settings, recovery design or contractual support.
Oversight adds evidence, not approval
The CTP rules cover governance, risk management, dependency and supply-chain risk, technology and cyber resilience, change management, mapping, incident management and termination of services. They also create channels for self-assessment, scenario testing, incident notification and information sharing.
Those mechanisms should improve the evidence available to firms over time. A provider may have to test its ability to continue a material service under a severe but plausible scenario, exercise an incident playbook with representative financial firms and share information about resilience. Regulators can gather information, commission skilled-person work and enforce the rules.
But the regime was deliberately written not to replace firm-level controls. The 2024 joint policy statement says firms remain accountable for managing risks in arrangements with a designated provider. HM Treasury repeated the point when announcing the first four names.
The distinction can be kept simple:
| Evidence from CTP oversight | Evidence the buying firm still needs |
|---|---|
| System-level resilience of designated critical services | Fitness of the exact service and configuration for the use case |
| Provider incident communication under the regime | The firm’s own escalation, customer communication and workaround |
| Provider mapping and scenario testing | Mapping from the service to the firm’s important business process |
| Provider termination and recovery capabilities | Data portability, substitute service and an executable exit decision |
| Regulatory scrutiny of the designated entity | Due diligence on resellers, models, integrators and other subcontractors |
Source: HM Treasury’s July 2026 designations and the Bank/PRA/FCA CTP policy statement. Last verified 2026-07-23.
The left column can reduce duplicated investigation. It cannot become a tick that erases the right column.
AI makes the dependency wider
The first CTPs are cloud and technology providers, not AI-model companies as a category. Yet the designation arrives while financial firms are moving more AI workloads onto the same concentrated infrastructure.
The Bank and FCA’s 2024 survey found that 75% of responding financial firms were already using AI. One third of reported AI use cases were third-party implementations. The three most-named providers accounted for 73% of cloud providers and 44% of model providers in the survey. Nearly half of respondents said they had only a partial understanding of the AI technologies they used.
Those figures describe a dependency chain, not merely a vendor market. A hosted model can rely on one cloud for inference, another service for identity, a third-party data source and an internal process that assumes all of them are available. A provider can be resilient while the assembled workflow is fragile.
The survey also found that 55% of AI use cases had some degree of automated decision-making, although only 2% were fully autonomous. Materiality therefore depends on the task, data and decision path as much as on the model name. A summarisation assistant and an automated fraud hold may use the same infrastructure but require different evidence, fallbacks and human authority.
This is why the government’s 14 July Financial Services AI Adoption Plan points in two directions at once. It recommends accelerating CTP oversight, including assessment of key AI and cloud providers, while also proposing a voluntary third-party AI assurance scheme. Shared assurance could reduce repeated questionnaires. The plan still says each firm would remain responsible for the risks of implementing the model.
Keep a one-page dependency file
A smaller regulated firm does not need to reproduce the regulators’ system-level work. It needs a short file that makes its own dependency and response visible.
For every material cloud-backed AI service, record:
- The service. Name the contracting entity, product, region, reseller and model version or family where relevant.
- The business process. State what stops, degrades or becomes unsafe when the service is unavailable or wrong.
- The data path. Record what enters the service, where it is retained, which logs exist and how access is revoked.
- The decision boundary. Identify what the system may do, where a person intervenes and who can disable it.
- The interruption limit. Set an honest time after which the business impact becomes intolerable.
- The fallback. Name the manual route, degraded service or substitute provider and the person allowed to activate it.
- The evidence feed. List the provider notices, CTP information, tests and contract reviews that keep the file current.
- The exit. Record export format, data deletion, replacement lead time and the last date the route was tested.
This is not a new framework. It is the minimum translation between a provider’s resilience and the firm’s service obligation. Existing outsourcing, operational-resilience, security and data-protection records should supply most of it.
Test the gap the designation cannot close
Choose one material service on a designated provider and simulate a two-hour loss. Do not test whether the provider has a status page. Test the firm’s side of the boundary.
Can the team identify the affected customers and decisions? Can it stop automated actions without losing an audit trail? Does the fallback work with current data? Who is authorised to invoke the contingency? Which reseller or integrator joins the incident call? What evidence will show that service and data integrity have been restored?
Then simulate a quieter failure: the cloud is available, but the model endpoint, identity link or data connector is not. CTP oversight is aimed at critical services and system-wide resilience. Many costly operational failures will still occur inside a firm’s particular assembly of non-critical components.
The first designations are useful because concentrated providers now face direct, coordinated scrutiny that individual firms could not create. Treat the resulting evidence as an input. Keep the supplier decision, configuration risk, fallback and exit route in the firm’s own hands.
Frequently asked questions
Does Critical Third Party designation mean a cloud provider is approved for financial services?
No. The Bank of England, PRA and FCA explicitly say designation is not authorisation and does not mean a provider is inherently more resilient or better suited to a particular firm.
Which providers were first designated as UK Critical Third Parties?
Amazon Web Services EMEA SARL, Google Cloud EMEA Limited, Microsoft Ireland Operations Limited and Oracle Corporation UK Limited were designated from 13 July 2026.
Does the new regime remove a regulated firm's supplier duties?
No. It complements existing outsourcing and operational-resilience requirements. Firms remain accountable for due diligence, risk management, contingency planning and their own third-party arrangements.
What should a smaller financial firm record for a critical cloud service?
Record the service and legal entity, supported business process, data and model dependencies, acceptable interruption, incident contacts, recovery evidence, substitutes and a tested exit or portability route.
Sources
- Official UK financial regulators to begin overseeing Critical Third Parties announced by HM Treasury Bank of England accessed
- Official UK financial system strengthened with new safeguards for major technology providers HM Treasury accessed
- Primary The Critical Third Parties (Designation) Regulations 2026 — regulation 2 The National Archives accessed
- Official AI Adoption Plan: Financial Services HM Treasury accessed
- Official PS16/24 — Operational resilience: Critical third parties to the UK financial sector Bank of England, PRA and FCA accessed
- Official Artificial intelligence in UK financial services — 2024 Bank of England and FCA accessed
Image credit: Photo: warehouse colleagues reviewing a checklist — Centre for Ageing Better, Pexels License (Pexels)
Daniel Brennan covers the UK and Ireland tech business beat for Flint Brief.
Spotted an error or want a right of reply? hello@flintbrief.com (subject [Right of reply]).