The Bank of England, Prudential Regulation Authority, and Financial Conduct Authority have been granted statutory oversight of critical third-party technology providers to UK financial services, with the framework taking effect from 13 July 2026. HM Treasury has formally designated Amazon, Google, Microsoft, and Oracle as 'critical third parties' under the new regime. The development was reported by Guardian Business, FT Companies, and the Bank of England.

The regulatory framework grants supervisors direct powers to oversee the cyber resilience and operational continuity of these firms as they relate to UK financial infrastructure. The Bank of England published formal guidance confirming that supervision of designated Critical Third Parties commences on 13 July 2026, with the stated objective of preventing system failures capable of disrupting UK financial services.

Amazon Web Services, Google Cloud, Microsoft Azure, and Oracle Cloud are the designated entities. Each operates as a cloud infrastructure provider to UK-regulated financial institutions, creating the systemic dependency that the new framework is designed to address. The oversight applies specifically to services these firms provide to the UK financial sector, not to their wider commercial operations.

HM Treasury confirmed the designations and stated that the measure is intended to improve resilience across financial system infrastructure. The Bank of England noted that the regime covers non-regulated entities whose services are critical to UK financial stability, representing an extension of regulatory reach beyond traditionally supervised firms.

Sources: Guardian Business, FT Companies, BOE