The Bank of England (the Bank), the Prudential Regulation Authority (PRA) and the Financial Conduct Authority (FCA) will start overseeing the first Critical Third Parties (CTPs) on following designation by HM Treasury (HMT).
Critical Third Parties (CTPs) are technology and other service providers whose services underpin the UK financial system. The HMT has announced its first designations of four global cloud services and technology providers: Amazon Web Services EMEA SARL, Google Cloud EMEA Limited, Microsoft Ireland Operations Ltd, and Oracle Corporation UK Limited. As many firms rely on these services, disruption or failure could affect multiple firms or markets at the same time, potentially impacting UK financial stability and services used by millions of consumers and businesses.
For the first time, the three regulators will jointly oversee these CTPs under a new, proportionate regime, focused on the resilience of the critical services they provide to the UK financial sector. The regulators will work together with the CTPs to address system‑level risks and reduce the risk of disruption to the services they provide spreading across the UK financial system. This will strengthen system-wide resilience and improve coordination and information sharing across the UK financial sector. CTPs must identify and manage risks to their critical services effectively and maintain open, timely communication with regulators and the firms that rely on them, particularly during major incidents.
Together, these changes support a more resilient environment for firms to operate in, which will, in turn, support financial stability and confidence in UK financial markets.
This regime complements, but does not replace, existing outsourcing and operational resilience rules for regulated firms who remain responsible for managing their own third-party arrangements, including due diligence, risk management and contingency planning.
Sarah Breeden, Deputy Governor for Financial Stability at the Bank of England, said: “As critical third parties become increasingly embedded in the operations of financial institutions, they can introduce new forms of systemic risk. Our proportionate approach to overseeing these providers will ensure that these dependencies are managed in a way that safeguards financial stability.”
Katharine Braddick, Deputy Governor for Prudential Regulation and CEO of the PRA, said “By bringing critical third parties into the scope of oversight, we are ensuring that the infrastructure underpinning UK financial services is robust enough to support UK financial stability and confidence. This directly supports the PRA’s objective to promote the safety and soundness of regulated firms.”
Nikhil Rathi, Chief Executive at the FCA, said “Critical third parties provide essential services which support innovation and growth. At the same time, when the same providers serve thousands of firms, a single failure can reverberate across the financial system. Operationalising this regime strengthens our ability to tackle those risks and improve overall resilience, ensuring the UK remains a safe and attractive place to do business.”
Freddy Dezeure, Deputy Chief Information Security Officer for Europe at Microsoft, said “For more than 40 years, Microsoft has worked closely with UK government agencies to help support citizens, improve services, and secure and enhance the resilience of the digital ecosystem.
“The designation of Microsoft Ireland Operations Limited as a critical third party marks a new chapter in this relationship, and Microsoft remains fully committed to complying with the relevant oversight requirements and the UK’s cybersecurity and resilience laws.”
A spokesperson for Google Cloud said “Google Cloud EMEA Limited is committed to supporting the operational resilience of the UK financial sector by delivering secure, scalable, and resilient services. We are confident that, with effective implementation and meaningful industry engagement, this new Critical Third Party framework can enhance the long-term resilience of the UK’s financial ecosystem and increase understanding, transparency, and trust between all parties.”
Michael Jefferson, Head of Financial Services Public Policy EMEA at AWS, said “AWS supports the objectives of the UK Authorities to ensure a robust UK financial system. AWS will comply with all applicable regulations, and we remain committed to helping customers to meet their business and operational resilience objectives.”
Kevin Kimber, Senior Vice President, General Manager UK&I at Oracle, said “Oracle supports the UK Government’s important objective of enhancing the operational resilience of the UK financial sector. We are committed to working closely with the regulators and our financial services customers toward that objective, while also supporting the Government in accelerating innovation and promoting long-term economic growth.”
HMT is responsible for deciding which third-party providers are designated as CTPs, and for any future designations or de-designations. The regulators will periodically review whether CTPs continue to meet the designation criteria, make recommendations to HMT, and evaluate the effectiveness of the oversight approach. The Bank, PRA and FCA will continue to work closely with HMT, the financial services industry and designated CTPs as the regime is implemented, while supporting innovation and UK growth and competitiveness.