UK Regulators to Oversee Amazon, Google, Microsoft, Oracle as Critical Third Parties
HM Treasury has identified Amazon Web Services EMEA, Google Cloud EMEA, Microsoft Ireland Operations, and Oracle UK as the inaugural Critical Third Parties (CTPs) in a new regulatory framework. This initiative will begin enforcement on January 1, 2025, with oversight from the Bank of England, Prudential Regulation Authority, and Financial Conduct Authority, aimed at safeguarding the UK’s financial sector. Effective July 13, 2026, the CTPs will need to address risks, maintain communication with regulators, and enhance their resilience. Additionally, the UK and EU have established a Memorandum of Understanding for harmonized regulatory oversight.
Key facts
- HM Treasury designated Amazon Web Services EMEA SARL, Google Cloud EMEA Limited, Microsoft Ireland Operations Ltd, and Oracle Corporation UK Limited as the first Critical Third Parties.
- Oversight by the Bank of England, PRA, and FCA begins on 13 July 2026.
- The regime aims to strengthen resilience of services critical to the UK financial system.
- CTPs must identify and manage risks to their critical services and maintain open communication with regulators.
- The regime complements existing outsourcing and operational resilience rules for regulated firms.
- Sarah Breeden, Deputy Governor for Financial Stability, highlighted systemic risks from CTPs.
- Nikhil Rathi, FCA Chief Executive, noted that a single failure could affect thousands of firms.
- The UK and EU have signed a Memorandum of Understanding to coordinate oversight under similar regimes.
Entities
Institutions
- Bank of England
- Prudential Regulation Authority
- Financial Conduct Authority
- HM Treasury
- Amazon Web Services EMEA SARL
- Google Cloud EMEA Limited
- Microsoft Ireland Operations Ltd
- Oracle Corporation UK Limited
Locations
- United Kingdom