- Access the UK press release on AWS, Microsoft, Google finance sector watch here.
The UK government placed four of the world’s largest cloud computing companies under direct regulatory oversight by designating them as “critical third parties” to the financial sector. This first-of-its-kind measure aims to prevent a single technology outage from disrupting banks, insurers, and payment systems nationwide.
The designated firms are Microsoft Ireland Operations Ltd, Google Cloud EMEA Ltd, Amazon Web Services EMEA SARL and Oracle Corporation UK Ltd. From today, the Bank of England, the Prudential Regulation Authority (PRA) and the Financial Conduct Authority (FCA) will jointly supervise the resilience of the cloud services these companies provide to UK financial firms.
Why does it matter?
British banks, insurers, and financial market infrastructure operators rely heavily on a few cloud providers for core operations. Regulators warn that this concentration creates a single point of failure. An outage or cyberattack at a major supplier could simultaneously disrupt many financial firms and their customers, rather than being limited to a single company, as with a traditional IT failure.
What changes under the new regime?
Designation does not indicate that these companies are newly authorised or endorsed by regulators, nor does it transfer legal responsibility for resilience from the banks and insurers that use their services. Financial firms remain responsible for managing their own third-party risk.
The four companies must now comply with requirements set by the Bank of England, the PRA, and the FCA regarding the identification, management, and recovery of operational incidents affecting critical UK financial services. Regulators are authorized to collect information from these providers, conduct incident-management exercises, review required self-assessments, and take disciplinary action if standards are not met.
The regime is based on the Financial Services and Markets Act 2023, which authorizes the Treasury to designate critical third parties on regulators’ recommendations. Regulators published the final framework rules in November 2024, effective from January 1, 2025. However, no company was designated until Monday. The four designations announced are the first to take effect under regulations that take effect on July 13, 2026.
The Treasury stated that additional providers may be included in the regime as regulators identify other suppliers whose services are systemically important to the financial sector. Companies already under direct oversight by the Bank, PRA, or FCA in another capacity will not be separately designated as critical third parties.
The wider context
Britain’s approach is intended to complement similar regulations, such as the European Union’s Digital Operational Resilience Act (DORA) and the US Bank Service Company Act. However, UK regulators have emphasized that alignment with other regimes will not compromise their primary objective of safeguarding domestic financial stability.
The framework was developed following a formal consultation from December 2023 to March 2024, during which regulators received 62 industry responses. Most respondents supported the plan, although at least one questioned whether additional oversight was necessary.
India regulates cloud risk through financial institutions, not providers
India currently regulates cloud providers indirectly through financial institutions, rather than supervising cloud companies directly. The RBI’s regulatory philosophy holds that responsibility for operational resilience, cybersecurity, and customer protection always remains with the regulated entity (RE), such as a bank, NBFC, or payment system operator, even when IT infrastructure is outsourced to third-party vendors.
The RBI expanded its framework in April 2023 with the Master Direction on Outsourcing of IT Services, explicitly including cloud computing services under regulated IT outsourcing. The Directions require regulated entities to conduct due diligence when selecting cloud providers, assess concentration risk, ensure business continuity and disaster recovery, maintain audit rights over service providers, monitor subcontracting, and establish exit strategies if a provider fails or the relationship ends. The Directions also clarify that outsourcing does not reduce a regulated entity’s responsibility to customers or the RBI.
If a bank uses Amazon Web Services, Microsoft Azure, or Google Cloud for critical workloads, the RBI supervises the bank’s management of the outsourcing relationship, not the cloud provider directly. The bank is responsible for ensuring the provider meets security, resilience, data protection, and audit standards.
India has acknowledged the risks of the financial sector’s increasing reliance on a few global cloud providers. In late 2024, the RBI was collaborating with Indian Financial Technology and Allied Services (IFTAS) to develop a dedicated cloud platform for banks and financial institutions. This initiative aims to offer an alternative to foreign hyperscale cloud providers, reduce costs for smaller institutions, enhance operational resilience, and mitigate concentration risk in critical financial infrastructure. Unlike the UK, this approach focuses on market and infrastructure intervention rather than introducing a new supervisory regime for cloud providers.
Also read: