FirstCover
Go back

When the Cloud Becomes Part of the Financial System: Why the UK Is Regulating Big Tech

The UK has designated Amazon, Google, Microsoft, and Oracle as Critical Third Parties (CTPs), bringing major cloud providers under direct financial regulation. This responds to concentration risk: when many banks rely on the same cloud services, a shared failure can cascade across the sector. The new rules give regulators direct oversight of providers’ governance, risk management, and incident response. CTPs must run annual stress tests and report major outages promptly. Banks, however, remain responsible for their own resilience. The regime aims to uncover systemic dependencies that individual firm-level supervision cannot see, before the next large-scale disruption hits.
Regulatory Compliance Aug 12, 2026
hero-image

One update, 8.5 million machines

In July 2024, CrowdStrike sent out a faulty security-software update. About 8.5 million Windows devices went down. Organizations that had no connection to one another suddenly faced the same blue screen, at the same time, for the same reason.

The failure did not start in Microsoft's Azure cloud. It came from a security product installed across a vast number of systems. That distinction mattered technically, but it offered little comfort to anyone trying to restore a machine. A component that most users never saw had become a common point of failure across companies and industries.

Three years earlier, AWS had shown how the same problem could develop inside a cloud platform. In December 2021, congestion in an internal network in its US-EAST-1 region spread into monitoring, internal DNS, authorization services, and parts of the EC2 control plane. Services that looked separate to customers still relied on shared systems underneath.

Neither incident became a UK financial-stability crisis. Both exposed the mechanism regulators fear. A bank can operate its own apps, controls, and recovery plans while sharing an identity service, network layer, security tool, or subcontractor with many of its peers. If that common layer fails, institutions that appear separate can go down together.

How individual resilience creates shared dependency

Cloud computing can make an individual bank more resilient. Large providers offer specialist security teams, geographic redundancy, rapid patching, and infrastructure that may be stronger than systems maintained entirely in-house.

The picture changes when hundreds of firms make the same sensible choice. Risk that once sat inside separate data centers begins to collect around a smaller number of providers and technical components. A problem in a shared control plane or identity system can then travel across firms instead of staying inside one.

A 2024 survey by the Bank of England and the Financial Conduct Authority gives one indication of that concentration. Among the cloud-provider names reported by respondents, the three most frequently named accounted for about 73%. The figure is not a market-share estimate and does not mean that three providers host 73% of critical workloads. It shows how often the same names recur in firms' reported dependencies.

This is also the limit of traditional outsourcing supervision. A regulator can ask each bank how it manages a supplier, yet still miss the full network of customers, subcontractors, internal services, and common failure points inside the supplier itself. Seeing the system requires access at the provider level.

The UK brings cloud providers inside the regulatory perimeter

On July 10, 2026, HM Treasury designated Amazon Web Services EMEA SARL, Google Cloud EMEA Limited, Microsoft Ireland Operations Limited, and Oracle Corporation UK Limited as Critical Third Parties, or CTPs. The designations took effect on July 13, when the Bank of England, the Prudential Regulation Authority, and the Financial Conduct Authority began overseeing them directly.

The legal framework was already in place. Parliament created the statutory powers in the Financial Services and Markets Act 2023. Regulators published final rules in November 2024, and those rules took effect on January 1, 2025. The July 2026 action applied them to named companies for the first time.

The boundary is narrow. The designation covers systemic services supplied to the UK financial sector, not every product or global operation of Amazon, Alphabet, Microsoft, or Oracle. It does not turn a cloud company into a bank, grant it regulatory approval, or guarantee that its services are secure. HM Treasury can add other providers later if their disruption could threaten financial stability or confidence in the system.

The change is direct visibility. Regulators can now examine governance, risk management, supply-chain dependencies, cyber resilience, change controls, service mapping, incident management, and plans for an orderly termination of services at the provider itself. They no longer have to reconstruct the provider's risk profile from the partial view available to each customer.

What the rules change in practice

The first deadlines arrive quickly. A newly designated CTP must submit an interim self-assessment within three months, followed by annual assessments. For the first four providers, that puts the initial filing around October 13, 2026.

Scenario testing must take place at least once a year. The provider has to show whether its systemic services can continue through a severe but plausible disruption. A separate incident-management exercise must be held within 12 months of designation, using a representative group of financial-sector customers. Later exercises generally take place at least every two years.

Real incidents trigger initial, intermediate, and final reports. Regulators generally expect the final report within 30 working days after an incident is resolved, although the rule does not impose a fixed statutory deadline. A provider that needs longer must say when the report will arrive.

For Microsoft, Amazon, Google, and Oracle, the immediate work will be organizational: dedicated regulatory governance, better maps of services and dependencies, more formal testing, stronger incident reporting, and evidence that important services can recover within acceptable limits. Contracts with financial firms are also likely to become more specific about audit rights, regulatory access, subcontractors, data portability, termination support, and recovery planning.

Banks and insurers do not get to hand over responsibility. They still have to select providers, understand their dependencies, test business continuity, and maintain workable recovery and exit plans. A second cloud contract does not automatically solve the problem if both environments share identity, networking, software, or operational teams.

The first self-assessments and exercises will show whether the new regime can uncover shared weaknesses that individual firms could not see. The practical test is whether direct access gives regulators a usable map of those dependencies before the next major outage.

Disclaimer: This article is for informational and research purposes only and does not constitute any investment advice.

More posts

blog image 1 Capital Markets Nasdaq's Proposed $5 Million MVLS Rule: From Getting Listed to Staying Qualified
Nasdaq has proposed a new continued listing requirement that would require every company on the Nasdaq Global Market, Global Select Market, and Capital Market to maintain a Market Value of Listed Securities (MVLS) of at least $5 million. On its face this reads like a routine threshold adjustment. It is not. The proposal would convert a sustained low valuation from a curable deficiency into a near immediate suspension event, and it would strip away protections that listed companies have long relied on during an appeal. For boards, management teams, and their advisors, the practical takeaway is that staying qualified is becoming nearly as demanding as getting listed in the first place.
blog image 1 Capital Markets U.S. IPO Trends, SPAC Activity, and Listing Regulatory Rules
This report tracks all U.S. public-market IPO activity from January 1 through February 27, 2026, and maps the parallel tightening of listing and regulatory frameworks relevant to small-cap issuer survivability. Because IPO counts vary materially across data providers—driven by differences in SPAC inclusion, minimum deal size, and treatment of micro-cap foreign issuers—the report anchors to two complementary datasets and keeps their definitions explicit throughout.
blog image 1 Capital Markets What Insurance Does a Public Company Actually Need?
Going public reshapes a company's risk profile in ways a standard commercial insurance program was never designed to handle. Shareholders can sue when earnings disappoint. Regulators have new visibility into governance decisions. A data breach that a private company might weather quietly becomes a mandatory SEC disclosure — and often a securities class action. Employees who were always a source of litigation risk are now part of a story that analysts, journalists, and plaintiffs' lawyers follow closely. This guide walks through the core insurance lines every public company program should include, explains how each one works in practice, and grounds the analysis in real claims data and recent litigation. The aim isn't to overwhelm with policy language — it's to give boards, CFOs, and risk managers a clear picture of what they're buying and why it matters before they need it.