When the Bank of England decides to directly supervise Microsoft, Amazon, Google, and Oracle, it’s not a symbolic gesture. It’s the formal acknowledgment that a cloud outage could now trigger a systemic financial crisis — and that traditional regulators aren’t equipped to prevent it on their own.
Four names, a new rulebook
On July 13, 2026, HM Treasury formally designated four entities as Critical Third Parties (CTPs) to the UK financial sector: Amazon Web Services EMEA, Google Cloud EMEA, Microsoft Ireland Operations, and Oracle Corporation UK. These are the European and UK subsidiaries — not the parent companies directly, but the operational branches that host the systems of British banks and insurers.
The regime operates under the Financial Services and Markets Act. Three regulators will jointly oversee these providers: the Bank of England, the Prudential Regulation Authority (PRA), and the Financial Conduct Authority (FCA). This is the first time technology providers — not banks, not insurers, not funds — have fallen under the direct jurisdiction of UK financial regulators.
The problem: concentration risk that became systemic
The logic is straightforward, but the implications run deep. British banks have overwhelmingly moved to cloud infrastructure. Not one or ten — virtually all of them. And they’ve concentrated on a handful of providers. If AWS goes down for four hours, it’s not a few internal services that slow down: it’s potentially millions of transactions freezing, payment systems stalling, and risk data becoming inaccessible.
This scenario is no longer hypothetical. Major cloud outages in recent years — AWS in December 2021, Microsoft Azure in January 2023, Google Cloud in April 2024 — each cascaded across hundreds of services. The question was never whether an outage would hit the financial sector, but when.
Real powers, calibrated scope
The regulators won’t oversee every aspect of these companies’ operations — only services deemed critical to the UK financial system. But within that scope, their powers are substantial: assessing operational resilience, gathering information, setting requirements, and as a last resort, barring a CTP from providing services to regulated financial institutions.
Simon Hall, Head of Prudential Policy Division at the Bank of England, described the regime as “risk-focused, proportionate and pragmatic.” He “strongly encouraged closer cooperation between CTPs and the regulators.” The tone is diplomatic, but the message is clear: voluntary cooperation is preferred, but enforcement tools exist.
UK vs. EU: two philosophies, one diagnosis
The European Union has built its own framework through DORA (Digital Operational Resilience Act), which came into force in January 2025. Both regimes start from the same diagnosis — systemic dependence on cloud infrastructure — but diverge in their approach.
The UK regime is qualitative: no numerical thresholds, designation is a case-by-case judgment call. DORA sets quantitative criteria (for example, serving more than 10% of EU financial institutions). Another key difference: in the UK, the cloud provider bears the information-gathering burden. Under DORA, it’s the financial institutions themselves that must document their dependency.
The two systems aren’t operating in silos. In January 2026, the FCA, the Bank of England, and EU supervisory authorities (EBA, EIOPA, ESMA) signed a Memorandum of Understanding to coordinate their oversight and share information during incidents — cyber attacks, major outages, service interruptions.
What this means for the cloud giants
For Microsoft, Amazon, Google, and Oracle, this designation creates a new compliance layer specifically tied to financial services. Audits, resilience requirements, and reporting obligations stack on top of an already dense regulatory environment (GDPR, NIS2, DSA). And the UK is just the beginning: other jurisdictions are watching this model.
But the real question is elsewhere. The CTP regime implicitly recognizes that these companies have become infrastructure — not in the metaphorical sense, but in the regulatory one. When a cloud provider is supervised like a systemically important financial actor, the market has already ruled on its indispensability. And the consequences of that recognition will extend well beyond financial services.
