The UK Treasury has designated Microsoft, Google, Amazon and Oracle as critical third parties for financial services, bringing their cloud operations under direct oversight from July 13. The Bank of England and the Financial Conduct Authority will use the new regime to scrutinize resilience, incident response and systemic risk.

The UK Treasury has designated Microsoft, Google, Amazon and Oracle as critical third parties for financial services, bringing their cloud operations under direct oversight from July 13.

The move gives the Bank of England and the Financial Conduct Authority new powers over technology providers whose services underpin banks, insurers and other parts of the UK financial system. Officials say the aim is to reduce systemic risk if a major cloud provider suffers an outage, cyber incident or other failure.

The Treasury said the designation followed a period of evidence gathering and engagement with the firms. It had already been given the power to make such designations in January 2025, but only moved ahead after assessing which companies were most important to UK finance.

Why the firms were named

The four companies were selected because their cloud services support large amounts of financial activity. That makes them central to the infrastructure of UK finance even though they are not banks or insurers themselves.

Regulators have been concerned for some time about concentration risk in the sector. A relatively small number of large providers sit underneath systems used across the market, so a failure at one company could ripple through multiple institutions at once.

That concern has become more acute as banks, payment firms, insurers and other market infrastructure operators have grown more dependent on cloud services for core operations. The policy treats that dependence as a financial-stability issue, not just a procurement or IT resilience problem.

The regime is narrower than broader European-style oversight models. Instead of covering all large digital platforms, it focuses on providers judged to be systemic to UK financial services.

What the oversight changes

From Monday, July 13, the Bank of England and the FCA will be able to oversee the designated firms directly. In practice, that is expected to mean closer scrutiny of resilience controls, incident handling and related stress-testing requirements.

The government has not yet set out every reporting, testing and disclosure obligation in detail. That means the broad framework is confirmed, but some operational questions remain open.

Even so, the designation marks a significant shift. UK regulators will be able to look beyond the banks and payments firms that buy cloud services and focus on the infrastructure layer itself. That is the point of the critical third party regime: to supervise firms whose failure could threaten the wider financial system.

The companies have publicly welcomed the announcement, according to multiple reports. Their response matters because the new regime creates a direct supervisory relationship with UK regulators over services that have become essential to financial infrastructure.

Timeline and next steps

The immediate next step is the start of direct oversight on July 13, 2026. That is when regulators are expected to begin applying the framework in practice.

The wider chronology began earlier. The Treasury gained the legal power to make critical third party designations in January 2025, then spent a period gathering evidence and engaging with providers before naming the four companies on July 10.

Regulators are then expected to begin testing how intrusive the new regime will be, including how they use resilience and incident-response powers. The implementation phase will show how quickly the framework is applied to each provider and how far it reaches into day-to-day operations.

The Treasury may also expand the regime later if it decides additional providers are systemic to the UK financial system. For now, the focus is on Microsoft, Google, Amazon and Oracle, and on reducing the chance that a cloud disruption could affect a large share of the market at once.

Revision note

Expanded with chronology, oversight details, sector context and next steps.