The UK will begin to closely regulate Microsoft, Google, Amazon and Oracle as they have been deemed critical third parties for their cloud services in the financial sector.
The move to bring these firms under closer regulatory scrutiny as the looming threat of a cyber-attack of an operational outage affecting one of these critical services could impact the overall stability of the UK financial sector.
The critical third parties will be oversseen by three regulators – the Financial Conduct Authority, The Bank of England, and the Prudential Regulation Authority – which will focus on the resilience of the firms’ services.
Regulators will work together with the firms to address system-level risks and reduce the risk of disruption to the services they provide spreading across the UK financial system.
This aims to strengthen system-wide resilience and improve coordination and information sharing across the UK financial sector.
The firms are tasksed with indentifying and managing risks to their critical services effectively, as well as mainting open, timely communication with regulators and firms they work with, especially during major incidents.
The new regime is meant to compliment, not replace, existing frameworks for regulation outsourcing and operational resiliencce for regulated firms meant to manage their own third-party risks.
“Critical third parties provide essential services which support innovation and growth. At the same time, when the same providers serve thousands of firms, a single failure can reverberate across the financial system,” Nikhil Rathi, chief executive at the FCA, said.
“Operationalising this regime strengthens our ability to tackle those risks and improve overall resilience, ensuring the UK remains a safe and attractive place to do business.”
Recommended reading
- UK Biobank Gets Millions to Boost Health Data Storage Capabilities
- CMA Delays Decision on Cloud Market Probe
- AWS Commits Over £180 Million to GenAI Startups
- New Survey Reveals UK T&L Has “Significant” Data and AI Gap
Treasury is responsible for deciding which third party providers are designated as critical, and any future designations or de-designations. The regulators will periodically review whether these firms continue to meet the designation criteria, making recommendations to Treasury, and evaluate the effectiveness of the oversight approach.
The Bank, PRA and FCA will continue to work closely with Treasury, the financial services industry and designated CTPs as the regime is implem





