Breaking

UK’s critical third parties regime cannot fine AWS or Microsoft

UK's critical third parties regime cannot fine AWS or Microsoft

HM Treasury designated Amazon Web Services, Google Cloud, Microsoft and Oracle as Critical Third Parties on July 8, 2026, and the Bank of England, the Prudential Regulation Authority (PRA) and the Financial Conduct Authority (FCA) began jointly overseeing them on July 13, 2026 — but the statute that created the regime gives those regulators no power to fine the four providers, which is the single most consequential feature of the framework and the one least discussed.

The Critical Third Parties (Designation) Regulations 2026 (SI 2026/777), made on July 8, 2026 under section 312L(1) of the Financial Services and Markets Act 2000 as inserted by the Financial Services and Markets Act 2023 (FSMA 2023), name four legal entities: Amazon Web Services EMEA SARL, Google Cloud EMEA Limited, Microsoft Ireland Operations Limited and Oracle Corporation UK Limited, each designated with effect from July 13, 2026. This analysis covers what designation obliges those entities to do, what it changes for the regulated firms sitting on top of them, how the UK compares with the European Union, the United States, Singapore and Australia, and why the missing fining power reshapes the compliance calculus rather than weakening it.

Key facts

  • Instrument: The Critical Third Parties (Designation) Regulations 2026, SI 2026/777, made July 8, 2026, in force July 13, 2026 (legislation.gov.uk).
  • Designating body: HM Treasury, not the regulators, under section 312L of FSMA 2000. Supervision sits with the Bank, the PRA and the FCA.
  • Entities designated: Amazon Web Services EMEA SARL, Google Cloud EMEA Limited, Microsoft Ireland Operations Limited, Oracle Corporation UK Limited.
  • Rules already in force: the joint CTP rulebook, published November 12, 2024 in PS16/24 (FCA PS24/16), took effect January 1, 2025 and applies automatically on designation.
  • No fining power: “FSMA does not provide the regulators with a power to impose a penalty on CTPs” (PS16/24, paragraph 3.23). Sanctions run through section 312R.
  • Concentration measured: the top three third-party providers of cloud, models and data accounted for 73%, 44% and 33% of all named providers (Bank of England and FCA, 2024).
  • First deadline: interim self-assessments due within three months of designation — on or about October 13, 2026.

Methodology and sources

This analysis rests on primary documents. The designation is read from SI 2026/777 as made, not from press coverage; the enabling powers from sections 312L to 312V of FSMA 2000 as inserted by FSMA 2023. The substance of the obligations is taken from the regulators’ joint policy statement PS16/24 (the FCA’s equivalent numbering is PS24/16), published November 12, 2024, with the accompanying supervisory statement SS6/24 and the CTP approach document. Attributed quotations are verbatim from the HM Treasury press release of July 10, 2026, the Bank of England news release of the same date, and the Treasury Committee Chair’s statement of July 13, 2026. Comparative material is drawn from Regulation (EU) 2022/2554 (the Digital Operational Resilience Act, or DORA), the Monetary Authority of Singapore’s Notice on Technology Risk Management, the Australian Prudential Regulation Authority’s Prudential Standard CPS 230, and the United States Bank Service Company Act. The window runs from FSMA 2023 receiving Royal Assent to August 2026. Where the regime is untested, this analysis says so.

What designation actually does — and the sanction that is not there

Designation as a Critical Third Party is not authorisation. HM Treasury may designate a provider only if, in its opinion, a failure in or disruption to the services that provider supplies to firms could threaten the stability of, or confidence in, the UK financial system — the statutory test in section 312L. Designation then switches on four regulatory powers. Section 312M allows rules imposing duties on the CTP in connection with the services it provides to firms. Section 312N allows a written direction to do, or refrain from doing, anything specified. Section 312P allows information-gathering from the CTP and from “Persons Connected with a CTP”, the appointment of skilled persons, and investigations. Sections 312Q and 312R carry the disciplinary powers — and section 312R is the point most often missed. The regulators may impose conditions, limitations, prohibitions or restrictions on a CTP’s provision of services to regulated firms. What they may not impose is a penalty. PS16/24 records the position without ambiguity at paragraph 3.23: “FSMA does not provide the regulators with a power to impose a penalty on CTPs.”

The obligations that bite sit in the joint rulebook in force since January 1, 2025, which applies immediately on designation. Six CTP Fundamental Rules require a CTP to conduct its business with integrity, with due skill, care and diligence, and in a prudent manner; to maintain effective risk strategies and risk management systems; to organise and control its affairs responsibly and effectively; and to deal with the regulators in an open and co-operative way. After consultation the regulators narrowed the first five to systemic third-party services rather than every service supplied, while Fundamental Rule 6 continues to apply broadly. Layered on top are eight Operational Risk and Resilience Requirements: governance, risk management, dependency and supply chain risk management, technology and cyber resilience, change management, mapping, incident management, and termination of services.

Reporting and testing obligations sit alongside those rules. A CTP must submit a written interim self-assessment to the regulators within three months of designation and an annual self-assessment thereafter, sharing a summary of the annual document with the firms it supplies systemic third-party services to. It must test its ability to keep providing material services in severe but plausible scenarios, and must test its financial sector incident management playbook annually with a representative sample of the firms it serves, updating the regulators on resulting changes no later than six months after the exercise. Incident reporting is phased: an initial report as soon as practicable after a CTP operational incident, intermediate reports after any significant change in the circumstances previously described, and a final report. The regulators declined to fix a deadline for the initial report, reasoning that CTP incidents vary too much in complexity, and stated in SS6/24 that where detail and timeliness conflict, the CTP should prioritise timeliness.

How five jurisdictions handle the same concentration problem

Jurisdiction / regulator Effective date Scope Key requirement Penalty / sanction
UK — HM Treasury designates; Bank of England, PRA and FCA supervise July 13, 2026 Four designated CTPs; systemic third-party services only Six Fundamental Rules, eight Operational Risk and Resilience Requirements, interim self-assessment within three months (SI 2026/777; PS16/24) No financial penalty available. Section 312R: conditions, limitations, prohibitions or restrictions on supplying regulated firms
EU — EBA, EIOPA and ESMA as Lead Overseers under DORA Designations November 18, 2025; DORA applied January 17, 2025 19 designated critical ICT third-party providers Oversight plans, information requests, general investigations and on-site inspections at the provider and material subcontractors (Regulation (EU) 2022/2554) Article 35: periodic penalty payments up to 1% of average daily worldwide turnover, daily for up to six months
US — Federal Reserve, OCC and FDIC Bank Service Company Act 1962; interagency guidance June 6, 2023 No designation regime; examination reaches services performed for a bank 12 U.S.C. § 1867(c) permits examination of a service performed for a depository institution as if performed in-house; OCC Bulletin 2023-17 sets the life-cycle framework Enforcement runs against the bank, not the provider
Singapore — MAS Notice on Technology Risk Management, in force All MAS-regulated financial institutions; obligation on the institution Unscheduled downtime per critical system capped at four hours in any 12-month period; notify MAS within one hour of discovering a relevant incident Regulatory action against the financial institution; no provider designation regime
Australia — APRA Prudential Standard CPS 230 commenced July 1, 2025; contract transition to July 1, 2026 APRA-regulated entities; “material service providers” identified by the entity, not designated by APRA Register of material service providers filed with APRA, first submission due October 1, 2025; critical operations and tolerance levels set by the entity Prudential action against the regulated entity; APRA does not supervise the provider

Sources: The Critical Third Parties (Designation) Regulations 2026; PS16/24; Regulation (EU) 2022/2554; 12 U.S.C. § 1867; OCC Bulletin 2023-17; MAS Notice on Technology Risk Management; APRA Prudential Standard CPS 230. Last updated: August 26, 2026.

The table exposes a genuine split. Only two of the five jurisdictions reach the provider at all. The UK and the EU designate named legal entities and supervise them directly; the United States, Singapore and Australia regulate the dependency by regulating the dependent. Washington’s approach is the oldest and least direct — the Bank Service Company Act of 1962 lets federal banking agencies examine a service performed for a depository institution as though the institution were performing it in-house, and the interagency guidance of June 6, 2023 sets out a life cycle that binds the bank. Singapore is prescriptive in a different way: rather than supervising the vendor, the Monetary Authority of Singapore (MAS) imposes an outcome on the institution — no more than four hours of unscheduled downtime on any critical system in any 12-month period, and notification to MAS within one hour of discovering a relevant incident. Australia’s Prudential Standard CPS 230, which commenced July 1, 2025, asks entities to identify their own material service providers and file a register, the first due October 1, 2025, with a further year to July 1, 2026 to bring legacy contracts into line.

Where the UK and the EU diverge is in the sanction, and the divergence is stark. The European Supervisory Authorities designated 19 critical ICT third-party providers on November 18, 2025, assigning a Lead Overseer — the European Banking Authority, the European Insurance and Occupational Pensions Authority or the European Securities and Markets Authority — to each. Under Article 35 of DORA, a Lead Overseer that meets non-compliance can impose periodic penalty payments of up to 1% of the provider’s average daily worldwide turnover, charged daily for as long as six months. Applied to a hyperscaler, that is a coercive instrument of real magnitude. The UK regulators hold nothing equivalent. Their strongest tool under section 312R is to restrict or prohibit a designated provider from supplying regulated firms — a sanction that is, in principle, far more severe than any fine, and precisely for that reason far harder to use. The FCA acknowledged as much in PS16/24, recording that five respondents warned enforcement involving prohibition could have adverse consequences for firms and their end customers, and replying that it “recognises that firms may face challenges obtaining services from an alternative CTP.”

“As critical third parties become increasingly embedded in the operations of financial institutions, they can introduce new forms of systemic risk. Our proportionate approach to overseeing these providers will ensure that these dependencies are managed in a way that safeguards financial stability.”

Sarah Breeden, Deputy Governor for Financial Stability, Bank of England (Bank of England)

Enforcement context: the fines still land on the bank

Because the CTP regime carries no penalty power, the enforcement record that matters for firms is the one built against firms — and it is substantial. On December 20, 2022 the FCA and the PRA fined TSB Bank plc a combined £48,650,000 for operational risk management and governance failings, including the management of outsourcing risks, arising from the April 2018 migration of customer data onto a new IT platform. The data moved successfully; the platform failed immediately, disrupting branch, telephone, online and mobile banking. Every TSB branch and a significant proportion of its 5.2 million customers were affected. The FCA’s share was £29,750,000 and the PRA’s £18,900,000; TSB settled and took a 30% discount, without which the combined penalty would have been £69,500,000 (FCA).

The closer precedent is smaller and older. On May 30, 2019 the FCA and the PRA jointly fined Raphaels Bank £1,887,252 — £775,100 from the FCA and £1,112,152 from the PRA — for failing to manage its outsourcing arrangements between April 2014 and December 2016. The trigger was a technology incident at a card processor on December 24, 2015 that took authorisation and processing services down for more than eight hours, leaving 3,367 customers unable to use prepaid and charge cards and blocking 5,356 attempted transactions. The largest affected programme served seasonal workers who relied on those cards to receive wages. The failure was the vendor’s; the finding was that Raphaels lacked adequate processes to understand and assess its outsourced providers’ business continuity and disaster recovery arrangements. As our coverage of the Raphaels penalty noted at the time, the fine attached to the bank’s oversight of the arrangement rather than to the outage itself. Nothing in the CTP regime alters that allocation. PS16/24 states at paragraph 2.42 that the accountability and responsibility of individual firms, their boards and senior management for operational resilience and third-party risk management “will not change due to the implementation of the CTP oversight regime.”

What this means for brokers, exchanges, payment firms and compliance teams

The most important operational consequence of designation is one of information, not liability. A designated CTP must share a summary of its annual self-assessment with the firms it supplies systemic third-party services to, report incidents to affected firms as well as to the regulators, and run its incident management playbook exercise with a representative sample of those firms. Compliance and operational-resilience teams at brokers, contracts-for-difference (CFD) providers, prop-trading firms, exchanges and payment institutions should expect a new inbound stream — self-assessment summaries, three-phase incident reports, playbook exercise invitations — and decide now who owns it and how it feeds the firm’s own impact tolerances. The impact tolerance framework for important business services is the natural home for that material; a self-assessment summary filed and never mapped against a tolerance is a governance failure waiting to be found.

What does not change is the obligation. A firm running its matching engine, client money ledger or market-data pipeline on one of the four designated entities is in the same regulatory position now as on July 12, 2026. Due diligence, exit planning, substitutability analysis and contractual resilience terms remain the firm’s own responsibility. PS16/24 is blunt on the temptation to read designation as a quality mark, warning that designation “does not mean that it is inherently more resilient or better suited to provide one or more services to a given firm than a non-designated third party providing the same or similar services.” The practical checklist is unglamorous: refresh the mapping of which important business services depend on which designated entity and region; confirm contracts carry audit, information and step-in rights that survive designation; re-run exit analysis assuming a section 312R restriction is a live, if remote, scenario; record the board discussion. Multi-cloud arrangements of the kind seen when Iress connected to AWS, Microsoft Azure and Google Cloud Platform, or in State Street’s dual-provider infrastructure deal, reduce single-provider exposure but do not remove concentration risk where both providers sit inside the same designated population.

One scope limit is worth pinning down. Oversight applies only to systemic services supplied to the financial sector, not to the providers’ wider operations: a UK broker’s marketing analytics stack running on the same hyperscaler is outside the regime even though the vendor is inside it. The lesson from third-party market-data and terminal failures — including the disruption when a Bloomberg outage rattled global trading — is that the dependencies that hurt are frequently the ones nobody classified as critical.

“To finally see movement on this after we have pressed for months, including in our recent AI report, is a huge step forward. The Treasury is finally putting its powers to good use by improving oversight of the tech firms which our financial system relies upon. As the use of AI in financial services expands, I believe there may come a time when the government needs to consider designating specific AI firms under the Critical Third Parties Regime.”

Dame Meg Hillier, Chair, House of Commons Treasury Committee (Treasury Committee)

What’s next — the forward view

Three things are scheduled and one is contested. The interim self-assessments fall due within three months of designation, putting all four entities at on or about October 13, 2026 — the first substantive test of whether the regime produces usable supervisory information. Certain requirements are subject to transitional periods listed in Section 12 of SS6/24, so the full obligation set phases in rather than landing at once. And the regulators have committed to review periodically whether designated CTPs still meet the statutory criteria, making recommendations to HM Treasury on designation and de-designation alike.

Cross-border coordination is the second thread. On January 14, 2026 the European Supervisory Authorities signed a Memorandum of Understanding with the Bank of England, the PRA and the FCA covering cooperation, information sharing and coordination of oversight on providers captured by both regimes (FCA). The overlap is close but not exact. The EU’s list of 19, published under Article 31(9) of DORA, names Amazon Web Services EMEA Sarl, Google Cloud EMEA Limited and Microsoft Ireland Operations Limited — the identical legal entities the UK designated — but captures Oracle through Oracle Nederland B.V. rather than Oracle Corporation UK Limited (EBA). Group-level resilience planning therefore has to reconcile two supervisory perimeters drawn around different subsidiaries. The EU list also reaches beyond cloud to market-data and services firms including Bloomberg L.P., LSEG Data and Risk Limited, IBM, SAP SE and Accenture plc — a breadth the UK has not yet matched. Separately, HM Treasury has laid the regulators’ tripartite MoU before Parliament as required by section 312V of FSMA, governing how the three UK authorities divide CTP oversight and enforcement between them, none being the final arbiter.

The contested item is scope. The Treasury Committee’s report on artificial intelligence in financial services, published January 20, 2026, recommended HM Treasury designate the major AI and cloud providers by the end of 2026 and criticised the absence of progress to that point. The July designations answer the cloud half. The AI half is open: the Committee’s Chair has said the government may need to consider designating specific AI firms, and the Bank and FCA survey ranked critical third-party dependencies the second-highest systemic risk with the greatest expected increase over three years. Whether a model provider rather than an infrastructure provider can be designated on the section 312L test — and what “systemic third party services” would mean for one — is unresolved.

TL;DR

HM Treasury designated four cloud and technology entities — Amazon Web Services EMEA SARL, Google Cloud EMEA Limited, Microsoft Ireland Operations Limited and Oracle Corporation UK Limited — as Critical Third Parties under SI 2026/777, with the Bank of England, PRA and FCA beginning joint oversight on July 13, 2026. The rules themselves have been in force since January 1, 2025 and apply automatically on designation: six Fundamental Rules, eight Operational Risk and Resilience Requirements, phased incident reporting, and an interim self-assessment due within three months. Critically, PS16/24 confirms FSMA gives the regulators no power to fine a CTP; sanctions run to restriction or prohibition under section 312R. Regulated firms remain fully accountable for their own third-party risk. Concentration is real: the top three cloud providers accounted for 73% of all named providers in the Bank of England and FCA 2024 survey.

Frequently asked questions

Who designates a Critical Third Party — the regulators or the government?

HM Treasury designates. The power sits in section 312L of the Financial Services and Markets Act 2000, inserted by FSMA 2023, and is exercised by statutory instrument — here, SI 2026/777. The Bank of England, the PRA and the FCA supervise designated entities and may recommend designations and de-designations to HM Treasury, but they cannot designate. Conflating the two is the most common error in coverage of the regime. HM Treasury has confirmed it makes designation decisions following consultation with the third party and the three regulators.

Can UK regulators fine Amazon Web Services or Microsoft under this regime?

No. PS16/24 states at paragraph 3.23 that “FSMA does not provide the regulators with a power to impose a penalty on CTPs.” The disciplinary powers in sections 312Q and 312R allow the regulators to impose conditions, limitations, prohibitions or restrictions on a designated provider’s supply of services to regulated firms, and to censure. That is a structural sanction rather than a monetary one. By contrast, Article 35 of the EU’s DORA permits periodic penalty payments of up to 1% of average daily worldwide turnover for up to six months.

Does designation change my firm’s outsourcing obligations?

No. PS16/24 states at paragraph 2.42 that firms’, boards’ and senior managers’ accountability for operational resilience and third-party risk management does not change because of the CTP regime. Existing outsourcing, operational resilience and third-party risk rules continue to apply in full. What changes is the information available: designated providers must share annual self-assessment summaries, report incidents to affected firms, and run playbook exercises with a representative sample of customers, which should make existing obligations easier to discharge rather than lighter.

Does designation mean these providers are safer to use than others?

Explicitly not. PS16/24 records the regulators’ view that designation “does not mean that it is inherently more resilient or better suited to provide one or more services to a given firm than a non-designated third party providing the same or similar services.” Designation reflects the systemic consequence of failure, not the probability of it. Firms should not use the designation list as a procurement filter or as evidence of due diligence, and oversight covers only systemic services supplied to the financial sector, not the provider’s wider product estate.

How does the UK regime interact with the EU’s DORA?

Three of the four UK-designated entities — Amazon Web Services EMEA SARL, Google Cloud EMEA Limited and Microsoft Ireland Operations Limited — appear by the same legal name among the 19 critical ICT third-party providers the European Supervisory Authorities designated on November 18, 2025 under DORA. Oracle is captured by both regimes but through different subsidiaries: Oracle Corporation UK Limited in the UK, Oracle Nederland B.V. in the EU. The frameworks are separate but coordinated by a Memorandum of Understanding signed January 14, 2026. Sanctions differ sharply, with DORA permitting periodic penalty payments the UK regime lacks.

Will more providers be designated?

HM Treasury has said the programme is rolling, that there is no statutory limit on the number of CTPs, and that further designations may follow where providers meet the statutory criteria. The Treasury Committee’s January 20, 2026 report recommended designating major AI as well as cloud providers by the end of 2026, and its Chair has said specific AI firms may need to be considered. Payment infrastructure, market-data and core-banking platform providers are the other obvious candidates on a section 312L reading.

This article is informational analysis only and does not constitute legal, regulatory, tax, or investment advice. Regulatory frameworks change frequently and interpretation depends on facts and circumstances; primary documents and official regulator guidance always supersede summaries. Firms should consult qualified legal counsel and their relevant supervisory authority before taking any action based on the analysis above.

Rick Steves has seen business and economics through many lenses. He joined the financial services industry in 2009, and has been a financial journalist since 2011. He holds a degree in Business Administration and has experience producing real-time news, from both buy-side and sell-side, as well as for retail traders, brokers and service providers. Steves' work has appeared in a variety of online publications including FX Street, NewsBTC, FinanceFeeds, and The Industry Spread. Rick has great interest in the dynamics of the trading industry. The never-ending clash between technology, economics, regulation, and more importantly, the people.

Most Read

Related Posts

Imdustry insights

Stay Ahead

Get the latest news, insights, and market updates delivered to your inbox every day.

Enter your email address