The short read on the CTP regime, six weeks after it went live.
A new regulatory regime went live. The Treasury designated four companies as Critical Third Parties under FSMA 2000 (as amended by FSMA 2023). From that Monday, the three UK financial regulators – the Bank of England, the PRA and the FCA – could directly exercise statutory powers over the resilience of services those companies provide to UK financial firms.
The Treasury designated the companies. The regulators oversee them. Practical split:
The regime was foreshadowed in November 2024 and the final rules came into effect on 1 January 2025. The 13 July 2026 date is when the first designations took effect under those rules.
The CTPs must identify and manage risks to the critical services they provide to UK financial firms. They must communicate openly and in a timely way with regulators and firms, particularly during major incidents. The regulators can require information, demand remediation and act on systemic risks. It is operational resilience, not market conduct.
It does not give the FCA, the PRA or the Bank any authority over AWS’, Google’s, Microsoft’s or Oracle’s commercial terms. It does not affect their status as technology providers outside the UK financial services scope.
The first four designations are the opening tranche. Further designations are expected as the regime matures.
For the full picture on what the regime means for your money, the “still your bank’s job” nuance and the four things worth knowing, read the pillar piece.
Open the explainerThis is general information about a UK regulatory regime, not personal financial advice. Delphina’s own regulatory status is separate and is set out at /legal/regulatory-information.