Educational use only. Not financial, investment, tax or legal advice.
13 July 2026 Syd Lawrence 3 minute read

AWS, Google Cloud, Microsoft and Oracle are now supervised by the Bank of England. What changed on Monday.

The short read on the CTP regime, six weeks after it went live.

Syd Lawrence

Syd Lawrence

CEO & Co-founder at Delphina

In one paragraph

From Monday 13 July 2026, the Bank of England, the PRA and the FCA can directly oversee four technology companies for the first time: Amazon Web Services, Google Cloud, Microsoft and Oracle. They are called Critical Third Parties. It is a resilience regime, not an authorisation, not a data protection regime, and not a consumer rights regime. Your bank, pension provider and investing app stay responsible for their service to you.

What changed on 13 July 2026

A new regulatory regime went live. The Treasury designated four companies as Critical Third Parties under FSMA 2000 (as amended by FSMA 2023). From that Monday, the three UK financial regulators – the Bank of England, the PRA and the FCA – could directly exercise statutory powers over the resilience of services those companies provide to UK financial firms.

Who decided

The Treasury designated the companies. The regulators oversee them. Practical split:

  • Treasury – makes the designation decision on regulator recommendation.
  • Bank of England, PRA, FCA – jointly oversee the CTP for resilience of services to UK financial firms.

The regime was foreshadowed in November 2024 and the final rules came into effect on 1 January 2025. The 13 July 2026 date is when the first designations took effect under those rules.

What “oversee” means in practice

The CTPs must identify and manage risks to the critical services they provide to UK financial firms. They must communicate openly and in a timely way with regulators and firms, particularly during major incidents. The regulators can require information, demand remediation and act on systemic risks. It is operational resilience, not market conduct.

It does not give the FCA, the PRA or the Bank any authority over AWS’, Google’s, Microsoft’s or Oracle’s commercial terms. It does not affect their status as technology providers outside the UK financial services scope.

What this is not

Important distinctions to keep clear

  • Not authorisation. CTPs are not being added to the FCA’s register of authorised firms.
  • Not data protection. UK GDPR and the DPA 2018 obligations of the firms holding your data are unchanged.
  • Not consumer protection. The regime does not change complaint or redress routes for your bank, pension or investing app.
  • Not price control. The regulators gain no authority over commercial pricing or contract terms.

What to watch next

The first four designations are the opening tranche. Further designations are expected as the regime matures.

  • UK–EU coordination. A Memorandum of Understanding between UK and EU regulators on CTP oversight was signed alongside the regime.
  • More CTPs likely. Treasury decides on regulator recommendation. Any technology provider many regulated firms depend on is a candidate.
  • Guidance updates. Expect consultation responses and further FCA, PRA and Bank guidance over the next 12–24 months.

Read the long-form explainer

For the full picture on what the regime means for your money, the “still your bank’s job” nuance and the four things worth knowing, read the pillar piece.

Open the explainer

Sources

This is general information about a UK regulatory regime, not personal financial advice. Delphina’s own regulatory status is separate and is set out at /legal/regulatory-information.