A quiet shift in who can ask hard questions of the technology behind your money, in plain English.
You do not think about why. The screen loads, the balance is right, the payment goes out. Behind that screen sits a chain of technology you will never see: a data centre, a cloud platform, an authentication service, a payments processor. Each one is run by a company whose name you have probably read in a status page at 2am once and never looked at again.
In July 2024, a software update from a company called CrowdStrike went wrong. Flights stopped. Hospitals paused surgery. Shop tills froze. For one weekend, the modern economy looked remarkably like 1995. Then it unpaused, life resumed, and most people stopped thinking about the cloud again.
In 2025, 27% of incidents reported to the FCA by UK financial firms were attributed to a third party issue. 37% of those incidents were cyber-related. That is not a fintech hobby statistic. It is the share of operational incidents that, on the firms’ own reporting, came from someone they depend on rather than something inside their own four walls.
The FCA blog on 28 July 2026 named the incidents that brought this home for consumers. The CrowdStrike outage in 2024. The cyber incidents affecting retailers such as Marks & Spencer and Jaguar Land Rover. Different sectors. Same pattern. A single provider’s issue became a public-facing disruption.
For most people, those events felt like an IT story in the news. For UK financial regulators, they were a system stability story. If many UK banks, brokers, pension dashboards and investing apps rely on the same handful of technology providers, then a single outage or breach can move through multiple firms at once. That is what “system risk” means.
On Monday 13 July 2026, a new regulatory regime came into force. It is called the Critical Third Parties regime. It sits under FSMA 2000 as amended by FSMA 2023 and gives three UK regulators statutory powers over the resilience of technology services used by the financial sector.
The Treasury has designated four companies as Critical Third Parties under the regime. They are:
The regulators in question are the three with statutory responsibility for the UK financial system:
For the first time, the same regulators who supervise your bank can directly supervise the technology providers your bank depends on. The FCA’s statement puts it in one sentence: “For the first time, the three regulators will jointly oversee these CTPs under a new, proportionate regime, focused on the resilience of the critical services they provide to the UK financial sector.”
It does not mean authorisation. CTPs are not being turned into FCA-authorised firms. It does not mean data protection. The regime sits in operational resilience, not in the rules around your personal data. It does not mean price control or commercial terms. The regulators do not gain authority over what AWS, Google, Microsoft or Oracle charge, or what their contracts say.
It means three things:
The FCA is explicit on what this regime is not. “No framework can eliminate operational incidents entirely.” The same blog makes the point that resilience is not the same as never failing. It is about who knows first, who communicates fastest, and who recovers in a way the rest of the system can see and rely on.
It will not feel different on Monday morning. Your banking app will not announce anything. Your pension will not move. Your investing platform’s terms of service will not change. What changes is the second line of defence you have probably never thought about.
When the next CrowdStrike-style outage happens, your bank, pension provider and investing app will receive clearer and faster information from the cloud provider. The regulator now requires that level of communication. That does not remove incidents. It reduces the silence that follows them.
AWS, Google Cloud, Microsoft and Oracle are not being turned into FCA-authorised firms. The regime makes clear that oversight is on resilience only. If you ever read a marketing claim that conflates “supervised” with “authorised,” that claim is wrong. The distinction matters.
The Treasury designates CTPs on regulator recommendation. Four is the first tranche, not the complete list. Over the next 12–24 months, expect further designations as the regime matures. Any technology provider many regulated firms depend on is a candidate.
This is the line that is easy to skip. Do not skip it.
The FCA, the PRA and the Treasury are explicit about it: “This regime complements, does not replace, existing outsourcing and operational resilience rules for regulated firms who remain responsible for managing their own third-party arrangements.” If your banking app goes down, your bank is still on the hook first. If your pension dashboard misbehaves, your provider is still the firm you complain to. What changes is the second line of defence. The one you never saw. The regulator can now speak to the cloud provider directly, with statutory powers, about resilience for UK financial services. Your bank remains accountable to you, as it always has been.
There is no financial action to take. There is no ISA, pension or investment decision hiding behind this regime. The one thing worth doing is small.
Spend 30 seconds looking at the small print on your bank’s status page, your pension provider’s trust centre, or your investing app’s security page. You will see the name of the cloud provider underneath. That name is now under direct regulator scrutiny from 13 July 2026. You did not need to do anything to be protected by this regime. But you now know something most people do not.
The CTP regime is about resilience, not data protection. It asks the cloud provider to keep its critical services available for UK financial firms. It does not change what happens to your data under UK GDPR and the Data Protection Act 2018. Those rules are unchanged and remain the responsibility of the firm holding your data.
No. Designation as a Critical Third Party is not the same as FCA authorisation. CTPs are not authorised firms. They are being overseen for the resilience of the services they provide to UK financial firms. The FCA does not regulate their pricing, their terms of service, or what they do outside the resilience scope.
Not directly. The regime gives the Bank, the PRA and the FCA powers to require the CTP to identify and manage risks, and to communicate in a timely way during incidents. Your bank, pension provider and investing app remain responsible for their own service to you. If your banking app goes down, your bank is still the first line of response.
Because their services underpin the UK financial system. The Treasury designated Amazon Web Services, Google Cloud, Microsoft and Oracle on the regulator recommendation. If a major outage hits one of them, multiple UK financial firms can be affected at the same time. That is the system risk the regime is built to address. Further designations are expected as the regime matures.
No. The CTP regime does not change which accounts you hold or how you invest. What it changes is who can ask the cloud provider hard questions when something goes wrong, and what they must answer. Your bank's responsibility to manage its own third-party arrangements is unchanged. The regime is system-level, not personal finance advice.
This is general information about a UK regulatory change, not personal financial advice. The CTP regime is described by the FCA and HM Treasury. Delphina’s own regulatory status is separate and is set out at /legal/regulatory-information.