Educational use only. Not financial, investment, tax or legal advice.
Last updated 12/07/2026 Syd Lawrence 7 minute read

Your bank’s cloud is now watched by the Bank of England, the PRA and the FCA. Here’s why.

A quiet shift in who can ask hard questions of the technology behind your money, in plain English.

Syd Lawrence

Syd Lawrence

CEO & Co-founder at Delphina

The 60-second version

From Monday 13 July 2026, the Bank of England, the Prudential Regulation Authority and the Financial Conduct Authority can directly oversee four technology companies: Amazon Web Services, Google Cloud, Microsoft and Oracle. Those four are now officially classed as Critical Third Parties. This is the first time the people who supervise your bank have had the same reach into the cloud behind your bank. It is a structural change. It is not a product update and not a promise about your data.

Tap your banking app at 7am. It works.

You do not think about why. The screen loads, the balance is right, the payment goes out. Behind that screen sits a chain of technology you will never see: a data centre, a cloud platform, an authentication service, a payments processor. Each one is run by a company whose name you have probably read in a status page at 2am once and never looked at again.

In July 2024, a software update from a company called CrowdStrike went wrong. Flights stopped. Hospitals paused surgery. Shop tills froze. For one weekend, the modern economy looked remarkably like 1995. Then it unpaused, life resumed, and most people stopped thinking about the cloud again.

Why the regulators decided to act

The numbers that changed the conversation

In 2025, 27% of incidents reported to the FCA by UK financial firms were attributed to a third party issue. 37% of those incidents were cyber-related. That is not a fintech hobby statistic. It is the share of operational incidents that, on the firms’ own reporting, came from someone they depend on rather than something inside their own four walls.

The FCA blog on 28 July 2026 named the incidents that brought this home for consumers. The CrowdStrike outage in 2024. The cyber incidents affecting retailers such as Marks & Spencer and Jaguar Land Rover. Different sectors. Same pattern. A single provider’s issue became a public-facing disruption.

For most people, those events felt like an IT story in the news. For UK financial regulators, they were a system stability story. If many UK banks, brokers, pension dashboards and investing apps rely on the same handful of technology providers, then a single outage or breach can move through multiple firms at once. That is what “system risk” means.

What happened on Monday 13 July 2026

On Monday 13 July 2026, a new regulatory regime came into force. It is called the Critical Third Parties regime. It sits under FSMA 2000 as amended by FSMA 2023 and gives three UK regulators statutory powers over the resilience of technology services used by the financial sector.

The Treasury has designated four companies as Critical Third Parties under the regime. They are:

The first four designated CTPs

  • Amazon Web Services EMEA SARL
  • Google Cloud EMEA Limited
  • Microsoft Ireland Operations Ltd
  • Oracle Corporation UK Limited

The regulators in question are the three with statutory responsibility for the UK financial system:

  • The Bank of England – the central bank, with a Financial Stability mandate.
  • The Prudential Regulation Authority (PRA) – supervisor of banks, insurers and major investment firms. Chaired by the Governor of the Bank of England. Run day-to-day by the PRA Chief Executive, Katharine Braddick.
  • The Financial Conduct Authority (FCA) – conduct regulator for financial services and markets, led by Nikhil Rathi.

For the first time, the same regulators who supervise your bank can directly supervise the technology providers your bank depends on. The FCA’s statement puts it in one sentence: “For the first time, the three regulators will jointly oversee these CTPs under a new, proportionate regime, focused on the resilience of the critical services they provide to the UK financial sector.”

What “oversee” means in practice

It does not mean authorisation. CTPs are not being turned into FCA-authorised firms. It does not mean data protection. The regime sits in operational resilience, not in the rules around your personal data. It does not mean price control or commercial terms. The regulators do not gain authority over what AWS, Google, Microsoft or Oracle charge, or what their contracts say.

It means three things:

  1. CTPs must identify and manage risks to the critical services they provide to UK financial firms.
  2. CTPs must maintain open, timely communication with the regulators and with the firms that rely on them, especially during major incidents.
  3. Regulators can ask what the CTP is doing to keep those services available, recover from disruption, and prevent recurrence.

The FCA is explicit on what this regime is not. “No framework can eliminate operational incidents entirely.” The same blog makes the point that resilience is not the same as never failing. It is about who knows first, who communicates fastest, and who recovers in a way the rest of the system can see and rely on.

What this is, and what it is not

Staying in the lane the regulator drew

  • It is about resilience. Keeping the critical services available, recovering them when they fail, communicating during a major incident.
  • It is not about consumer protection in the usual FCA sense. There is no change to how complaints are handled, no change to redress rules.
  • It is not about data protection. UK GDPR and the Data Protection Act 2018 obligations are unchanged. Your data protection rights are not affected by this regime.
  • It is not about pricing or competition. The CTP regime does not give the regulators any authority over commercial terms.
  • It is not about authorisation. CTPs are not being brought into the FCA’s authorised population.

What this means for you, the user

It will not feel different on Monday morning. Your banking app will not announce anything. Your pension will not move. Your investing platform’s terms of service will not change. What changes is the second line of defence you have probably never thought about.

1. Faster, clearer information when the next incident hits

When the next CrowdStrike-style outage happens, your bank, pension provider and investing app will receive clearer and faster information from the cloud provider. The regulator now requires that level of communication. That does not remove incidents. It reduces the silence that follows them.

2. The cloud behind you is not authorised by the FCA in the same way your bank is

AWS, Google Cloud, Microsoft and Oracle are not being turned into FCA-authorised firms. The regime makes clear that oversight is on resilience only. If you ever read a marketing claim that conflates “supervised” with “authorised,” that claim is wrong. The distinction matters.

3. Expect more names on the list

The Treasury designates CTPs on regulator recommendation. Four is the first tranche, not the complete list. Over the next 12–24 months, expect further designations as the regime matures. Any technology provider many regulated firms depend on is a candidate.

It is still your bank’s job

This is the line that is easy to skip. Do not skip it.

The FCA, the PRA and the Treasury are explicit about it: “This regime complements, does not replace, existing outsourcing and operational resilience rules for regulated firms who remain responsible for managing their own third-party arrangements.” If your banking app goes down, your bank is still on the hook first. If your pension dashboard misbehaves, your provider is still the firm you complain to. What changes is the second line of defence. The one you never saw. The regulator can now speak to the cloud provider directly, with statutory powers, about resilience for UK financial services. Your bank remains accountable to you, as it always has been.

Your action this week (not your money, your mental model)

There is no financial action to take. There is no ISA, pension or investment decision hiding behind this regime. The one thing worth doing is small.

One small action this week

Spend 30 seconds looking at the small print on your bank’s status page, your pension provider’s trust centre, or your investing app’s security page. You will see the name of the cloud provider underneath. That name is now under direct regulator scrutiny from 13 July 2026. You did not need to do anything to be protected by this regime. But you now know something most people do not.

Frequently asked questions

Is my data safer in the cloud now?

The CTP regime is about resilience, not data protection. It asks the cloud provider to keep its critical services available for UK financial firms. It does not change what happens to your data under UK GDPR and the Data Protection Act 2018. Those rules are unchanged and remain the responsibility of the firm holding your data.

Does the FCA now authorise Amazon, Google, Microsoft and Oracle?

No. Designation as a Critical Third Party is not the same as FCA authorisation. CTPs are not authorised firms. They are being overseen for the resilience of the services they provide to UK financial firms. The FCA does not regulate their pricing, their terms of service, or what they do outside the resilience scope.

What happens if AWS goes down - does the Bank of England step in?

Not directly. The regime gives the Bank, the PRA and the FCA powers to require the CTP to identify and manage risks, and to communicate in a timely way during incidents. Your bank, pension provider and investing app remain responsible for their own service to you. If your banking app goes down, your bank is still the first line of response.

Why were these four companies singled out?

Because their services underpin the UK financial system. The Treasury designated Amazon Web Services, Google Cloud, Microsoft and Oracle on the regulator recommendation. If a major outage hits one of them, multiple UK financial firms can be affected at the same time. That is the system risk the regime is built to address. Further designations are expected as the regime matures.

Does this change what I should do with my money?

No. The CTP regime does not change which accounts you hold or how you invest. What it changes is who can ask the cloud provider hard questions when something goes wrong, and what they must answer. Your bank's responsibility to manage its own third-party arrangements is unchanged. The regime is system-level, not personal finance advice.

Related Delphina guides

Sources

This is general information about a UK regulatory change, not personal financial advice. The CTP regime is described by the FCA and HM Treasury. Delphina’s own regulatory status is separate and is set out at /legal/regulatory-information.