FCA
Financial Conduct Authority (UK)
UK regulators to start oversight of first Critical Third Parties from 13 July 2026
Published
Jul 9, 2026
Effective
Jul 13, 2026
Topics
Operational resilience, Critical third parties, Outsourcing, Cloud services, Incident management, Financial stability
Executive Summary
The FCA, Bank of England and PRA have announced that they will begin overseeing the first Treasury-designated Critical Third Parties on 13 July 2026. The designations bring four global cloud and technology providers into the UK CTP regime, which is intended to address system-level operational resilience risks where disruption at a common supplier could affect multiple firms, markets or consumers simultaneously. The regulators’ oversight is focused on the resilience of critical services provided to the UK financial sector and is not equivalent to authorisation of the providers. CTPs are expected to identify and manage risks to those services and maintain open, timely communication with regulators and dependent firms, particularly during major incidents. For regulated firms and financial market infrastructures, the announcement does not replace existing outsourcing or operational resilience obligations. Firms remain responsible for due diligence, risk management, contingency planning and their own third-party arrangements. The immediate business priority is to identify dependencies on the designated providers and adjust supplier, incident and resilience governance accordingly.
What Changed
Previous
No third-party providers had been announced as designated CTPs under the regime.
New
Amazon Web Services EMEA SARL, Google Cloud EMEA Limited, Microsoft Ireland Operations Ltd and Oracle Corporation UK Limited are designated as CTPs.
Previous
The final CTP rules were in force, but applied to a provider only once designated by Treasury.
New
The three regulators will start oversight of the first CTPs on 13 July 2026.
Previous
Technology providers were primarily managed by regulated firms through outsourcing, supplier risk and operational resilience arrangements.
New
Designated CTPs are directly overseen by the UK financial regulators for system-level resilience risks in critical services.
Previous
Firms were responsible for due diligence, risk management and contingency planning for third-party arrangements.
New
Those responsibilities continue, even where the supplier is now a designated CTP.
Previous
No active list of designated CTPs had been announced.
New
The scope of entities under the regime is expected to evolve as further designations are considered.
Business Impact
Who is affected
Directly affected
Amazon Web Services EMEA SARL, Google Cloud EMEA Limited, Microsoft Ireland Operations Ltd and Oracle Corporation UK Limited as Treasury-designated CTPs for the resilience of critical services supplied to UK financial firms.
Indirectly affected
UK regulated firms and financial market infrastructures using these providers, because existing outsourcing, third-party risk management and operational resilience obligations remain.
Jurisdictions
United Kingdom
Business processes
Third-party risk management and supplier onboarding, Outsourcing and material third-party arrangement governance, Operational resilience mapping of important business services, Cloud concentration risk assessment, Incident escalation and regulatory communications, Business continuity, exit and contingency planning, Board and senior management resilience reporting
Estimated effort
Medium
Compliance risk
High
Affected Reports
| Field | Validation rule |
|---|---|
| Supplier legal entity name | Internal third-party records should identify whether relevant services are provided by one of the four named Treasury-designated CTP legal entities. |
| CTP designation status | Internal supplier reference data should record CTP designation status for the named providers from 13 July 2026 for oversight, escalation and monitoring purposes. |
| Designation is not authorisation | Controls and communications should not describe CTP designation as FCA, PRA or Bank of England authorisation; the FCA statement confirms oversight is limited to resilience of services supplied to UK financial firms. |
Recommended Actions
- 1AI generatedStep 1 of 7
complete an exposure scan across legal entities, business services and outsourcing inventories to identify reliance on the four designated CTPs.
- 2AI generatedStep 2 of 7
update third-party risk and cloud concentration dashboards to add CTP designation status, legal entity name and affected important business services.
- 3AI generatedStep 3 of 7
review contracts, service-level arrangements and incident protocols with designated CTPs to ensure timely information sharing during major incidents.
- 4AI generatedStep 4 of 7
refresh operational resilience scenarios for severe disruption at a designated CTP, including contingency, substitution and exit considerations.
- 5AI generatedStep 5 of 7
ensure outsourcing and material third-party reporting processes continue to operate; the CTP regime complements rather than replaces existing firm obligations.
- 6AI generatedStep 6 of 7
brief accountable executives, operational resilience owners and procurement teams that CTP designation is not regulatory authorisation or a substitute for due diligence.
- 7AI generatedStep 7 of 7
monitor Treasury and regulator publications for future designations, de-designations, supervisory statements, templates or incident communication guidance.
Timeline
publication
Nov 2024
FCA, Bank of England and PRA introduced final rules and policy for the UK CTP regime.
effective date
Jan 1, 2025
Final CTP rules and policy came into effect and apply immediately to CTPs once designated by Treasury.
publication
Jul 10, 2026
FCA published the statement announcing Treasury’s first CTP designations and the start of regulatory oversight.
effective date
Jul 13, 2026
Bank of England, PRA and FCA start overseeing the first designated CTPs; the regulations come into effect.
Sources
AI-generated analysis is based on the following primary sources. Always verify against the official publication.
- Regulatory statementFinancial Conduct AuthorityJul 10, 2026UK financial regulators to begin overseeing Critical Third Parties announced by Treasury ↗
https://www.fca.org.uk/news/statements/uk-financial-regulators-overseeing-critical-third-parties-announced-treasury
- Regulatory guidance webpageFinancial Conduct AuthorityDate not specifiedCritical third parties ↗
https://www.fca.org.uk/firms/outsourcing-and-operational-resilience/critical-third-parties
- Policy statementFinancial Conduct AuthorityNov 2024PS24/16: Operational resilience: Critical third parties to the UK financial sector ↗
https://www.fca.org.uk/publications/policy-statements/ps24-16-operational-resilience-critical-third-parties-uk-financial-sector
- Regulatory reporting guidance webpageFinancial Conduct AuthorityDate not specifiedReporting material third party arrangements ↗
https://www.fca.org.uk/firms/outsourcing-and-operational-resilience/reporting-material-third-party-arrangements
- Primary legislationlegislation.gov.ukJun 29, 2023Financial Services and Markets Act 2023 ↗
https://www.legislation.gov.uk/ukpga/2023/29/contents/enacted
Related Evidence
Verified source support for this analysis
The evidence agent checks whether the drafted finding is supported by official publications and relevant public source material.
Receive updates like this by email
Get AI-generated analysis for the regulators and topics you care about.