← Back to updates
FCA

FCA

Financial Conduct Authority (UK)

High Impact

UK regulators to start oversight of first Critical Third Parties from 13 July 2026

Published

Jul 9, 2026

Effective

Jul 13, 2026

Topics

Operational resilience, Critical third parties, Outsourcing, Cloud services, Incident management, Financial stability

Executive Summary

The FCA, Bank of England and PRA have announced that they will begin overseeing the first Treasury-designated Critical Third Parties on 13 July 2026. The designations bring four global cloud and technology providers into the UK CTP regime, which is intended to address system-level operational resilience risks where disruption at a common supplier could affect multiple firms, markets or consumers simultaneously. The regulators’ oversight is focused on the resilience of critical services provided to the UK financial sector and is not equivalent to authorisation of the providers. CTPs are expected to identify and manage risks to those services and maintain open, timely communication with regulators and dependent firms, particularly during major incidents. For regulated firms and financial market infrastructures, the announcement does not replace existing outsourcing or operational resilience obligations. Firms remain responsible for due diligence, risk management, contingency planning and their own third-party arrangements. The immediate business priority is to identify dependencies on the designated providers and adjust supplier, incident and resilience governance accordingly.

What Changed

newFirst Treasury CTP designations

Previous

No third-party providers had been announced as designated CTPs under the regime.

New

Amazon Web Services EMEA SARL, Google Cloud EMEA Limited, Microsoft Ireland Operations Ltd and Oracle Corporation UK Limited are designated as CTPs.

newJoint regulatory oversight starts

Previous

The final CTP rules were in force, but applied to a provider only once designated by Treasury.

New

The three regulators will start oversight of the first CTPs on 13 July 2026.

newDirect CTP resilience expectations now attach to named providers

Previous

Technology providers were primarily managed by regulated firms through outsourcing, supplier risk and operational resilience arrangements.

New

Designated CTPs are directly overseen by the UK financial regulators for system-level resilience risks in critical services.

modifiedRegulated firms’ obligations remain in place

Previous

Firms were responsible for due diligence, risk management and contingency planning for third-party arrangements.

New

Those responsibilities continue, even where the supplier is now a designated CTP.

newOngoing designation and review process

Previous

No active list of designated CTPs had been announced.

New

The scope of entities under the regime is expected to evolve as further designations are considered.

Business Impact

Who is affected

Directly affected

Amazon Web Services EMEA SARL, Google Cloud EMEA Limited, Microsoft Ireland Operations Ltd and Oracle Corporation UK Limited as Treasury-designated CTPs for the resilience of critical services supplied to UK financial firms.

Indirectly affected

UK regulated firms and financial market infrastructures using these providers, because existing outsourcing, third-party risk management and operational resilience obligations remain.

Jurisdictions

United Kingdom

Business processes

Third-party risk management and supplier onboarding, Outsourcing and material third-party arrangement governance, Operational resilience mapping of important business services, Cloud concentration risk assessment, Incident escalation and regulatory communications, Business continuity, exit and contingency planning, Board and senior management resilience reporting

Estimated effort

Medium

Compliance risk

High

Affected Reports

CTP designation and supplier criticality registerCloud and technology dependency map for important business servicesCritical services resilience and continuity assessmentMajor incident escalation and communications playbook involving designated CTPsOutsourcing and material third-party arrangement governance pack
FieldValidation rule
Supplier legal entity nameInternal third-party records should identify whether relevant services are provided by one of the four named Treasury-designated CTP legal entities.
CTP designation statusInternal supplier reference data should record CTP designation status for the named providers from 13 July 2026 for oversight, escalation and monitoring purposes.
Designation is not authorisationControls and communications should not describe CTP designation as FCA, PRA or Bank of England authorisation; the FCA statement confirms oversight is limited to resilience of services supplied to UK financial firms.

Recommended Actions

7 suggested next steps· derived from source analysis
  1. 1
    AI generatedStep 1 of 7

    complete an exposure scan across legal entities, business services and outsourcing inventories to identify reliance on the four designated CTPs.

  2. 2
    AI generatedStep 2 of 7

    update third-party risk and cloud concentration dashboards to add CTP designation status, legal entity name and affected important business services.

  3. 3
    AI generatedStep 3 of 7

    review contracts, service-level arrangements and incident protocols with designated CTPs to ensure timely information sharing during major incidents.

  4. 4
    AI generatedStep 4 of 7

    refresh operational resilience scenarios for severe disruption at a designated CTP, including contingency, substitution and exit considerations.

  5. 5
    AI generatedStep 5 of 7

    ensure outsourcing and material third-party reporting processes continue to operate; the CTP regime complements rather than replaces existing firm obligations.

  6. 6
    AI generatedStep 6 of 7

    brief accountable executives, operational resilience owners and procurement teams that CTP designation is not regulatory authorisation or a substitute for due diligence.

  7. 7
    AI generatedStep 7 of 7

    monitor Treasury and regulator publications for future designations, de-designations, supervisory statements, templates or incident communication guidance.

Timeline

publication

Nov 2024

FCA, Bank of England and PRA introduced final rules and policy for the UK CTP regime.

effective date

Jan 1, 2025

Final CTP rules and policy came into effect and apply immediately to CTPs once designated by Treasury.

publication

Jul 10, 2026

FCA published the statement announcing Treasury’s first CTP designations and the start of regulatory oversight.

effective date

Jul 13, 2026

Bank of England, PRA and FCA start overseeing the first designated CTPs; the regulations come into effect.

Sources

AI-generated analysis is based on the following primary sources. Always verify against the official publication.

Related Evidence

Verified source support for this analysis

The evidence agent checks whether the drafted finding is supported by official publications and relevant public source material.

Receive updates like this by email

Get AI-generated analysis for the regulators and topics you care about.

Pulse is built by Datox. Datox automates AIFMD Annex IV and SEC Form PF reporting end to end.

See the Datox platform