Risk Horizon
Live

Intelligence generated by AI from public regulatory sources. Not investment or regulatory advice. Verify before relying on any output.

IncreasingHigh2026-08-02

UK regulators to oversee first designated Critical Third Parties

ConductOtherSanctionsCross-JurisdictionalUnited KingdomConf: High
Regulatory Event

The Bank of England, PRA and FCA will begin oversight of the first Critical Third Parties from 13 July 2026, following HM Treasury designation of AWS, Google Cloud, Microsoft and a fourth provider.

Analysis

HM Treasury has designated the first Critical Third Parties under the new UK CTP regime, targeting global cloud and technology providers underpinning the financial system. The Bank, PRA and FCA will begin direct oversight, marking a structural shift in how systemic technology dependencies are supervised.

Relevance

Introduces direct regulatory oversight of cloud and tech providers, materially reshaping operational resilience obligations for firms reliant on them.

Required Action

Action Required

Map dependencies on designated CTPs, update third-party risk frameworks, and prepare for regulator information requests and resilience testing.

Justification

First activation of the UK CTP regime is a landmark systemic resilience measure with broad implications for all regulated firms.

Control Commentary

Refresh CTP dependency mapping and operational resilience impact tolerances. Engage vendor management to align contracts with new CTP oversight expectations and prepare for coordinated regulator scenario testing.

Source

The Bank of England, PRA and FCA will start overseeing the first critical third parties on 13 July 2026, following Treasury designation of 4 global cloud and technology providers including Amazon Web Services EMEA, Google Cloud EMEA, and Microsoft Ireland.

RH-2026-07-21-001