Sullivan & Cromwell LLP Logo Sullivan & Cromwell LLP Logo
  • Lawyers
  • Practices
  • Insights
  • About
  • Careers
  • Alumni
  • Twitter icon
  • LinkedIn icon
  •  icon
  • Podcasts icon
© 2026 Sullivan & Cromwell LLP
    • Home
    • Lawyers
    • Practices
    • Insights
    • About
    • Careers
    • Alumni
    Home /  Insights /  Memos and Newsletters /  Memo
    Memos

    UK Brings Large Tech Providers into Regulatory Perimeter as Critical Third Parties

    July 24, 2026 | min read |
    • Related Practices

    Introduction

    Financial regulators globally have become concerned about the increasing reliance of financial institutions and financial market infrastructure (“FMI”) on a small number of third-party service providers, particularly in cloud and data services. In response, in 2023 the UK introduced a Critical Third Party (“CTP”) regime, the policy objective of which is to mitigate the systemic risks that could arise if the disruption or failure of a major service provider were to affect the resilience of financial institutions or the wider UK financial system. Last week, HM Treasury (“HMT”) designated, with effect from 13 July 2026, the following global cloud services and technology providers as CTPs: Microsoft Ireland Operations Limited, Google Cloud EMEA Limited, Amazon Web Services EMEA SARL, and Oracle Corporation UK Limited.[1]

    As a result of their designation as CTPs, these entities are now subject to oversight by the Prudential Regulation Authority (“PRA”), the Financial Conduct Authority (“FCA”), and the Bank of England (“BoE”) in its role as the regulator of FMI. The designations are significant because they are one of the few instances in which entities outside the financial sector have been brought within the UK’s financial regulatory perimeter and under the direct supervisory remit of the UK financial regulators. This is even more remarkable in an era where the government’s growth agenda is affecting regulatory approach and priorities and pushing for a reduction in regulatory complexity and burden. The designations show that HMT and the regulators are still ready to expand the reach of regulation beyond traditional financial firms to safeguard stability and services used by consumers and businesses, and enhance system-wide resilience.

    The CTP framework consists of legislation,[2] which gives HMT the power to designate an entity as a CTP and confers powers of oversight and enforcement on the regulators, as well as rules made by the BoE, PRA, and FCA[3] alongside guidance and supervisory expectations.[4] The legislation gives the regulators powers to make rules relating to the services that CTPs provide to regulated financial institutions and FMI (collectively referred to in this note as “regulated firms”), to direct a CTP to take certain actions or to cease an activity, and to gather information from a CTP or a person connected with a CTP. The regulators also have various investigatory and disciplinary powers.[5] The designations were made on the basis of evidence and research provided to HMT on the use of third-party service providers by regulated firms, and take into account the materiality of the services provided to regulated firms and the concentration of firms to which the CTP provides services.

    Scope

    Although CTP designation occurs at the entity level, regulatory oversight is limited to the services provided to regulated firms. According to the regulators, the term “service” should be interpreted broadly and includes, among others, a facility,[6] activities, functions, processes and tasks,[7] and Information and Communications Technology (“ICT”) services.[8]

    The UK regulators’ rules consist of six Fundamental Rules, which are high-level principles similar to those that apply to regulated firms, eight operational risk and resilience requirements, evidence requirements, information sharing requirements and incident reporting and notifications. The rules apply to the provision of any service by a CTP to a regulated firm. However, certain rules (such as the eight operational risk and resilience requirements) only apply to the provision of systemic third-party services. A systemic third-party service is defined in the regulators’ rulebooks as a service provided by a CTP to one or more regulated firms where the failure in, or disruption to, the provision of such service could threaten the stability of, or confidence in, the UK financial system.

    Regulated firms are firms authorized in the UK (with a Part IV, FSMA authorization) as well as authorized e-money and payment institutions and FMIs such as UK clearing houses, exchanges, central securities depositories, recognised payment systems and service providers to payment systems.[9]

    Extraterritorial Reach of Regulators’ Oversight

    Although the regulators’ rules apply to the designated CTP at an entity level, where a CTP relies on other entities within its group for delivering systemic third-party services to regulated firms, some of the rules will affect, directly or indirectly, those group entities. The regulators have the power to require information or documents from a CTP or a person connected with a CTP. Persons connected with a CTP are members of the CTP’s group, a controller of a CTP and officers, managers, employees or agents of the CTP. The regulators may also exercise their powers to require a “skilled persons” report in respect of a CTP or a connected person. However, the power to appoint a skilled person, which applies when a regulator considers there has been a breach of rules, applies only to a CTP. Indirect application arises at the supervisory level. The regulators expect a CTP to ensure that group entities involved in its supply chain cooperate with it in satisfying the rules and Fundamental Rules 2, 3 and 6 implicitly require a CTP to ensure its group entities facilitate its compliance. A CTP would need to inform the regulators of a change to its group structure as part of its compliance with the rule to be open and cooperative with the regulators where the change may lead to a change in the entity that is designated or if the change affects delivery of systemic third-party services to regulated firms.[10]

    CTP Location

    The CTP regime applies to a CTP’s services regardless of the location from which they are provided. Neither the statutory provisions nor the regulators require a CTP whose head office is outside the UK to establish a UK subsidiary or branch. However, the regulators’ rules require a CTP to appoint a central point of contact and to provide a UK address for service of documents and statutory notices.

    Comparison with EU and U.S. Regimes

    The UK’s regime is broadly comparable to requirements regarding “critical ICT third party providers” under the EU’s Digital Operational Resilience Act.[11] However, it is not limited to ICT service providers and could in the future apply to other types of third-party providers and their services, including firms providing specific AI services. The UK regime is also broader than the U.S. Bank Service Company Act (“BSCA”),[12] in terms of the scope of regulated firms to which services are provided. Generally, the BSCA only applies to service providers to certain banking organizations, and the scope of services covered by the BSCA itself is more limited than that in the UK.[13] However, the UK CTP regime has a lighter approach to regulation than under U.S. federal banking law (including BSCA) and regulations, which generally provide authority to U.S. federal banking agencies to regulate and examine certain service providers to banking organizations.

    Implementation

    The FSMA requirements and regulators’ rules, which took effect on 1 January 2025, apply to a CTP upon designation. However, the regulators have established transitional measures for some of the obligations. For example, a CTP need only submit an initial self-assessment within three months of its designation, and its initial mapping, first round scenario testing, and incident management playbook exercise must be undertaken within 12 months of its designation date.[14]

    Impact on Regulated Firms

    The CTP regime sits alongside and bolsters the financial stability outcomes of the operational resilience, outsourcing, and third-party risk management requirements that apply to regulated firms. Designation of a CTP does not remove the responsibility of regulated firms, and their boards and senior management over their third-party services and outsourcing arrangements. Regulated firms must continue to undertake appropriate risk assessments, due diligence, and contingency planning and carry out ongoing oversight of their service providers. However, some elements of the CTP regime will assist regulated firms in managing these risks, such as the requirements for a CTP to share information with its customers that are regulated firms.

    Among other actions, a CTP may need to revise its existing contractual arrangements with UK-regulated firms, and possibly with their own service providers. This can be done at the next appropriate renewal or revision point.



    [1] Critical Third Parties (Designation) Regulations 2026 (SI 2026/777).

    [2] Chapter 3C, Part XVIII, Financial Services and Markets Act 2000 (“FSMA”), inserted by the Financial Services and Markets Act 2023.

    [3] See the Critical Third Parties sourcebook in the FCA Handbook, the Critical Third Parties Part of the PRA Rulebook, and the Critical Third Parties Part of the BoE FMI Rulebook.

    [4] See PRA policy statement 16/24 | FCA policy statement 24/16 – Operational resilience: Critical third parties to the UK financial sector, 12 November 2024, including related links.

    [5] The regulators’ powers are set out in sections 312M to 312R, FSMA.

    [6] Section 312L(8), FSMA.

    [7] Financial Stability Board, Enhancing Third-Party Risk Management and Oversight: A toolkit for financial institutions and financial authorities, 4 December 2023, pg. 4.

    [8] BoE, PRA, and FCA Supervisory Statement, Operational resilience: Critical third parties to the UK financial sector, SS6/24, 12 November 2024.

    [9] Section 312L(8), FSMA.

    [10] CTP Fundamental Rule 6. The regulators discuss the application of the regime to group entities in their Supervisory Statement on Operational resilience (see fn 8) and in the Regulators’ Approach to the Oversight of Critical Third Parties, 12 November 2024.

    [11] Regulation (EU) 2022/2554 of the European Parliament and of the Council of 14 December 2022 on digital operational resilience for the financial sector and amending Regulations (EC) No 1060/2009, (EU) No 648/2012, (EU) No 600/2014, (EU) No 909/2014 and (EU) 2016/1011.

    [12] 12 U.S. Code § 1861 et seq.

    [13] Id. § 1867(c). The BSCA applies to “check and deposit sorting and posting, computation and posting of interest and other credits and charges, preparation and mailing of checks, statements, notices, and similar items, or any other clerical, bookkeeping, accounting, statistical, or similar functions performed” for a bank. The federal banking agencies have interpreted this to include services provided by technology service providers. See Federal Reserve Board, Supervision and Regulation Report, at 17 (May 2022) (citing 12 U.S. Code §§ 1464(d)(7), 1867(c)(1)).

    [14] For a complete list, see PRA and FCA Supervisory Statement, Operational resilience: Critical third parties to the UK financial sector, SS6/24, 12 November 2024.

    Read More
    Stay Updated

    Subscribe to stay current on S&C Insights.

    Related Practices Related Practices

    • Europe
    • Financial Services
    • General Practice
    • Technology
    Sullivan & Cromwell LLP Logo Sullivan & Cromwell LLP Logo
    • Twitter icon
    • LinkedIn icon
    • RSS Feed icon
    • Podcasts icon
    • Contact Us
    • Cookies
    • Privacy & Disclaimers
    • Attorney Advertising
    © 2026 Sullivan & Cromwell LLP