Feature Third-Party Risk
UK Critical Third Parties: What the 2026 Cloud Designations Mean for TPRM
Four UK critical-third-party designations took effect July 13, 2026. Separate provider duties, firm duties, PS26/2, and existing U.S. authority.
Table of Contents
TL;DR
- A UK statutory instrument designated four cloud-provider legal entities as critical third parties, effective July 13, 2026.
- The regime creates direct duties and oversight for the designated providers. It does not displace regulated firms’ own outsourcing and operational-resilience duties.
- PS26/2 applies March 18, 2027 and creates a separate implementation track for operational-incident and material third-party reporting.
- The United States already has statutory bank-service-provider examination authority under 12 U.S.C. § 1867(c). The UK regime is different, not the first imaginable form of provider oversight.
August 17, 2026 Status Update
The Critical Third Parties (Designation) Regulations 2026 name:
- Amazon Web Services EMEA SARL;
- Google Cloud EMEA Limited;
- Microsoft Ireland Operations Limited; and
- Oracle Corporation UK Limited.
The designations took effect July 13, 2026. The Bank of England’s joint announcement explains that the Bank, PRA, and FCA began overseeing the designated providers under the critical-third-party framework.
That is a current legal status. It should not be confused with two separate questions:
- what regulated firms must continue doing for their own third-party arrangements; and
- what changes under PS26/2 from March 18, 2027.
What Direct CTP Oversight Covers
The regulators’ PS24/16 policy statement establishes the rules and expectations for designated critical third parties. The framework addresses matters such as governance, operational-risk management, resilience testing, incident response, information, and cooperation with regulators.
The oversight is systemic in focus. Regulators can assess whether disruption at a provider could threaten confidence or stability across firms that depend on common services.
Three scope controls matter:
- Use the designated legal entity. A brand name is not a substitute for the entity named in the regulation.
- Map the service. Not every product, affiliate, or contract has the same role in a systemic third-party service.
- Separate provider and firm duties. The provider’s regulatory obligations do not become the customer’s obligations by copy-and-paste.
Firms Still Own Their Resilience
Direct oversight of a cloud provider does not guarantee that a financial firm’s architecture, configuration, data flows, access controls, recovery objectives, or exit strategy are sound.
A regulated firm should still be able to show, as applicable:
- service and data-flow inventories;
- important-business-service dependency mapping;
- due diligence and ongoing monitoring;
- direct and fourth-party concentration analysis;
- tested continuity and recovery arrangements;
- incident escalation and regulatory assessment;
- contractual rights and practical limits;
- substitutability and exit analysis; and
- board or senior-management risk decisions.
The key exam question is not “Is our provider designated?” It is “Can we remain within impact tolerance when this provider or a shared service fails?”
Build a Designation-to-Service Crosswalk
A provider designation is made at the named-entity level, while operational risk appears at the service, region, architecture, and business-process levels. A practical crosswalk should therefore connect the regulation to the firm’s own dependency evidence.
For each relationship with a designated provider, record:
| Field | Control question |
|---|---|
| Designated legal entity | Is this the exact entity named in the statutory instrument? |
| Contracting entity | Which affiliate signed the agreement, and how does it relate to the designated entity? |
| Service and region | Which product, deployment model, and location support the firm? |
| Important business service | Which customer or market outcome depends on it? |
| Data and access | What information, credentials, keys, logs, or administrative rights are involved? |
| Subcontractor dependency | Which material downstream services support delivery? |
| Recovery and exit | What has been tested, what assumptions remain, and who owns the decision? |
This is a recommended operating record, not a claim that PS24/16 imposes this exact table on every financial firm. Its purpose is to stop a designation flag from becoming a yes/no field that says nothing about actual exposure.
The crosswalk should reconcile with the firm’s cloud concentration risk and continuity analysis and its fourth-party and subcontractor risk map. Differences between those records should become owned exceptions, not silent data cleanups.
What Provider Oversight Does Not Prove for the Customer
Direct regulatory oversight can improve information and accountability at the systemic-provider layer. It still does not prove that an individual customer’s implementation is resilient.
The firm needs its own evidence for questions such as:
- whether production and backup environments share a hidden control plane, identity service, region, or network dependency;
- whether customer-managed configuration caused a vulnerability that sits outside the provider’s service commitment;
- whether recovery tests used realistic data volumes, credentials, dependencies, and decision makers;
- whether failover preserved security, transaction integrity, and customer communications rather than merely restoring compute;
- whether logs and incident details arrive soon enough for the firm’s own regulatory analysis;
- whether a substitute service can be activated without incompatible data formats, licensing limits, or untested manual work;
- whether the contract gives the firm evidence it can actually use; and
- whether management accepted any residual concentration risk with a defined review trigger.
An assurance report, provider exercise, or regulator statement can support that file. None automatically closes a customer-specific gap. Preserve the evidence source, period, scope, exclusions, reviewer, and action taken so the board can see what was tested—and what was not.
Reassess When the Dependency Changes
Do not let designation mapping become an annual checkbox. Trigger a review when the contracting entity changes, a service moves region, a critical function is added, a material subcontractor changes, recovery architecture is redesigned, an incident challenges an assumption, or the provider changes a relevant service term.
The review should identify the affected important business service, update concentration and exit analysis, test whether existing assurance still covers the deployment, and record any management acceptance. If no control changes, preserve the evidence supporting that conclusion. This trigger-based workflow is a risk-management recommendation; the firm’s applicable rules and contracts determine the exact required action.
Retain the prior and revised crosswalk so reviewers can reconstruct the decision.
PS26/2 Is a Separate March 2027 Workstream
The FCA’s PS26/2 policy statement says the operational-incident and third-party reporting rules apply from March 18, 2027.
Do not describe those firm-level requirements as having taken effect with the July 2026 designations. Maintain a separate implementation record covering scope, data ownership, material-third-party records, reporting triggers, submission governance, quality checks, and readiness testing.
A practical sequence is:
- identify in-scope regulated entities;
- reconcile third-party records across procurement, TPRM, resilience, security, and finance;
- assign owners for each required field;
- test incident escalation and submission decisions; and
- obtain governance sign-off before the application date.
Contract Changes Are Fact-Specific
The CTP designations do not automatically rewrite a customer’s cloud agreement. Contract actions should be tied to the firm’s applicable rules, service criticality, current terms, and tested operational need.
Useful review questions include:
- Can the firm obtain information needed for its own incident and regulatory decisions?
- Do audit, access, and cooperation terms match applicable law and the service model?
- Are subcontractors and material locations visible enough for concentration analysis?
- Are recovery commitments measurable and testable?
- Is transition assistance detailed enough to support a realistic exit?
- Do liability, suspension, and termination clauses undermine the continuity strategy?
These are risk-based contract recommendations unless a cited rule imposes a specific term on the firm.
The U.S. Comparison Needs Precision
The UK regime creates a named, cross-sector designation and oversight framework for providers judged systemically important to UK financial services. The United States does not use that same designation architecture.
But U.S. federal banking agencies are not limited to examining only the bank’s four walls. The Bank Service Company Act provision at 12 U.S.C. § 1867(c) provides examination and regulatory authority over covered services performed for depository institutions, to the same extent as if the institution performed the services itself.
A careful comparison is therefore:
| United Kingdom | United States |
|---|---|
| Named CTP designation based on potential systemic impact | Statutory examination authority tied to services performed for regulated depository institutions |
| Joint Bank/PRA/FCA oversight framework | Authority allocated to the appropriate federal banking agency |
| Cross-firm systemic-service focus | Bank-service and supervisory nexus |
Neither model relieves the financial institution of its own third-party-risk responsibilities.
So What?
For UK-regulated firms, the immediate task is not to outsource resilience to the new CTP supervisors. Confirm the designated legal entities in the dependency map, keep firm-level controls operating, and build PS26/2 readiness for March 18, 2027.
For U.S. institutions, use the UK development as a concentration-risk signal without claiming that U.S. agencies have no provider-examination authority.
The Third-Party Risk Management Kit can structure inventory, due diligence, concentration, monitoring, and exit evidence. Contract and control decisions still require entity-specific legal and operational review.
Primary sources: UK designation regulation | Bank of England designation announcement | PS24/16 CTP rules | PS26/2 reporting policy | 12 U.S.C. § 1867
◆ Need the working template?
Start with the source guide.
These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.
◆ Related template
Third-Party Risk Management (TPRM) Kit
Complete vendor risk management lifecycle from initial due diligence to ongoing oversight.
◆ Immaterial Findings · Weekly
Sharp risk & compliance insights. No fluff.
◆ FAQ
Frequently asked questions.
Which providers became UK critical third parties in July 2026?
What does designation do?
Does direct oversight replace a financial firm's outsourcing duties?
When does PS26/2 apply?
Does the United States lack authority to examine bank service providers?
Author
Rebecca Leung
Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.
◆ Related framework
Third-Party Risk Management (TPRM) Kit
Complete vendor risk management lifecycle from initial due diligence to ongoing oversight.
◆ Keep reading
Related posts.
Third-Party Risk
DORA Register of Information: Turn the 2024 Dry-Run Results Into a Data-Quality Control
Only 6.5% of 947 integrated DORA dry-run registers passed all 116 checks. Here is a repeatable remediation and evidence process.
Aug 16, 2026
Third-Party Risk
Your Bank Partner Just Got an OCC Consent Order. What Happens to Your Fintech Program.
In May 2026, the OCC made public a consent order against Community Federal Savings Bank for BSA/AML deficiencies tied to fintech-partner payment processing growth—wire, ACH, and cross-border volume the bank couldn't supervise. Fintechs whose programs run through enforcement-action banks face program pause, enhanced scrutiny, or termination. Here's what your TPRM program needs to monitor.
Aug 3, 2026
Third-Party Risk
Fourth-Party Risk: A Practical Subcontractor Evidence File
Use the 2023 interagency guidance to scope subcontractor risk, contract controls, concentration analysis, and examiner-ready evidence.
Jul 30, 2026