Skip to content
RiskTemplates · The Daily Brief Tuesday, August 18, 2026
Wire FINRA's 24 Enforcement Review Recommendations: Read Them as Proposals, Not Rules AUG 11

Feature Third-Party Risk

UK Critical Third Parties: What the 2026 Cloud Designations Mean for TPRM

Four UK critical-third-party designations took effect July 13, 2026. Separate provider duties, firm duties, PS26/2, and existing U.S. authority.

Table of Contents

TL;DR

  • A UK statutory instrument designated four cloud-provider legal entities as critical third parties, effective July 13, 2026.
  • The regime creates direct duties and oversight for the designated providers. It does not displace regulated firms’ own outsourcing and operational-resilience duties.
  • PS26/2 applies March 18, 2027 and creates a separate implementation track for operational-incident and material third-party reporting.
  • The United States already has statutory bank-service-provider examination authority under 12 U.S.C. § 1867(c). The UK regime is different, not the first imaginable form of provider oversight.

August 17, 2026 Status Update

The Critical Third Parties (Designation) Regulations 2026 name:

  • Amazon Web Services EMEA SARL;
  • Google Cloud EMEA Limited;
  • Microsoft Ireland Operations Limited; and
  • Oracle Corporation UK Limited.

The designations took effect July 13, 2026. The Bank of England’s joint announcement explains that the Bank, PRA, and FCA began overseeing the designated providers under the critical-third-party framework.

That is a current legal status. It should not be confused with two separate questions:

  1. what regulated firms must continue doing for their own third-party arrangements; and
  2. what changes under PS26/2 from March 18, 2027.

What Direct CTP Oversight Covers

The regulators’ PS24/16 policy statement establishes the rules and expectations for designated critical third parties. The framework addresses matters such as governance, operational-risk management, resilience testing, incident response, information, and cooperation with regulators.

The oversight is systemic in focus. Regulators can assess whether disruption at a provider could threaten confidence or stability across firms that depend on common services.

Three scope controls matter:

  • Use the designated legal entity. A brand name is not a substitute for the entity named in the regulation.
  • Map the service. Not every product, affiliate, or contract has the same role in a systemic third-party service.
  • Separate provider and firm duties. The provider’s regulatory obligations do not become the customer’s obligations by copy-and-paste.

Firms Still Own Their Resilience

Direct oversight of a cloud provider does not guarantee that a financial firm’s architecture, configuration, data flows, access controls, recovery objectives, or exit strategy are sound.

A regulated firm should still be able to show, as applicable:

  • service and data-flow inventories;
  • important-business-service dependency mapping;
  • due diligence and ongoing monitoring;
  • direct and fourth-party concentration analysis;
  • tested continuity and recovery arrangements;
  • incident escalation and regulatory assessment;
  • contractual rights and practical limits;
  • substitutability and exit analysis; and
  • board or senior-management risk decisions.

The key exam question is not “Is our provider designated?” It is “Can we remain within impact tolerance when this provider or a shared service fails?”

Build a Designation-to-Service Crosswalk

A provider designation is made at the named-entity level, while operational risk appears at the service, region, architecture, and business-process levels. A practical crosswalk should therefore connect the regulation to the firm’s own dependency evidence.

For each relationship with a designated provider, record:

FieldControl question
Designated legal entityIs this the exact entity named in the statutory instrument?
Contracting entityWhich affiliate signed the agreement, and how does it relate to the designated entity?
Service and regionWhich product, deployment model, and location support the firm?
Important business serviceWhich customer or market outcome depends on it?
Data and accessWhat information, credentials, keys, logs, or administrative rights are involved?
Subcontractor dependencyWhich material downstream services support delivery?
Recovery and exitWhat has been tested, what assumptions remain, and who owns the decision?

This is a recommended operating record, not a claim that PS24/16 imposes this exact table on every financial firm. Its purpose is to stop a designation flag from becoming a yes/no field that says nothing about actual exposure.

The crosswalk should reconcile with the firm’s cloud concentration risk and continuity analysis and its fourth-party and subcontractor risk map. Differences between those records should become owned exceptions, not silent data cleanups.

What Provider Oversight Does Not Prove for the Customer

Direct regulatory oversight can improve information and accountability at the systemic-provider layer. It still does not prove that an individual customer’s implementation is resilient.

The firm needs its own evidence for questions such as:

  • whether production and backup environments share a hidden control plane, identity service, region, or network dependency;
  • whether customer-managed configuration caused a vulnerability that sits outside the provider’s service commitment;
  • whether recovery tests used realistic data volumes, credentials, dependencies, and decision makers;
  • whether failover preserved security, transaction integrity, and customer communications rather than merely restoring compute;
  • whether logs and incident details arrive soon enough for the firm’s own regulatory analysis;
  • whether a substitute service can be activated without incompatible data formats, licensing limits, or untested manual work;
  • whether the contract gives the firm evidence it can actually use; and
  • whether management accepted any residual concentration risk with a defined review trigger.

An assurance report, provider exercise, or regulator statement can support that file. None automatically closes a customer-specific gap. Preserve the evidence source, period, scope, exclusions, reviewer, and action taken so the board can see what was tested—and what was not.

Reassess When the Dependency Changes

Do not let designation mapping become an annual checkbox. Trigger a review when the contracting entity changes, a service moves region, a critical function is added, a material subcontractor changes, recovery architecture is redesigned, an incident challenges an assumption, or the provider changes a relevant service term.

The review should identify the affected important business service, update concentration and exit analysis, test whether existing assurance still covers the deployment, and record any management acceptance. If no control changes, preserve the evidence supporting that conclusion. This trigger-based workflow is a risk-management recommendation; the firm’s applicable rules and contracts determine the exact required action.

Retain the prior and revised crosswalk so reviewers can reconstruct the decision.

PS26/2 Is a Separate March 2027 Workstream

The FCA’s PS26/2 policy statement says the operational-incident and third-party reporting rules apply from March 18, 2027.

Do not describe those firm-level requirements as having taken effect with the July 2026 designations. Maintain a separate implementation record covering scope, data ownership, material-third-party records, reporting triggers, submission governance, quality checks, and readiness testing.

A practical sequence is:

  1. identify in-scope regulated entities;
  2. reconcile third-party records across procurement, TPRM, resilience, security, and finance;
  3. assign owners for each required field;
  4. test incident escalation and submission decisions; and
  5. obtain governance sign-off before the application date.

Contract Changes Are Fact-Specific

The CTP designations do not automatically rewrite a customer’s cloud agreement. Contract actions should be tied to the firm’s applicable rules, service criticality, current terms, and tested operational need.

Useful review questions include:

  • Can the firm obtain information needed for its own incident and regulatory decisions?
  • Do audit, access, and cooperation terms match applicable law and the service model?
  • Are subcontractors and material locations visible enough for concentration analysis?
  • Are recovery commitments measurable and testable?
  • Is transition assistance detailed enough to support a realistic exit?
  • Do liability, suspension, and termination clauses undermine the continuity strategy?

These are risk-based contract recommendations unless a cited rule imposes a specific term on the firm.

The U.S. Comparison Needs Precision

The UK regime creates a named, cross-sector designation and oversight framework for providers judged systemically important to UK financial services. The United States does not use that same designation architecture.

But U.S. federal banking agencies are not limited to examining only the bank’s four walls. The Bank Service Company Act provision at 12 U.S.C. § 1867(c) provides examination and regulatory authority over covered services performed for depository institutions, to the same extent as if the institution performed the services itself.

A careful comparison is therefore:

United KingdomUnited States
Named CTP designation based on potential systemic impactStatutory examination authority tied to services performed for regulated depository institutions
Joint Bank/PRA/FCA oversight frameworkAuthority allocated to the appropriate federal banking agency
Cross-firm systemic-service focusBank-service and supervisory nexus

Neither model relieves the financial institution of its own third-party-risk responsibilities.

So What?

For UK-regulated firms, the immediate task is not to outsource resilience to the new CTP supervisors. Confirm the designated legal entities in the dependency map, keep firm-level controls operating, and build PS26/2 readiness for March 18, 2027.

For U.S. institutions, use the UK development as a concentration-risk signal without claiming that U.S. agencies have no provider-examination authority.

The Third-Party Risk Management Kit can structure inventory, due diligence, concentration, monitoring, and exit evidence. Contract and control decisions still require entity-specific legal and operational review.


Primary sources: UK designation regulation | Bank of England designation announcement | PS24/16 CTP rules | PS26/2 reporting policy | 12 U.S.C. § 1867

◆ Need the working template?

Start with the source guide.

These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.

◆ Immaterial Findings · Weekly

Sharp risk & compliance insights. No fluff.

◆ FAQ

Frequently asked questions.

Which providers became UK critical third parties in July 2026?
The designation regulation names Amazon Web Services EMEA SARL, Google Cloud EMEA Limited, Microsoft Ireland Operations Limited, and Oracle Corporation UK Limited. The designations took effect on July 13, 2026. Use the legal entities in the regulation rather than treating every affiliate or product as separately designated.
What does designation do?
Designation brings the named critical third parties within direct oversight by the Bank of England, PRA, and FCA for the systemic third-party services covered by the regime. The regulators' PS24/16 framework sets rules and expectations for resilience, risk management, testing, incident handling, information, and regulatory cooperation.
Does direct oversight replace a financial firm's outsourcing duties?
No. A firm's due diligence, outsourcing, operational-resilience, concentration, contract, register, incident, and exit responsibilities continue as applicable. Provider oversight does not transfer accountability for the firm's important business services.
When does PS26/2 apply?
The FCA and PRA state that the operational-incident and third-party reporting policy in PS26/2 applies from March 18, 2027. It is separate from the July 2026 critical-third-party designations and should have its own implementation plan.
Does the United States lack authority to examine bank service providers?
No. Under 12 U.S.C. § 1867(c), services performed for a depository institution can be subject to regulation and examination by the appropriate federal banking agency to the same extent as if the institution performed them itself. That authority is not identical to the UK's cross-sector designation regime, but it makes a blanket 'no U.S. direct oversight' comparison inaccurate.
Rebecca Leung

Author

Rebecca Leung

Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.

◆ Related framework

Third-Party Risk Management (TPRM) Kit

Complete vendor risk management lifecycle from initial due diligence to ongoing oversight.

Immaterial Findings · Newsletter

The brief, in your inbox.

Enforcement of the week, a framework breakdown, and the prompts that are actually worth running. Delivered to your inbox. Free.