Feature Business Continuity
The UK Just Put AWS, Azure, Google Cloud, and Oracle Under Direct Financial Regulatory Oversight. Here's What US Financial Services Needs to Build for Cloud Concentration Risk.
On July 13, 2026, the UK's Critical Third Parties regime went live with four cloud hyperscalers designated under direct FCA/PRA oversight. The US interagency TPRM proposed guidance addresses the same concentration risk. Here's what your business continuity and vendor risk programs need to do.
Table of Contents
TL;DR
- On July 13, 2026, the UK’s Critical Third Parties regime went live with AWS, Microsoft Azure, Google Cloud, and Oracle under direct oversight by the Bank of England, FCA, and PRA.
- The UK now has direct intervention tools — including compelling cloud providers to supply information, undergo resilience assessments, and address identified risk to service continuity.
- US firms aren’t insulated: any US institution with UK operations has direct obligations; US regulators are signaling they’ll move in the same direction.
- Your business continuity program needs cloud concentration risk scenarios, documented exit strategies, and tested RTO/RPO targets for cloud-dependent critical systems — not just vendor questionnaire checkboxes.
Most financial institutions have a vendor questionnaire for their cloud provider. Very few have tested what happens when that provider goes down for three days.
That gap — between “we have a TPRM process” and “we actually know we can survive a cloud outage” — is exactly what regulators on both sides of the Atlantic started closing in July 2026.
What Happened on July 13, 2026
On July 10, 2026, HM Treasury published designations under the UK’s Critical Third Parties (CTP) regime, a framework created under the Financial Services and Markets Act 2023 that went live in January 2025. Four cloud hyperscalers were named:
- Amazon Web Services EMEA SARL
- Google Cloud EMEA Limited
- Microsoft Ireland Operations Ltd
- Oracle Corporation UK Limited
The designations took effect July 13, 2026. As of that date, each provider sits under joint supervision from the Bank of England, the Prudential Regulation Authority (PRA), and the Financial Conduct Authority (FCA) — specifically covering the systemic services these companies provide to UK-regulated banks, insurers, and financial market infrastructures.
This isn’t the same as becoming a regulated financial institution. AWS, Azure, Google Cloud, and Oracle remain outside the authorisation regime that applies to banks and insurers. But the Bank of England, PRA, and FCA now have direct intervention tools: compelling designated providers to hand over information, conducting resilience assessments, requiring remediation of identified risks to service continuity, and issuing CTP-specific binding rules.
The six fundamental rules that CTPs must now follow track the same high-level principles UK-regulated financial firms already operate under — but applied directly to the cloud providers themselves. This is a structural intervention in the cloud supply chain for financial services.
Why This Matters to US Financial Services Teams
There are two distinct reasons US compliance and risk teams need to pay attention.
Your UK Operations Have Direct Obligations
Any US financial institution with a UK-regulated subsidiary, FCA-authorized entity, or PRA-supervised insurer has already been operating under the UK’s framework for managing critical third-party relationships. The CTP designation formalizes and escalates that framework.
Under the CTP regime, UK-regulated firms are expected to manage their relationship with designated providers in a manner consistent with the new supervisory expectations — which means contract provisions, monitoring programs, and resilience testing requirements that align with what the Bank of England, PRA, and FCA are now directly assessing at the cloud provider level. If your UK operations haven’t updated their cloud vendor governance since January 2025 when the CTP regime launched, the July designations make that overdue.
US Regulation Is Moving in the Same Direction
The interagency TPRM proposed guidance published September 11, 2026 by the OCC, Federal Reserve, FDIC, and NCUA introduces a harm-based proportionate oversight standard. The proposed framework explicitly weights “magnitude and likelihood of harm” — and harm at industry scale from a single cloud provider outage is exactly the scenario that harm-based analysis produces.
OCC’s Spring 2026 Semiannual Risk Perspective flagged elevated operational risk from technology concentration. The OCC’s June 2026 Cybersecurity Report found that documented controls without demonstrated, tested capability no longer satisfy examiner expectations. Both statements point in the same direction: examiners are moving from “do you have a plan?” to “did you test it against a real cloud outage scenario?”
The EU’s DORA framework, enforceable since January 2025, requires explicit ICT concentration risk assessments for EU-regulated entities. US financial institutions operating in the EU are already subject to this framework. The UK CTP designation is a parallel mechanism reaching the same cloud providers through a different regulatory lever.
The Concentration Math
The cloud market is structurally concentrated, and the financial sector is structurally dependent on it.
AWS holds approximately 32% of global cloud market share. Microsoft Azure holds around 23%. Google Cloud holds approximately 12%. Together, three providers control more than two-thirds of the market that most of the financial services industry has migrated its critical systems into.
A six-hour AWS us-east-1 outage in July 2012 took down Netflix, Instagram, Pinterest, and major portions of the internet. In a financial services context, a sustained outage — 24 to 72 hours — of a major cloud region would simultaneously impair dozens of financial institutions running core banking, payment processing, fraud detection, and risk management systems on the same infrastructure.
This is the macroprudential concern regulators are addressing. When individual institutions each make rational vendor decisions — AWS is reliable, cost-effective, well-supported — and each follows reasonable TPRM procedures, the aggregate result is a systemic single point of failure. The UK CTP regime is the first direct regulatory intervention in that dynamic. It won’t be the last.
What’s Missing from Most BCP Programs
The gap in most financial services business continuity programs isn’t a lack of documentation. It’s a lack of cloud-specific scenario coverage and tested exit capability.
A cloud concentration risk scenario in a BCP needs to address:
Scope of dependency: What critical business services depend on your primary cloud provider? For most fintechs, this is a long list: core application hosting, data storage, analytics pipelines, payment processing integrations, identity services, monitoring and alerting systems. A realistic dependency map is the starting point — not the abbreviated list that shows up in vendor questionnaires.
RTO and RPO for cloud-dependent systems: Recovery time and recovery point objectives set in the abstract become meaningless if they’re never tested against a scenario where the cloud provider itself is unavailable. If your RTO is 4 hours but your failover capability depends on spinning up instances in the same provider’s secondary region, you may not actually have a 4-hour RTO.
Exit strategy and portability: Documented exit plans are a standard TPRM deliverable. Tested exit plans are rare. Cloud portability is genuinely difficult: data egress costs are real, committed-spend arrangements create switching penalties, and most organizations discover their architecture is more provider-specific than their migration plan assumed. The exit strategy in your TPRM documentation should reflect whether you’ve actually attempted to move a representative workload.
Multi-cloud or hybrid strategy: Not every organization can achieve true multi-cloud redundancy — the cost and complexity are significant. But most organizations can identify their highest-criticality services and implement provider diversity for those specific systems. The UK CTP framework implicitly encourages this; US regulators are moving toward explicitly requiring it for critical services.
What Your Program Needs to Add
The operational resilience vs. business continuity regulatory shift over the past several years has changed what regulators expect from BCP programs. The BCBS 2021 principles, UK PS6/21, and DORA all moved toward a “within impact tolerances” standard: not “do you have a recovery plan,” but “can you demonstrate that critical services remain within your defined tolerance levels when a severe disruption occurs.”
Applied to cloud concentration risk, that framework produces three specific additions to a mature BCP:
1. Cloud provider outage scenarios in your tabletop exercise calendar. The standard tabletop exercise menu — datacenter fire, ransomware, key employee loss — needs a cloud provider extended outage scenario. Run it against your most cloud-dependent critical service. Map what goes dark, what stays available, what your workaround is, and at what point operations become genuinely impaired.
2. Concentration risk assessment in your TPRM program. Under the proposed US interagency guidance, concentration risk — having multiple services dependent on the same provider — is a risk factor that should affect how you assess the overall magnitude of harm from that relationship. This is a calculation your current TPRM program may not be making explicitly.
3. Updated contract provisions for cloud CTP relationships. The UK CTP framework creates new regulatory expectations for how UK-regulated firms manage their contracts with designated providers. Even if you don’t have UK operations, updating cloud provider contracts to include resilience testing evidence sharing, incident notification timelines, and exit facilitation provisions is now industry practice, not competitive advantage.
The Business Continuity & Disaster Recovery Kit includes cloud provider outage scenario templates, an RTO/RPO testing framework, and concentration risk assessment checklists built for financial services BCP programs that need to catch up to where examiner expectations have landed.
”So What?” — The Near-Term Work
The UK CTP regime is the first time cloud providers themselves have been brought under direct financial regulatory oversight. US regulators are tracking this closely and moving toward the same destination through a different path — the proposed interagency TPRM guidance’s harm-based standard is explicitly designed to capture concentration risk of exactly this type.
The near-term priority list for financial services BCP and TPRM teams:
Immediate:
- Map your cloud dependency by service and by provider — which critical business services run on which cloud platforms
- Identify where your BCP RTO/RPO assumptions depend on accessing the same provider’s secondary resources (a different region of the same cloud is still concentrated risk)
- Review whether your most recent tabletop exercise included a cloud provider outage scenario
30–60 days:
- Add at least one cloud provider extended-outage scenario to your next tabletop exercise
- Update your TPRM concentration risk documentation to reflect multi-service dependency on a single cloud provider
- If you have UK operations, review cloud contracts against the CTP framework expectations; if you have EU operations, confirm your DORA concentration risk assessment is current
60–90 days:
- Document your tested exit strategy for your highest-criticality cloud-dependent services
- Submit comments on the US interagency TPRM proposed guidance (comment period closes November 16, 2026) if your organization has views on how concentration risk should be assessed under the harm-based standard
The UK designated four cloud providers in July. The question for US financial services BCP programs isn’t whether this concentration risk is real — it’s whether your program documents that you’ve thought it through.
Sources
- Data Center Dynamics: UK Treasury designates hyperscalers as Critical Third Parties
- Pinsent Masons: Cloud provider designations bring UK CTP regime to life
- Gresham: DORA in 2026 — why cloud resilience defines compliance
- Microsoft: Strengthening operational resilience and reducing concentration risk
- Arnold & Porter: Federal agencies shift TPRM toward tailored risk-based approach
◆ Need the working template?
Start with the source guide.
These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.
◆ Related template
Business Continuity & Disaster Recovery (BCP/DR) Kit
BCP and DR templates with BIA, recovery procedures, and a standalone tabletop exercise kit.
◆ Immaterial Findings · Weekly
Sharp risk & compliance insights. No fluff.
◆ FAQ
Frequently asked questions.
What did the UK designate on July 13, 2026?
Does the UK CTP regime affect US-based financial institutions?
What is cloud concentration risk and why do examiners care?
What should US financial institutions include in their BCP for cloud provider outages?
What US regulatory guidance addresses cloud concentration risk?
How does DORA relate to cloud concentration risk for US financial institutions?
Author
Rebecca Leung
Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.
◆ Related framework
Business Continuity & Disaster Recovery (BCP/DR) Kit
BCP and DR templates with BIA, recovery procedures, and a standalone tabletop exercise kit.
◆ Keep reading
Related posts.
Business Continuity
The OCC's 2026 Cybersecurity Report Changed the Standard. Documenting Controls Isn't Enough Anymore.
The OCC's June 2026 Cybersecurity and Financial System Resilience Report shifts examiner expectations from control documentation to demonstrated, tested capability. Here is what that means for your program.
Sep 19, 2026
Business Continuity
AWS Went Down in October. Most BCPs Assumed It Wouldn't. Here's How to Fix That.
The October 2025 AWS DNS outage knocked out DynamoDB endpoints across multiple regions. Most financial institution BCPs treat cloud infrastructure as a given, not a dependency to plan around. Here's what FFIEC and DORA actually require — and what cloud-aware recovery planning looks like.
Sep 12, 2026
Business Continuity
Your BCP Is a Document. The FFIEC BCM Booklet Wants a Management Process. Here's What Examiners Are Testing.
The FFIEC Business Continuity Management booklet shifted the examination standard from recovery planning to operational resilience — but most fintechs and community banks still have a document, not a management process. Here are the seven BCM components, the most common examination findings, and what a defensible program actually looks like.
Sep 7, 2026