Skip to content
RiskTemplates · The Daily Brief Sunday, September 27, 2026
Wire OFAC Just Codified Its Penalty Playbook. What 31 CFR Part 505 Means for Your Sanctions Compliance Program. SEP 26

Feature Business Continuity

The UK Just Put AWS, Azure, Google Cloud, and Oracle Under Direct Financial Regulatory Oversight. Here's What US Financial Services Needs to Build for Cloud Concentration Risk.

On July 13, 2026, the UK's Critical Third Parties regime went live with four cloud hyperscalers designated under direct FCA/PRA oversight. The US interagency TPRM proposed guidance addresses the same concentration risk. Here's what your business continuity and vendor risk programs need to do.

By Rebecca Leung · September 22, 2026 ·
Table of Contents

TL;DR

  • On July 13, 2026, the UK’s Critical Third Parties regime went live with AWS, Microsoft Azure, Google Cloud, and Oracle under direct oversight by the Bank of England, FCA, and PRA.
  • The UK now has direct intervention tools — including compelling cloud providers to supply information, undergo resilience assessments, and address identified risk to service continuity.
  • US firms aren’t insulated: any US institution with UK operations has direct obligations; US regulators are signaling they’ll move in the same direction.
  • Your business continuity program needs cloud concentration risk scenarios, documented exit strategies, and tested RTO/RPO targets for cloud-dependent critical systems — not just vendor questionnaire checkboxes.

Most financial institutions have a vendor questionnaire for their cloud provider. Very few have tested what happens when that provider goes down for three days.

That gap — between “we have a TPRM process” and “we actually know we can survive a cloud outage” — is exactly what regulators on both sides of the Atlantic started closing in July 2026.

What Happened on July 13, 2026

On July 10, 2026, HM Treasury published designations under the UK’s Critical Third Parties (CTP) regime, a framework created under the Financial Services and Markets Act 2023 that went live in January 2025. Four cloud hyperscalers were named:

  • Amazon Web Services EMEA SARL
  • Google Cloud EMEA Limited
  • Microsoft Ireland Operations Ltd
  • Oracle Corporation UK Limited

The designations took effect July 13, 2026. As of that date, each provider sits under joint supervision from the Bank of England, the Prudential Regulation Authority (PRA), and the Financial Conduct Authority (FCA) — specifically covering the systemic services these companies provide to UK-regulated banks, insurers, and financial market infrastructures.

This isn’t the same as becoming a regulated financial institution. AWS, Azure, Google Cloud, and Oracle remain outside the authorisation regime that applies to banks and insurers. But the Bank of England, PRA, and FCA now have direct intervention tools: compelling designated providers to hand over information, conducting resilience assessments, requiring remediation of identified risks to service continuity, and issuing CTP-specific binding rules.

The six fundamental rules that CTPs must now follow track the same high-level principles UK-regulated financial firms already operate under — but applied directly to the cloud providers themselves. This is a structural intervention in the cloud supply chain for financial services.

Why This Matters to US Financial Services Teams

There are two distinct reasons US compliance and risk teams need to pay attention.

Your UK Operations Have Direct Obligations

Any US financial institution with a UK-regulated subsidiary, FCA-authorized entity, or PRA-supervised insurer has already been operating under the UK’s framework for managing critical third-party relationships. The CTP designation formalizes and escalates that framework.

Under the CTP regime, UK-regulated firms are expected to manage their relationship with designated providers in a manner consistent with the new supervisory expectations — which means contract provisions, monitoring programs, and resilience testing requirements that align with what the Bank of England, PRA, and FCA are now directly assessing at the cloud provider level. If your UK operations haven’t updated their cloud vendor governance since January 2025 when the CTP regime launched, the July designations make that overdue.

US Regulation Is Moving in the Same Direction

The interagency TPRM proposed guidance published September 11, 2026 by the OCC, Federal Reserve, FDIC, and NCUA introduces a harm-based proportionate oversight standard. The proposed framework explicitly weights “magnitude and likelihood of harm” — and harm at industry scale from a single cloud provider outage is exactly the scenario that harm-based analysis produces.

OCC’s Spring 2026 Semiannual Risk Perspective flagged elevated operational risk from technology concentration. The OCC’s June 2026 Cybersecurity Report found that documented controls without demonstrated, tested capability no longer satisfy examiner expectations. Both statements point in the same direction: examiners are moving from “do you have a plan?” to “did you test it against a real cloud outage scenario?”

The EU’s DORA framework, enforceable since January 2025, requires explicit ICT concentration risk assessments for EU-regulated entities. US financial institutions operating in the EU are already subject to this framework. The UK CTP designation is a parallel mechanism reaching the same cloud providers through a different regulatory lever.

The Concentration Math

The cloud market is structurally concentrated, and the financial sector is structurally dependent on it.

AWS holds approximately 32% of global cloud market share. Microsoft Azure holds around 23%. Google Cloud holds approximately 12%. Together, three providers control more than two-thirds of the market that most of the financial services industry has migrated its critical systems into.

A six-hour AWS us-east-1 outage in July 2012 took down Netflix, Instagram, Pinterest, and major portions of the internet. In a financial services context, a sustained outage — 24 to 72 hours — of a major cloud region would simultaneously impair dozens of financial institutions running core banking, payment processing, fraud detection, and risk management systems on the same infrastructure.

This is the macroprudential concern regulators are addressing. When individual institutions each make rational vendor decisions — AWS is reliable, cost-effective, well-supported — and each follows reasonable TPRM procedures, the aggregate result is a systemic single point of failure. The UK CTP regime is the first direct regulatory intervention in that dynamic. It won’t be the last.

What’s Missing from Most BCP Programs

The gap in most financial services business continuity programs isn’t a lack of documentation. It’s a lack of cloud-specific scenario coverage and tested exit capability.

A cloud concentration risk scenario in a BCP needs to address:

Scope of dependency: What critical business services depend on your primary cloud provider? For most fintechs, this is a long list: core application hosting, data storage, analytics pipelines, payment processing integrations, identity services, monitoring and alerting systems. A realistic dependency map is the starting point — not the abbreviated list that shows up in vendor questionnaires.

RTO and RPO for cloud-dependent systems: Recovery time and recovery point objectives set in the abstract become meaningless if they’re never tested against a scenario where the cloud provider itself is unavailable. If your RTO is 4 hours but your failover capability depends on spinning up instances in the same provider’s secondary region, you may not actually have a 4-hour RTO.

Exit strategy and portability: Documented exit plans are a standard TPRM deliverable. Tested exit plans are rare. Cloud portability is genuinely difficult: data egress costs are real, committed-spend arrangements create switching penalties, and most organizations discover their architecture is more provider-specific than their migration plan assumed. The exit strategy in your TPRM documentation should reflect whether you’ve actually attempted to move a representative workload.

Multi-cloud or hybrid strategy: Not every organization can achieve true multi-cloud redundancy — the cost and complexity are significant. But most organizations can identify their highest-criticality services and implement provider diversity for those specific systems. The UK CTP framework implicitly encourages this; US regulators are moving toward explicitly requiring it for critical services.

What Your Program Needs to Add

The operational resilience vs. business continuity regulatory shift over the past several years has changed what regulators expect from BCP programs. The BCBS 2021 principles, UK PS6/21, and DORA all moved toward a “within impact tolerances” standard: not “do you have a recovery plan,” but “can you demonstrate that critical services remain within your defined tolerance levels when a severe disruption occurs.”

Applied to cloud concentration risk, that framework produces three specific additions to a mature BCP:

1. Cloud provider outage scenarios in your tabletop exercise calendar. The standard tabletop exercise menu — datacenter fire, ransomware, key employee loss — needs a cloud provider extended outage scenario. Run it against your most cloud-dependent critical service. Map what goes dark, what stays available, what your workaround is, and at what point operations become genuinely impaired.

2. Concentration risk assessment in your TPRM program. Under the proposed US interagency guidance, concentration risk — having multiple services dependent on the same provider — is a risk factor that should affect how you assess the overall magnitude of harm from that relationship. This is a calculation your current TPRM program may not be making explicitly.

3. Updated contract provisions for cloud CTP relationships. The UK CTP framework creates new regulatory expectations for how UK-regulated firms manage their contracts with designated providers. Even if you don’t have UK operations, updating cloud provider contracts to include resilience testing evidence sharing, incident notification timelines, and exit facilitation provisions is now industry practice, not competitive advantage.

The Business Continuity & Disaster Recovery Kit includes cloud provider outage scenario templates, an RTO/RPO testing framework, and concentration risk assessment checklists built for financial services BCP programs that need to catch up to where examiner expectations have landed.

”So What?” — The Near-Term Work

The UK CTP regime is the first time cloud providers themselves have been brought under direct financial regulatory oversight. US regulators are tracking this closely and moving toward the same destination through a different path — the proposed interagency TPRM guidance’s harm-based standard is explicitly designed to capture concentration risk of exactly this type.

The near-term priority list for financial services BCP and TPRM teams:

Immediate:

  • Map your cloud dependency by service and by provider — which critical business services run on which cloud platforms
  • Identify where your BCP RTO/RPO assumptions depend on accessing the same provider’s secondary resources (a different region of the same cloud is still concentrated risk)
  • Review whether your most recent tabletop exercise included a cloud provider outage scenario

30–60 days:

  • Add at least one cloud provider extended-outage scenario to your next tabletop exercise
  • Update your TPRM concentration risk documentation to reflect multi-service dependency on a single cloud provider
  • If you have UK operations, review cloud contracts against the CTP framework expectations; if you have EU operations, confirm your DORA concentration risk assessment is current

60–90 days:

  • Document your tested exit strategy for your highest-criticality cloud-dependent services
  • Submit comments on the US interagency TPRM proposed guidance (comment period closes November 16, 2026) if your organization has views on how concentration risk should be assessed under the harm-based standard

The UK designated four cloud providers in July. The question for US financial services BCP programs isn’t whether this concentration risk is real — it’s whether your program documents that you’ve thought it through.


Sources

◆ Need the working template?

Start with the source guide.

These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.

◆ Immaterial Findings · Weekly

Sharp risk & compliance insights. No fluff.

◆ FAQ

Frequently asked questions.

What did the UK designate on July 13, 2026?
On July 10, 2026, HM Treasury designated four cloud hyperscalers as Critical Third Parties (CTPs) under FSMA 2023: Amazon Web Services EMEA SARL, Google Cloud EMEA Limited, Microsoft Ireland Operations Ltd, and Oracle Corporation UK Limited. The designations took effect July 13, 2026. These four providers are now under joint supervision of the Bank of England, the Prudential Regulation Authority, and the Financial Conduct Authority for the systemic services they provide to UK-regulated financial institutions.
Does the UK CTP regime affect US-based financial institutions?
Yes, in two ways. First, any US financial institution with UK-regulated operations — a UK bank subsidiary, an FCA-regulated entity, or a PRA-supervised insurer — now has direct obligations tied to how it manages its cloud provider relationships. Second, the UK CTP framework is a leading indicator: the US interagency TPRM proposed guidance published September 11, 2026 addresses concentration risk from cloud dependency explicitly, and regulators on both sides of the Atlantic are converging on the same framework.
What is cloud concentration risk and why do examiners care?
Cloud concentration risk is the systemic exposure that arises when a large portion of the financial sector depends on a small number of cloud providers. AWS holds roughly 32% of global cloud market share, Azure approximately 23%, and Google Cloud around 12%. A single extended outage at any of these providers could simultaneously impair dozens or hundreds of financial institutions — a single-point-of-failure problem at industry scale. Regulators increasingly treat this as a macroprudential concern, not just an individual institution's operational risk.
What should US financial institutions include in their BCP for cloud provider outages?
Business continuity plans need to explicitly scenario-test cloud provider outages. That means modeling an extended outage (72+ hours) of your primary cloud provider, identifying which critical business services become unavailable, documenting RTO and RPO targets for cloud-dependent systems, and testing whether workarounds or secondary systems can actually sustain operations. Exit strategies — the documented ability to migrate workloads to an alternative provider — should be tested, not just described on paper.
What US regulatory guidance addresses cloud concentration risk?
The interagency TPRM proposed guidance published September 11, 2026 (OCC, Fed, FDIC, and NCUA) uses a harm-based standard that explicitly weighs concentration risk — the magnitude of harm that could arise from simultaneous failures across multiple institutions using the same provider. OCC Bulletin 2023-17 and the Spring 2026 Semiannual Risk Perspective both flag technology concentration as an elevated operational risk area. The OCC's June 2026 Cybersecurity Report found that documented controls without tested capability no longer satisfy examiner expectations.
How does DORA relate to cloud concentration risk for US financial institutions?
The EU's Digital Operational Resilience Act (DORA), which became enforceable in January 2025, imposes ICT third-party risk management requirements on financial entities operating in the EU, including explicit concentration risk reporting. US financial institutions with EU-regulated entities are subject to DORA and must conduct ICT concentration risk assessments. DORA's treatment of cloud concentration — firms remain responsible for resilience regardless of where the failure originates — mirrors what UK CTP is now doing directly with the cloud providers themselves.
Rebecca Leung

Author

Rebecca Leung

Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.

◆ Related framework

Business Continuity & Disaster Recovery (BCP/DR) Kit

BCP and DR templates with BIA, recovery procedures, and a standalone tabletop exercise kit.

Immaterial Findings · Newsletter

The brief, in your inbox.

Enforcement of the week, a framework breakdown, and the prompts that are actually worth running. Delivered to your inbox. Free.