Skip to content

Critical Third Parties (CTPs): UK regulators introduce direct oversight of systemic providers

POSTED BY
false
Critical Third Parties (CTPs): UK regulators introduce direct oversight of systemic providers
3:50

Over the past few years, the UK regulatory authorities have been developing a framework to introduce direct oversight of Critical Third Parties (CTPs) supplying the financial services sector, aiming to address the systemic risks that stem from firms’ concentrated dependence on them. In this article, we explain how the framework operates, its role in addressing systemic third-party risk and what it means for financial services firms. 

What has the UK announced on CTPs?

In July 2026, HM Treasury announced the designation of the first CTPs, marking an important milestone in the implementation of the UKs new regulatory oversight framework. This announcement brings Amazon Web Services EMEA SARL, Google Cloud EMEA, Microsoft Ireland Operations and Oracle Corporation UK under direct oversight by the Bank of England, Financial Conduct Authority (FCA) and Prudential Regulation Authority (PRA).  

The framework focuses only on CTP services that are deemed systemic, meaning their disruption could threaten the stability or confidence of the UK financial system. It gives the regulators direct oversight of those services as well as their critical dependencies, creating a new layer of resilience supervision beyond individual firms.

Rubber stamp icon in dark blue with cyan dots

FSMA 2023

Introduced the statutory basis for the UK CTP framework, including HM Treasury designation powers and regulatory authority relating to rules and oversight. 

Tick_Cyan

CTP oversight framework finalised

The FCA, PRA, and BoE published finalised rules and supervisory expectations for designated CTPs. 

Dark blue flag icon

First CTPs designated

HM Treasury designated the first CTPs, bringing four major cloud and technology providers under direct regulatory oversight. 

 
How does the UK CTP framework build on existing regulation?

The designation of the first CTPs marks the practical implementation of a framework that has been under development for several years. It reflects a broader regulatory trend towards direct oversight of critical service providers, similar to initiatives such as the EU's Digital Operational Resilience Act (DORA).

How CTP oversight helps address systemic third-party risk

The designation of the first CTPs recognises a growing challenge for the financial sector, as some third-party risks cannot be fully understood or managed by individual firms acting alone.

Our work with members on third-party risk management has consistently highlighted the difficulties firms face in assessing systemic concentration risks, particularly where many organisations rely on the same small group of service providers. While firms can manage their own relationships, they have limited visibility of vulnerabilities that exist across the wider ecosystem. 

Direct regulatory oversight helps address this gap by creating a sector-wide view of resilience, enabling earlier identification of vulnerabilities and supporting more coordinated responses to disruptions that could affect multiple firms simultaneously. 

“Whereas this framework does not replace firms’ third-party risk management responsibilities, it does reflect the need for regulators to be involved in overseeing third-party dependency risk at the systemic level. It’s encouraging to see this step forward that will hopefully strengthen resilience across the financial sector.”

Steve Bishop, Research & Information Director, ORX

 

What does it mean for financial services firms? 

The framework is designed to complement, not replace, firms' existing third-party risk management responsibilities. 

Firms remain responsible for activities such as due diligence, ongoing monitoring, supplier governance, resilience testing, contingency planning, and incident response. The new framework does not transfer accountability from firms to regulators. 

Instead, it gives regulators and, by extension, firms greater visibility into the resilience of critical services and creates direct channels for information sharing, coordination and engagement with designated providers. 

What happens next for CTP oversight in the UK?

The designation of the first CTPs is an important milestone in the evolution of systemic third-party risk management. While the long-term impact will become clearer as the framework matures, it represents a significant step towards addressing resilience risks closer to their source. 

We will continue to monitor developments in this area and engage with members to understand how the framework is evolving in practice and what it means for third-party risk management and operational resilience.