Reflecting the financial industry’s ever-growing tech dependency, financial regulators in the U.K. are starting to oversee the handful of large tech firms that sit at the centre of the financial sector’s work.
Starting July 13, the U.K. financial regulators — the Financial Conduct Authority, the Bank of England and the Prudential Regulation Authority — will oversee Amazon, Google, Microsoft and Oracle. These are the first firms designated as “critical third parties” by the HM Treasury.
The designations reflect the fact that the services provided by these firms underpin the UK financial system.
“As many firms rely on these services, disruption or failure could affect multiple firms or markets at the same time, potentially impacting U.K. financial stability and services used by millions of consumers and businesses,” the regulators said.
The joint oversight from the financial authorities will focus on ensuring the resilience of the services the tech firms provide to the financial sector — to that end, the regulators will work with the designated firms, “to address system-level risks and reduce the risk of disruption to the services they provide spreading across the U.K. financial system.”
The new oversight arrangement for the tech giants sits alongside the existing outsourcing and operational resilience rules for regulated financial firms, the regulators noted.
“As critical third parties become increasingly embedded in the operations of financial institutions, they can introduce new forms of systemic risk. Our proportionate approach to overseeing these providers will ensure that these dependencies are managed in a way that safeguards financial stability,” said Sarah Breeden, deputy governor for financial stability at the Bank of England, in a release.
HM Treasury will be responsible for designating tech firms as critical providers that are subject to the financial regulators’ oversight — including adding firms to the list in the future. The regulators will also make recommendations about whether designated firms continue to meet the designation criteria based on periodic reviews.
The financial regulators were given new powers to oversee critical service providers under legislation first adopted in 2020, and revised in 2023 — the regulators’ rules implementing these responsibilities took effect in 2025.