---
title: "When the Supplier Becomes the Systemic Risk: the UK's Cloud Designations and What They Change for Insurers"
source_url: https://abgalis.com/papers/uk-critical-third-parties-cloud-concentration
canonical: https://abgalis.com/papers/uk-critical-third-parties-cloud-concentration
description: "Abgalis Paper 06 — the UK"
publisher: Abgalis Limited
author: Abgalis Research
date_published: 2026-07-15
date_modified: 2026-07-15
keywords: ["critical third parties", "cloud concentration", "operational resilience", "FSMA 2023", "PS16/24", "DORA", "ORSA", "systemic risk", "insurers"]
retrieved: 2026-08-01
content_signal: search=yes, ai-input=yes, ai-train=no
citation: "Abgalis Research, 'When the Supplier Becomes the Systemic Risk: the UK's Cloud Designations and What They Change for Insurers', Abgalis Limited, https://abgalis.com/papers/uk-critical-third-parties-cloud-concentration"
license_note: >-
  May be quoted and cited in AI-generated answers with attribution to the author named
  above and a link to source_url. Not licensed for model training or fine-tuning
  (ai-train=no; Art. 4 reservation, EU Directive 2019/790).
---
ABGALIS Position Brief · Paper 06 · 2026

# When the Supplier *Becomes the Systemic Risk*

On 13 July 2026 the UK designated four cloud providers as Critical Third Parties. For insurers and reinsurers this is not an IT story — it is an operational-risk, capital and board-reporting story.

Operational Resilience · Concentration · ORSA ·

## What changed on 13 July

HM Treasury designated four cloud providers as Critical Third Parties (CTPs) to the UK financial system: Amazon Web Services EMEA SARL, Microsoft Ireland Operations Limited, Google Cloud EMEA Limited and Oracle Corporation UK Limited. It is the first use of the designation power created by the Financial Services and Markets Act 2023, and it moves a familiar concentration into a new regulatory category. The providers most of the sector already depends on are now, formally, part of the sector's supervised perimeter — overseen directly by the Bank of England, the Prudential Regulation Authority and the Financial Conduct Authority.

The designation does not, by itself, impose new obligations on regulated firms. It creates a supervised relationship between the regulators and the four providers. Under the CTP oversight regime — finalised in **PS16/24** on 12 November 2024 and commenced in January 2025 — the regulators can now gather information from a designated CTP, assess its resilience arrangements, and make and enforce CTP-specific rules. The framework rests on two pillars: a set of **CTP Fundamental Rules** (conduct-level expectations), and **Operational Risk and Resilience Requirements** covering dependency and supply-chain mapping, "key Nth-party" subcontractors, self-assessment, scenario testing and incident-playbook exercises, with results shared with both regulators and firms.

### Broader than DORA, and it leaves your contracts to you

Two design choices matter. First, the UK regime is **technology-neutral** — a CTP can be any critical supplier, not only an ICT one — which is broader than the EU's DORA, whose oversight framework is confined to ICT third parties. Second, unlike DORA, the UK regime **does not mandate specific contractual terms** between the CTP and the firms that use it. The regulators supervise the provider's resilience; they do not rewrite your outsourcing contracts. The duty to map the dependency, test it and price its failure stays with the firm.

## Why the concentration is the point

The rationale is not abstract. A 2024 Bank of England / FCA survey found that Microsoft, Google and Amazon between them accounted for roughly **73% of UK financial-sector cloud services**. That is the concentration a designation regime exists to address: when a supermajority of firms rely on a handful of suppliers, a single provider's outage stops being one firm's operational incident and becomes a correlated, sector-wide event. The failure mode is not "a vendor is unreliable" — these are among the most reliable operators in the economy — but "everyone fails in the same place at the same time, and no one can fail over, because the alternatives are the other three designated firms."

This is the cross-domain transmission problem in a single, unusually legible example. Operational resilience, third-party risk and systemic concentration are usually modelled as separate exposures. Here they are the same exposure wearing three labels. A CTP outage during a peak-claims period — a windstorm, a flood, a cyber-accumulation event — would land operational disruption and underwriting stress on the balance sheet simultaneously, through the same node. That correlation is exactly what a single-domain view misses.

## The insurer's residual obligations did not go away

It would be a mistake to read the designation as the regulators taking the problem off firms' desks. The opposite is closer to the truth. Firms relying on a designated CTP still have to:

1. **Assess and document the outsourcing arrangement** — due diligence, materiality assessment, exit and substitutability analysis — under existing PRA and FCA outsourcing and operational-resilience expectations.

2. **Notify regulators** before entering into, or materially changing, an important outsourcing or third-party arrangement.

3. **Maintain a Register of Information** on material third-party arrangements and submit it annually, aligned to the incident and third-party reporting framework the Bank confirmed in **PS7/26** (March 2026).

4. **Ensure contracts enable timely incident information** to be received, so the firm can meet its own reporting timelines when the CTP has an event.

## Four gaps to close now

| Action | What it means in practice |

| --- | --- |

| Map to the named entities | Resolve resilience mapping to AWS EMEA SARL, Microsoft Ireland Operations Ltd, Google Cloud EMEA Ltd and Oracle Corporation UK Ltd — including where they sit inside your key Nth-party chain. Concentration hides one layer down. |

| Scenario-test a CTP outage | Model a multi-hour to multi-day outage of your primary provider, timed to a peak-claims or renewal window. If your failover target is a second designated CTP, that is a concentration, not a mitigation. |

| Carry it into the ORSA | Treat CTP concentration as a named, quantified operational-risk scenario with a capital or management-action consequence — not a paragraph of assurance. Make the correlation with underwriting stress visible to the board. |

| Give the board the number | Directors should be able to answer, in one line: what share of our critical services depends on a single CTP, and what happens on day two of an outage? If that number is not reported, fix that first. |

The designation is a signal that the regulators now regard cloud concentration as a matter of financial stability, not procurement. Firms that already model third-party failure as a transmission channel — rather than a line item in an IT risk register — will find the news changes little except the supervisory attention it attracts. Firms that don't have roughly eighteen months of regulatory momentum, and one clearly worded 73% statistic, telling them where to start.

---

**Source:** [https://abgalis.com/papers/uk-critical-third-parties-cloud-concentration](https://abgalis.com/papers/uk-critical-third-parties-cloud-concentration) · Abgalis Research, published by Abgalis Limited (England and Wales, no. 17247499)

**Cite as:** Abgalis Research, *When the Supplier Becomes the Systemic Risk: the UK's Cloud Designations and What They Change for Insurers*, Abgalis Limited. https://abgalis.com/papers/uk-critical-third-parties-cloud-concentration

**Usage:** citation with attribution permitted; model training not permitted (`ai-train=no`).

**More:** [https://abgalis.com/llms.txt](https://abgalis.com/llms.txt) · full corpus: [https://abgalis.com/llms-full.txt](https://abgalis.com/llms-full.txt)
