ABGALIS Position Brief · Paper 06 · 2026

When the Supplier
Becomes the Systemic Risk

On 13 July 2026 the UK designated four cloud providers as Critical Third Parties. For insurers and reinsurers this is not an IT story — it is an operational-risk, capital and board-reporting story.

Operational ResilienceConcentrationORSA

What changed on 13 July

HM Treasury designated four cloud providers as Critical Third Parties (CTPs) to the UK financial system: Amazon Web Services EMEA SARL, Microsoft Ireland Operations Limited, Google Cloud EMEA Limited and Oracle Corporation UK Limited. It is the first use of the designation power created by the Financial Services and Markets Act 2023, and it moves a familiar concentration into a new regulatory category. The providers most of the sector already depends on are now, formally, part of the sector's supervised perimeter — overseen directly by the Bank of England, the Prudential Regulation Authority and the Financial Conduct Authority.

The designation does not, by itself, impose new obligations on regulated firms. It creates a supervised relationship between the regulators and the four providers. Under the CTP oversight regime — finalised in PS16/24 on 12 November 2024 and commenced in January 2025 — the regulators can now gather information from a designated CTP, assess its resilience arrangements, and make and enforce CTP-specific rules. The framework rests on two pillars: a set of CTP Fundamental Rules (conduct-level expectations), and Operational Risk and Resilience Requirements covering dependency and supply-chain mapping, "key Nth-party" subcontractors, self-assessment, scenario testing and incident-playbook exercises, with results shared with both regulators and firms.

Broader than DORA, and it leaves your contracts to you

Two design choices matter. First, the UK regime is technology-neutral — a CTP can be any critical supplier, not only an ICT one — which is broader than the EU's DORA, whose oversight framework is confined to ICT third parties. Second, unlike DORA, the UK regime does not mandate specific contractual terms between the CTP and the firms that use it. The regulators supervise the provider's resilience; they do not rewrite your outsourcing contracts. The duty to map the dependency, test it and price its failure stays with the firm.

Why the concentration is the point

The rationale is not abstract. A 2024 Bank of England / FCA survey found that Microsoft, Google and Amazon between them accounted for roughly 73% of UK financial-sector cloud services. That is the concentration a designation regime exists to address: when a supermajority of firms rely on a handful of suppliers, a single provider's outage stops being one firm's operational incident and becomes a correlated, sector-wide event. The failure mode is not "a vendor is unreliable" — these are among the most reliable operators in the economy — but "everyone fails in the same place at the same time, and no one can fail over, because the alternatives are the other three designated firms."

This is the cross-domain transmission problem in a single, unusually legible example. Operational resilience, third-party risk and systemic concentration are usually modelled as separate exposures. Here they are the same exposure wearing three labels. A CTP outage during a peak-claims period — a windstorm, a flood, a cyber-accumulation event — would land operational disruption and underwriting stress on the balance sheet simultaneously, through the same node. That correlation is exactly what a single-domain view misses.

The insurer's residual obligations did not go away

It would be a mistake to read the designation as the regulators taking the problem off firms' desks. The opposite is closer to the truth. Firms relying on a designated CTP still have to:

  1. Assess and document the outsourcing arrangement — due diligence, materiality assessment, exit and substitutability analysis — under existing PRA and FCA outsourcing and operational-resilience expectations.
  2. Notify regulators before entering into, or materially changing, an important outsourcing or third-party arrangement.
  3. Maintain a Register of Information on material third-party arrangements and submit it annually, aligned to the incident and third-party reporting framework the Bank confirmed in PS7/26 (March 2026).
  4. Ensure contracts enable timely incident information to be received, so the firm can meet its own reporting timelines when the CTP has an event.

Four gaps to close now

ActionWhat it means in practice
Map to the named entitiesResolve resilience mapping to AWS EMEA SARL, Microsoft Ireland Operations Ltd, Google Cloud EMEA Ltd and Oracle Corporation UK Ltd — including where they sit inside your key Nth-party chain. Concentration hides one layer down.
Scenario-test a CTP outageModel a multi-hour to multi-day outage of your primary provider, timed to a peak-claims or renewal window. If your failover target is a second designated CTP, that is a concentration, not a mitigation.
Carry it into the ORSATreat CTP concentration as a named, quantified operational-risk scenario with a capital or management-action consequence — not a paragraph of assurance. Make the correlation with underwriting stress visible to the board.
Give the board the numberDirectors should be able to answer, in one line: what share of our critical services depends on a single CTP, and what happens on day two of an outage? If that number is not reported, fix that first.

The designation is a signal that the regulators now regard cloud concentration as a matter of financial stability, not procurement. Firms that already model third-party failure as a transmission channel — rather than a line item in an IT risk register — will find the news changes little except the supervisory attention it attracts. Firms that don't have roughly eighteen months of regulatory momentum, and one clearly worded 73% statistic, telling them where to start.

Read the full paper (PDF)

The full Position Brief covers the regime framework, the DORA contrast, the cross-domain reading, and the four gaps to close now. Abgalis maps how a single shock — a CTP outage among them — moves across the seven domains of an insurer's risk, and where it lands on capital.

Abgalis Limited · London · [email protected]
Abgalis, Abgalis Engine, ICRIP and the seven-domain framework are trademarks of Abgalis Limited, with associated UK and PCT patent filings. This briefing is general thought leadership and does not constitute legal, regulatory, actuarial, investment or compliance advice.