On 13 July 2026 the UK designated four cloud providers as Critical Third Parties. For insurers and reinsurers this is not an IT story — it is an operational-risk, capital and board-reporting story.
Operational ResilienceConcentrationORSAHM Treasury designated four cloud providers as Critical Third Parties (CTPs) to the UK financial system: Amazon Web Services EMEA SARL, Microsoft Ireland Operations Limited, Google Cloud EMEA Limited and Oracle Corporation UK Limited. It is the first use of the designation power created by the Financial Services and Markets Act 2023, and it moves a familiar concentration into a new regulatory category. The providers most of the sector already depends on are now, formally, part of the sector's supervised perimeter — overseen directly by the Bank of England, the Prudential Regulation Authority and the Financial Conduct Authority.
The designation does not, by itself, impose new obligations on regulated firms. It creates a supervised relationship between the regulators and the four providers. Under the CTP oversight regime — finalised in PS16/24 on 12 November 2024 and commenced in January 2025 — the regulators can now gather information from a designated CTP, assess its resilience arrangements, and make and enforce CTP-specific rules. The framework rests on two pillars: a set of CTP Fundamental Rules (conduct-level expectations), and Operational Risk and Resilience Requirements covering dependency and supply-chain mapping, "key Nth-party" subcontractors, self-assessment, scenario testing and incident-playbook exercises, with results shared with both regulators and firms.
Two design choices matter. First, the UK regime is technology-neutral — a CTP can be any critical supplier, not only an ICT one — which is broader than the EU's DORA, whose oversight framework is confined to ICT third parties. Second, unlike DORA, the UK regime does not mandate specific contractual terms between the CTP and the firms that use it. The regulators supervise the provider's resilience; they do not rewrite your outsourcing contracts. The duty to map the dependency, test it and price its failure stays with the firm.
The rationale is not abstract. A 2024 Bank of England / FCA survey found that Microsoft, Google and Amazon between them accounted for roughly 73% of UK financial-sector cloud services. That is the concentration a designation regime exists to address: when a supermajority of firms rely on a handful of suppliers, a single provider's outage stops being one firm's operational incident and becomes a correlated, sector-wide event. The failure mode is not "a vendor is unreliable" — these are among the most reliable operators in the economy — but "everyone fails in the same place at the same time, and no one can fail over, because the alternatives are the other three designated firms."
This is the cross-domain transmission problem in a single, unusually legible example. Operational resilience, third-party risk and systemic concentration are usually modelled as separate exposures. Here they are the same exposure wearing three labels. A CTP outage during a peak-claims period — a windstorm, a flood, a cyber-accumulation event — would land operational disruption and underwriting stress on the balance sheet simultaneously, through the same node. That correlation is exactly what a single-domain view misses.
It would be a mistake to read the designation as the regulators taking the problem off firms' desks. The opposite is closer to the truth. Firms relying on a designated CTP still have to:
| Action | What it means in practice |
|---|---|
| Map to the named entities | Resolve resilience mapping to AWS EMEA SARL, Microsoft Ireland Operations Ltd, Google Cloud EMEA Ltd and Oracle Corporation UK Ltd — including where they sit inside your key Nth-party chain. Concentration hides one layer down. |
| Scenario-test a CTP outage | Model a multi-hour to multi-day outage of your primary provider, timed to a peak-claims or renewal window. If your failover target is a second designated CTP, that is a concentration, not a mitigation. |
| Carry it into the ORSA | Treat CTP concentration as a named, quantified operational-risk scenario with a capital or management-action consequence — not a paragraph of assurance. Make the correlation with underwriting stress visible to the board. |
| Give the board the number | Directors should be able to answer, in one line: what share of our critical services depends on a single CTP, and what happens on day two of an outage? If that number is not reported, fix that first. |
The designation is a signal that the regulators now regard cloud concentration as a matter of financial stability, not procurement. Firms that already model third-party failure as a transmission channel — rather than a line item in an IT risk register — will find the news changes little except the supervisory attention it attracts. Firms that don't have roughly eighteen months of regulatory momentum, and one clearly worded 73% statistic, telling them where to start.
The full Position Brief covers the regime framework, the DORA contrast, the cross-domain reading, and the four gaps to close now. Abgalis maps how a single shock — a CTP outage among them — moves across the seven domains of an insurer's risk, and where it lands on capital.