The critical third parties regime: the UK model compared with DORA

The critical third parties regime: the UK model compared with DORA

In short: The critical third parties regime brought Amazon Web Services EMEA SARL, Google Cloud EMEA Limited, Microsoft Ireland Operations Limited and Oracle Corporation UK Limited under FCA, PRA and Bank of England oversight on 13 July 2026, under SI 2026/777 and Chapter 3C of FSMA 2000. The UK regime binds providers with rules and directions but confers no financial-penalty power. EU DORA backs its compulsory oversight measures with periodic penalty payments.

By Rob Bratby, Managing Partner, Bratby Law. 30+ years in regulated industries, including current Fractional General Counsel to UKPI. Chambers UK Band 2 (Telecommunications), Legal 500 Leading UK Telecoms Partner.

If a bank, insurer, e-money institution or payment institution runs a service its customers depend on from a hyperscale cloud platform, that platform is now regulated in its own right. Four providers came inside the UK financial regulatory perimeter on 13 July 2026, and their obligations are owed to the regulators directly rather than through the contract with their customers. The customer’s own obligations are untouched, which is the point most easily lost: designating a supplier moves no risk off the firm that uses a designated supplier.

Key findings (HM Treasury, FCA, Bank of England, ESAs)

  • HM Treasury designated four cloud providers as critical third parties with effect from 13 July 2026, by the Critical Third Parties (Designation) Regulations 2026 (SI 2026/777), made 8 July 2026. Source: legislation.gov.uk
  • The designation power sits in section 312L of the Financial Services and Markets Act 2000, inserted by section 18(3) of the Financial Services and Markets Act 2023 with effect from 29 August 2023. Source: legislation.gov.uk
  • There is no statutory limit on the number of critical third parties, and HM Treasury described the regime as rolling. Source: HM Treasury, 10 July 2026
  • Chapter 3C confers no power to impose a financial penalty on a designated provider. The enforcement toolkit is a censure statement under section 312Q and a prohibition or limitation notice under section 312R. Source: legislation.gov.uk
  • Under EU DORA, the Lead Overseer may impose a periodic penalty payment of up to 1% of a provider’s average daily worldwide turnover, daily, for up to six months (Article 35(6) to (8)). Source: Regulation (EU) 2022/2554
  • The European Supervisory Authorities designated nineteen critical ICT third-party service providers on 18 November 2025, including three of the four UK designees on the same legal entity. Source: EBA, 18 November 2025
Designated entityDesignated in the UK fromAlso designated by the ESAs
Amazon Web Services EMEA SARL13 July 2026Yes, 18 November 2025, same entity
Google Cloud EMEA Limited13 July 2026Yes, 18 November 2025, same entity
Microsoft Ireland Operations Limited13 July 2026Yes, 18 November 2025, same entity
Oracle Corporation UK Limited13 July 2026Oracle Nederland B.V. designated, a different entity

How the UK critical third parties regime works

HM Treasury holds the designation power under section 312L(1) of the Financial Services and Markets Act 2000 (FSMA 2000). It may designate a person supplying services to authorised persons, relevant service providers or financial market infrastructure entities, and only where in its opinion a failure in or disruption to those services could threaten the stability of, or confidence in, the UK financial system. Section 312L(3) sets two factors it must weigh: how material the services are to the delivery of essential activities, and the number and type of firms supplied.

The definition of “relevant service provider” in section 312L(8) is what brings payments into this. It covers an e-money institution under regulation 2(1) of the Electronic Money Regulations 2011, and an authorised payment institution, small payment institution or registered account information service provider under regulation 2(1) of the Payment Services Regulations 2017. Being supplied does not make a PSP a designated critical third party; it makes its supplier capable of designation. The PSP still sits inside the regime’s operation: it is a “firm” for CTPS purposes, a section 312R notice can prohibit or condition its receipt of services, and section 312S(6) gives it a right to refer such a notice to the Tribunal.

Designation follows a procedure rather than a hearing. Under section 312L(4) the Treasury must consult the FCA, the PRA and the Bank of England, give the candidate written notice with a reasonable period for written representations, and have regard to what it receives. SI 2026/777 records that each step was taken.

Designation attaches to a named legal person, not to a group or a brand, and only one of the four is a UK-incorporated company: Oracle Corporation UK Limited, number 01782505. Amazon Web Services EMEA SARL is a Luxembourg company on the Companies House register as an overseas company, number FC034225, with a UK establishment. Google Cloud EMEA Limited and Microsoft Ireland Operations Limited do not appear on that register under those names. Whether a firm’s own cloud contract is with a designated entity is therefore a question of fact on the contract.

What the regulators’ rules require of a designated provider

The FCA, PRA and Bank of England published their rules on 12 November 2024 as FCA PS24/16 and PRA PS16/24, with effect from 1 January 2025. The FCA rules sit in the Critical Third Parties sourcebook (CTPS), added to the Handbook by the Critical Third Parties Instrument 2024. The PRA rules sit in the Critical Third Parties Part of the PRA Rulebook.

Designation does not put the whole of a provider’s business inside the rules. The operative concept is the “systemic third party service”, a service whose failure or disruption could threaten the stability of, or confidence in, the UK financial system. CTPS 3.1.1R splits the application: CTP Fundamental Rules 1 to 5, covering integrity, due skill and care, prudence, risk management, and responsible organisation and control, apply only to systemic third party services; Fundamental Rule 6, open and co-operative dealing with a regulator, applies to any service supplied to firms. CTPS 1.3.1R disapplies any territorial limit.

Eight operational risk and resilience requirements sit at CTPS 4.2 to 4.9: governance, risk management, dependency and supply chain risk management, technology and cyber resilience, change management, mapping, incident management and termination of a systemic third party service. Several carry a first-year clock. Mapping, a first incident management playbook, and a playbook exercise with a representative sample of firms are each due within 12 months, the exercise repeating at least every two years. Under CTPS 6.1.1R an interim self-assessment goes to the regulators within three months of designation by the Treasury, which for these four is 13 October 2026, with an annual self-assessment thereafter.

CTPS 7.1 changes what a customer can obtain, though it is narrower than it first appears. The duty runs to “a firm to which it provides any systemic third party services” (CTPS 7.1.1R), so a customer taking only non-systemic services gets nothing under it. For a firm that qualifies, CTPS 7.1.2R names the CTPS 5 testing results, the annual self-assessment redacted as appropriate, and the maximum tolerable level of disruption for each systemic third party service supplied to it.

Incident reporting under CTPS 8 runs in three stages on three triggers: an initial report to the regulators and affected firms as soon as is practicable after the incident occurs, with a further tranche to the regulators alone (CTPS 8.1.1R); an intermediate report as soon as is practicable after any significant change in circumstances (CTPS 8.2.1R); and a final report within a reasonable time of resolution (CTPS 8.3.1R). None carries a clock of the four-hour or 72-hour kind found elsewhere in financial services reporting.

How DORA’s oversight framework works

The EU built the same idea on a different chassis. Regulation (EU) 2022/2554, the Digital Operational Resilience Act (DORA), has applied since 17 January 2025, and Articles 31 to 44 establish an oversight framework for critical ICT third-party service providers. The European Supervisory Authorities designate through the Joint Committee against four cumulative criteria in Article 31(2), and an undesignated provider may apply to be designated (Article 31(11)). Each gets a single Lead Overseer, the EBA, EIOPA or ESMA, allocated by whichever sector’s financial entities hold the largest aggregate balance-sheet assets among that provider’s customers (Article 31(1)(b)).

The Lead Overseer’s powers divide in two, and the division decides the enforcement. Requests for information (Article 37), general investigations (Article 38) and on-site inspections (Article 39) are compulsory. Recommendations under Article 35(1)(d) are not: a provider may give a reasoned explanation for not following one (Article 42(1)), and the consequences of refusal are public disclosure (Article 42(2)) and, as a last resort, a decision by a national competent authority requiring financial entities to suspend or terminate the arrangement (Article 42(6)). The trigger for that last step is the financial entity’s failure to address the identified risk, not the provider’s refusal in itself.

The pecuniary instrument sits at Article 35(6) to (8) and attaches to the compulsory measures alone. Where a provider does not comply with an information, investigation or follow-up-report measure, and 30 calendar days have passed since notification, the Lead Overseer must impose a periodic penalty payment. It runs daily until compliance is achieved, for up to six months, at up to 1% of average daily worldwide turnover in the preceding business year. Article 35(9) makes it administrative and enforceable, with the amounts going to the EU budget: a compliance measure, not a fine. Declining a recommendation does not attract it.

Where the two regimes diverge

Both regimes place duties directly on the provider, and the comparison has to be drawn power by power rather than regime by regime. DORA’s information, investigation, inspection and follow-up-report measures under Articles 35(1)(a) to (c) and 37 to 39 are compulsory and carry the periodic penalty payment; its recommendations under Article 35(1)(d) may be declined with reasons. The UK’s rules under section 312M and directions under section 312N bind across the board, but Chapter 3C gives the regulators no financial-penalty power to enforce any of them.

IssueUK critical third parties regimeEU DORA oversight
Who designatesHM Treasury, by statutory instrument (FSMA 2000 s 312L(1))The ESAs through the Joint Committee, by administrative act (Art 31(1)(a))
Test appliedTreasury opinion on threat to stability or confidence, weighing two factors (s 312L(2), (3))Four cumulative criteria (Art 31(2)) plus a delegated act
Can a provider volunteerNo mechanismYes, on reasoned application, decided within six months (Art 31(11))
SupervisorFCA, PRA and Bank of England jointlyA single Lead Overseer: EBA, EIOPA or ESMA (Art 31(1)(b))
Are requirements binding on the providerYes throughout: rules under s 312M and directions under s 312NSplit: information, investigation, inspection and follow-up-report measures are compulsory (Arts 35(1)(a) to (c), 37 to 39); recommendations may be declined with reasons (Arts 35(1)(d), 42(1))
Pecuniary measure against the providerNone in Chapter 3CPeriodic penalty payment for non-compliance with the compulsory measures only, up to 1% of average daily worldwide turnover, daily, up to six months (Art 35(6) to (8))
Cutting off the serviceRegulator notice prohibiting or limiting supply or receipt (s 312R)Competent authority decision requiring suspension or termination, as a last resort (Art 42(6))
Local establishmentNot requiredA designated third-country provider must establish an EU subsidiary within 12 months (Art 31(12))
Procedural protectionsWarning notice and decision notice before censure or a prohibition notice, and a right for the provider, and for affected firms, to refer specified regulator decisions to the Tribunal (s 312S). Not an appeal against the Treasury’s designationRights of defence and access to the file before a periodic penalty payment is imposed (Art 35(11)). Not an appeal route as such

Section 312Q says only that a regulator “may publish a statement to that effect” where it considers a provider has contravened a Chapter 3C requirement. The general financial-penalty provision does not fill the gap of its own motion: section 206(1) of FSMA 2000 applies to an authorised person, and section 206(1A) extends it to others only for Part 5A designated-activities requirements. Section 206 therefore turns on whatever regulatory status the person independently holds, which designation neither confers nor rules out.

There is a sting in that for the customer. Section 312R(8) deems a person who breaches a prohibition, condition or limitation in a section 312R notice to have contravened a requirement imposed under FSMA 2000, and where that person is an authorised person, section 206 then applies. A firm that carried on taking a prohibited service could face a penalty. The provider whose conduct produced the notice would not.

Commercial and operational implications

For a firm taking a systemic third party service from one of the four, the immediate change is informational. CTPS 7.1 puts testing results, the redacted annual self-assessment and the maximum tolerable level of disruption into that firm’s hands as a matter of rule, where previously each was a negotiated concession or was simply unavailable. That material has an obvious use in resilience mapping and board reporting, and it arrives without a contractual amendment. The qualification matters commercially: a customer taking only non-systemic services from a designated provider acquires no CTPS 7.1 rights.

Which services are systemic is not on any public record. The regulators identify them when recommending designation and notify the provider at that point, reviewing them periodically thereafter (Approach to the oversight of critical third parties, section 3), but the lists at legislation.gov.uk and on the regulators’ pages name four legal persons and no services. For a firm the boundary surfaces through CTPS 7.1.2R(3): a maximum tolerable level of disruption exists only for a systemic third party service, so the services carrying one are the services the provider treats as systemic in that relationship. The inference works by omission rather than by label, and the unit is the provider’s own service definition, which may bundle connected services together.

The second change is a risk with no contractual analogue. A section 312R notice can prohibit a firm from continuing to receive a service or make its receipt conditional: a regulatory route to losing a dependency, distinct from insolvency, breach or termination, and independent of anything the firm has done. Section 312R(4) requires the regulator to be satisfied that exercising the power will not itself threaten stability, a meaningful constraint where the provider is a hyperscaler, but not an assurance.

Nothing in the regime moves the firm’s own obligations. HM Treasury said so directly in its notes to editors on 10 July 2026: “Financial firms remain responsible for managing risks arising from their third-party suppliers”, and “Regulatory oversight applies only to the systemic services provided to the financial sector, not firms’ wider operations”. The payments regulation obligations a PSP already carries are unchanged, as are the operational resilience rules in FCA PS21/3 and PRA PS6/21 and SS1/21, in full application since 31 March 2025. From 18 March 2027 the separate incident and third-party reporting regime in FCA PS26/2 and PRA PS7/26 adds firm-facing reporting duties alongside.

For a firm operating on both sides of the Channel, the two regimes apply to the same providers on largely the same entities, with one exception: Oracle is designated on Oracle Corporation UK Limited here and on Oracle Nederland B.V. in the EU, so a group-level assumption of symmetry would be wrong. The FCA, Bank of England and PRA signed a Memorandum of Understanding with the ESAs on 14 January 2026 on cooperation and information sharing. Our commercial and technology contract support page covers cloud arrangements negotiated against both regimes.

Viewpoint

I read the missing penalty power as a considered choice, and section 312R(4) supports that reading: requiring a regulator to be satisfied that exercising the prohibition power will not itself threaten stability shows the drafters alive to the difficulty of acting against a provider whose disruption is the very risk the regime addresses. Censure, plus a prohibition power conditioned on not causing instability, answers that problem, if more quietly than DORA does. That is an inference from the structure of the Chapter, not from anything Parliament said about the omission.

In advising firms on cloud arrangements in regulated sectors, the binding constraint has rarely been the enforcement toolkit. It has been the absence of any route to the provider’s own resilience evidence. CTPS 7.1 opens that route for firms taking systemic third party services, and will matter more in practice than section 312Q ever will. The first milestone will not help them, though: the interim self-assessments due on 13 October 2026 go to the regulators alone, the requirement to share them with firms having been removed while the three-month deadline was held (PS16/24, paragraph 2.145). The annual self-assessment that follows is the one to watch.

Frequently asked questions

Which providers are designated as critical third parties in the UK?

Amazon Web Services EMEA SARL, Google Cloud EMEA Limited, Microsoft Ireland Operations Limited and Oracle Corporation UK Limited, each with effect from 13 July 2026 under the Critical Third Parties (Designation) Regulations 2026 (SI 2026/777). HM Treasury described the regime as rolling, and there is no statutory limit on the number that may be designated.

Can the FCA or the Bank of England fine a critical third party?

No. Chapter 3C of FSMA 2000 contains no financial-penalty power. Section 312Q allows a regulator to publish a statement of censure, and section 312R allows it to publish a notice prohibiting or limiting the supply or receipt of services. Section 206 of FSMA 2000 applies to authorised persons and, under section 206(1A), to designated-activities requirements, so it does not cover a critical third party.

Does designation apply to everything the provider does?

No. CTPS 3.1.1R applies CTP Fundamental Rules 1 to 5 and the operational risk and resilience requirements only to “systemic third party services” supplied to firms. Fundamental Rule 6, on open and co-operative dealing with a regulator, applies to any service supplied to firms. HM Treasury put the same point plainly on 10 July 2026: “Regulatory oversight applies only to the systemic services provided to the financial sector, not firms’ wider operations”.

Are payment institutions and e-money institutions inside the regime?

They are not designated merely because they use a designated supplier, but they are squarely within the regime’s operation. Section 312L(8) of FSMA 2000 makes an electronic money institution, an authorised payment institution, a small payment institution and a registered account information service provider “relevant service providers“, so a supplier to them can be designated. They are also “firms” for the purposes of CTPS, small payment institutions and small e-money institutions included, so the CTPS 7.1 information duties run in their favour on any systemic third party services supplied to them. A notice under section 312R can prohibit or condition their receipt of services, and section 312S(6) gives them a right of reference to the Tribunal against it.

What happens if a UK designated provider is also designated under DORA?

Both regimes apply, on their own terms. Three of the four UK designees appear on the ESAs’ 18 November 2025 list of nineteen critical ICT third-party service providers on the same legal entity. The UK imposes binding rules and directions but gives its regulators no Chapter 3C penalty power. DORA combines compulsory information, investigation and inspection measures, backed by a periodic penalty payment of up to 1% of average daily worldwide turnover, with recommendations a provider may decline with reasons. The UK regulators and the ESAs signed a cooperation Memorandum of Understanding on 14 January 2026.

For advice on how the critical third parties regime and DORA apply to your cloud and managed-service arrangements, contact Rob Bratby at Bratby Law.

Select topics of interest

Similar Posts