News and updates from Maple

Your cloud provider just became a regulated entity. Here's what that does, and doesn't, change for you. image

Your cloud provider just became a regulated entity. Here's what that does, and doesn't, change for you.

From 13 July 2026, four of the world's largest cloud providers, Amazon Web Services, Google Cloud, Microsoft and Oracle, became directly regulated by UK financial authorities for the first time. HM Treasury designated them as Critical Third Parties, and the Bank of England, the PRA and the FCA now have powers to oversee the resilience of the services they provide to the UK financial sector directly, not just through the firms that use them.

If you're a hedge fund, family office or insurer, this is genuinely good news. It's also easy to misread, and the misreading matters more than the news itself.

What's actually changing

Before this designation, if your firm relied on a cloud platform for anything critical, the regulator's only lever was you: they supervised how you managed that relationship, not the provider itself. From 13 July, the Bank, PRA and FCA can go further, they can require the designated providers themselves to meet resilience standards, run scenario testing, and produce incident management playbooks, with real intervention powers if something's seriously wrong.

That's a meaningful structural shift. A single outage at one of these providers no longer just affects the firms that noticed, it's now something regulators are watching for directly, because the same handful of platforms sit underneath a very large share of the sector at once.

What isn't changing

This is the part worth being clear-eyed about: designation is not authorisation, and it doesn't transfer your own responsibility anywhere. The regulators have been explicit that firms still carry their own third party risk management and due diligence duties in full. Your regulator will still expect you, specifically, to be able to answer for how you manage that dependency, not point at a CTP designation and consider the job done.

If anything, this raises the bar on what a good answer looks like, because "we use a major cloud provider so we're fine" was never really a satisfactory answer, and it's even less of one now that regulators are watching those providers closely enough to notice when something's genuinely wrong.

The reporting change sitting just behind this one

There's a second, related piece worth having on your radar even though it's not live yet. The FCA's PS26/2 policy statement, published in March 2026, introduces formal rules on operational incident reporting and third party arrangements, with the rules coming into force in March 2027. Once in force, in-scope firms will need to report significant operational incidents to the FCA and maintain an annual register of material third party arrangements.

That's roughly eight months away as things stand, which sounds like plenty of time. In practice, a register like that is only easy to produce if your IT support has been keeping the underlying information properly all along, who you rely on, what for, and what happens if it breaks. Firms starting that exercise from scratch next year will have a harder time than firms whose IT provider has been tracking it as a matter of course.

What's worth doing now

  • Ask your IT provider whether they can already tell you, in writing, which critical third parties your systems actually depend on, cloud platforms included.
  • Ask whether they're tracking the CTP designations and what it means for your own arrangements, rather than treating it as background noise.
  • If you don't already have something resembling a third party register, start one now, informally, rather than waiting for March 2027 to make it mandatory.

None of this is about switching providers or panicking about cloud risk. It's about making sure the accountability that was always yours doesn't get discovered for the first time during an audit.