Bank of England Gets Power to Regulate Amazon, Google and Other Cloud Giants Serving UK Banks

New rules taking effect this week mean two regulators can now inspect and direct the tech companies that keep Britain's financial system running, a first for the UK.

ThreatVectr NewsdeskAI-assistedPublished Updated · Editor: Lee Brown· 3 min read
Illustration: the Bank of England building in the City of London, shot from directly above at midday
Illustration made with AI. Not a photograph of the events described.
Share

Key points

  • From Monday, the Bank of England and the Financial Conduct Authority gain direct oversight of large cloud and tech providers serving UK banks.
  • Four firms have been classed as "critical third parties"; they reportedly include Amazon and Google, as well as Oracle and Microsoft.
  • The FCA, the UK body that polices financial services and protects consumers, shares oversight responsibility with the Bank of England.
  • The goal is to cut the risk that IT outages or cyber-attacks at these firms disrupt services for millions of UK customers.
  • No specific breach triggered the change: regulators acted on the structural risk of too many banks depending on too few tech suppliers.

Britain's banks don't run on their own computers any more. They've outsourced storage, processing and software to a handful of giant technology companies, most of them American. That works well until one of those companies has a serious problem.

From Monday, the Bank of England and the FCA have the authority to tell those companies exactly what resilience standards they must meet. If a cloud provider, a company renting computing power and storage over the internet, fails to comply, regulators can act directly rather than going through the bank that hired them.

Why does this matter to ordinary bank customers?

A single outage at a major cloud company can freeze payments and shut down business payroll systems across multiple banks at once. Regulators aren't reacting to one specific incident. They're reacting to a concentration risk: too many critical financial services sitting on too few tech platforms. When we reported on the AI oversight gap in UK financial services on 7 July, the same structural anxiety was present, namely that regulators were already struggling to keep pace with how dependent the sector had become on a small number of external technology providers.

The Guardian named Amazon and Google among the four firms brought under the new framework, and also cited Oracle and Microsoft.

The Bank of England and the FCA can now set minimum standards for how these firms protect themselves against cyber-attacks and recover from failures. They can request information, run tests and require changes. The firms themselves carry the compliance burden, not just the banks that use them.

That's the meaningful shift. Existing rules only let regulators pressure banks about their suppliers indirectly. A bank could demand contractual protections from Amazon Web Services, but regulators couldn't reach Amazon itself. That gap closes this week.

The change sits within the Financial Services and Markets Act 2023, which gave the Treasury the power to designate technology companies as "critical third parties" when their failure could threaten UK financial stability.

Should you worry?

Not immediately. This is a structural fix, not a response to an active crisis. The practical test will come the first time a designated firm pushes back on a regulator's demand, and how firmly the Bank of England responds will tell us whether these powers have real teeth.

What affected organisations should do now. Banks using cloud services from any designated firm should review their contracts and check what new audit or reporting rights apply. Tech suppliers should treat the FCA and Bank of England as direct regulators, not clients of their clients, and assign compliance owners accordingly.

© 2026 Threat Vectr