Skip to main content
ExplainerSystemic RiskExplainerAug 27, 2026, 11:03 AM· 5 min read

How Financial Regulators' New Oversight of Critical Tech Vendors Rewrites the Rules of Big Tech Liability and Systemic Risk

Financial authorities in the UK, EU, and US are shifting their focus from regulating banks to directly overseeing the cloud providers that host them. This historic pivot acknowledges that the primary systemic risk to global finance is now tech vendor concentration.

By Lila Morgan

Financial Regulators 40%Technology Vendors 30%Industry Analysts 30%
Financial Regulators
Advocate for direct oversight of tech vendors to mitigate systemic risk.
Technology Vendors
Emphasize their superior security and the shared responsibility model.
Industry Analysts
Focus on the practical challenges of enforcing these new rules.

Summary

  • Financial regulators are shifting oversight from banks to the tech vendors that host their infrastructure.
  • The UK designated AWS, Google Cloud, Microsoft, and Oracle as Critical Third Parties in July 2026.
  • The EU's DORA framework mandates direct supervision of critical tech vendors serving the financial sector.
  • Concentration risk is high, with the top three cloud providers controlling 68% of enterprise cloud spending.
  • Regulators aim to prevent a single tech outage from causing a systemic financial crisis.

What everyone gets wrong about banking regulation is that it is primarily about capital requirements, liquidity ratios, and stopping rogue traders. The popular image of systemic risk is a bank running out of money and sparking a contagion of defaults. But the evidence points to a completely different vulnerability: a server outage at a tech giant in Seattle, Redmond, or Mountain View. Today, the infrastructure of global finance is hosted almost entirely on the cloud, meaning the biggest threat to the financial system is no longer a bank failure, but a vendor failure.

Financial regulators have quietly realized this and are rewriting the rules of the game. Rather than just regulating the banks, authorities in the United Kingdom, the European Union, and the United States are shifting their focus to the technology companies that actually run the banks' underlying systems. This marks a historic inversion of financial oversight, expanding the regulatory perimeter deep into Silicon Valley.

The mechanism for this shift is the designation of "Critical Third Parties" (CTPs). In July 2026, the UK's HM Treasury, alongside the Bank of England and the Financial Conduct Authority, officially designated four global cloud and technology providers—Amazon Web Services, Google Cloud, Microsoft, and Oracle—as the first CTPs. For the first time, these tech giants are under direct regulatory oversight by financial authorities, not just data privacy watchdogs.[1]

The European Union has taken a similar, legally binding approach with the Digital Operational Resilience Act (DORA), which entered into full effect in January 2025. DORA creates a comprehensive risk management framework that applies not only to roughly 22,000 financial entities but directly to their critical information and communication technology providers. If a tech vendor is deemed critical to the EU financial sector, it must submit to direct supervision by European financial regulators.[2]

New frameworks like DORA and the CTP regime allow regulators to directly oversee tech vendors.

Why the sudden urgency? The answer lies in the sheer concentration of the cloud market. While banks often market their digital transformations as bespoke, resilient innovations, the reality is that they are all renting space from the same three landlords. AWS, Microsoft Azure, and Google Cloud control roughly 68% of total enterprise cloud spending globally.

The answer lies in the sheer concentration of the cloud market.

When regulators survey the financial sector, the concentration is even starker. A joint survey by the Bank of England and the FCA found that the top three cloud providers accounted for 73% of all named providers used by UK financial firms. This creates a massive single point of failure. If one of these hyperscalers experiences a severe outage, it wouldn't just take down one bank; it could simultaneously blind multiple major financial institutions, halting payments, trades, and account access across the economy.[1]

The financial sector's reliance on a small number of cloud providers has created a new kind of systemic risk.

The Financial Stability Board, an international body that monitors the global financial system, has echoed these concerns. In its toolkit for third-party risk management, the FSB cautioned that while cloud adoption can reduce costs and speed up the deployment of new products, the market is concentrated around a small number of providers. This limited pool gives tech vendors outsized bargaining power and leaves community banks struggling to negotiate transparency or incident response protocols.

The regulatory mechanism being deployed is not about breaking up the tech giants, but about enforcing operational resilience. Under the UK's CTP regime and the EU's DORA, these designated technology providers must prove they can withstand cyberattacks, manage their own supply chain risks, and guarantee service continuity during a crisis. Regulators now have the power to demand information, conduct threat-led penetration testing, and assess the vendors' disaster recovery plans.[1][2]

However, the actual capability of regulators to enforce these rules remains uncertain. While DORA allows European authorities to impose daily penalty payments of up to 1% of a provider's average worldwide turnover for non-compliance, the UK regime currently lacks the power to levy direct financial fines on CTPs. Instead, UK regulators can restrict or prohibit a tech vendor from providing future services to the financial sector—a "nuclear option" that might be too disruptive to ever actually use.[1][2]

Furthermore, there is a gap between what is announced and what is technically feasible. Tech companies operate on a shared responsibility model, meaning they secure the infrastructure, but the bank is responsible for securing its own data and applications. Regulators are demanding system-wide resilience, but cloud providers do not have visibility into the specific workloads their financial clients are running.

Regulators are now demanding threat-led penetration testing and disaster recovery audits directly from tech vendors.

The scope of this oversight is also expanding beyond basic cloud hosting. The UK Treasury Committee has already recommended that major artificial intelligence providers be designated as critical third parties by the end of 2026. As banks integrate generative AI and machine learning models into trading algorithms and risk assessments, the dependency on external tech vendors deepens, stacking model concentration on top of infrastructure concentration.[1]

Ultimately, this regulatory shift acknowledges a fundamental truth about modern finance: banks are increasingly becoming highly regulated software companies. As long as the financial system relies on a handful of tech vendors to function, those vendors will be treated as systemically important financial infrastructure, rewriting the boundaries of tech liability for the foreseeable future.[3]

Definitions

Critical Third Party (CTP)
A regulatory designation for external service providers, such as cloud hosts, whose disruption could cause widespread financial instability.
Digital Operational Resilience Act (DORA)
A comprehensive European Union regulation designed to ensure that all participants in the financial system have the necessary safeguards to mitigate cyberattacks and IT failures.
Hyperscaler
A massive cloud service provider, such as Amazon Web Services, Google Cloud, or Microsoft Azure, capable of providing computing and storage services at a global scale.
Shared Responsibility Model
A cloud security framework where the provider is responsible for the security of the cloud (infrastructure), while the customer is responsible for security in the cloud (data and applications).
Systemic Risk
The risk that the failure of one entity or cluster of entities could trigger a cascading collapse of the entire financial system.

Sources

Source coverage

3 outlets

3 viewpoints surfaced

Financial Regulators 40%Technology Vendors 30%Industry Analysts 30%
  1. [1]Bank of EnglandFinancial Regulators

    Operational resilience: Critical third parties to the UK financial sector

    Read on Bank of England
  2. [2]IBMTechnology Vendors

    What is the Digital Operational Resilience Act (DORA)?

    Read on IBM
  3. [3]Factlen Editorial TeamIndustry Analysts

    Synthesis by Factlen editorial team

    Read on Factlen Editorial Team

Comments

Stay informed

Every angle. Every day.

Get meta stories with full source coverage and perspective breakdowns delivered to your inbox.