Skip to content

InvestNot yet confirmed elsewhere1 publisher3 min readPublished

Designation day: your cloud vendor now answers to three regulators, and you still answer for it

The first critical third parties have been designated, putting technology, data and operations suppliers under direct UK supervision. Firm-level responsibility does not move an inch.

The Investor · Invest desk

How we use AISend a correction

Illustration accompanying Designation day: your cloud vendor now answers to three regulators, and you still answer for it
Generated illustration

What happened

  • The government's new oversight regime is live and the first critical third parties have been formally designated.
  • The Bank of England, PRA and FCA will supervise those providers jointly and directly, covering the services they sell to UK firms and market infrastructures.
  • The regulators say the regime neither replaces firms' own resilience duties nor extends to every supplier a firm uses.

Why it matters

  • exposure A concentrated dependency is no longer a private entry in an outsourcing file: three authorities are now looking at the same provider from the other side, and can see how many of their firms sit...
  • constraint Supervision of the vendor buys a firm no relief from its own obligations, so resilience work now has to be done twice over: once inside the firm and once in coordination with a supervised supplier.
  • decision Vendor selection acquires a question it did not have, because a designated provider comes with joint testing and shareable self-assessments that an undesignated one does not.
  • cost Joint exercises and self-assessment sharing consume engineering and risk hours on both sides of the contract, and the post is silent on who funds them.

Take the two percentages the supervisors put in the same paragraph and multiply them. If 27% of incidents firms reported to the FCA in 2025 were attributed to a third party [5], and 37% of those were cyber-related [6], then roughly one in ten reported incidents was a cyber failure that occurred somewhere other than the reporting firm [16]. That is the number the regime is built on: not a catastrophe, but a steady tithe of outages that a firm's own controls could not have prevented because the failure was not on its premises.

The supervisory logic follows from concentration rather than severity. The post says banks, insurers, payment firms and FMIs increasingly depend on a relatively small number of common providers, among them cloud providers, technology firms and data providers [4], and that oversight is aimed at system-level risk where many firms rely on the same service, plus coordination and information-sharing during major incidents [3]. Designation is what converts a line in a supplier register into a counterparty the Bank of England, PRA and FCA oversee directly and jointly [2], under powers the government granted for this purpose [1].

What the designated providers owe is specified: identify and manage the risks in the critical services they supply, test and improve their resilience arrangements, and engage openly with regulators and firms during incidents [9]. What clients get is described more softly, as better visibility of risk and better communication when something large breaks [15], delivered partly through joint testing exercises and the sharing of self-assessments where appropriate [10].

Read the caveats as carefully as the powers. The regulators state plainly that the regime does not replace firms' responsibility for their own operational resilience and third party arrangements, and does not extend to every provider a firm uses [11]; the existing firm-level rules stand and are complemented, not superseded [13]; and the regime cannot and will not end all disruptions [12]. A firm whose critical vendor is now supervised has gained an information channel and lost no accountability.

One practical gap sits in the source itself: it does not name the designated providers or say how many were designated [14]. Until that list is in hand, nobody can reconcile it against a supplier register, which is the only exercise that tells an operator whether this regime touches them at all. It is also worth noticing where the contagion evidence comes from. The examples offered are the 2024 CrowdStrike outage, which hit organisations worldwide [7], and cyber incidents at Marks & Spencer and Jaguar Land Rover [8] - retailers and a carmaker, cited to a financial services audience. The regulators are arguing from other people's outages because the shared-dependency failure they are supervising against has mostly happened elsewhere so far.

What to watch

  • Publication of the designated cohort by name, which is what lets a firm reconcile the list against its own supplier register.
  • Whether the FCA's next incident data moves the third-party share off 27%, and the cyber share off 37% of that.
  • The first joint testing exercise between a designated provider and its UK clients: scope, who runs it, and who absorbs the cost.

Clarity's read

What the record supports and how the coverage leans. The claims behind it follow.

Reality

Evidence58
Adoption47
Hype gap+6
Incentives66
Confidence55
Why these scores

Claim ledger

Ranked by verification strength, evidence, and original report placement.

  1. [1]

    The government granted the Bank of England, PRA and FCA powers to implement a new oversight regime, and has now designated the first critical third parties (CTPs).

    ReportedSupportedSource: Post written in the voice of the Bank of England, PRA and FCA, published by Crowdfund InsiderView cited source
  2. [2]

    The Bank of England, PRA and FCA will together directly oversee the designated providers, with a targeted, proportionate focus on ensuring the services they provide to UK financial firms and financial market infrastructures are resilient.

    ReportedSupportedView cited source
  3. [3]

    The oversight aims to address system level risks, where many firms rely on the same services from common service providers, and to improve coordination and information-sharing across the sector, particularly during major incidents.

    ReportedSupportedView cited source

Sources

1 independent publisher whose own reporting we read for this story.

  1. crowdfundinsider.com

    1 article · August 25, 2026

    Strengthening resilience across an increasingly interconnected financial system

Share your take

Let Clarity write the post for you.

Signed-in readers get a short post drafted on this story in the register they choose — narrative, analytical, or a direct position — editable to the last word before it goes anywhere. The share buttons at the top of this story work without an account.

Topics and entities

Follow any of these and your For You feed starts watching them — no settings page required.

Loading related stories