
Critical-provider oversight does not outsource a bank’s vendor review
The UK’s first critical-third-party designations bring cloud dependencies under direct oversight. Firms still own due diligence, risk management and contingency planning.
I would reject a vendor-review shortcut that says, “The regulator oversees this provider, so we can rely on that.” The UK's new critical-third-party regime explicitly leaves work with the financial firm.
The FCA's July 10 announcement said joint oversight would begin on July 13 following Treasury designation of four entities: Amazon Web Services EMEA SARL, Google Cloud EMEA Limited, Microsoft Ireland Operations Ltd and Oracle Corporation UK Limited. The focus is resilience of critical services supporting the UK financial sector.
The same notice says firms retain responsibility for their own third-party arrangements, including due diligence, risk management and contingency planning. It also distinguishes designation from regulatory authorisation. This is additional oversight of an important dependency, not a general seal of approval for everything sold under a familiar cloud brand.
My operational reading is simple: the evidence available to a vendor review may improve, but the firm's decision still needs an owner.
Start with the service, not the logo
A hypothetical bank might run a customer-facing AI assistant on a cloud service associated with one of those groups. A procurement slide could place the provider's logo next to “regulated critical third party” and leave the impression that the whole application has inherited a safety assessment.
That slide skips the actual arrangement. Which legal entity supplies the service? Which service is being relied on? What does the bank control in its configuration, operating process and customer journey? Which dependencies sit outside the cloud contract?
Those questions matter before anyone draws comfort from the designation. The provider's wider resilience and the bank's implementation are connected, but they are not the same object of review.
I would ask the service owner to explain one plausible disruption from the customer's perspective. What stops working, how is the issue detected and what can the firm still do? The answer should identify the evidence it relies on and the assumptions it has not tested.
An assurance about the provider can support that explanation. It cannot describe the firm's own escalation tree, staffing or decision to suspend a customer feature. Those remain local operating choices.
Use supervision as an input to a decision
The sensible response is to update the dependency record, identify relevant information channels and review how provider communications reach the people responsible for the affected service. A major incident notice is useful only if somebody can connect it to an action.
I would keep the division of responsibility visible in the review. Provider evidence belongs beside the firm's configuration checks and contingency plan, with each item attached to the question it can actually answer. An unknown should remain visible rather than disappear beneath the provider's designation.
This is not a claim that the new regime is merely symbolic. Direct oversight can address risks that are difficult for an individual customer to influence. Its system-level purpose is precisely why it should not be mistaken for a complete assessment of one firm's deployment.
The applicable legal obligations need to be assessed for the particular arrangement. The practical point here follows the regulator's own distinction: added supervision does not erase retained responsibilities.
Treat a critical-third-party designation as a reason to improve the vendor evidence record, not as permission to retire it.


