UK follows DORA as resilience scrutiny widens

Sarah Breeden

From today, Monday 13 July, the Bank of England, the Prudential Regulation Authority and the Financial Conduct Authority will jointly oversee Amazon Web Services, Google Cloud, Microsoft and Oracle after HM Treasury designated them as the UK’s first Critical Third Parties.

The move brings four of the world’s largest cloud and technology providers directly within the UK’s financial resilience oversight regime, extending regulatory scrutiny beyond banks and towards the infrastructure that increasingly powers the financial system.

It also means the UK is moving closer to the approach taken under the EU’s Digital Operational Resilience Act, or DORA, which also allows regulators to oversee technology providers considered critical to the financial sector.

For banking quality assurance, software testing and operational resilience, the development represents a significant shift upstream. Regulators will no longer focus solely on whether individual financial institutions can withstand disruption, but also on whether the shared technology platforms supporting thousands of firms are sufficiently resilient.

‘Critical’ third parties

The Bank said Critical third parties are providers “whose services underpin the UK financial system”, warning that widespread dependence on the same suppliers means disruption could spread rapidly across institutions and markets.

“As many firms rely on these services, disruption or failure could affect multiple firms or markets at the same time, potentially impacting UK financial stability and services used by millions of consumers and businesses,” the regulators stressed.

The Bank of England

That concentration risk has become increasingly difficult for banks to manage through conventional supplier assurance alone. Financial institutions can test their own applications, controls and recovery procedures, but they have limited visibility into the underlying systems operated by major cloud providers.

The new regime therefore places the resilience of those providers under direct regulatory scrutiny for the first time.

“For the first time, the three regulators will jointly oversee these CTPs under a new, proportionate regime, focused on the resilience of the critical services they provide to the UK financial sector,” the Bank said.

They explained that “the regulators will work together with the CTPs to address system-level risks and reduce the risk of disruption to the services they provide spreading across the UK financial system.”

Testing moves up

The move expands the boundaries of resilience assurance. Testing can no longer end at the bank’s own technology perimeter when core applications, data services, APIs, authentication systems and increasingly AI workloads depend on infrastructure controlled by external providers.

Banks will still need to validate their own systems, but regulators are now also examining the shared foundations beneath them.

The regime will require designated providers to identify and manage risks to their critical services and maintain communication with regulators and financial institutions, particularly during major incidents.

“CTPs must identify and manage risks to their critical services effectively, and maintain open, timely communication with regulators and the firms that rely on them, particularly during major incidents,” the Bank of England said in a statement shared with QA Financial.

That creates a stronger regulatory expectation around evidence, incident readiness and the ability to demonstrate that critical services can continue operating, or recover quickly, when failures occur.

It also reinforces the direction established under DORA, where testing, third-party oversight and operational resilience are treated as connected parts of the same assurance framework.


“As critical third parties become increasingly embedded in the operations of financial institutions, they can introduce new forms of systemic risk.”

– Sarah Breeden, BoE

The UK regulators confirmed that designated providers may also be covered by overseas regimes, including DORA, and have signed an agreement with EU authorities to support cooperation and information sharing.

“CTPs may also be regulated under similar regimes in other jurisdictions, including the EU’s Digital Operational Resilience Act (DORA),” the Bank added

The overlap is especially relevant for global banks that operate across both the UK and European Union and frequently depend on the same cloud providers, platforms and software services in multiple jurisdictions.

For those firms, the emerging regulatory model points towards greater alignment around service mapping, concentration risk, resilience validation and evidence that disruption can be contained before it becomes systemic.

Sarah Breeden, Deputy Governor for Financial Stability at the Bank of England, said the growing role of external providers had introduced new risks that could not be addressed solely through supervision of financial institutions.

“As critical third parties become increasingly embedded in the operations of financial institutions, they can introduce new forms of systemic risk,” she said.

“Our proportionate approach to overseeing these providers will ensure that these dependencies are managed in a way that safeguards financial stability.”

The designation of the four providers also operationalises powers that have been under mounting political scrutiny.

Dame Meg Hillier

Earlier this year, Treasury Committee chair Dame Meg Hillier criticised delays in activating the regime, warning that the financial system remained exposed while the relevant powers were unused.

“The powers offered by the Critical Third Parties Regime are sitting unused while we remain vulnerable,” she said at the time. “I simply cannot understand why this is taking so long.”

The beginning of formal oversight now marks a transition from regulatory concern to practical supervision.

The significance lies in how that supervision is likely to influence expectations placed on banks. Financial institutions will still have to understand their dependencies, test their contingency arrangements and prove that critical business services can remain within tolerance when a supplier fails.

The Bank stressed that direct oversight of providers does not remove those obligations.

“This regime complements, but does not replace, existing outsourcing and operational resilience rules for regulated firms who remain responsible for managing their own third-party arrangements including due diligence, risk management and contingency planning,” it said.

That means the new regime does not transfer responsibility for resilience from banks to cloud providers. Instead, it creates two connected layers of assurance.

Technology providers must demonstrate the resilience of their critical services, while banks must continue testing whether their own systems and business processes can survive degradation or loss of those services.


“The powers offered by the Critical Third Parties Regime are sitting unused while we remain vulnerable.”

– Meg Hillier

For testing teams, this could mean more emphasis on cloud exit planning, failover, degraded-service scenarios, supplier outages, data portability, recovery validation and dependencies that cross several providers simultaneously.

It may also require banks to produce clearer evidence showing how third-party failures affect important business services, rather than relying on contractual commitments or supplier certifications as proof of resilience.

Katharine Braddick, Deputy Governor for Prudential Regulation and chief executive of the PRA, said the regime was intended to strengthen the infrastructure supporting the wider sector.

“By bringing critical third parties into the scope of oversight, we are ensuring that the infrastructure underpinning UK financial services is robust enough to support UK financial stability and confidence,” she said.

“This directly supports the PRA’s objective to promote the safety and soundness of regulated firms.”

Former Barclays executive Katharine Braddick, Deputy Governor for Prudential Regulation

The development comes as UK regulators are also placing greater emphasis on live validation, scenario analysis and evidence-based assurance across AI, cyber risk and operational resilience.

The Bank of England has already confirmed that it is using simulations to examine how AI-driven trading systems could behave during periods of market stress, including whether multiple agents could exhibit correlated or “herding” behaviour.

That work reflects a broader shift away from treating technology risk as something that can be addressed through governance policies alone.

Ed Birchall

As Ed Birchall, vice-president for enterprise AI at Nuix, previously argued: “The Bank of England testing AI-driven systemic risk is a big signal, not just for regulators, but for every financial institution.”

“We’re moving from ‘AI experimentation’ to ‘AI as market infrastructure’,” he said.

The designation of AWS, Google Cloud, Microsoft and Oracle adds another dimension to that transition. These companies are not only cloud infrastructure providers but increasingly supply the platforms, computing capacity and AI services on which banks are building their next generation of applications.

As AI becomes more deeply embedded in financial services, resilience testing will therefore need to cover both the behaviour of AI systems and the infrastructure supporting them.

The systemic concern is no longer simply whether one model, application or institution fails. It is whether multiple firms depending on common platforms could experience disruption at the same time.

Meanwhile, FCA chief executive Nikhil Rathi said the concentration of services among a small number of providers creates the potential for individual failures to spread widely.

“Critical third parties provide essential services which support innovation and growth,” he said.

“At the same time, when the same providers serve thousands of firms, a single failure can reverberate across the financial system.”

Nikhil Rathi

“Operationalising this regime strengthens our ability to tackle those risks and improve overall resilience, ensuring the UK remains a safe and attractive place to do business.”

The FCA has also been pushing financial institutions towards more realistic forms of testing through its AI Live Testing initiative.

Moreover, Ed Towers, head of advanced analytics at the FCA, previously said: “We’re providing a structured but flexible space where firms can test AI-driven services in real-world conditions, all with our regulatory support and oversight.”

The regulator has defined the system under examination broadly, rather than limiting testing to the underlying model.

“We broadly define the AI system as: the actual AI model, information on the deployment context and core risks … governance and human in the loop considerations, evaluation techniques as well as the input and output controls,” Towers explained.

That full-system approach closely mirrors the challenge posed by critical third-party dependencies. A bank cannot assess resilience by testing an application in isolation when its performance depends on external infrastructure, network services, APIs, data platforms and recovery processes.

The expansion of oversight to technology providers therefore strengthens the case for testing that follows an important business service across the entire supporting stack.

It also supports the Bank’s wider message that resilience needs to be demonstrated rather than assumed.

“Cyber-attacks remain a major threat to the financial sector,” the Bank has previously warned, adding that resilience “can no longer be assumed, it must be proven.”

External tech layer

For QA and resilience teams, the CTP regime turns that principle towards the external technology layer.

Banks will need to show that they understand where critical dependencies sit, what happens when those services become unavailable and whether alternative arrangements genuinely work under pressure.

The providers themselves will face scrutiny over the resilience of the services on which much of the sector depends.

The regulators said the regime would improve coordination and information sharing across the financial system, while allowing them to examine risks that no individual bank could fully assess on its own.

“This will strengthen system-wide resilience and improve coordination and information sharing across the UK financial sector,” they said.

The authorities will periodically review whether designated providers continue to meet the criteria for oversight and may recommend future designations or removals to HM Treasury.

The scope is therefore likely to evolve as the financial system becomes more dependent on external software, data and technology services.


“By bringing third parties into the scope of oversight, we are ensuring that the infrastructure underpinning UK financial services is robust enough.”

Katharine Braddick

For testing teams, the direction is already clear. Third-party assurance is moving beyond questionnaires, certificates and contractual commitments towards stronger validation of how services perform during disruption.

The UK regime does not remove banks’ responsibility to test their own resilience. It widens the regulatory field so that the technology providers beneath those banks must also answer questions about risk, recovery and system-wide impact.

Testing is moving upstream, from applications and institutions towards the cloud platforms that increasingly function as financial infrastructure.

And as the UK aligns more closely with DORA, the ability to produce credible, auditable evidence of resilience across the entire technology chain is becoming a regulatory requirement rather than a matter of internal good practice.


16 SEPTEMBER IN LONDON

REGISTER TODAY – SIMPLY CLICK HERE


Why not become a QA Financial subscriber?

It’s entirely FREE

* Receive our weekly newsletter every Wednesday * Get priority invitations to our Forum events *

SIGN UP HERE TODAY


REGULATION & COMPLIANCE

Looking for more news on regulations and compliance requirements driving developments in software quality engineering at financial firms? Visit our dedicated Regulation & Compliance page here.


READ MORE


WATCH NOW


QA FINANCIAL PODCASTS

CLICK HERE TO LISTEN TO OUR EXCLUSIVE CONVERSATIONS