UK CTP Regime: Why Hyperscaler Oversight Doesn't Cover Your Contract Obligations.

On 13 July 2026, the Bank of England, the Prudential Regulation Authority (PRA), and the Financial Conduct Authority (FCA) began directly overseeing four hyperscalers: Amazon Web Services, Microsoft, Google Cloud, and Oracle. The regime shifts who regulators can go to. It does nothing to shift what firms must be able to demonstrate.


For the first time, UK regulators can go straight to a provider whose failure could ripple across the whole sector, instead of only ever going through the firms that use them. That is a genuine structural shift in how operational resilience is supervised. It is also not the part that demands the most attention from a compliance team.

The critical third party (CTP) regime gives regulators a direct line to the provider. It does nothing to the obligation to know what a firm has actually signed with that provider, or with the 40 suppliers underneath it, or with the fourth-party subcontractors the paperwork does not name properly. The regime created a new power for regulators. It did not resolve the challenge of maintaining a live, consolidated view of a licensing estate that has grown faster than any team can track by hand.

What CTP designation actually does

This is about systemic exposure. If a hyperscaler has a bad day, that is no longer purely its problem and the firm's problem. It is the regulator's problem, and now they can act on it directly. Four providers are designated today. HM Treasury has already said the list will grow.

What it does not do

Direct oversight of a hyperscaler does not touch a firm's obligation to know what it has actually signed with that provider. The regulator's new powers point at the provider. Accountability for the contract terms, the exit plan, and the concentration risk still points squarely at the firm. This is not a new obligation; Article 28 registers and third-party oversight requirements have been building for a while. What 13 July did was create the first real test of whether firms can produce specific answers when someone actually asks.

The question that gets asked

When a regulator, an auditor, or a board asks what happens if this provider fails, they are not asking for a PDF. They are asking for a specific answer: what is the exit clause, what is the notice period, what data portability commitments exist, and which other agreements reference this one. If that answer is distributed across a master agreement, a hundred-plus order schedules, and however many amendments have landed since signature, somebody is reading documents to construct an answer that should already exist. This pattern shows up inside real licensing estates: over 150 interlinked documents, with no way to check a single obligation without opening most of them. That is not a compliance gap. It is an operational one. CTP designation just made it visible.

What changes once the database is live, not static

The firms that handle this well are not the ones with the thickest binder of supplier contracts. They are the ones who can answer a specific question in minutes, because obligations, restrictions, and exit terms sit in one consolidated, structured view instead of a folder of PDFs someone re-reads from scratch every time. The same capability lets a licensing team clear a new product use case without reading a hundred order schedules, or lets a bank confirm a fee cap without a lengthy document review.

What to do before the next designation lands

Do not wait for a primary provider to appear on the Treasury's list. Build the database now, for the suppliers already known to matter, so the next designation is a non-event rather than a scramble. Three questions worth being able to answer today, in minutes rather than days: what is the exit clause on the most critical supplier contract, what is the current amendment status on it, and who else internally is relying on terms buried in that same agreement.

Next
Next

The amendment you don't know is missing