Home icon

AWS designated as a critical third party to the UK financial sector

Security Blog



AWS has been designated as a critical third party (CTP) to the UK financial sector by HM Treasury under a new regulatory framework that came into force on January 1, 2025.

  • AWS will be subject to requirements relating to its Systemic Third-Party Services under the CTP regime
  • AWS must conduct self-assessment of these services against CTP regime criteria
  • The Bank of England, PRA, and FCA have direct oversight authority over AWS
  • Financial services customers retain full accountability for operational resilience despite using AWS services
  • AWS will publish materials to help customers with operational resilience planning and third-party risk management
  • AWS offers Well-Architected Framework and cloud incident management resources to support customer resilience

AWS remains committed to supporting UK financial services customers in meeting their operational resilience obligations while complying with the new CTP regulatory framework.



Go to article

The AWS News Feed is currently looking for gold sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.

Related articles

Nov 19
2025
AWS designated as a critical third-party provider under EU’s DORA regulation
Jan 8
2025
AWS Responds to Basel Committee on Banking Supervision (BCBS) on Principles for the sound management of third-party risk
Apr 11
2024
UK regime for critical third parties and its impact on financial services customers
Feb 27
2026
AWS now supports Bacs Direct Debit as a payment method for UK customers

The AWS News Feed is currently looking for silver sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.