AWS designated as a critical third party to the UK financial sector
Security Blog
AWS has been designated as a critical third party (CTP) to the UK financial sector by HM Treasury under a new regulatory framework that came into force on January 1, 2025.
- AWS will be subject to requirements relating to its Systemic Third-Party Services under the CTP regime
- AWS must conduct self-assessment of these services against CTP regime criteria
- The Bank of England, PRA, and FCA have direct oversight authority over AWS
- Financial services customers retain full accountability for operational resilience despite using AWS services
- AWS will publish materials to help customers with operational resilience planning and third-party risk management
- AWS offers Well-Architected Framework and cloud incident management resources to support customer resilience
AWS remains committed to supporting UK financial services customers in meeting their operational resilience obligations while complying with the new CTP regulatory framework.
The AWS News Feed is currently looking for gold sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.
Related articles
Nov 19
2025
2025
AWS designated as a critical third-party provider under EU’s DORA regulation
Jan 8
2025
2025
AWS Responds to Basel Committee on Banking Supervision (BCBS) on Principles for the sound management of third-party risk
Apr 11
2024
2024
UK regime for critical third parties and its impact on financial services customers
Feb 27
2026
2026
AWS now supports Bacs Direct Debit as a payment method for UK customers
The AWS News Feed is currently looking for silver sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.