On a single afternoon last October, more than 2,000 companies — among them Lloyds Banking Group, one of Britain's largest lenders — lost access to online services because of a software glitch in a data centre in Northern Virginia, a suburb of Washington DC. The disruption was brief by some measures, but its reach was vast: it traced directly back to Amazon Web Services, a firm headquartered thousands of miles from the customers whose accounts it indirectly served. That episode crystallised a concern that regulators had been circling for years. Starting this Monday, the Bank of England and the Financial Conduct Authority (FCA) will assume direct supervisory authority over the UK operations of Amazon Web Services, Google Cloud, Oracle and Microsoft.
The four companies have been formally designated "critical third parties" by the UK government, giving regulators a legal basis to demand stress tests, require disclosure of cyber-attacks, power outages and natural disasters, and compel evidence that adequate resilience measures are in place. The powers had been granted in theory since January 2025, but the government took more than eighteen months to identify which companies would actually be covered — a delay that drew sharp criticism from lawmakers. The rationale is not difficult to understand. Banks have progressively offloaded core functions — data storage, fraud detection algorithms, digital payment infrastructure — onto a handful of foreign-owned cloud platforms.
According to the Treasury Committee, British bank customers collectively experienced the equivalent of more than one full month of IT failures between 2023 and 2025. That figure is a measure not merely of inconvenience but of concentrated systemic risk: when the same few firms underpin hundreds of financial institutions simultaneously, a single point of failure can ripple outward at extraordinary speed.