What The UK–EU MoU on Critical Third Parties Means for Vendor Programs
CyberKainos. Reading time: 5 mins
If your vendor programme hasn’t been updated to reflect this new reality, it needs to be.
Last week, HM Treasury quietly made history. Amazon Web Services, Google Cloud, Microsoft, and Oracle became the first firms to be formally designated as Critical Third Parties to the UK financial sector bringing them within the direct supervisory reach of the FCA, Bank of England, and Prudential Regulation Authority (PRA).
For risk and compliance teams, the designation itself was not a surprise. These providers essentially underpin UK financial services infrastructure, and their systemic importance has been recognised in policy discussions for years – they are definition of critical third parties. What the designations confirm, however, is that the regulatory landscape for third-party risk has fundamentally and permanently changed.
Vendor management is no longer a procurement and contracting discipline with a compliance overlay. It is, increasingly, a regulated activity in its own right and has been building since the UK’s Critical Third Parties (CTP) regime came into effect in January 2025, accelerated by the January 2026 Memorandum of Understanding (MoU) between UK and EU regulators. If your vendor programme hasn’t been updated to reflect this new reality, it needs to be.
What the MoU Actually Does
In January 2026, the FCA, Bank of England, and PRA signed an MoU with the three European Supervisory Authorities to coordinate oversight of critical third-parties operating across both jurisdictions.
This has established a framework for information sharing and supervisory cooperation on providers that fall under the UK’s CTP regime and their EU equivalents under DORA. It covers both routine oversight and incident response, explicitly including scenarios such as cyber-attacks or major outages where cross-border dependencies mean a local supervisory response is no longer adequate on its own.
This MoU is not is a new rulebook. It doesn’t change the obligations on financial firms directly. What it does is signal unambiguously where supervision is heading: toward coordinated, system-wide scrutiny of the technology dependencies that underpin financial services on both sides of the Channel. When regulators in London and Frankfurt are sharing information about the same provider’s resilience, your own oversight of that provider needs to be credible enough to withstand questions from either direction.
The UK CTP Regime: A Quick Recap
The UK’s CTP regime gives the FCA, PRA, and Bank of England direct oversight powers over third-party providers whose failure could threaten the stability of the UK financial system. Rules came into effect in January 2025, with HM Treasury retaining the power to formally designate providers.
The four initial designations: AWS, Google Cloud, Microsoft, and Oracle were made on last on the 13th July and they are not expected to be the last. The FCA has already indicated that AI providers and market data firms could be considered in future rounds.
Crucially, the regime does not transfer responsibility for managing third-party risk away from financial firms. The FCA has been explicit: CTP designation is not a badge of safety. Regulated firms remain fully accountable for managing their own dependencies, including on designated CTPs. Regulators will oversee the providers directly but they will still judge financial firms on whether their governance holds together when a shared dependency fails.
What This Means for Your Vendor Programme
For most financial services firms, the practical implications of the MoU and the CTP regime fall into four areas.
Your dependency mapping needs to be current and complete. The CTP regime and the UK–EU MoU both rest on the premise that regulators need visibility of systemic concentrations, which means financial firms need that visibility first. If your third-party register doesn’t clearly identify which of your critical business services rely on now-designated CTPs, that is a gap that needs closing. Firms with EU operations will already be familiar with DORA’s Register of Information requirement; the discipline required is similar.
Contracts with designated CTPs need reviewing. The CTP rules introduce requirements for what regulated firms must include in their contracts with designated providers, covering service levels, resilience standards, audit and access rights, incident notification obligations, and exit arrangements. These are not aspirational standards; they are minimum provisions the FCA expects to see in place. Contracts signed before January 2025 are unlikely to contain all of them, and even more recent agreements may not fully reflect the enhanced requirements for designated providers specifically.
Exit planning needs to be credible, not theoretical. One of the most consistent themes in both the UK and EU regulatory frameworks is the requirement for realistic and tested exit strategies from critical providers. The question regulators are increasingly asking is not “do you have an exit plan?” but “could you actually execute it?” For providers that have now been formally designated as systemically critical, that question carries more weight because their designation implicitly confirms that any failure would be disruptive at scale. Firms need to demonstrate that they have genuinely thought through what happens if a designated CTP experiences a prolonged outage, and that their business continuity planning reflects that scenario.
Incident response needs to account for provider-level disruption. The MoU specifically covers information sharing during incidents. If a designated CTP experiences a significant disruption, UK and EU regulators will be coordinating their response. Financial firms need to be able to detect, classify, and respond to provider-level incidents quickly and to communicate with regulators coherently when that happens. Firms that have built their incident response planning around internal system failures rather than external dependency disruptions will find that framework tested when the next major cloud outage occurs.
The Bigger Picture: From Outsourcing to Operational Dependency
Financial services infrastructure runs on just a handful of cloud providers and technology vendors. The concentration of that dependency creates risks that individual firms cannot manage in isolation, because a failure at the provider level doesn’t affect one firm; it affects many simultaneously, creating the kind of correlated disruption that individual resilience planning cannot address.
This is why the CTP regime and DORA have bought systemically important providers inside the regulatory perimeter. The MoU ensures that regulators on both sides of the Channel are coordinating their oversight of providers that straddle both markets. And the first designations confirm that this is no longer theory it is live supervision.
For financial services firms, the implication is straightforward: the bar for third-party risk management has risen permanently. Annual due diligence reviews and standard outsourcing questionnaires were never adequate for managing systemic dependencies, and regulators have now formalised that view. What is required is continuous, evidence-based oversight of critical suppliers with governance structures, contractual provisions, and operational resilience planning that are genuinely fit for purpose, not inherited from a framework designed for a different era.
How CyberKainos Can Help
We have over 20 years’ experience working with financial services firms to build oversight of critical third parties to reflect current regulatory realities.
Whether you need to review and update your critical third parties’ register in light of the CTP designations, stress-test your exit strategies against realistic provider disruption scenarios, audit your contracts with designated CTPs against the FCA’s minimum provisions, or build the governance and reporting infrastructure to give your board credible, ongoing visibility of your dependency risks, our team has the regulatory expertise and practical experience to help.
The first CTP designations are live. Regulatory scrutiny of how firms manage their dependencies on these providers is already intensifying. This is not a problem that benefits from delay.