In a blog published on April 11th, AWS outlined key points of its response to the UK regulators’ consultation paper, CP26/23 ‘Operational resilience: Critical third parties to the UK financial sector’.
The blog, ‘UK regime for critical third parties and its impact on financial services customers’, was written by Michael Jefferson, head of Financial Services Public Policy UK, Middle East, Africa and Switzerland and Arvind Kannan, Principal Compliance Specialist.
The Financial Services and Markets Act 2023 allows HM Treasury to designate a third party as critical in consultation with the Bank of England (BoE), Prudential Regulation Authority (PRA), and Financial Conduct Authority (FCA) (the Authorities) and AWS states that it is preparing for this regime based on the assumption that it will be designated as a critical third party (CTP).
In the blog the authors set out key points from the AWS response to CP26/23, these being:
- Advanced technologies, such as cloud computing, have significant benefits for the financial sector, including increased security, flexibility, operational resilience, rapid scalability and reliability. So, it is important that the implementation of any requirements does not introduce barriers on how AWS’s financial services customers choose to use technologies on a location or industry basis.
- While AWS welcomes the risk-based, outcomes-focused regime set out in the CP, it identified opportunities where changes could help better meet the objectives of the regime. These include introducing the AWS shared responsibility model as an appropriate regulatory concept for operational resilience; emphasising that any information required to be provided to the regulator under the regime will always be on a proportionate, useful, and relevant basis; and avoiding a requirement for regulated firms to adopt a multi-vendor cloud strategy as part of the CTP regime.
- AWS also proposed specific changes to the Operational Risk & Resilience Requirements, approaches to ascertaining material services, incident management, the financial sector playbook and scenario testing. It identified these areas as they are where the proposals do not fit with the operating model of potential CTPs, such as cloud service providers, or how customers use them.






