From Monday this week, the Bank of England, the Prudential Regulation Authority and the FCA began directly overseeing four global technology providers — Amazon Web Services, Microsoft Azure, Google Cloud and Oracle — after HM Treasury formally designated them “Critical Third Parties” to the UK financial system. It’s the first time regulators have had direct powers over the cloud infrastructure that banks, insurers and payment providers depend on, rather than only being able to regulate the financial firms that use it. The logic is straightforward: so much of the UK’s financial plumbing now runs on a handful of cloud platforms that a serious outage at one of them could ripple across the whole economy at once.
You don’t need to be a bank for this to matter to your business. Most SMEs now run on exactly the same infrastructure this regime is designed to protect — the same cloud platforms host your email, your accounting software, your customer data, and very likely several of the SaaS tools your business runs on day to day. The regulation itself only applies to financial institutions, but the underlying vulnerability it’s responding to — concentrated dependency on a small number of providers — applies just as much to a ten-person company as it does to a high street bank.
What the regulation actually changes
Regulators can now gather information directly from these providers, assess their resilience, and set rules to address risks to service continuity. What it explicitly does not do, and what the regulators themselves have been clear about, is let financial firms hand off their own vendor-risk responsibilities. Banks are still required to do their own due diligence, manage the risk their providers create, and have contingency plans ready for when — not if — something goes wrong. That’s the part worth sitting with as an SME owner, because if regulated banks with compliance teams still can’t outsource this responsibility, an unregulated small business certainly can’t either.
The question most SMEs haven’t answered
If your primary cloud provider, accounting platform, or core business software had a multi-day outage tomorrow, do you have a plan — or would you be finding out live what your actual exposure looks like? Most small businesses have never stress-tested this question, because cloud services have historically been reliable enough that it felt theoretical. The Bank of England’s move is a signal that regulators no longer treat it as theoretical, and neither should you. A basic contingency plan doesn’t need to be sophisticated: know which of your tools are genuinely load-bearing for the business, keep an independent, current copy of anything irreplaceable, and know how you’d operate — even in a reduced capacity — if one of them went dark for a few days.
Building resilience without over-engineering it
This isn’t a call to abandon the cloud or spread your business across five providers out of caution — that creates its own complexity and cost for most SMEs without a proportionate benefit. It’s a call to know your dependencies and keep your own house in order regardless of what your providers do. Archive.Partners helps businesses keep an independent, accessible archive of critical records and data outside any single vendor’s ecosystem, which is precisely the kind of low-effort insurance that matters if a “too big to fail” provider has a bad day anyway.
The takeaway
Regulators have just accepted that cloud concentration is a systemic risk worth actively managing — for the financial sector today, but the same logic applies to any business built on the same platforms. You can’t demand the same oversight powers as the Bank of England, but you can ask yourself the same question they’re now asking of the providers: if this went down, what’s the plan? If you don’t have an answer, that’s this week’s task, not a someday one.