For more than 40 years Microsoft has worked closely with UK government agencies to help support business, improve citizen services, and secure and enhance the resilience of the digital ecosystem. As Microsoft’s role in the financial services industry has increased as a key provider in supporting financial firms run critical and important business services, so has its responsibility to meet the demands of customers and regulators alike.
It is thus the natural evolution of Microsoft’s role that HM Treasury has designated Microsoft Ireland Operations Limited (MIOL) as a critical third party to the UK financial sector, a designation publicly announced on July 10, 2026.1 MIOL recognizes its responsibilities as a critical third party and is fully committed to complying with the applicable oversight requirements and the UK’s cybersecurity and resilience laws. As with its designation as a Critical Third Party Service Provider under the EU Digital Operational Resilience Act, MIOL will continue to focus its responsibilities on supporting the financial services industry and enhancing overall operational resilience of the financial ecosystem.
Understanding the UK critical third parties regime
The CTP regime created under the Financial Services and Markets Act 2023, gives HM Treasury the power to designate third-party service providers as “critical” to the UK financial sector, and gives the Bank of England, the Prudential Regulation Authority (PRA), and the Financial Conduct Authority (FCA), collectively “the regulators,” the ability to set rules for, gather information from, and oversee those critical third party providers.
The regime exists because financial firms increasingly rely on a small number of third parties for services that are critical and important to their business operations. The regulators’ aim is to manage the risk that a failure in, or disruption to, one of those services could affect many firms at once and, in turn, threaten the stability of the wider financial system. Notably, the UK regime is technology-neutral (it is not limited to cloud providers), and designation is made by HM Treasury on the recommendation of the regulators.
What the designation means and what it does not
As a designated critical third party, MIOL is subject to direct oversight by the regulators in relation to the services identified as systemic. In practice, this involves engagement with the regulators under a set of fundamental rules, alongside expectations in areas such as self-assessment, scenario testing, incident management, and incident reporting. A core principle of the regime is that a critical third party should deal with the regulators in an open and cooperative way, an approach MIOL fully embraces as a critical third party under the UK CTP regime.
It is equally important to be clear about what the designation does not change. As with the EU’s DORA regime, financial firms remain primarily accountable as regulated institutions. As set forth in Supervisory Statement SS6/24:2
The CTP duties complement the requirements and expectations for firms on operational resilience, outsourcing and third party risk management. The CTP oversight regime sits alongside these requirements and expectations but does not eliminate, reduce nor replace the accountability of firms, their boards and senior management (including individuals performing SMFs).
Microsoft, as a technology provider, is committed to meeting its own obligations and helping its customers meet theirs, while the regulatory responsibilities of a financial institution remain with the institution. For our customers, it is business as usual: there are no material changes to the Microsoft services they rely on today.
Supporting our customers’ operational resilience
Microsoft has long invested in the security, compliance, and resilience of its cloud platform, and that investment is what enables us to support financial institutions as they meet their own regulatory obligations. We take a global, scaled approach to these requirements, ensuring that customers can have confidence that consistent operational and security controls apply wherever they operate. The capabilities most relevant to operational resilience include:
- Continuous threat monitoring with Microsoft Sentinel: real-time threat detection and continuous security monitoring, with automated incident handling and evidence workflows that support operational-resilience expectations.
- Threat protection with Microsoft Defender XDR: cross-platform threat protection and advanced response capabilities.
- Governance and compliance management with Microsoft Purview Compliance Manager: regulatory assessment templates that help organizations assess and track compliance across Microsoft cloud services.
- Compliance and policy enforcement with Azure Policy: compliance monitoring and policy adherence across hybrid and multicloud environments.
- Lifecycle security and compliance management with Microsoft Unified: helps operationalize incident management and resilience controls aligned with regulatory expectations.
For customers with deeper compliance assurance needs, Compliance for Microsoft Cloud (EDE) is an optional Microsoft Unified Support add-on that provides a dedicated engineer focused on compliance-related scenarios, helping customers interpret Microsoft controls and support regulatory and assurance discussions. These tools are designed to help customers strengthen their own resilience posture; they do not transfer or discharge a firm’s regulatory responsibilities, which remain with the firm.
A consistent, global approach
This is not Microsoft’s first such designation. MIOL was designated a critical Information and Communication Technology (ICT) third party service provider in November 2025. Under the European Union’s Digital Operational Resilience Act (DORA), regulators have direct oversight of companies identified as critical third-party providers (including MIOL).
The UK regulators have designed their regime to be compatible with similar approaches in other jurisdictions, and Microsoft’s goal is to meet these expectations consistently in the provisioning of the systemic services, engaging constructively with regulators and maintaining the resilience of the services on which our customers depend.
Our commitment
Microsoft is fully committed to complying with the UK’s operational resilience requirements and to cooperating with the regulators. We will continue to focus on earning and maintaining the trust of financial institutions and investing in the resilience of the platform that underpins their most critical workloads. We will keep our customers and partners informed as the regime continues to take shape.
Explore how Microsoft helps financial leaders navigate regulatory requirements
- Explore how Microsoft helps financial leaders build trust, apply AI responsibly, and turn data into more confident decisions in our Trust and Intelligence in Financial Services ebook.
- Learn more about Microsoft’s platform strategy for regulated financial services: Microsoft for Financial Services
- See how Microsoft frames regulatory compliance as a long-term strategic challenge: Compliance Overview
Learn More
UK regulatory sources
- Bank of England: Critical Third Parties (CTPs)
- Bank of England SS6/24: Critical third parties to the UK financial sector
- FCA PS24/16: Operational resilience: Critical third parties to the UK financial sector
- HM Treasury: Approach to Designating Critical Third Parties
- Outsourcing and third party risk management
Related Microsoft perspectives
- As regulation intensifies, Microsoft helps financial leaders meet growing demands (Apr 2026)
- 3 ways Microsoft is helping the financial industry prepare for new DORA regulations (Sep 2024)
2 – SS6/24 – Critical third parties to the UK financial sector | Bank of England