Skip to main content Frontier Transformation Frontier Accelerate AI for business Use cases Consumer goods Digital sovereignty Education Overview Power and utilities Oil and gas Mining Overview Banking Capital markets Insurance Overview Defense and intelligence Transportation and urban infrastructure Social services and public health Public safety and justice Public finance Overview Defense and intelligence Federal civilian State and local governments Cloud for US government AI for US government Overview Providers Payors Life sciences Health solutions Overview Industrial transformation Media and entertainment Overview Automotive Travel and transportation Retail Telecommunications Microsoft 365 Copilot AI agents at work Microsoft IQ Agent 365 Security for AI Copilot Studio Microsoft Foundry Microsoft Agent Factory Azure AI apps and agents Microsoft Marketplace Copilot+ PCs Microsoft Copilot Download the Copilot app Microsoft responsible AI Principles and approach Tools and practices Advancing sustainability Securing AI Data protection and privacy AI 101 AI learning hub Industry blog Microsoft Cloud blog Support for business Industry documentation

For more than 40 years Microsoft has worked closely with UK government agencies to help support business, improve citizen services, and secure and enhance the resilience of the digital ecosystem. As Microsoft’s role in the financial services industry has increased as a key provider in supporting financial firms run critical and important business services, so has its responsibility to meet the demands of customers and regulators alike.

It is thus the natural evolution of Microsoft’s role that HM Treasury has designated Microsoft Ireland Operations Limited (MIOL) as a critical third party to the UK financial sector, a designation publicly announced on July 10, 2026.1 MIOL recognizes its responsibilities as a critical third party and is fully committed to complying with the applicable oversight requirements and the UK’s cybersecurity and resilience laws. As with its designation as a Critical Third Party Service Provider under the EU Digital Operational Resilience Act, MIOL will continue to focus its responsibilities on supporting the financial services industry and enhancing overall operational resilience of the financial ecosystem.

Understanding the UK critical third parties regime

The CTP regime created under the Financial Services and Markets Act 2023, gives HM Treasury the power to designate third-party service providers as “critical” to the UK financial sector, and gives the Bank of England, the Prudential Regulation Authority (PRA), and the Financial Conduct Authority (FCA), collectively “the regulators,” the ability to set rules for, gather information from, and oversee those critical third party providers.

The regime exists because financial firms increasingly rely on a small number of third parties for services that are critical and important to their business operations. The regulators’ aim is to manage the risk that a failure in, or disruption to, one of those services could affect many firms at once and, in turn, threaten the stability of the wider financial system. Notably, the UK regime is technology-neutral (it is not limited to cloud providers), and designation is made by HM Treasury on the recommendation of the regulators.

What the designation means and what it does not

As a designated critical third party, MIOL is subject to direct oversight by the regulators in relation to the services identified as systemic. In practice, this involves engagement with the regulators under a set of fundamental rules, alongside expectations in areas such as self-assessment, scenario testing, incident management, and incident reporting. A core principle of the regime is that a critical third party should deal with the regulators in an open and cooperative way, an approach MIOL fully embraces as a critical third party under the UK CTP regime.

It is equally important to be clear about what the designation does not change. As with the EU’s DORA regime, financial firms remain primarily accountable as regulated institutions. As set forth in Supervisory Statement SS6/24:2

The CTP duties complement the requirements and expectations for firms on operational resilience, outsourcing and third party risk management. The CTP oversight regime sits alongside these requirements and expectations but does not eliminate, reduce nor replace the accountability of firms, their boards and senior management (including individuals performing SMFs).

Microsoft, as a technology provider, is committed to meeting its own obligations and helping its customers meet theirs, while the regulatory responsibilities of a financial institution remain with the institution. For our customers, it is business as usual: there are no material changes to the Microsoft services they rely on today.

Supporting our customers’ operational resilience

Microsoft has long invested in the security, compliance, and resilience of its cloud platform, and that investment is what enables us to support financial institutions as they meet their own regulatory obligations. We take a global, scaled approach to these requirements, ensuring that customers can have confidence that consistent operational and security controls apply wherever they operate. The capabilities most relevant to operational resilience include:

  • Continuous threat monitoring with Microsoft Sentinel: real-time threat detection and continuous security monitoring, with automated incident handling and evidence workflows that support operational-resilience expectations.
  • Threat protection with Microsoft Defender XDR: cross-platform threat protection and advanced response capabilities.
  • Governance and compliance management with Microsoft Purview Compliance Manager: regulatory assessment templates that help organizations assess and track compliance across Microsoft cloud services.
  • Compliance and policy enforcement with Azure Policy: compliance monitoring and policy adherence across hybrid and multicloud environments.
  • Lifecycle security and compliance management with Microsoft Unified: helps operationalize incident management and resilience controls aligned with regulatory expectations.

For customers with deeper compliance assurance needs, Compliance for Microsoft Cloud (EDE) is an optional Microsoft Unified Support add-on that provides a dedicated engineer focused on compliance-related scenarios, helping customers interpret Microsoft controls and support regulatory and assurance discussions. These tools are designed to help customers strengthen their own resilience posture; they do not transfer or discharge a firm’s regulatory responsibilities, which remain with the firm.

A consistent, global approach

This is not Microsoft’s first such designation. MIOL was designated a critical Information and Communication Technology (ICT) third party service provider in November 2025. Under the European Union’s Digital Operational Resilience Act (DORA), regulators have direct oversight of companies identified as critical third-party providers (including MIOL).

The UK regulators have designed their regime to be compatible with similar approaches in other jurisdictions, and Microsoft’s goal is to meet these expectations consistently in the provisioning of the systemic services, engaging constructively with regulators and maintaining the resilience of the services on which our customers depend.

Our commitment

Microsoft is fully committed to complying with the UK’s operational resilience requirements and to cooperating with the regulators. We will continue to focus on earning and maintaining the trust of financial institutions and investing in the resilience of the platform that underpins their most critical workloads. We will keep our customers and partners informed as the regime continues to take shape.

Explore how Microsoft helps financial leaders navigate regulatory requirements

Learn More

UK regulatory sources

Related Microsoft perspectives


1UK financial regulators to begin overseeing Critical Third Parties announced by HM Treasury | Bank of England

2SS6/24 – Critical third parties to the UK financial sector | Bank of England

Explore
Microsoft Cloud solutions

Discover how the most trusted and comprehensive cloud can help you meet the challenges of a rapidly changing world.

Connect with us on social