Cloud computing has become fundamental to the financial services industry, giving firms the scalability and flexibility to modernise their technology infrastructure. But as institutions increasingly rely on a small number of providers, that dependence is creating a new concentration risk, with implications for operational resilience, regulatory compliance and the wider financial system.
For RegTech, the challenge extends beyond managing individual firms’ cloud exposure. As regulators sharpen their focus on third-party dependencies and systemic vulnerabilities, technology providers and financial institutions must demonstrate not only that their systems are resilient, but that critical compliance functions can withstand disruption. The question is whether the industry’s cloud foundations are becoming a risk that compliance technology itself must help solve.
How exposed are financial institutions to a small number of cloud providers? Emil Kongelys, CTO of Muinmos, states he would frame the question slightly differently.
He said, “The short answer is that financial institutions are not necessarily more exposed than they were before cloud providers existed. Running systems on bare metal offers no greater guarantee of availability than running them in the cloud. Cloud concentration becomes a material risk when a provider stops operating in a region and workloads cannot be moved to another region, for example because of regulations.”
In that scenario, Kongelys said the more important question is how exposed financial institutions are to providers that are not cloud-agnostic.
“This risk is often underestimated because cloud providers now offer far more than infrastructure,” he remarked.
Systems can become deeply dependent on proprietary services, he added, making it extremely difficult to migrate at short notice.
Another question posed to Kongelys was what role RegTech’s can play in identifying and managing systemic technology dependencies.
“RegTechs are businesses,” he retorted. “As such, we have a strong commercial incentive to keep our services working. So, resilience, efficiency and continuity are therefore core business priorities for us; and that’s how we treat them.”
The Muinmos CTO has also believes that RegTech’s can also help companies map dependencies by automating the collection of relevant information, as well as identify when critical services are overly concentrated with a single provider, and support outage scenario testing.
“RegTechs can also monitor known cloud providers and relevant regions in real time, enabling firms to receive early warnings of potential outages,” he said.
Generally speaking, he added, RegTechs are well equipped to handle these issues as they are, at core, technology companies, whose performance, reputation and eventually very survival depends on uninterrupted services and long-time resilience.
A straightforward proposition
For years, the RegTech proposition has been straightforward: “Why build and maintain everything yourself when someone else can do it better, faster and at scale?”
As regulatory obligations multiply and the pace of change accelerates, outsourcing compliance technology offers firms a way to reduce the cost and complexity of keeping pace. Specialist providers can spread investment across multiple customers, continually develop their technology and absorb much of the operational burden.
“There is a strong argument for this model,” says Rich Kent, CTO of Taina Technology. “Regulatory change is relentless. Keeping systems, processes and people aligned with every new rule, supervisory expectation and reporting requirement is expensive and distracting.”
“Specialist providers can spread those costs across multiple customers, invest continuously in technology and absorb some of the operational burden. In effect, firms can turn a constantly changing compliance challenge into a managed service.”
The model also offers potential risk-management benefits, allowing firms to draw on the expertise and resources of specialist providers. However, as more RegTech services move to the cloud, outsourcing can introduce another layer of dependency into the compliance operating model.
“Cloud concentration has now become a RegTech problem,” Kent explains.
“If ten financial institutions outsource regulatory monitoring to ten RegTech providers, it might look like ten independent solutions. But if those providers rely on the same underlying cloud infrastructure, the apparent diversification can be somewhat misleading.”
A disruption at the infrastructure level could affect multiple RegTech services simultaneously, creating a concentration risk that extends beyond any individual provider.
“The dependency chain can therefore look something like: regulated firm, RegTech provider, cloud provider, infrastructure. And suddenly, the decision to outsource compliance has introduced a new concentration risk into the compliance operating model.”
This does not mean firms should abandon outsourcing or cloud-based technology. Rather, it highlights the importance of understanding the dependencies underpinning these arrangements.
“This isn’t a reason to abandon outsourcing or cloud. In fact, it would be a strange conclusion given the efficiency gains available. It is a reason to understand the dependency properly.”
UK regulators have increasingly recognised the systemic implications of shared technology infrastructure, with cloud services falling within the scope of third-party risk management and operational resilience. For RegTech buyers, this makes it important to look beyond the immediate provider and understand the wider ecosystem on which their compliance capabilities depend.
“The good news is that cloud concentration isn’t a new risk. It is a familiar third-party and operational-resilience problem appearing in a new part of the technology stack.”
Mitigation measures include appropriate due diligence, contractual protections, resilience testing, exit strategies and geographic redundancy. Multi-cloud or hybrid approaches may also help where proportionate, alongside greater visibility of fourth- and nth-party dependencies.
For firms assessing potential providers, the questions they ask must therefore extend beyond the technology itself.
“Not simply, ‘Does this provider use the cloud?’ but ‘How dependent is my compliance capability on its underlying technology ecosystem?’”
Ultimately, outsourcing RegTech remains a compelling economic and operational proposition, enabling firms to focus on their core business while specialists keep pace with changing regulatory demands. The challenge is ensuring that greater efficiency does not come at the expense of resilience.
“The answer isn’t to step off the treadmill,” Kent concludes. “It is to make sure the treadmill doesn’t have a single plug.”
Increasingly RegTech
On 13 July 2026, Amazon Web Services, Google Cloud, Microsoft and Oracle came under the direct oversight of UK financial regulators as designated Critical Third Parties, bringing the issue of cloud concentration firmly into the financial stability debate.
For financial institutions, however, the more immediate challenge is understanding their own exposure. As RelyComply explains, “the harder question is operational: can they actually see, measure and manage their own technology dependencies across the estate?”
“The answer is increasingly a RegTech question.”
Cloud adoption has delivered significant benefits to financial services, but it has also concentrated critical infrastructure among a relatively small number of providers. The Critical Third Parties regime, established under the Financial Services and Markets Act 2023, gives the Bank of England, PRA and FCA powers to oversee providers whose disruption could affect the wider financial system.
However, direct regulatory oversight of these providers does not remove firms’ own responsibilities.
“Each institution remains accountable for its own third-party risk management and operational resilience, which means understanding exactly where, and how heavily, it depends on these providers.”
As RelyComply points out, the issue extends beyond how much a bank spends with a particular cloud provider. A firm may work with multiple vendors while relying on the same underlying cloud platform, data centre, identity service, network provider or subcontractor. Apparent diversification can therefore conceal common points of failure.
European regulation reflects this broader understanding of technology concentration. The Digital Operational Resilience Act (DORA) requires firms to consider the risks arising from dependencies on individual or related critical ICT third-party providers, particularly where these could threaten critical or important functions. For institutions operating across the UK and EU, this makes a consistent view of technology dependencies increasingly important.
Can firms actually see their exposure?
For many financial institutions, the problem is not a complete absence of risk data. Most already maintain third-party registers, cloud inventories, procurement records, architecture diagrams and operational risk assessments. The difficulty lies in connecting these disparate sources.
“A technology estate is rarely a neat hierarchy of firm, vendor, service. It is a network of relationships.”
A business-critical application might depend on a software provider running on a hyperscaler, which in turn relies on other infrastructure providers. Data, authentication and resilience services introduce further dependencies, making it difficult to establish where risks overlap.
DORA’s implementing requirements reflect this complexity, requiring firms to maintain information on ICT services and relevant subcontractors to improve visibility across their technology supply chains.
For RelyComply, this creates a familiar challenge for the RegTech sector: “turning fragmented evidence into a continuously usable risk view.”
Where can RegTech help?
Technology concentration risk platforms can help connect procurement, configuration management, cloud, application, outsourcing and operational resilience data into a common dependency map.
Such a view would allow firms to move beyond a basic supplier list and answer more consequential questions. Which critical business services depend on AWS, Azure or Google Cloud? Where do supposedly independent suppliers share the same infrastructure? Which providers support the greatest number of critical functions, and what would happen if a particular provider, region, service or subcontractor became unavailable?
It could also help firms identify when concentration thresholds are approaching and assess whether new contracts would deepen existing dependencies.
“This shifts monitoring from a static supplier inventory towards continuous technology dependency intelligence,” RelyComply says.
Automation can strengthen this approach by collecting evidence, flagging changes in concentration, reconciling vendor information against internal architecture and supporting management and regulatory reporting.
“The objective is not simply to produce another dashboard. It is to make concentration risk visible at the point decisions are being made, particularly during procurement, cloud migration, outsourcing and major technology change.”
The regulatory direction reinforces the importance of the issue. The European Banking Authority’s June 2026 Risk Assessment Report found that banks identified ICT service provider dependencies as their biggest challenge among non-EU/EEA dependencies, with around 80% highlighting the issue in its risk assessment questionnaire.
From compliance register to dependency intelligence
Cloud concentration has consequently become more than a cloud strategy issue. It sits at the intersection of operational resilience, third-party risk, regulatory compliance and enterprise architecture.
For RelyComply, the next generation of RegTech must help firms move beyond identifying their critical suppliers to understanding the underlying infrastructure on which those suppliers depend.
“The next generation of RegTech should help firms answer not just ‘Who are our critical suppliers?’ but ‘Where are we collectively dependent on the same technology?’”
That requires firms to consider whether they can monitor third-party technology risk continuously, map dependencies beyond their direct contractual relationships and quantify the potential impact of shared infrastructure across critical services.
“If the answer requires multiple spreadsheets, manual reconciliations and periodic reviews, the concentration risk problem may already be bigger than the organisation can easily see.”
Copyright © 2026 RegTech Analyst
Copyright © 2026 RegTech Analyst


