Theme rationale
The 2022-2025 wave of operational-resilience regulation — DORA (EU), CPS 230 (Australia), the UK PRA Critical Third Parties regime, MAS TRM guidelines (Singapore) — converges on a shared structural problem: critical financial and operational infrastructure is now functionally dependent on a small number of hyperscale cloud and infrastructure providers. A concentration event at AWS, Azure, or Google Cloud has the potential to simultaneously impair thousands of regulated financial entities across multiple jurisdictions.
This theme captures instruments that move beyond disclosure-and-contract requirements (which leave the risk with financial entities) toward direct supervisor oversight of the technology providers themselves. The DORA CTPP designation (Art. 31) is the first instrument globally where a financial-sector regulator acquires direct inspection, investigation, and penalty powers over cloud providers — turning the technology supply chain into a supervised risk, not merely a disclosed one.
Structurally distinct from:
- `digital-sovereignty-data-localization` — which mandates data residency and local
platform establishment; DORA/CTPP oversight does not require data localisation, it requires resilience documentation and ESA access rights.
- `western-industrial-policy-stack` — which is subsidy- and incentive-led build
capacity; this theme is oversight-led risk mitigation.
- `trilateral-chip-equipment-perimeter` — which restricts hardware supply to
adversaries; this theme is about safeguarding existing digital infrastructure from operational failure.
Policy pattern
Typical instruments in this cluster: 1. Mandatory designation of critical technology/cloud providers to regulated financial entities, with direct supervisory authority over the provider 2. Joint examination team (JET) or equivalent multi-authority inspection rights, including extraterritorial reach to non-domestic data centres 3. Operational resilience testing mandates (TLPT, CBEST, red-team frameworks) 4. ICT third-party contractual minimum-content requirements and exit-strategy mandates 5. Concentration-risk caps or diversification recommendations for systemic cloud exposure