Financial services firms are not short of cloud ambition. What they are short of is certainty about what the FCA expects, and the result is a sector spread along a modernisation curve: a handful of cloud-first firms at one end, a long tail running ageing on-premise estates at the other, and most sitting somewhere between, moving carefully because the cost of a misstep feels regulatory rather than merely technical.
This piece sets out what the regulator actually asks of a cloud estate, where firms stall, and what moving well looks like, drawing on our cloud & infrastructure experience with regulated firms.
Cost gets the headlines, but it is rarely the real driver in this sector. The pressures we hear from IT leaders in regulated firms are more specific. Legacy estates are becoming harder to staff, because the engineers who know the old systems are retiring faster than the systems are. Clients raised on consumer technology expect portals and responsiveness that on-premise stacks struggle to deliver; and resilience expectations have quietly inverted: a decade ago cloud had to prove it was as safe as your server room, whereas today a firm running everything from one building has the harder case to make.
None of that removes the compliance question. It just changes its shape, from “should we move?” to “how do we move without creating the incident we are trying to prevent?”.
Because you can outsource the work but not the responsibility. That principle runs through everything the FCA has published on outsourcing and operational resilience: your firm remains accountable for services it has handed to a cloud provider, and “the provider handles that” is not an acceptable answer.
The operational resilience rules sharpened this considerably. Since March 2025, firms in scope have been expected to remain within their impact tolerances for important business services, which means knowing exactly which systems those services depend on, including the ones that live in someone else’s datacentre. A cloud migration that improves resilience on paper still has to prove it under testing.
Add the regime for critical third parties, created precisely because so much of the sector now depends on so few technology providers, and the direction is clear. Regulators are not against cloud – they are against firms that cannot explain their cloud, and the distinction between those two positions is the whole game for an IT leader in this sector.
A map, not a diagram. Important business services traced through to the systems and suppliers they depend on, kept current as the estate changes. Most firms have an architecture diagram. Far fewer have a dependency map that would survive contact with an incident.
Tested tolerances. Impact tolerances for each important business service, with evidence you can stay within them during severe but plausible disruption. Evidence means scenario testing, and scenario testing has a way of finding the assumptions nobody wrote down.
A live third-party register. Who you depend on, for what, with what exit arrangements. For material cloud arrangements the bar is higher again: exit plans the board has actually seen, and terms that allow audit and access.
Clarity on data. Where it lives and which jurisdiction governs it. Cloud regions make the question answerable, but default configurations do not answer it for you, and “wherever the provider put it” has never satisfied the FCA.
A board that can discuss it. Operational resilience is explicitly a board-level responsibility, and FCA supervisors have become comfortable asking directors questions their slide decks did not anticipate. The evidence trail needs to reach the top of the firm, in language the top of the firm can use.
The stall points repeat across the sector. A core system, often the one the business actually runs on, that no cloud provider will ever host comfortably; a change board that prices the risk of acting in detail and the risk of not acting at zero; a security team stretched thin enough that every migration waits behind an audit. And underneath all of it, the quiet worry that a misstep becomes a conversation with the regulator.
The firms that move anyway share a habit: they stop treating modernisation as one decision. A hybrid estate that keeps the stubborn core system on controlled infrastructure while everything around it modernises is not a compromise. For most mid-sized firms it is the destination. We set out that reasoning in hybrid cloud vs multi-cloud, and it applies doubly under regulation, where concentration risk already argues against putting everything in one place.
The other habit is sequencing for evidence. Move the workloads that generate compliance questions last, after the mapping and testing muscles have been built on lower-stakes migrations. A firm that has rehearsed its resilience story on the email estate tells a much better one about the client data platform, to the board and the regulator alike.
Not a big-bang migration with a war room and a countdown clock. In our experience the regulated firms that end up in the best position moved workload by workload, each move producing its own evidence, none of them betting the firm.
Mercer & Hole is a useful picture. A top-50 accountancy firm with an FCA-regulated financial planning practice, 300 staff across four UK offices, and previous suppliers who treated it as an undifferentiated account. Working with us, the firm consolidated its infrastructure and licensing into a predictable annual commitment, refreshed 350 laptops with zero-touch deployment, and brought voice into Teams, each step planned around the working day of a firm that cannot simply stop.
“What sets Highgate apart is the relationship. We’re a complex business with demanding requirements across four offices, and they treat us accordingly – responsive, fairly priced, and genuinely invested in getting it right. A vendor you can truly rely on.” – Tom Luknar, IT Manager at Mercer & Hole.
Notice what the quote is about. Not the technology, but the accountability. In a sector where the firm carries the regulatory responsibility whatever its suppliers do, a partner’s willingness to be answerable is the product, and it is the thing worth interviewing for when you choose one. The technology can be evaluated from a datasheet. The accountability only shows up in references.
The regulated firms that modernise fastest treat the FCA’s questions as design inputs rather than obstacles. Dependency mapping, exit planning, and tolerance testing all get cheaper when they shape the migration instead of auditing it afterwards, and the same evidence then serves both the regulator and the board.
If your dependency map would not survive an incident, start there before moving anything. The map converts directly into efficiency gains, because it shows which systems are ready to move and which need the hybrid treatment, and it doubles as the backbone of your business resilience evidence. We build these with regulated firms as the first stage of most engagements; talk to our team and we’ll set out how we’d approach it for yours.