Running regulated financial services in the cloud requires careful attention to compliance, data residency, and operational resilience. We share our approach to cloud architecture for fintech.
Cloud infrastructure offers compelling advantages for fintech companies:
However, operating regulated financial services in the cloud requires navigating FCA expectations and building architectures that maintain compliance.
The FCA treats cloud as outsourcing, subject to SYSC 8 requirements. Key obligations:
Before migrating to cloud:
Cloud contracts must include:
Under the FCA's operational resilience requirements, firms must:
For most UK fintech use cases, data should remain in UK or EU regions:
Configure service policies to prevent data leaving approved regions.
┌─────────────────────────────────────────────────────────────┐
│ VPC Architecture │
├─────────────────────────────────────────────────────────────┤
│ │
│ ┌─────────────┐ ┌─────────────┐ ┌─────────────┐ │
│ │ Public │ │ Private │ │ Data │ │
│ │ Subnet │ │ Subnet │ │ Subnet │ │
│ │ │ │ │ │ │ │
│ │ Load │ │ Application │ │ Database │ │
│ │ Balancers │──▶ Servers │──▶ Clusters │ │
│ │ │ │ │ │ │ │
│ └─────────────┘ └─────────────┘ └─────────────┘ │
│ │ │
│ │ WAF, DDoS Protection │
│ ▼ │
│ ┌─────────────┐ │
│ │ Internet │ │
│ │ Gateway │ │
│ └─────────────┘ │
└─────────────────────────────────────────────────────────────┘
Essential security measures:
Minimum availability requirements:
Define and test DR scenarios:
Comprehensive observability:
Centralise logs with appropriate retention for regulatory requirements (typically 5-7 years for financial records).
Manage infrastructure through code:
Cloud infrastructure enables fintech companies to build scalable, secure services without massive upfront investment. Meeting FCA expectations requires intentional architecture decisions around data residency, operational resilience, and audit capabilities. The investment in getting this right creates a foundation for compliant growth.