Multi Cloud vs Single Cloud: What's Right for NZ Fintech?

·19 min read·
--
--

New Zealand's financial services sector is at a genuine crossroads right now. As our banks and fintechs push further into digital transformation, the choice between single cloud and multi cloud architecture has become one of the more consequential calls a technology leader will make, and it is not one to get wrong. With the launch of the AWS Asia Pacific (New Zealand) Region, a planned NZD 7.5 billion investment in local infrastructure, and major banks including Kiwibank, BNZ and The Co-operative Bank deepening their cloud commitments, the conversation has shifted from whether to adopt cloud at all, to which cloud model best serves resilience, compliance and innovation.

This article looks at the multi cloud versus single cloud decision through the lens of New Zealand's own regulatory environment, market dynamics and the particular needs of our growing fintech sector. It draws on global surveys, regulatory frameworks and local case studies to build a practical framework for New Zealand fintech leaders working through this call.

1. The global context: why multi cloud is becoming the default

Before we get into what New Zealand should do, it is worth understanding where the rest of the world has landed, since our banks and fintechs do not make these calls in isolation. The global financial services industry is going through a real shift in cloud strategy. KPMG's Cloud Monitor 2025: Financial Services finds that cloud strategies in the financial sector are at a genuine turning point. Cloud first remains the standing order, but multi cloud architecture, sovereign offerings and financial operations, or FinOps, are all moving to centre stage. The report notes that hybrid and multi cloud architectures are now the norm, with the choice of model increasingly driven by regulation and controllability rather than technical preference alone.

This trend is backed up by LSEG's Global Cloud Survey, which surveyed 453 financial services executives worldwide. The research found that 87% of firms have increased their cloud investment over the past two years, and that 82% of firms now operate with either a multi cloud or hybrid cloud strategy, a clear shift toward flexibility and risk diversification. The same survey found that 84% of respondents have had to adjust their cloud strategies in response to regulatory frameworks such as the EU's Digital Operational Resilience Act and GDPR.

The message coming through globally is clear: multi cloud is fast becoming the default operating model for any company that needs resilience, regulatory flexibility, or architectural freedom.

Why financial services are leading the multi cloud charge

A few factors are driving this shift internationally:

Regulatory pressure. Regulations such as the EU's Digital Operational Resilience Act explicitly require financial institutions to run comprehensive ICT risk management frameworks, which pushes organisations toward multi vendor thinking. Exit planning has become a genuine regulatory expectation in many jurisdictions, not just a nice to have.

Risk mitigation. Cloud concentration, where a large share of a fintech's infrastructure sits with a single provider, has become a real concern for boards and regulators alike. Overreliance on one provider can mean a platform goes offline entirely during a provider outage, which is a serious problem when that infrastructure underpins core banking, payment processing, fraud detection or anti money laundering pipelines.

Reducing vendor lock in. When infrastructure sits entirely on one cloud platform, an organisation becomes dependent on that provider's proprietary services, APIs and pricing. Spreading workloads across providers reduces the impact of any single vendor's outage, policy change, or price rise.

Access to specialised services. Different providers are strong in different areas. A multi cloud approach lets organisations draw on the best service for each job while keeping a coherent overall architecture.

2. The New Zealand landscape: a market in transformation

Closer to home, New Zealand's financial services sector is going through its own cloud shift, shaped by local market dynamics, regulatory expectations, and some genuinely significant infrastructure investment landing on our shores.

The AWS New Zealand Region, a game changer

In September 2025, Amazon launched the AWS Asia Pacific (New Zealand) Region, representing more than NZD 7.5 billion in planned local infrastructure investment, expected to contribute around NZD 10.8 billion to New Zealand's GDP over fifteen years and support more than 1,000 full time equivalent jobs annually. This has real implications for NZ fintech:

  • Data sovereignty. New Zealand financial data can now live in New Zealand, on infrastructure governed by New Zealand law, without the compliance tension that came with routing everything through Sydney.

  • Performance. Local infrastructure reduces latency for real time financial applications. Ranjit Jayanandhan from Kiwibank called the local region a game changer, boosting performance, resilience and security while keeping data closer to customers.

  • Choice. The new region gives developers, startups and enterprises, alongside financial services organisations, more choice for running applications and serving end users from data centres located in New Zealand.

Kiwibank, MATTR and Deloitte all signed on as launch customers for the new AWS region, joining Vector, One NZ and Datacom, who had already committed. Kiwibank, New Zealand's largest locally owned bank serving over one million customers, expects to benefit from the local region's impact on performance and security.

Major NZ banks embracing cloud

Several of New Zealand's leading financial institutions are making significant cloud commitments:

Kiwibank has become the first financial provider in New Zealand to shift to a cloud hosted solution for payment processing, using ACI Worldwide's Enterprise Payments Platform. In doing so, the bank replaced over half of the technology underpinning its banking solutions.

BNZ has adopted a cloud first strategy, moving away from on premises environments and deploying new applications to the cloud by default.

The Co-operative Bank has partnered with 10x Banking to migrate its core banking infrastructure to a cloud native platform in a phased, multi year project serving more than 180,000 customers.

TSB Bank, one of Arinco's listed financial services clients, continues to invest in Azure governance and cloud capability as part of its broader technology modernisation.

ANZ Bank New Zealand is subject to the Reserve Bank of New Zealand's Outsourcing Policy, BS11, which governs cloud outsourcing arrangements for the country's largest banks.

The fintech ecosystem

Beyond the major banks, New Zealand's fintech ecosystem is growing at a fair clip. Dosh, a digital wallet and aspiring digital bank, has partnered with Visa and Pismo to build its cloud native core banking platform. Developments like these signal a broader trend: cloud adoption is no longer optional for NZ financial institutions, it is fast becoming table stakes for staying in the game.

3. The regulatory framework NZ fintech must navigate

New Zealand's regulatory environment for financial services cloud adoption is both sophisticated and demanding, and there is no shortcutting it. Understanding it properly is essential to the multi cloud versus single cloud decision.

The Reserve Bank of New Zealand's Outsourcing Policy, BS11

The Reserve Bank of New Zealand is the primary financial supervisory authority, regulating banks, insurers and non bank deposit takers. Financial institutions in New Zealand are permitted to use cloud services, provided they comply with the applicable legal and regulatory requirements.

The RBNZ expects large banks to follow its Outsourcing Policy, BS11, which covers governance, risk management, monitoring and oversight, audit rights, business continuity, security, and termination and subcontracting provisions. As of December 2023, New Zealand's four major banks were confirmed fully compliant with BS11, a milestone that took considerable work and around 1,500 engagements between the RBNZ and affected banks over six years. Crucially, the policy does not prohibit cloud outsourcing, but it does require institutions to understand where their data sits, who can access it, and under what legal authority.

For fintechs providing support services to licensed institutions, outsourcing arrangements may also fall under the RBNZ's or the Financial Markets Authority's outsourcing expectations.

The Privacy Act 2020

The Privacy Act 2020 is New Zealand's primary privacy and data protection legislation. It applies to any business operating in New Zealand and sets out 13 information privacy principles governing the collection, storage, use and disclosure of personal information.

A few provisions are particularly relevant to cloud strategy:

  • Principle 12 regulates how agencies can transfer personal information to entities overseas.

  • A mandatory privacy breach notification regime applies to notifiable privacy breaches, overseen by the Office of the Privacy Commissioner.

  • Organisations must be able to show that personal data remains within New Zealand jurisdiction or under a comparably safeguarded international framework.

For fintechs, this means cloud architecture choices carry a direct bearing on Privacy Act 2020 compliance exposure.

CERT NZ and the NZISM

CERT NZ provides practical security guidance that shapes cloud strategy, including advice on avoiding concentration risk and building blast radius containment into infrastructure design. The New Zealand Information Security Manual, known as the NZISM, offers similar guidance for government and defence adjacent sectors, where geographic and vendor diversity is often expected as a baseline rather than a bonus.

ISO 27001 certification

Both single cloud and multi cloud architectures can achieve ISO 27001 certification, though the practical pathway differs. A single provider environment tends to involve fewer moving parts to document and audit, while a multi cloud environment requires reconciling controls across providers, which typically takes longer and costs more to maintain on an ongoing basis. Organisations weighing this trade off should get a certification timeline and cost estimate from their own auditor rather than relying on a generic industry figure, since the difference depends heavily on how many providers and services are actually in scope.

4. Single cloud vs multi cloud: a comparative analysis

Single cloud: the case for simplicity and cost efficiency

Neither option is right or wrong on its own, so let us have an honest look at what each one is actually good for. Single cloud deployments, typically built on AWS, Azure or GCP, offer real advantages, particularly for early stage fintechs and startups.

Advantages:

  • Lower operational overhead. Consolidated licensing, a single support contract and simplified billing generally mean a lower monthly bill than an equivalent multi cloud setup.

  • Simplified management. One provider means one console, one set of APIs, one support relationship and one billing system.

  • Volume discounts. Committing volume to a single provider, particularly through AWS Savings Plans and Reserved Instances, can unlock meaningful discounts that are harder to reach when spend is split across vendors.

  • Faster time to market. With one provider, a small team can focus on building rather than managing the added complexity of inter cloud integration.

  • Predictable costs. Single cloud billing tends to be easier to forecast, which matters for a startup watching its runway closely.

Disadvantages:

  • Vendor lock in. Migrating away from a single provider later, once workloads depend on that provider's proprietary services, is a genuinely costly and slow undertaking, and leaves an organisation with limited leverage against future price rises.

  • A single point of failure. A provider outage can take an entire platform down at once, with no fallback.

  • Limited geographic redundancy. Running everything in one region does not, on its own, satisfy the resilience expectations regulators increasingly hold for critical financial infrastructure.

  • Data residency exposure. A single vendor's regional footprint may not cover every jurisdictional requirement a growing fintech eventually faces.

Multi cloud: the case for resilience and flexibility

Multi cloud architectures spread workloads across providers, for example AWS's Auckland region alongside Azure and GCP's Australian regions, offering real strategic advantages for the right organisation.

Advantages:

  • Reduced outage impact. Distributed redundancy means an incident at one vendor does not automatically cascade into a full outage, because critical workloads can fail over to another provider.

  • A stronger, testable exit strategy. A well designed multi cloud setup promotes portability and architectural abstraction from day one, which makes it technically and operationally realistic to move away from any single provider if the need arises, something regulators increasingly expect institutions to be able to demonstrate.

  • Vendor diversity and negotiating leverage. Competitive tension between vendors gives a growing organisation more room to negotiate on price and terms than it would have with a single locked in provider.

  • Access to best of breed services. Different workloads can sit with whichever provider genuinely suits them best, rather than being forced onto a single vendor's weaker offering in a given area.

Disadvantages:

  • Higher operational cost. Redundant tooling, inter cloud data transfer fees and multiple support contracts add up quickly. AWS's own guidance is a useful benchmark here: cross region and inter provider data transfer is billed per gigabyte, and those fees compound as data moves between clouds rather than staying within one provider's network.

  • Increased complexity. More platforms means more tools, integrations and interfaces to manage, which raises the risk of configuration errors and operational delay.

  • Talent requirements. Specialist, multi platform expertise is harder to find and retain than single provider expertise, and is a commonly cited barrier to multi cloud adoption.

  • A longer path to some certifications. Reconciling controls across more than one provider generally extends the time and cost needed to reach and maintain certifications such as ISO 27001, compared with a single provider environment.

5. Strategic considerations for NZ fintech

When single cloud makes sense

For some NZ fintechs, a single cloud strategy remains the sensible choice:

  1. Early stage startups. If you are a fintech startup with limited resources and can tolerate some downtime while you find product market fit, single cloud's lower overhead and faster time to market can be the difference between shipping and stalling.

  2. Simple workloads. Organisations running straightforward applications that do not need geographic diversity or specialised services from more than one provider may find single cloud entirely sufficient.

  3. Limited regulatory exposure. Fintechs not handling sensitive customer data, or not subject to RBNZ prudential supervision, tend to face fewer compliance pressures pushing them toward multi cloud.

  4. Tight budgets. For an organisation where every dollar counts, the lower overhead of single cloud can genuinely be the deciding factor.

When multi cloud is close to mandatory

For a growing number of NZ financial institutions, multi cloud is no longer just an option, it is becoming close to a baseline expectation:

  1. Regulated sectors. Finance, health and government are increasingly treated by regulators and risk teams as sectors where distributing risk across providers is the expected default, not a nice to have.

  2. Large banks. Institutions subject to the RBNZ's BS11 Outsourcing Policy and its operational resilience expectations are steadily moving toward multi cloud or hybrid strategies as part of demonstrating genuine exit capability.

  3. Critical national infrastructure. Organisations providing services that matter to New Zealand's financial stability need real geographic and vendor diversity to meet NZISM level expectations.

  4. Customer facing fintech at scale. For fintechs where downtime directly costs customer trust and revenue, the resilience case for multi cloud becomes hard to ignore once the customer base reaches meaningful size.

  5. Data sovereignty conscious organisations. Multi cloud can enable domestic first architectures that make Privacy Act 2020 compliance considerably more straightforward to demonstrate.

The polycloud distinction

It is worth pausing on the difference between multi cloud and polycloud, since the two get used interchangeably more often than they should. A multi cloud approach simply means using services from more than one provider, often for redundancy. A polycloud strategy is more deliberate again: strategically placing each workload on whichever provider suits it best, rather than duplicating the same infrastructure across vendors purely for backup. It is a more sophisticated, and more engineering intensive, way of getting the benefits of multiple providers without paying for redundant capability everywhere.

6. The cost trade off

The cost comparison between single cloud and multi cloud is more nuanced than simply comparing two monthly bills, and it pays to look past the invoice before making the call.

The visible cost

Single cloud generally comes with a lower headline monthly spend, thanks to consolidated billing and volume discounts. Multi cloud generally costs more day to day, driven by redundant tooling, multiple support contracts, and inter cloud data transfer fees that single cloud simply does not incur.

The hidden cost of single cloud

  • Vendor lock in. Migration away from a deeply embedded single provider is slow and expensive once proprietary services are woven through the architecture.

  • Outage impact. A single vendor incident can cascade into a full business disruption with no fallback path.

  • Pricing vulnerability. Limited leverage against future price increases from a provider an organisation cannot easily leave.

The hidden value of multi cloud

  • Competitive tension. Genuine alternatives at the negotiating table tend to produce better terms over time than a captive single provider relationship.

  • A demonstrable exit strategy. Something regulators are increasingly asking institutions to prove, not just assert.

  • Reduced concentration risk. The kind of risk that shows up as a major incident, not a line item, when it eventually bites.

The FinOps imperative

As KPMG's Cloud Monitor 2025 notes, FinOps models are creating real transparency and efficiency across platform boundaries. Whichever cloud model an organisation lands on, building genuine FinOps discipline is essential to keeping cloud costs under control, since the model choice on its own does not guarantee good cost outcomes either way.

7. The AI factor

There is one more wrinkle worth flagging. The rapid uptake of artificial intelligence adds a further layer to the cloud architecture decision. According to KPMG's Cloud Monitor 2025: Financial Services, 95% of financial service providers now use large language models such as GPT and Gemini in some part of their operations, a level of adoption that has moved well past the pilot stage in a single year.

AI workloads bring their own requirements that can influence cloud strategy:

  • Compute intensity. AI training and inference are genuinely compute hungry, and the most cost effective option can vary meaningfully between providers depending on the specific workload.

  • Data gravity. AI models need access to large datasets, and moving that data between clouds for processing can bring significant transfer costs of its own.

  • Specialised hardware. Different providers offer different AI optimised chips, for example AWS Trainium or Google's TPUs, and a workload that suits one may not suit another.

For fintechs building AI powered fraud detection, risk management and customer engagement systems, the underlying cloud architecture will meaningfully shape both what is possible and what it costs to run.

8. Implementation considerations for NZ fintech

Right, so say you have decided multi cloud is the way to go. A few implementation details matter more than they might first appear, and getting them wrong early is expensive to fix later.

1. Unified identity and access management

A multi cloud or hybrid architecture needs unified identity management and consistent policy enforcement across providers. Fragmented identity management is one of the fastest ways to open up security gaps and turn a routine audit into a difficult one.

2. A genuine vendor exit strategy

Regulators increasingly expect documented and tested exit strategies, not just a paragraph in a risk register. Relying heavily on proprietary services from a single provider makes exiting slow and costly, because systems have to be rebuilt from scratch rather than simply redeployed. A well designed multi cloud setup should build in portability from the very start, rather than trying to retrofit it later.

3. Network architecture

Data transfer between clouds adds both latency and fees. Getting the network design right, minimising unnecessary inter cloud data movement while still keeping genuine resilience, is one of the harder technical problems in a multi cloud build.

4. Security and compliance

A multi cloud environment needs unified security posture management across every provider in use, with consistent policy enforcement, clear encryption key separation, and proper incident isolation between environments.

5. Talent

Specialist, multi platform expertise remains one of the more commonly cited barriers to multi cloud adoption. Organisations need either staff who genuinely understand more than one major cloud platform, or a trusted partner who can supply that expertise credibly.

6. A phased approach

The Co-operative Bank's multi year, phased migration to 10x Banking's cloud native core is a good local illustration of a prudent approach: rather than a big bang cutover, a phased rollout lets an organisation build capability and manage risk incrementally, with the first customer facing benefits expected from late 2026.

9. A decision framework for NZ fintech leaders

Factor

Single cloud recommended

Multi cloud recommended

Stage

Early stage startup

Growth stage or enterprise

Budget

Constrained

Adequate for the added operational overhead

Regulatory exposure

Low, not RBNZ regulated

High, RBNZ regulated or critical infrastructure

Customer base

Small, tolerant of occasional downtime

Large, expects near constant uptime

Data sensitivity

Low

High, customer financial data and PII

AI workloads

Simple, single provider optimised

Complex, needs best of breed across providers

Geographic presence

New Zealand only

Multi region or international

Compliance resources

Limited

Dedicated compliance team

Technical expertise

Single provider focus

Multi provider expertise or partner support

Time horizon

Short term, cost focused

Long term, strategic flexibility focused

10. Conclusion

So, where does that leave us. The multi cloud versus single cloud decision for New Zealand fintech is not a binary choice with one right answer for everyone. It is a strategic call that has to be made against each organisation's own stage, budget and regulatory exposure, and anyone promising a one size fits all answer is probably selling something.

A few trends are clear, though. First, the global financial services industry is moving decisively toward multi cloud and hybrid architecture, with 82% of firms now operating multi cloud or hybrid strategies. NZ fintechs staying on single cloud for the long haul risk falling out of step with international peers.

Second, New Zealand's regulatory environment increasingly supports, and in places effectively expects, a multi cloud approach. The RBNZ's BS11 Outsourcing Policy, the Privacy Act 2020's data sovereignty requirements, and CERT NZ's resilience guidance all point toward architectures that distribute risk across more than one provider.

Third, the launch of the AWS New Zealand Region has opened up new options for NZ financial institutions to build sovereign, resilient architecture without the old compliance tension of routing everything through Sydney.

Fourth, the cost gap between single cloud and multi cloud is real but not fixed. It narrows as an organisation builds genuine FinOps capability and negotiates properly across vendors, and the hidden costs of single cloud lock in and concentration risk deserve a place in that total cost of ownership conversation too, not just the monthly invoice.

For an early stage fintech with limited resources and simple workloads, single cloud remains a perfectly sensible, pragmatic choice. But for any NZ financial institution serving customers at real scale, handling sensitive data, or sitting under prudential regulation, the question is increasingly not whether to adopt multi cloud, but how to do it properly. For New Zealand's fintech sector, that future is already well underway. Ngā mihi for reading.

sources

This article draws on publicly available regulatory sources, company announcements and industry reporting current as at August 2026. Figures reported by vendors and industry surveys have not been independently audited by the author, and readers weighing a specific architecture decision should get current, workload matched cost and compliance estimates from their own providers and advisors rather than relying on industry averages.

Nischal KhanalSystems & Performance EngineerInterested in Systems & Infrastructure Roles
Share