The European Banking Authority (EBA), the EU agency responsible for banking regulation and supervision, has released its final Guidelines on third-party risk management.
The framework is intended to be more proportionate and consistent, and it is aligned with the Digital Operational Resilience Act (DORA).
The central change is focus. The Guidelines concentrate on third-party arrangements that support critical or important functions (CIFs). These are services whose failure would seriously undermine a financial entity’s ability to operate.
By directing attention to these higher-risk relationships, the EBA aims to cut operational and supervisory effort spent on less significant arrangements without weakening risk controls.
The framework applies across both ICT and non-ICT services, so firms are expected to manage all outsourcing risk in one joined-up way. It covers every stage of a third-party relationship: initial risk assessment and due diligence, contract negotiation, subcontracting, ongoing monitoring, record-keeping and exit planning.
The final text reflects feedback gathered during the public consultation and through targeted engagement with stakeholders. It also draws on international standards, including the Basel Committee on Banking Supervision (BCBS) Principles for the Sound Management of Third-Party Risk.
Firms will have a two-year transitional period to adapt their processes, which the EBA says will allow implementation to proceed smoothly and proportionately.
The initiative forms part of the EBA’s wider programme to simplify its regulatory framework.
On the legal side, the Guidelines were drafted under Article 74 of Directive 2013/36/EU, which requires the EBA to further harmonise governance arrangements, processes and mechanisms at institutions across the EU.
The authority also considered Article 11 of PSD2 (Directive (EU) 2015/2366), Article 26 of the IFD (Directive 2019/2034/EU), Article 16 of MiFID II (Directive (EU) 2014/65), Article 34 of MiCAR (Regulation (EU) 2023/1114) and Article 16 of Regulation (EU) No 1093/2010.
Copyright © 2026 FinTech Global









