What Changed
- Focuses third-party risk oversight on critical or important functions (CIFs) across ICT and non-ICT services.
- Establishes a two-year transitional period to ensure proportionate implementation by financial entities.
- Harmonises governance rules under Directive 2013/36/EU alongside PSD2, IFD, MiFID II, MiCAR, and BCBS principles.
The European Banking Authority (EBA) has published its final Guidelines on the management of third-party risk, introducing a streamlined, proportionate, and harmonised regulatory framework aligned with the Digital Operational Resilience Act (DORA). The updated Guidelines focus specifically on third-party arrangements supporting critical or important functions (CIFs), defined as arrangements whose disruption would materially impair a financial entity's performance.
By concentrating regulatory oversight on higher-risk CIF arrangements, the EBA aims to reduce unnecessary operational and supervisory burdens for less material third-party service relationships while maintaining sound risk management practices. The Guidelines promote a holistic approach covering both Information and Communication Technology (ICT) and non-ICT service providers across the entire lifecycle of third-party arrangements. This lifecycle encompasses risk assessment, due diligence, contracting, subcontracting, ongoing monitoring, documentation, and exit strategies.
The final text reflects stakeholder feedback received during public consultation and targeted outreach activities. It also incorporates international standards, including the Basel Committee on Banking Supervision (BCBS) Principles for the Sound Management of Third-Party Risk.
To facilitate implementation, the EBA has provided a two-year transitional period. The final Guidelines were developed pursuant to Article 74 of Directive 2013/36/EU, which mandates the EBA to further harmonise institutions' internal governance arrangements, processes, and mechanisms across the European Union. In drafting the guidelines, the EBA also took into account provisions under Article 11 of Directive (EU) 2015/2366 (PSD2), Article 26 of Directive 2019/2034/EU (IFD), Article 16 of Directive (EU) 2014/65 (MiFID II), Article 34 of Regulation (EU) 2023/1114 (MiCAR), and Article 16 of Regulation (EU) No 1093/2010.
Financial institutions governed by EU financial legislation, as well as cross-border vendors providing critical services to EU financial entities, should review their governance, contracting, and risk management frameworks to align with the new guidance during the transitional period.
Who May Be Affected
EU financial institutions (banks, investment firms, payment service providers, crypto-asset service providers) and their ICT and non-ICT third-party service providers.
Cross-Border Context
Applies to EU-regulated financial entities and affects international third-party vendors supplying ICT or non-ICT services into the European Union.
What to check next
- The full text of the final EBA Guidelines on management of third-party risk when made available
- Supervisory expectations and communications issued by national competent authorities regarding the two-year transition
This article provides general information and does not constitute legal advice. Consult the official text and obtain advice appropriate to your circumstances where needed.
Prepared automatically with AI assistance from the official sources linked on this page. Translations and explanations do not replace the official text.