Source
European Banking Authority
September 18, 2026
The European Banking Authority (EBA) has published its final Guidelines on the management of third-party risk, aimed at creating a more proportionate and consistent framework aligned with DORA.
The Guidelines focus on third-party arrangements supporting critical or important functions (CIFs), where disruption could significantly impair a financial entity’s performance. They aim to reduce operational and supervisory burdens for less material arrangements while ensuring effective risk management.
The Guidelines promote a holistic approach to third-party risk management covering ICT and non-ICT services throughout the full lifecycle, including risk assessment, due diligence, contracting, monitoring, documentation, and exit strategies.
The development of the Guidelines incorporated stakeholder feedback and international standards, including the Basel Committee Principles for the Sound Management of Third-Party Risk. A two-year transitional period will facilitate smooth implementation.
The Guidelines are based on Article 74 of Directive 2013/36/EU and consider provisions from Directive (EU) 2015/2366, Directive 2019/2034, Directive (EU) 2014/65, Regulation (EU) 2023/1114, and Regulation (EU) No 1093/2010.