The EBA publishes its final Guidelines on the management of third-party risk, delivering a more proportionate and consistent framework aligned with DORA

  • Press Release
  • 18 September 2026

As part of the European Banking Authority’s (EBA) ongoing efforts to simplify its regulatory framework, the Guidelines focus on third-party arrangements supporting critical or important functions (CIFs) namely the disruption of which would materially impair the performance of a financial entity. By concentrating on these higher-risk arrangements, the Guidelines reduce unnecessary operational and supervisory burdens for less material ones while maintaining sound risk management.

The Guidelines promote a holistic approach to third-party risk management across ICT and non-ICT services and cover the full lifecycle of third-party arrangements, including risk assessment and due diligence, contracting, subcontracting, monitoring, documentation and exit strategies. 

They reflect stakeholders feedback received during the public consultation and through targeted outreach activities and take into account international standards, including the Basel Committee on Banking Supervision (BCBS) Principles for the Sound Management of Third-Party Risk.

A two-year transitional period will support a smooth and proportionate implementation.

Legal basis

The final Guidelines have been developed in accordance with Article 74 of Directive 2013/36/EU which mandates the EBA to further harmonise institutions' governance arrangements, processes and mechanisms across the EU. Article 11 of Directive (EU) 2015/2366/EU (PSD2), Article 26 of Directive 2019/2034/EU (IFD), Article 16 of Directive (EU) 2014/65 (MiFID II), Article 34 of Regulation (EU) 2023/1114 (MiCAR) and Article 16 of Regulation (EU) No 1093/2010 have also been taken into account. 

Documents

Final report on Guidelines on the sound management of third-party risk related to non-ICT services

(1.16 MB - PDF)

Press contacts

Franca Rosa Congiu