The European Banking Authority has published its final guidelines on third-party risk management to streamline compliance across EU financial entities. The updated framework aligns with the Digital Operational Resilience Act and focuses oversight on critical functions to reduce unnecessary burdens.
Focus on Critical or Important Functions
The European Banking Authority published its final guidelines on the management of third-party risk on 18 September 2026. The framework is designed to align with the Digital Operational Resilience Act and simplify regulatory requirements across the European Union.
Under the updated guidelines, supervisory attention concentrates on third-party arrangements supporting critical or important functions. These are defined as functions where disruption would materially impair the operational performance of a financial entity. By focusing on these higher-risk arrangements, the authority aims to lower unnecessary operational and supervisory burdens for less material services while maintaining sound governance.
Holistic Lifecycle and Governance Alignment
The guidelines establish an approach covering both information and communication technology and non-ICT third-party services. The scope spans the entire lifecycle of third-party arrangements, encompassing risk assessment, due diligence, contracting, subcontracting, monitoring, documentation and exit strategies.
The framework incorporates stakeholder feedback gathered through public consultations and targeted outreach. It also reflects international standards, including the Basel Committee on Banking Supervision Principles for the Sound Management of Third-Party Risk.
Developed under Article 74 of Directive 2013/36/EU to harmonise governance mechanisms across the EU, the guidelines also take into account provisions from PSD2, IFD, MiFID II, MiCAR, and Regulation (EU) No 1093/2010. A two-year transitional period is provided to support implementation.
Frequently Asked Questions
What is the primary focus of the new EBA third-party risk guidelines?
The guidelines focus on third-party arrangements supporting critical or important functions whose disruption would materially impair a financial entity’s performance.
How long is the transitional period for implementation?
Financial entities have a two-year transitional period to support implementation of the framework.



