All news

EBA Publishes Final Guidelines on Third-Party Risk Management Aligned with DORA

News
EBA Publishes Final Guidelines on Third-Party Risk Management Aligned with DORA

The European Banking Authority has published its final guidelines on third-party risk management to streamline compliance across EU financial entities. The updated framework aligns with the Digital Operational Resilience Act and focuses oversight on critical functions to reduce unnecessary burdens.

Focus on Critical or Important Functions

The European Banking Authority published its final guidelines on the management of third-party risk on 18 September 2026. The framework is designed to align with the Digital Operational Resilience Act and simplify regulatory requirements across the European Union.

Under the updated guidelines, supervisory attention concentrates on third-party arrangements supporting critical or important functions. These are defined as functions where disruption would materially impair the operational performance of a financial entity. By focusing on these higher-risk arrangements, the authority aims to lower unnecessary operational and supervisory burdens for less material services while maintaining sound governance.

Holistic Lifecycle and Governance Alignment

The guidelines establish an approach covering both information and communication technology and non-ICT third-party services. The scope spans the entire lifecycle of third-party arrangements, encompassing risk assessment, due diligence, contracting, subcontracting, monitoring, documentation and exit strategies.

The framework incorporates stakeholder feedback gathered through public consultations and targeted outreach. It also reflects international standards, including the Basel Committee on Banking Supervision Principles for the Sound Management of Third-Party Risk.

Developed under Article 74 of Directive 2013/36/EU to harmonise governance mechanisms across the EU, the guidelines also take into account provisions from PSD2, IFD, MiFID II, MiCAR, and Regulation (EU) No 1093/2010. A two-year transitional period is provided to support implementation.

Frequently Asked Questions

What is the primary focus of the new EBA third-party risk guidelines?

How long is the transitional period for implementation?

Sources

Primary reference materials

Related news