The EBA publishes its final Guidelines on the management of third-party risk, delivering a more proportionate and consistent framework aligned with DORA
Why this matters
This is a final EBA guideline publication establishing mandatory requirements for third-party risk management across ICT and non-ICT services. It applies to critical or important functions and covers the full lifecycle of third-party arrangements. The guidelines are legally binding under multiple EU directives and regulations, with a defined transitional period. This represents a major harmonization effort across the EU financial sector with concrete implementation obligations.
AI-generated classification rationale, not a full analysis. Verify with the original EBA source before acting. Full disclaimer.
What the EBA said
As part of the European Banking Authority’s (EBA) ongoing efforts to simplify its regulatory framework, the Guidelines focus on third-party arrangements supporting critical or important functions (CIFs) namely the disruption of which would materially impair the performance of a financial entity. By concentrating on…
Extract from EBA . Read the full notice at the source for the authoritative text.
Context
European Banking Authority (EBA) — The EU's banking regulator, author of the single rulebook and binding technical standards. We track 18 updates from them.
EU-wide financial regulation through ESMA, EBA, and the ECB. Browse all European Union updates.
This update is classified under Operational Resilience / Outsourcing, Senior Managers / Governance, Banking & Credit and Investment Management.