The European Banking Authority (EBA), the EU body mandated to harmonise the governance arrangements of financial institutions across the bloc, has released its final Guidelines on third-party risk management.
The framework is designed to be more proportionate and consistent, and it is aligned with the Digital Operational Resilience Act (DORA).
At the heart of the Guidelines is a sharper focus on third-party arrangements that support critical or important functions (CIFs). These are functions whose disruption would significantly undermine a financial entity’s ability to operate. By directing attention to these higher-risk relationships, the EBA aims to cut unnecessary operational and supervisory demands linked to less material arrangements, while still preserving robust risk controls.
The framework takes a holistic view, applying to both ICT and non-ICT services. It spans the entire lifecycle of a third-party relationship: risk assessment and due diligence, contract formation, subcontracting, ongoing monitoring, record-keeping and exit planning. Firms will have two years to adapt, with the transitional period intended to allow orderly and proportionate adoption.
The EBA shaped the final text using input gathered through its public consultation and targeted engagement with stakeholders. It also drew on international standards, among them the Basel Committee on Banking Supervision (BCBS) Principles for the Sound Management of Third-Party Risk.
The publication forms part of the EBA’s broader programme to streamline its regulatory framework. The authority operates under a mandate to bring greater uniformity to the governance processes and mechanisms used by institutions throughout the EU.
The legal foundation for the Guidelines is Article 74 of Directive 2013/36/EU. In drafting them, the EBA also considered Article 11 of PSD2 (Directive (EU) 2015/2366), Article 26 of the Investment Firms Directive (Directive 2019/2034/EU), Article 16 of MiFID II (Directive (EU) 2014/65), Article 34 of MiCAR (Regulation (EU) 2023/1114) and Article 16 of Regulation (EU) No 1093/2010.
Copyright © 2026 RegTech Analyst
Copyright © 2026 RegTech Analyst





