The European Banking Authority published its final Guidelines on the management of third-party risk on September 18, 2026. The Guidelines require financial entities to focus on third-party arrangements that support critical or important functions, where disruptions could materially impair performance.
The Guidelines align with the Digital Operational Resilience Act (DORA) and aim to reduce operational and supervisory burdens for less critical third-party arrangements while ensuring sound risk management practices.
These Guidelines apply to all regulated entities that rely on third-party arrangements for critical functions, as identified by the EBA.
No specific deadline for compliance is stated in the material, but financial institutions are encouraged to review the Guidelines to align their risk management frameworks accordingly.