The European Banking Authority has issued new guidelines designed to sharpen supervision of third-party arrangements linked to critical functions, in a move intended to simplify parts of the EU banking regulatory framework while preserving robust risk controls.
A More Proportionate Supervisory Model
The new approach concentrates attention on arrangements whose disruption could materially affect a financial institution’s operations. By doing so, regulators and firms can direct resources toward higher-risk dependencies rather than spreading oversight too thinly across lower-risk service relationships.
Follow THE FUTURE on LinkedIn, Facebook, Instagram, X and Telegram
In practice, the framework aims to reduce unnecessary operational and supervisory burdens associated with less material third-party arrangements, while maintaining strong standards for governance, resilience and risk management.
Covering The Full Third-Party Lifecycle
The guidelines apply to both ICT and non-ICT services, reflecting the increasingly interconnected nature of modern financial operations. Rather than treating technology risk in isolation, the EBA has adopted a more holistic approach to third-party risk management.
The framework spans the entire lifecycle of an arrangement, including risk assessment, due diligence, contracting, subcontracting, ongoing monitoring, documentation and exit planning. That breadth is significant: in financial services, risk does not end at onboarding. It evolves as dependencies deepen, services change, and counterparties expand their own supplier chains.
Feedback From Industry And International Standards
The EBA said the final version incorporates feedback from a public consultation, together with input gathered through targeted outreach. It also takes account of international standards, including the Basel Committee on Banking Supervision’s Principles for the Sound Management of Third-Party Risk.
That alignment matters. As banks and investment firms operate across jurisdictions and through increasingly complex vendor ecosystems, regulatory convergence helps reduce fragmentation and supports more consistent control frameworks.
A Transitional Period For Implementation
To support adoption, the EBA has предусмотрed a two-year transitional period, giving institutions and supervisors time to adapt to the new requirements in a proportionate and orderly way. The phased approach should help firms recalibrate internal policies, renegotiate contracts where needed and strengthen oversight of the most material external dependencies.
Broader Legal And Regulatory Context
The guidelines were developed under Directive 2013/36/EU, which requires the EBA to further harmonise governance arrangements, processes and mechanisms across EU institutions. In shaping the final text, the authority also considered several other key pieces of EU legislation, including the second Payment Services Directive, the Investment Firms Directive, the Markets in Financial Instruments Directive and the Markets in Crypto-Assets Regulation.
The regulation establishing the EBA was also taken into account, underscoring the breadth of the legal foundation behind the new framework.
What The New Rules Mean For Institutions
For banks, investment firms and other financial entities, the message is clear: not every outsourced service warrants the same level of regulatory attention. The new guidelines are designed to ensure that oversight is proportionate to the potential impact of failure, with greater scrutiny reserved for arrangements supporting functions that could seriously disrupt operations if compromised.
In a sector where resilience has become a board-level priority, the EBA’s move reflects a broader regulatory trend: fewer blanket requirements, more risk-based judgment and a sharper focus on material exposures.