Regulationtomorrow iconRegulationtomorrowSep 29, 2026 ~1 min source read

EBA Finalises Guidelines on Third-Party Risk for Non-ICT Services: A More Proportionate Framework Aligned with DORA

The Final Report sets out the EBA's response to feedback on its earlier consultation, together with the final text of the guidelines. On 18 September 2026, the European Banking Authority (EBA) published its Final Report on guidelines on the sound management of third-party risk regarding non-ICT services.

Share this story

Send the public story page.

Useful takeaways from this story.

On 18 September 2026, the European Banking Authority (EBA) published its Final Report on guidelines on the sound management of third-party risk regarding non-ICT services.

The Final Report sets out the EBA's response to feedback on its earlier consultation, together with the final text of the guidelines.

The EBA presents the guidelines as part of its wider effort to simplify its regulatory framework.

Building the complete brief

The page is ready to read now. The fuller skim-friendly version will appear here automatically.

The useful part

On 18 September 2026, the European Banking Authority (EBA) published its Final Report on guidelines on the sound management of third-party risk regarding non-ICT services. The Final Report sets out the EBA's response to feedback on its earlier consultation, together with the final text of the guidelines. The EBA presents the guidelines as part of its wider effort to simplify its regulatory framework.

How it works

  • The guidelines are addressed both to Member State competent authorities (NCAs) and directly to financial institutions.
  • They set out the internal governance and risk management arrangements that a broad range of firms should have in place when they rely on third-party service providers (TPSPs) for non-ICT services.
  • The guidelines also extend to third-country branches and to approved financial holding companies and mixed financial holding companies.
  • NCAs and financial institutions must make every effort to comply with them.
  • Drawing the line with DORA The guidelines apply to non-ICT services provided by TPSPs, other than those falling within Chapter V of the Digital Operational Resilience Act (DORA).

Keep reading in the app

Open the app view to save this story, compare related coverage, and continue from the same source.

Open in app