The European Banking Authority issued final guidelines on managing risks from third-party providers of non-information and communications technology services. The framework focuses on governance and risk management when regulated financial firms rely on external providers. It places particular emphasis on services supporting critical or important functions.
The guidelines are addressed to competent authorities in European Union member states. Their scope includes banks and specified investment firms, payment institutions, electronic-money institutions, asset-referenced-token issuers and certain mortgage creditors. Services falling within Chapter V of the Digital Operational Resilience Act are excluded.
FRAMEWORK TARGETS NON-ICT DEPENDENCIES
The distinction prevents the new guidance from duplicating DORA’s separate regime for contractual arrangements involving ICT third-party providers. Firms must instead apply the EBA framework to relevant outsourced or externally provided non-ICT services within its scope.
The guidelines set expectations for internal governance, risk assessment and ongoing monitoring. Competent authorities are expected to review those arrangements through the supervisory processes applicable to each type of regulated institution.
IMPLEMENTATION WILL MOVE TO NATIONAL SUPERVISORS
The final report follows an earlier consultation and incorporates the EBA’s responses to industry feedback. It provides a common supervisory basis intended to make oversight of non-ICT third-party risk more consistent and proportionate across member states.
The next milestone is implementation by competent authorities and affected firms under the timetable specified in the final report. Banks should identify covered arrangements, distinguish them from DORA services and assess whether governance, documentation or monitoring processes require changes.