EBA Guidelines on Sound Management of Third-Party Risk
The EBA Guidelines on Sound Management of Third-Party Risk are draft guidance issued by the European Banking Authority to help financial institutions and certain investment firms manage the risks that arise when they rely on outside providers for services. As of the July 2025 consultation, the draft focuses specifically on non-ICT (non-technology) related services provided by third parties. Because the draft was published for consultation and public hearing rather than as a finalized standard, its provisions may change before adoption.
A draft set of Guidelines developed by the European Banking Authority (EBA), released for consultation on 8 July 2025, that specifies internal governance arrangements, including sound risk management practices, for institutions and investment firms in relation to third-party arrangements covering non-ICT related services provided by third-party service providers. The Guidelines are intended to establish a more comprehensive approach to managing third-party risks and, according to consultation responses, to align closely with the Digital Operational Resilience Act (DORA), which addresses ICT-related third-party risk. Scope note: as evidenced, the draft is expressly limited to non-ICT related services and therefore does not itself govern ICT third-party arrangements, which fall under DORA; practitioners should also treat this as consultation-stage guidance rather than a finalized or binding standard, and its final content, applicability, and effective date were not established in the evidence provided. The framework applies within the EU financial-sector supervisory context and should not be assumed to apply across other jurisdictions or sectors.
Why it matters
For EU financial institutions, third-party arrangements covering non-ICT services, ranging from outsourced operational functions to professional and support services, have historically been governed by a patchwork of guidance, most notably the EBA's earlier work on outsourcing arrangements. The draft EBA Guidelines on Sound Management of Third-Party Risk, released for consultation on 8 July 2025, signal the regulator's intent to establish a more comprehensive and consistent approach to how institutions and certain investment firms govern and manage these relationships. For risk, compliance, and procurement professionals, this matters because it shapes supervisory expectations around internal governance and risk management practices for a category of third-party dependency that sits outside the technology-focused regime.
Who it's relevant to
Inside EBA Guidelines on Sound Management of Third-Party Risk
Common questions
Answers to the questions practitioners most commonly ask about EBA Guidelines on Sound Management of Third-Party Risk.
