EBA Guidelines on Third-Party Risk
The EBA Guidelines on Third-Party Risk are draft guidelines issued by the European Banking Authority setting out how financial entities should manage risks arising from their arrangements with third parties. They cover the full life cycle of these arrangements, from risk assessment onward, and focus on services that are not related to information and communication technology (ICT). As of the evidence provided, they were published for consultation on 8 July 2025 and are therefore in draft form rather than finalized.
Draft supervisory guidelines (referenced as EBA/CP/2025/12) proposed by the European Banking Authority specifying internal governance arrangements, including sound risk management, that institutions and investment firms are expected to apply across the life cycle of third-party arrangements (for example risk assessment through to the ongoing stages of the arrangement). Their stated scope is third-party risk management with regard to non-ICT related services, positioning them alongside but distinct from ICT-focused requirements; per the consultation responses in the evidence, they are intended to create a comprehensive approach to managing third-party risks and to align closely with the Digital Operational Resilience Act (DORA). The evidence describes these as draft guidelines under consultation launched 8 July 2025; it does not establish a finalized text, effective date, or the precise boundary of institutions covered, so the specific in-scope entity population and any interaction with existing outsourcing guidance should be confirmed against the finalized instrument rather than assumed.
Why it matters
For financial entities in the EU, third-party arrangements have long been governed by a patchwork of expectations, with the EBA's existing outsourcing guidance addressing one part of the picture and the Digital Operational Resilience Act (DORA) addressing ICT-related third-party risk. The draft EBA Guidelines on Third-Party Risk (EBA/CP/2025/12), published for consultation on 8 July 2025, are significant because they aim to extend structured supervisory expectations to non-ICT related third-party services, an area that has historically received less consolidated attention than ICT dependencies. This matters to risk and compliance teams that must demonstrate to supervisors that they manage the full range of external dependencies, not only technology providers.
Who it's relevant to
Inside EBA Guidelines on Third-Party Risk
Common questions
Answers to the questions practitioners most commonly ask about EBA Guidelines on Third-Party Risk.
