Skip to main content
Category: Regulatory Frameworks

EBA Guidelines on Third-Party Risk

Also known as: EBA Guidelines on the sound management of third-party risk, EBA Draft Guidelines on third-party risk management (non-ICT related services), EBA/CP/2025/12
Simply put

The EBA Guidelines on Third-Party Risk are draft guidelines issued by the European Banking Authority setting out how financial entities should manage risks arising from their arrangements with third parties. They cover the full life cycle of these arrangements, from risk assessment onward, and focus on services that are not related to information and communication technology (ICT). As of the evidence provided, they were published for consultation on 8 July 2025 and are therefore in draft form rather than finalized.

Formal definition

Draft supervisory guidelines (referenced as EBA/CP/2025/12) proposed by the European Banking Authority specifying internal governance arrangements, including sound risk management, that institutions and investment firms are expected to apply across the life cycle of third-party arrangements (for example risk assessment through to the ongoing stages of the arrangement). Their stated scope is third-party risk management with regard to non-ICT related services, positioning them alongside but distinct from ICT-focused requirements; per the consultation responses in the evidence, they are intended to create a comprehensive approach to managing third-party risks and to align closely with the Digital Operational Resilience Act (DORA). The evidence describes these as draft guidelines under consultation launched 8 July 2025; it does not establish a finalized text, effective date, or the precise boundary of institutions covered, so the specific in-scope entity population and any interaction with existing outsourcing guidance should be confirmed against the finalized instrument rather than assumed.

Why it matters

For financial entities in the EU, third-party arrangements have long been governed by a patchwork of expectations, with the EBA's existing outsourcing guidance addressing one part of the picture and the Digital Operational Resilience Act (DORA) addressing ICT-related third-party risk. The draft EBA Guidelines on Third-Party Risk (EBA/CP/2025/12), published for consultation on 8 July 2025, are significant because they aim to extend structured supervisory expectations to non-ICT related third-party services, an area that has historically received less consolidated attention than ICT dependencies. This matters to risk and compliance teams that must demonstrate to supervisors that they manage the full range of external dependencies, not only technology providers.

Who it's relevant to

Compliance and regulatory affairs teams in EU banks and investment firms
These teams are the primary audience, as the draft guidelines specify internal governance and sound risk management expectations for institutions and investment firms. They will need to track the consultation outcome, assess how the non-ICT scope maps to their existing third-party inventories, and prepare for how the finalized text may interact with current outsourcing guidance, recognizing that these points are not yet settled in the draft.
Third-party and vendor risk management functions
Because the guidelines address the full life cycle of third-party arrangements from risk assessment through the ongoing stages, TPRM functions should note the emphasis on continuous oversight rather than onboarding alone. The explicit focus on non-ICT related services means teams may need to ensure their frameworks cover services that fall outside the ICT scope already governed under DORA.
Operational resilience and DORA implementation leads
The draft states an intent to align closely with DORA and to create a comprehensive approach to third-party risk. Resilience leads coordinating DORA obligations should monitor how the non-ICT guidance is positioned relative to ICT-focused requirements, keeping the two scopes distinct while identifying where governance and processes might be harmonized once the instrument is finalized.
Industry associations and consultation respondents
Bodies such as AFME have engaged with the consultation, reflecting that scope, definitions, and interactions with existing guidance remain open questions. Members relying on such associations for advocacy should follow the consultation responses to anticipate potential changes between the draft and the finalized guidelines.

Inside EBA Guidelines on Third-Party Risk

Scope and application
The guidelines address how regulated financial institutions govern arrangements with external providers, with particular emphasis on outsourcing arrangements. Depending on the specific instrument, the scope may be narrower than the full universe of third-party relationships an institution maintains, and applicability typically depends on whether an arrangement meets the relevant definition of outsourcing rather than covering every vendor or supplier.
Governance and internal responsibility
Expectations that the management body retains accountability for arrangements with third parties, that they cannot delegate their ultimate responsibility to a provider, and that an appropriate internal governance framework oversees these relationships. This addresses organizational accountability but does not itself perform the operational assessment work.
Register or documentation of arrangements
Expectations to maintain a documented inventory of relevant arrangements, often distinguishing those supporting critical or important functions from other arrangements. This supports oversight and supervisory review but is a record-keeping mechanism rather than an assurance that the underlying risks are controlled.
Risk assessment and due diligence
Expectations to assess risks before entering an arrangement and to conduct due diligence on the prospective provider. This typically covers pre-contract evaluation; ongoing monitoring is treated as a distinct, continuing obligation rather than being satisfied by onboarding due diligence alone.
Contractual requirements
Expectations regarding provisions in written agreements, which may include access and audit rights, information security, sub-contracting or chain arrangements, business continuity, data location, and termination or exit terms. The presence of contractual rights does not by itself demonstrate that those rights are exercised or that the provider performs as required.
Concentration and sub-outsourcing considerations
Attention to concentration at the institution and, where relevant, sector level, and to risks arising where a provider relies on its own sub-providers (chain arrangements). This extends consideration beyond the direct relationship toward downstream dependencies, though visibility into lower tiers is typically limited.
Ongoing monitoring and exit strategies
Expectations for continued monitoring of provider performance and risk over the life of the arrangement, and for documented exit strategies for arrangements supporting critical or important functions so that services can be transitioned or brought back in-house if needed.

Common questions

Answers to the questions practitioners most commonly ask about EBA Guidelines on Third-Party Risk.

Are the EBA Guidelines on Third-Party Risk the same as a binding EU regulation that applies uniformly across all sectors?
No. EBA guidelines are supervisory expectations issued by the European Banking Authority and are addressed principally to financial institutions and their competent authorities, not to every sector. They operate on a 'comply or explain' basis, meaning national competent authorities indicate whether they adopt them and institutions are expected to follow them or justify departures. This is distinct from directly applicable EU regulations, which carry legal force without national transposition. Applicability, timing, and interpretive detail can therefore vary by jurisdiction and by the type of institution supervised.
Does following the EBA Guidelines mean an institution has covered all of its supply chain risk?
Not necessarily. The guidelines are oriented toward an institution's direct arrangements with third parties, particularly outsourcing and other service arrangements within scope of the financial sector's supervisory framework. They do not, by themselves, deliver full multi-tier supply chain risk management, which extends across fourth-party and Nth-party relationships and the physical and logistical flows of goods and services. Concentration risk arising deeper in the chain, and dependencies beyond the first tier, may require additional processes that the guidelines flag but do not fully resolve on their own.
How do the EBA Guidelines relate to distinguishing outsourcing from other third-party arrangements?
A recurring implementation point is that the guidelines treat outsourcing arrangements with particular rigor, so institutions typically need a clear internal method to classify whether a given arrangement is outsourcing or another type of third-party service. This classification drives the level of governance, documentation, and oversight expected. Depending on the arrangement, requirements around register-keeping, exit planning, and audit and access rights may differ. Misclassifying an arrangement can lead to applying too little or too much control, so many programs formalize the assessment criteria and document the rationale.
What governance and documentation elements do programs typically build to align with the guidelines?
In many programs, alignment involves maintaining a register of relevant arrangements, defining board and senior-management accountability, conducting pre-contractual due diligence proportionate to the risk, and embedding contractual provisions covering matters such as audit and access rights, sub-outsourcing, data location, and termination. Ongoing monitoring rather than one-time onboarding review is generally emphasized, because point-in-time assessments can become stale. The degree of formality is usually calibrated to whether the arrangement is critical or important, so lower-risk arrangements may warrant lighter documentation.
How should institutions approach exit strategies under this framework?
Exit and termination planning is typically expected for arrangements assessed as critical or important, so that an institution can transfer or bring back a service without unacceptable disruption. Practical implementation often includes documented exit plans, identification of alternative providers or in-house options where feasible, and consideration of whether substitutability is realistically available given concentration in the market. It is worth distinguishing this planning from business continuity and disaster recovery: exit planning addresses ending or replacing a relationship, whereas continuity and recovery address maintaining or restoring service during disruption.
How do these guidelines interact with related third-party frameworks and standards an institution may already use?
Institutions frequently operate the guidelines alongside other tools, such as questionnaire-based assessments or standards addressing information security in supplier relationships, and third-party assurance reports. It is important to keep the roles distinct: an attestation or an assurance report reflects a defined scope and period and is not equivalent to independent certification or to the supervisory expectations themselves. The guidelines set out what supervised institutions are expected to govern; other frameworks can support evidence-gathering, but mapping between them typically requires care so that gaps in scope, timing, or independent verification are not overlooked.

Common misconceptions

The EBA guidelines govern all third-party relationships a financial institution has.
The guidelines place particular emphasis on outsourcing arrangements and, for many obligations, on those supporting critical or important functions. Not every vendor, supplier, or service provider relationship necessarily falls within the same expectations, and whether an arrangement is treated as outsourcing depends on how it meets the relevant definition.
The guidelines are a global standard equivalent to an internationally binding regime.
They are issued in a European context for institutions within the relevant supervisory perimeter. Regulatory expectations for third-party and outsourcing arrangements differ across regions and sectors, so these guidelines should not be presented as a universal framework applicable everywhere.
Meeting the contractual and register requirements means the third-party risk is controlled.
Maintaining a register and including required contractual provisions are documentation and rights-preservation measures. They do not by themselves verify provider performance or eliminate risk; ongoing monitoring, and where relevant independent verification, remain necessary and are treated as separate obligations.

Best practices

Determine early whether each arrangement meets the relevant definition of outsourcing and whether it supports a critical or important function, since these classifications typically drive which specific expectations apply.
Maintain a current, structured register of arrangements that distinguishes critical or important functions, and treat it as a living record rather than a one-time onboarding artifact.
Treat pre-contract due diligence and ongoing monitoring as distinct activities, and establish continuing oversight so that point-in-time assessments do not become the sole basis for reliance over the life of the arrangement.
Negotiate and preserve access, audit, information security, sub-contracting, and termination provisions in written agreements, and put processes in place to actually exercise those rights rather than relying on their existence alone.
Assess concentration at both the institution level and, where relevant, more broadly, and evaluate chain arrangements where a provider depends on its own sub-providers, while acknowledging that visibility into lower tiers is often limited.
Develop and periodically test documented exit strategies for arrangements supporting critical or important functions, distinguishing the ability to transition or reinstate a service from routine business continuity or disaster recovery measures.
Promotional banner for the Pentest Readiness checklist download