Story details
The European Banking Authority published final third-party risk guidelines on 18 September, aligned with DORA. They focus on external arrangements supporting functions whose disruption could materially impair a financial firm.
The guidance covers risk assessment, due diligence, contracts, subcontracting, monitoring, records and exit planning across ICT and non-ICT services. A two-year transition is intended to support implementation. The EBA says concentrating on higher-risk arrangements should ease unnecessary burden on less material ones while retaining sound risk management.