EU EBA Banking Brief
Headline
EBA publishes final Guidelines on third-party risk management, scoped to critical or important functions and aligned with DORA
Executive Summary
The EBA published final Guidelines on September 18, 2026 governing third-party arrangements that support critical or important functions at financial entities. The Guidelines concentrate supervisory and operational requirements on higher-risk arrangements. Less material third-party relationships face reduced compliance burdens, while the framework maintains alignment with the Digital Operational Resilience Act.
Bottom Line
The final Guidelines establish a tiered third-party risk framework in which the full weight of EBA requirements falls only on arrangements supporting critical or important functions. Financial entities carry an obligation to classify their third-party arrangements against this threshold; misclassification that places a critical or important function arrangement outside the framework's scope creates a direct supervisory exposure. The DORA alignment means firms with compliant ICT third-party governance already satisfy the structural requirements of the Guidelines for technology-related arrangements, but the Guidelines extend beyond ICT to all third-party relationships meeting the critical or important function definition.
Key Regulatory Signals
- Scope Narrows to Critical or Important Functions: The Guidelines apply specifically to third-party arrangements whose disruption would materially impair a financial entity's performance. Firms must identify which arrangements meet this threshold and apply the full risk-management framework only to those relationships, reducing compliance overhead for lower-risk vendor contracts.
- DORA Alignment Removes Duplicative Obligations: The Guidelines are explicitly calibrated to the Digital Operational Resilience Act's requirements for ICT third-party risk. Financial entities already building DORA-compliant third-party registers and contractual frameworks carry those structures directly into EBA Guideline compliance, avoiding parallel regimes.
- Proportionality Principle Reshapes Supervisory Expectations: National competent authorities supervising third-party risk under the Guidelines are expected to concentrate examination resources on critical or important function arrangements. Firms with large but predominantly non-critical vendor populations face a materially lighter supervisory footprint under the final text than under prior EBA guidance.
- Operational Burden Reduction Is Structural, Not Discretionary: The EBA frames the reduced burden for non-critical arrangements as a design feature of the framework, not a supervisory tolerance. Firms cannot apply the lighter treatment to arrangements that meet the critical or important function definition, regardless of internal risk appetite.
Regulatory Delta
- The final Guidelines replace the EBA's 2019 outsourcing guidelines, which applied a broader scope not limited to critical or important functions. This represents a deliberate narrowing of the framework's perimeter.
- Alignment with DORA is an explicit structural feature rather than an incidental outcome. The Guidelines are designed to sit within the DORA ecosystem rather than operate as a parallel supervisory layer, reducing duplicative compliance obligations for in-scope financial entities.
- The European Commission's regulatory simplification agenda, active across multiple ESA mandates in 2025 and 2026, provides the legislative context for the proportionality design embedded in these Guidelines.
Materiality Classification
HIGH — Final EBA Guidelines with sector-wide application alter existing third-party risk management practice across all EBA-supervised financial entities, requiring firms to reclassify vendor arrangements and restructure compliance frameworks against the critical or important function threshold.
Intelligence Outlook
Monitor the EBA for the official application date and any accompanying regulatory technical standards or implementing technical standards linked to this rulemaking, and monitor national competent authorities for supervisory expectations on the critical or important function classification methodology.