EBA - Final report on EBA Guidelines on the sound management of third-party risk regarding non-ICT services

The Guidelines focus on third-party arrangements supporting critical or important functions (CIFs) namely the disruption of which would materially impair the performance of a financial entity. By concentrating on these higher-risk arrangements, the Guidelines reduce unnecessary operational and supervisory burdens for less material ones while maintaining sound risk management.

The Guidelines promote a holistic approach to third-party risk management across ICT and non-ICT services and cover the full lifecycle of third-party arrangements, including risk assessment and due diligence, contracting, subcontracting, monitoring, documentation and exit strategies.

They reflect stakeholders feedback received during the public consultation and through targeted outreach activities and take into account international standards, including the Basel Committee on Banking Supervision (BCBS) Principles for the Sound Management of Third-Party Risk.

A two-year transitional period will support a smooth and proportionate implementation