EBA publishes final Guidelines on management of third-party risk aligned with DORA

Original title: EBA E-mail alert 18 September, 2026

The EBA has published its final Guidelines on the management of third-party risk, creating a more proportionate and consistent regulatory framework that aligns with DORA requirements. These guidelines provide EU financial institutions with clearer expectations for managing risks associated with third-party service providers and outsourced functions. Organizations subject to DORA and EBA supervision will need to assess their third-party risk management practices against these new guidelines.

What changed

  • EBA releases final Guidelines on third-party risk management that establish a proportionate and consistent framework for EU financial institutions.
  • The guidelines are aligned with DORA requirements, ensuring consistency between third-party risk management expectations and the Digital Operational Resilience Act's provisions.
  • The framework aims to provide clearer regulatory expectations for managing risks related to third-party service providers and outsourced functions across the EU financial sector.

Who is affected

EU financial institutions subject to DORA and EBA supervision, including banks and other regulated entities that rely on third-party service providers and outsourced functions.

Summary generated by a language model; the official text prevails. Not legal advice.