The European Banking Authority has published its final guidelines on third-party risk management, introducing a framework focused on critical or important functions and aligned with the EU’s Digital Operational Resilience Act (DORA).

The European Banking Authority (EBA) has published its final guidelines on the management of third-party risk, aiming to simplify regulatory requirements while strengthening oversight of critical outsourcing and service arrangements. The framework has been aligned with the EU’s Digital Operational Resilience Act (DORA)  The guidelines focus on third-party arrangements that support critical or important functions (CIFs), where disruption could materially affect a financial institut