Find the Right GRC Solution

Search and compare GRC technology built for the problems you’re trying to solve

EBA Finalizes Third-Party Risk Guidelines With Focus on Critical Functions

EBA Finalizes Third-Party Risk Guidelines With Focus on Critical Functions

By
Key Takeaways
  • Critical Functions Take Priority: The EBA’s final Guidelines focus requirements on third-party arrangements supporting critical or important functions whose disruption could materially impair a financial entity.
  • ICT and Non-ICT Risk Come Together: The framework takes a holistic approach to third-party risk across both ICT and non-ICT services.
  • Full Third-Party Lifecycle Covered: The Guidelines address risk assessment, due diligence, contracting, subcontracting, monitoring, documentation and exit strategies.
  • Proportionality Is Central: By concentrating requirements on higher-risk arrangements, the EBA aims to reduce unnecessary operational and supervisory burdens for less material relationships.
  • Two-Year Transition: Financial institutions will have a two-year transitional period to implement the Guidelines.
Deep Dive

The European Banking Authority has finalized its Guidelines on third-party risk management, concentrating the new framework on the outside relationships that matter most when something goes wrong.

The Guidelines focus on third-party arrangements supporting critical or important functions, or CIFs. These are functions whose disruption would materially impair the performance of a financial entity. The distinction gives institutions room to treat less consequential relationships differently, rather than subjecting every provider to the same degree of scrutiny.

It is a deliberately more proportionate approach. The EBA said the narrower focus should reduce unnecessary operational and supervisory burdens associated with less material arrangements while preserving sound risk management where the consequences of disruption are greater.

The Guidelines also bring ICT and non-ICT services within a more holistic approach to third-party risk. For financial institutions, that means looking beyond the familiar boundaries of technology outsourcing and considering the importance of the service itself.

That judgment follows the relationship from beginning to end. The Guidelines address risk assessment and due diligence before an arrangement is established, contractual requirements once it is in place, the use of subcontractors, ongoing monitoring and documentation, and the planning required to leave a provider when the relationship ends.

Exit planning is particularly important in arrangements supporting critical or important functions. A financial institution that depends heavily on an outside provider has to consider not only whether the provider can perform the work today, but how the institution would respond if the arrangement could no longer continue.

The final Guidelines reflect feedback gathered during the EBA’s public consultation and targeted outreach activities. They also take international standards into account, including the Basel Committee on Banking Supervision’s Principles for the Sound Management of Third-Party Risk.

The result is a framework intended to sit more coherently alongside the EU’s Digital Operational Resilience Act. DORA established a harmonized framework for managing ICT-related risks in the financial sector. The EBA’s Guidelines extend the third-party risk discussion across ICT and non-ICT services while keeping the regulatory attention centered on arrangements capable of materially affecting an institution.

Institutions will not be expected to make the transition overnight. The EBA has provided a two-year transitional period to support implementation, giving firms time to assess existing arrangements and bring their third-party risk management practices into line with the new framework.

The Guidelines rest principally on Article 74 of Directive 2013/36/EU, which mandates the EBA to further harmonize governance arrangements, processes and mechanisms among institutions across the European Union. The EBA also took into account Article 11 of the revised Payment Services Directive, Article 26 of the Investment Firms Directive, Article 16 of MiFID II, Article 34 of the Markets in Crypto-Assets Regulation and Article 16 of Regulation (EU) No 1093/2010.

For institutions with hundreds or thousands of outside relationships, the practical consequence begins with a deceptively simple question: which of them actually matter enough that their failure could materially impair the business?

Answering it properly determines much of what follows. Once an arrangement supports a critical or important function, due diligence, contracting, subcontracting, monitoring, documentation and exit planning become parts of the same risk-management problem. The EBA’s final Guidelines put that distinction at the center of the framework and give institutions two years to put it into practice.

The GRC Report is your premier destination for the latest in governance, risk, and compliance news. As your reliable source for comprehensive coverage, we ensure you stay informed and ready to navigate the dynamic landscape of GRC. Beyond being a news source, the GRC Report represents a thriving community of professionals who, like you, are dedicated to GRC excellence. Explore our insightful articles and breaking news, and actively participate in the conversation to enhance your GRC journey.

🔒
Cancel anytime
Full archive access
Custom alerts

Oops! Something went wrong