{"id":70299,"date":"2026-09-25T14:53:33","date_gmt":"2026-09-25T12:53:33","guid":{"rendered":"https:\/\/www.usd.de\/?p=70299"},"modified":"2026-09-25T14:53:46","modified_gmt":"2026-09-25T12:53:46","slug":"tprm-eba-publishes-guidelines-non-ict-services","status":"publish","type":"post","link":"https:\/\/www.usd.de\/en\/tprm-eba-publishes-guidelines-non-ict-services\/","title":{"rendered":"TPRM: EBA Publishes Guidelines on Third-Party Risk Management for Non-ICT Services"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">The <a href=\"https:\/\/www.eba.europa.eu\/homepage\" data-type=\"link\" data-id=\"https:\/\/www.eba.europa.eu\/homepage\" target=\"_blank\" rel=\"noopener\">European Banking Authority<\/a> (EBA) has published its final Guidelines on the management of third-party risk. The aim is to establish a consistent yet proportionate framework for managing risks arising from the use of third-party service providers (TPSPs).<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">With the new Guidelines, the EBA is extending key requirements of <a href=\"https:\/\/www.usd.de\/en\/security-consulting\/third-party-risk-management-tprm\/\" data-type=\"link\" data-id=\"https:\/\/www.usd.de\/en\/security-consulting\/third-party-risk-management-tprm\/\">Third-Party Risk Management<\/a> (TPRM) to relevant non-ICT services. While <a href=\"https:\/\/www.usd.de\/en\/security-consulting\/dora\/\" data-type=\"link\" data-id=\"https:\/\/www.usd.de\/en\/security-consulting\/dora\/\">DORA<\/a> already defines requirements for managing ICT services, the new Guidelines address third-party arrangements outside the ICT domain. Financial entities will therefore also be required to establish structured TPRM processes for these third-party arrangements in the future.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The Guidelines apply, among others, to:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Credit institutions<\/li>\n\n\n\n<li>Investment firms<\/li>\n\n\n\n<li>Payment institutions and electronic money institutions<\/li>\n\n\n\n<li>Certain crypto-asset service providers<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">As a result, the Guidelines cover large parts of the regulated financial sector.<\/p>\n\n\n\n<div style=\"height:21px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<h2 class=\"wp-block-heading\">Focus on Critical or Important Functions<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The primary focus is on third-party arrangements supporting critical or important functions. These arrangements are subject to specific risk management requirements throughout the entire lifecycle of the respective third-party arrangement. At the same time, the EBA consistently follows the principle of proportionality and explicitly excludes numerous types of services with limited relevance for operational resilience from the scope of application. This allows financial entities to concentrate their efforts on third-party arrangements that are relevant to operational resilience.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The Guidelines assess third-party risks not only at the individual entity level but also within the context of corporate groups. Parent companies are expected to ensure that governance structures and processes are designed consistently across the group.<\/p>\n\n\n\n<div style=\"height:21px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<h2 class=\"wp-block-heading\">Information Register for Non-ICT Services as a Key Challenge<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">In practice, the required information register for non-ICT services is likely to become particularly relevant. It should be maintained as consistently as possible with the information register already required under DORA. Many financial entities are familiar with the associated challenges from their DORA implementation efforts: information on third-party arrangements is often maintained across different systems, contractual data is not always up to date, and a complete overview of existing third-party arrangements is frequently lacking. The new Guidelines now extend these transparency requirements to the non-ICT domain.<\/p>\n\n\n\n<div style=\"height:8px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<div class=\"wp-block-columns is-layout-flex wp-container-core-columns-is-layout-8f761849 wp-block-columns-is-layout-flex\">\n<div class=\"wp-block-column is-layout-flow wp-block-column-is-layout-flow\" style=\"flex-basis:66.66%\">\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p class=\"wp-block-paragraph\">\"At the same time, the close alignment with DORA creates opportunities for implementation. The EBA explicitly encourages financial entities to take an integrated approach to existing governance structures, processes, and policies for ICT and non-ICT third-party arrangements. Institutions therefore do not necessarily need to establish parallel structures but can build on and further develop existing DORA processes. This integrated approach helps ensure consistent risk management, avoids duplication of effort, and allows organizations to leverage the experience gained from DORA implementation when addressing the new requirements.\"<\/p>\n\n\n\n<div style=\"height:8px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<p class=\"has-small-font-size wp-block-paragraph\"><em>Victoria Kunde, Senior Consultant at usd AG<\/em><\/p>\n<\/blockquote>\n<\/div>\n\n\n\n<div class=\"wp-block-column is-vertically-aligned-top is-layout-flow wp-block-column-is-layout-flow\" style=\"flex-basis:33.33%\">\n<figure class=\"wp-block-image aligncenter size-large is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"977\" src=\"https:\/\/www.usd.de\/wp-content\/uploads\/Victoria-Kunde_rund-1024x977.png\" alt=\"\" class=\"wp-image-41071\" style=\"aspect-ratio:1.0481302884177963;object-fit:cover;width:194px;height:auto\" \/><\/figure>\n<\/div>\n<\/div>\n\n\n\n<div style=\"height:21px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<h2 class=\"wp-block-heading\">Transition Period for Existing Arrangements, Immediate Application for New Arrangements<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The Guidelines were published on 18 September 2026, but are not yet applicable. The EBA generally provides for a two-year transition period for implementation. While new third-party arrangements will be required to comply with the Guidelines immediately, existing arrangements will gradually be brought into scope in connection with updates to the underlying contractual arrangements.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\" \/>\n\n\n\n<div style=\"height:8px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<p class=\"wp-block-paragraph\">Would you like to assess the impact of the new EBA Guidelines on your Third-Party Risk Management framework? Our experts can support you in evaluating and implementing the requirements. <a href=\"https:\/\/www.usd.de\/en\/contact-form-security-consulting\/\" data-type=\"page\" data-id=\"12359\">Contact us<\/a>.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Related publication: <a href=\"https:\/\/www.eba.europa.eu\/sites\/default\/files\/2026-09\/dc9ccbb3-79b9-493d-b693-c21adeffbcc9\/Final%20report%20on%20GL%20on%20third-party%20risk%20management.pdf\" target=\"_blank\" rel=\"noopener\">Guidelines on the sound management of third-party risk regarding non-ICT services<\/a><\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n","protected":false},"excerpt":{"rendered":"<p>The European Banking Authority (EBA) has published its final Guidelines on the management of third-party risk. The aim is to establish a consistent yet proportionate framework for managing risks arising from the use of third-party service providers (TPSPs). With the new Guidelines, the EBA is extending key requirements of Third-Party Risk Management (TPRM) to relevant [&hellip;]<\/p>\n","protected":false},"author":117,"featured_media":70284,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_et_pb_use_builder":"off","_et_pb_old_content":"","_et_gb_content_width":"","inline_featured_image":false,"footnotes":""},"categories":[410,373],"tags":[15030,7884,15241,15035,7886,15036,7887],"class_list":["post-70299","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-financial-sector-compliance-en","category-news-en","tag-drittparteienrisiken","tag-drittparteienrisikomanagement-en","tag-eba","tag-ict-third-party-risk-management","tag-third-party-risk-management-en","tag-third-party-governance","tag-tprm-en"],"_links":{"self":[{"href":"https:\/\/www.usd.de\/en\/wp-json\/wp\/v2\/posts\/70299","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.usd.de\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.usd.de\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.usd.de\/en\/wp-json\/wp\/v2\/users\/117"}],"replies":[{"embeddable":true,"href":"https:\/\/www.usd.de\/en\/wp-json\/wp\/v2\/comments?post=70299"}],"version-history":[{"count":6,"href":"https:\/\/www.usd.de\/en\/wp-json\/wp\/v2\/posts\/70299\/revisions"}],"predecessor-version":[{"id":70318,"href":"https:\/\/www.usd.de\/en\/wp-json\/wp\/v2\/posts\/70299\/revisions\/70318"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.usd.de\/en\/wp-json\/wp\/v2\/media\/70284"}],"wp:attachment":[{"href":"https:\/\/www.usd.de\/en\/wp-json\/wp\/v2\/media?parent=70299"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.usd.de\/en\/wp-json\/wp\/v2\/categories?post=70299"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.usd.de\/en\/wp-json\/wp\/v2\/tags?post=70299"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}