From Outsourcing to Third Party Arrangements: The New EBA Guidelines on Third-Party Risk Management 1/2
On 8 July 2025, the European Banking Authority (EBA) published a new consultation paper on the EBA Guidelines for third-party risk management.
The draft goes well beyond the previous Outsourcing Guidelines from 2019. The objective is to establish a harmonised European framework for managing third-party risks, aligned in particular with the Digital Operational Resilience Act (DORA).
Part 1 of the analysis highlights the key innovations and main content; a practical assessment will follow in Part 2.