The European Banking Authority (EBA) is moving towards a more targeted approach to third-party risk management, with regulatory attention increasingly focused on outsourcing arrangements involving critical or important functions. The approach is intended to reduce unnecessary compliance burdens while ensuring that banks maintain stronger oversight where a third-party failure could materially affect critical operations, customers or financial stability.
The shift is significant because banks increasingly depend on external providers for cloud computing, technology infrastructure, data processing and other essential services. Under a risk-based model, institutions would need to apply greater due diligence, contractual safeguards, monitoring and exit planning to providers supporting critical functions, while lower-risk outsourcing arrangements could face proportionately lighter requirements. This places greater importance on correctly identifying which outsourced activities are genuinely critical and maintaining an up-to-date assessment as business dependencies change.
For banks, the development reinforces a central principle of third-party risk management: outsourcing a function does not outsource responsibility. Institutions still need clear accountability, resilience measures, access to relevant information, incident-management arrangements and viable exit strategies for critical providers. The targeted approach also highlights the importance of distinguishing between ordinary vendor relationships and dependencies that could create significant concentration, operational or systemic risk if disrupted.
Want to deepen your expertise beyond today’s news?
Explore practical certification courses designed for banking, risk, insurance, compliance, ESG, AI, and emerging technologies professionals.
Learn from industry experts and earn certifications from RMAI and BFSI Sector Skill Council of India.
#Riskmanagementnews