critical or important functions

  • EBA Third-Party Risk Guidelines: Non-ICT Scope and the Two-Year Clock

    On 18 September 2026 the European Banking Authority published EBA/GL/2026/09, its final guidelines on the sound management of third-party risk relating to non-ICT services. The EBA third-party risk guidelines widen the governed perimeter beyond outsourcing, which remains a subset, to non-ICT third-party arrangements within the Guidelines’ defined scope, with particular focus on arrangements supporting critical…