outsourcing

  • EBA Third-Party Risk Guidelines: Non-ICT Scope and the Two-Year Clock

    On 18 September 2026 the European Banking Authority published EBA/GL/2026/09, its final guidelines on the sound management of third-party risk relating to non-ICT services. The EBA third-party risk guidelines widen the governed perimeter beyond outsourcing, which remains a subset, to non-ICT third-party arrangements within the Guidelines’ defined scope, with particular focus on arrangements supporting critical…

  • CSSF Circular 26/915: DORA Circulars Re-Mapped for Third-Country Branches

    On 27 August 2026 the CSSF published Circular 26/915, and it applies with immediate effect. Circular CSSF 26/915 updates the Luxembourg ICT and outsourcing circular framework following the European Commission position on DORA’s applicability to third-country branches. It removes the TCB categories within the CSSF’s remit from the relevant pre-DORA circular provisions and maps them…

  • SS2/21 Outsourcing: The PRA Register and Notification Guide

    SS2/21 is the PRA’s supervisory statement on outsourcing and third-party risk management. Its main scope covers UK banks, building societies and PRA-designated investment firms; insurance and reinsurance firms and groups in scope of Solvency II, including Lloyd’s and managing agents; and UK branches of overseas banks and insurers. It has been the working reference for…

  • DORA Register of Information – A Practical Guide for Financial Entities

    Your compliance team has a list of ICT providers. Your procurement team has a different list. Your IT department has a third list that includes vendors nobody told compliance about. You now have until 31 March 2026 to reconcile all three into a single, structured, template-compliant DORA Register of Information and submit it to the…