third-party risk

  • EBA Third-Party Risk Guidelines: Non-ICT Scope and the Two-Year Clock

    On 18 September 2026 the European Banking Authority published EBA/GL/2026/09, its final guidelines on the sound management of third-party risk relating to non-ICT services. The EBA third-party risk guidelines widen the governed perimeter beyond outsourcing, which remains a subset, to non-ICT third-party arrangements within the Guidelines’ defined scope, with particular focus on arrangements supporting critical…

  • CPMI-IOSCO Third-Party Risk at FMIs: The 1 December Deadline

    On 8 September 2026 the Committee on Payments and Market Infrastructures and the International Organization of Securities Commissions published for public comment a discussion paper, “FMIs’ reliance on third-party service providers: challenges and risks,” and set a comment deadline of 1 December 2026. It is the clearest signal yet of where CPMI-IOSCO third-party risk work…

  • BCBS Third-Party Risk Principles: DORA and Outsourcing Rules

    On 10 December 2025 the Basel Committee on Banking Supervision published its Principles for the sound management of third-party risk, a 22-page Guidelines publication setting out 12 principles for how banks and their supervisors handle the providers now sitting inside almost every banking process. For the banking sector it supersedes the 2005 Joint Forum paper…

  • Basel Committee ICT Risk Management: The Four Root Causes of Incidents

    On 2 June 2026 the Basel Committee on Banking Supervision published a range-of-practices report on information and communication technology (ICT) risk management. It draws on a survey of 16 jurisdictions and centres on how global and domestic systemically important banks handle the technology failures that take critical services offline. The Basel Committee ICT risk management…

  • FSB AI Sound Practices: Consultation Closes, Final Report Next

    On 6 August 2026 the Financial Stability Board published the public responses to its consultation on Sound Practices for Responsible Adoption of Artificial Intelligence (AI). The FSB AI sound practices were put out for comment on 10 June 2026, the comment window closed on 22 July 2026, and the FSB now says it expects to…

  • Japan FSA IT Resilience Report 2026: Four Supervisory Fronts for Banks

    Japan’s Financial Services Agency published its Analytical Report on IT Resilience in the Financial Sector on 30 July 2026, and the framing in the executive summary is blunt: the management of financial institutions needs to recognise IT risk and cyber risk as top management priorities. The Japan FSA IT resilience report carries no template and…

  • DORA ICT Incident Reporting: What the ESAs First Annual Report Reveals

    If your firm filed a major incident under DORA in 2025, that report has now been counted. On 3 June 2026 the three European Supervisory Authorities published their first annual report on major ICT-related incidents, putting a hard number on what used to be guesswork: how many major incidents the EU financial sector reports, where…

  • DORA Register of Information – A Practical Guide for Financial Entities

    Your compliance team has a list of ICT providers. Your procurement team has a different list. Your IT department has a third list that includes vendors nobody told compliance about. You now have until 31 March 2026 to reconcile all three into a single, structured, template-compliant DORA Register of Information and submit it to the…