Beyond the Tech: EU Banking Watchdog Sets Guidelines for Non-ICT Risk
The European Banking Authority finalises instructions for how lenders must manage physical and operational third-party providers.
The Brussels Desk · Updated 6h ago
What happened
The European Banking Authority (EBA)—the EU watchdog tasked with drafting unified regulatory rules for the bloc's banking sector—has finalised its guidelines on managing non-ICT (information and communications technology) third-party risk. While recent EU rulebooks have concentrated heavily on cybersecurity and tech vendors, these new guidelines address operational reliance on non-digital external partners, such as physical security providers, facilities managers, legal advisors, and outsourced administrative services. The framework sets out clear expectations for how financial institutions across member states must evaluate, monitor, and mitigate the risks associated with hiring external contractors for non-tech roles.
Why it matters
For ordinary account holders and businesses, financial stability relies on more than just secure servers and online banking apps. An operational disruption at an outsourced document archive, physical security provider, or administrative support firm can halt banking operations just as effectively as a network glitch. For financial institutions, the finalised rules mean extending systematic risk assessments beyond IT departments to cover every external vendor agreement on their books.
The Brussels angle
Brussels rulemaking often follows a familiar pattern: after spending years building heavy regulatory fortresses around digital networks, authorities eventually turn their attention to the front door. The EBA's guidelines bridge a long-standing gap in institutional oversight, ensuring that while software vendors are strictly monitored under digital resilience rules, traditional operational contractors are not left in a regulatory gray zone. In typical EU fashion, the agency relies on soft law and supervisory guidance to harmonise standards across all 27 national banking authorities without needing a fresh legislative battle in the European Parliament.
What happens next
National financial regulators across the EU member states will incorporate the EBA guidelines into their day-to-day supervisory routines. Commercial banks and financial firms will now be required to audit their non-tech vendor relationships and update their risk management frameworks to align with the finalized standard.
Written from these sources
Facts are extracted from primary institutional material and written independently by The Gazette desk.
The Brief
Brussels, decoded, once a week. No fog, no jargon, one good dry joke.