The Brussels Desk · IndependentBrussels desk
What It MeansSaturday, 26 September 2026 · 2 min read

Know Your Vendors: EU Banking Regulator Sets Final Rules for Financial Subcontracting

The European Banking Authority finalises its oversight framework for third-party risk, leaving banks with nowhere to hide when external software fails.

The Brussels Desk · Updated 1h ago

What happened

The European Banking Authority (EBA)—the EU regulatory body responsible for maintaining stability and standardisation across the bloc's banking sector—has issued its final guidelines on third-party risk management. The updated rules establish detailed expectations for how financial institutions must monitor and manage operational risks steming from external contractors, software vendors, and service providers. A new analysis by Deloitte highlights the practical compliance steps banks must take to meet the supervisory requirements.

Why it matters

Modern banking relies heavily on digital supply chains, from cloud infrastructure to payment processing software. When a key technology vendor suffers an outage or cyber incident, consumer access to accounts and payments can grind to a halt. The EBA's guidelines ensure that financial institutions maintain direct responsibility for the security and resilience of their outsourced operations, protecting consumer deposits and system stability regardless of how many subcontractors are involved.

The Brussels angle

In the EU regulatory ecosystem, agency guidelines serve to harmonise how national regulators enforce European law. The EBA's approach to third-party risk rests on a core principle of European bureaucracy: you can outsource the work, but you can never outsource the paperwork or the responsibility. Financial institutions operating across member states will now have to apply uniform standards to vendor due diligence, ensuring that a bank in Frankfurt and a fintech in Dublin face identical expectations when managing external service providers.

What happens next

Financial institutions across the EU will now conduct internal audits to benchmark their current vendor agreements against the final guidelines. National central banks and supervisory authorities will integrate these updated expectations into their regular supervisory reviews, forcing lenders to update their risk registers and contractual clauses.

ebabankingfinanceregulation

Written from these sources

Facts are extracted from primary institutional material and written independently by The Gazette desk.

The Brief

Brussels, decoded, once a week. No fog, no jargon, one good dry joke.