The EACB welcomes the opportunity to comment on the EBA draft Guidelines on the sound management of third-party risk, with focus on non-ICT risks. We appreciate the initiative to harmonise third-party risk management and build on existing EBA Guidelines to ensure consistency and avoid fragmentation.
We underline the importance of ensuring consistency between the DORA and the EBA Draft Guidelines on sound third-party risk management. Indeed, the degree of dependency should be the determining factor for distinguishing between “non-critical or important” non-ICT services and “critical or important” non-ICT services. Similarly, requirements regarding the register and minimum contractual provisions should not diverge concretely in substance or scope. We believe indeed that the final version of the Guidelines should ensure that identical circumstances are addressed by uniform terminology and definitions.
If a third-party arrangement does not qualify as outsourcing, it is difficult to see which prudential risks related to the core banking business the draft Guidelines would aim to address. ICT-related risks are already comprehensively covered by DORA, outsourcing and in general critical or important functions are addressed under the EBA Guidelines. Expanding the scope beyond these boundaries would impose disproportionate and unjustified burdens without achieving tangible supervisory benefits.
In sum, we stress the importance of:
- Aligning the definition and assessment of “critical or important functions (CIFs)” strictly with DORA, avoiding additional or broader criteria that would capture almost all third-party arrangements.
- Allowing centralised and compatible registers, allowing institutions to maintain either separate DORA and non-ICT registers or one consolidated version, without new mandatory data fields.
- Enabling group- and IPS-level centralisation of registers, monitoring and due-diligence processes, provided that individual institutions can generate entity-specific extracts on request.
- Limiting the most stringent requirements—enhanced due diligence, detailed contractual clauses, exit strategies, and business impact analyses—to CIFs only, applying a risk-based and proportional approach for all other services.
- Excluding regulated financial or utility services such as insurance or market data from the scope, and ensure that Annex I remains illustrative and non-exhaustive.
- Allow pragmatic sub-outsourcing through pre-defined conditions and pooled audits aligned with DORA terminology.