
Outsourcing & Cloud Risk Management: EBA Guidelines
A practical guide to third-party and cloud risk management for financial institutions, updated for EBA/GL/2026/09, the Guidelines on the sound management of third-party risk published on 18 September 2026, which replace the 2019 outsourcing Guidelines and govern non-ICT arrangements while DORA governs ICT and cloud: classification of critical or important functions, risk assessment, due diligence, register, contractual requirements, subcontracting, monitoring, concentration risk and exit strategies.
About this course
This course is a practical guide to outsourcing, third-party and cloud risk management for financial institutions, built on the current European framework. It covers the EBA Guidelines on the sound management of third-party risk (EBA/GL/2026/09), published on 18 September 2026, which repeal the 2019 outsourcing Guidelines (EBA/GL/2019/02) and extend the perimeter from outsourcing to all non-ICT third-party arrangements supporting critical or important functions, together with DORA's third-party ICT risk management requirements for cloud and other ICT services. It covers classification and criticality assessment, pre-contractual analysis and due diligence, the register and its alignment with the DORA register, mandatory contractual provisions, subcontracting, access and audit rights, termination and exit strategies, monitoring, concentration risk and governance, including board accountability and the prohibition on becoming an empty shell. Designed for compliance officers, risk managers, internal auditors, procurement teams and members of the management body overseeing outsourcing and third-party risk. Includes a Belgian supervisory perspective.

