The European Union’s key banking regulator has issued guidelines to help large banks manage the risk of disruption if an important IT provider has an outage or a third party cannot continue to supply critical services.

The European Banking Authority’s (EBA) guidelines apply to third-party risk management across information and communication technology (ICT) and non-ICT services and cover the full lifecycle of third-party arrangements, including risk assessment and due diligence, contracting, subcontracting, monitoring, documentation and exit strategies.

Neil Hodge is a freelance business journalist and photographer based in Nottingham, United Kingdom. He writes on insurance and risk management, corporate governance, internal audit, compliance, and legal...