Third-party risk management under EBA, NIS2 and DORA

Third-party risk management under EBA, NIS2 and DORA – from supplier list to working governance

Third-party management is more than a supplier register. How to move from a static list to working supplier governance that holds up to EBA, DORA and NIS2 – as a lifecycle.

Summary: Third-party management is more than a supplier register. EBA, DORA and NIS2/the Swedish Cybersecurity Act all point the same way: understand your supplier dependencies, assess the risks, set the right requirements and follow up over time. Here is how to move from a static list to working supplier governance – as a lifecycle.

Many organisations today depend on external suppliers for IT, cloud services, operations, support, development, security and business-critical processes. That makes third-party management more than a procurement question.

For banks, insurers and other financial actors, the requirements have long existed through, among other things, the EBA guidelines on outsourcing. With DORA, the requirements on ICT third-party risk have become even clearer in the financial sector. At the same time, NIS2 and the Swedish Cybersecurity Act highlight the supply chain as a central part of cybersecurity work for more sectors. DORA covers, among other things, ICT risk management, ICT third-party risk, testing and incident reporting, while NIS2 sets requirements for risk-management measures and incident reporting in more essential sectors.

The practical problem is rarely that the organisation lacks suppliers in a register. The problem is that you don’t always know which suppliers are critical, what risks they pose, which requirements have actually been set and whether the suppliers are followed up over time.

Third-party management needs to be a lifecycle

Effective third-party management does not begin when the contract is signed and does not end when the supplier is onboarded.

It needs to cover the whole lifecycle:

  • identifying and classifying suppliers
  • assessing criticality and dependencies
  • supplier review and due diligence
  • risk analysis
  • requirements and contracts
  • ongoing follow-up
  • incident and continuity planning
  • exit strategy and termination

The EBA outsourcing framework has long emphasised governance, documentation, risk assessment, due diligence, contracts, monitoring and exit. The EBA’s more recent work on third-party risk goes in the same direction and describes the lifecycle with risk assessment, due diligence, the contract phase, subcontractors, monitoring, exit strategies and termination processes.

1. Start by knowing which suppliers you have

Many organisations have more supplier dependencies than they first think. This is especially true once you count cloud services, SaaS solutions, consultants, operations partners, support agreements, integration suppliers and subcontractors.

A first step is therefore to create or quality-assure a supplier register.

The register should not just contain names and contract owners. It should also show:

  • which service the supplier delivers
  • which business process is affected
  • what information the supplier handles
  • whether personal data is processed
  • whether the service is business-critical
  • which systems or integrations are involved
  • whether subcontractors are used
  • who the internal owner is
  • when the next follow-up is due

Without that overview, the risk work easily becomes reactive.

2. Classify suppliers by criticality

Not all suppliers should be handled the same way. An office-supplies vendor does not pose the same risk as a cloud platform, a banking system, a medical records system or a security-critical operations partner.

Suppliers therefore need to be classified.

Common questions are:

  • Is the service critical or important to the business?
  • Could an outage affect customers, members, patients or an essential function?
  • Does the supplier have access to sensitive information?
  • Is the service hard to replace?
  • Is there concentration risk, for example dependence on a single cloud provider?
  • Are there subcontractors in the chain?
  • Is the delivery affected by regulatory requirements?

The classification determines how deep the review needs to be and how often the supplier should be followed up.

3. Do supplier reviews before deciding

A supplier review should be done before a new supplier is chosen or before an existing contract is renewed for a critical service.

The review should be adapted to the risk level. For a low-criticality supplier a simpler check may be enough. For a critical IT or information-handling supplier, a much more structured assessment is often needed.

A supplier review can cover:

  • information security and technical controls
  • data protection and processing of personal data
  • incident handling
  • continuity and recovery capability
  • financial stability
  • subcontractors
  • geographic location of data and support
  • certifications and audit reports
  • contract terms and the right to follow up
  • exit options and data return

The purpose is not to collect documents for their own sake. The purpose is to understand whether the supplier is suitable for the risk you are actually taking.

4. The risk analysis should link the supplier to the business

A common weakness in third-party management is that the risk analysis becomes too generic. The supplier is assessed in isolation, but not based on what it actually does for the organisation.

A good risk analysis links the supplier to the business process.

That means assessing:

  • what happens if the service goes down
  • which information is affected
  • which regulatory requirements apply to the service
  • which dependencies exist on other systems or suppliers
  • what recovery time is required
  • whether there are manual alternatives
  • which risk-reducing measures already exist
  • which risks need to be accepted, remediated or followed up

It is only when the risk analysis is linked to real business impact that it becomes useful for decisions.

5. The contract must support follow-up and control

A good supplier contract should not only govern price, support and termination. For critical suppliers, the contract also needs to support security, follow-up and compliance.

That can involve requirements for:

  • information security
  • incident reporting
  • continuity and recovery
  • subcontractors
  • logging and traceability
  • the right to audit or follow up
  • handling of personal data
  • geographic location of data
  • change management
  • exit and data return
  • cooperation during incidents and supervision

DORA particularly highlights ICT third-party risk, key contractual requirements and the oversight of critical ICT third-party providers in the financial sector.

6. Ongoing reviews are at least as important as onboarding

Many organisations do a good initial supplier review but lose the follow-up after the contract is signed.

That is risky.

Suppliers change. Services change. Subcontractors are replaced. Incidents occur. Certifications expire. The organisation’s own use of the service grows.

Third-party management therefore needs to be maintained over time.

For critical suppliers there should be a plan for ongoing follow-up, for example:

  • an annual or semi-annual supplier review
  • an updated risk analysis
  • a review of incidents and deviations
  • checking audit reports or certifications
  • follow-up of SLA and availability
  • checking subcontractors
  • follow-up of continuity and recovery capability
  • checking whether the contract still matches the usage

This is often where third-party management becomes real. Not in the checklist at procurement, but in the recurring follow-up.

7. Incident, continuity and exit must fit together

A critical supplier is not just a contractual relationship. It is often a dependency in the organisation’s own continuity capability.

Every critical supplier therefore needs to be linked to:

  • the incident process
  • continuity planning
  • recovery requirements
  • escalation paths
  • a communication plan
  • allocation of responsibilities
  • alternative ways of working
  • an exit strategy

The exit strategy is particularly important. It should not just state that the contract can be terminated. It should show how the organisation can switch supplier, bring the service in-house, recover its data or continue operations if the supplier can no longer deliver.

For financial actors this is a central part of both outsourcing governance and digital operational resilience.

8. Third-party management requires ownership

Another common challenge is that responsibility falls between functions.

Procurement owns the contract. IT owns the technology. Legal reviews the terms. Information security does the risk assessment. The business owns the process. Data protection is responsible for personal-data matters.

Everyone is involved, but no one owns the whole.

Third-party management therefore needs a clear governance model:

  • who owns the supplier
  • who owns the risk
  • who approves new suppliers
  • who follows up critical suppliers
  • who handles deviations
  • who reports to management
  • who decides on risk acceptance

Without clear ownership, third-party risk easily becomes a paperwork exercise.

How Kristensson i Skåne can help

Kristensson i Skåne helps organisations build, improve and maintain third-party management based on requirements from, among others, EBA, DORA, NIS2/the Swedish Cybersecurity Act, GDPR and ISO 27001.

We can support you as an advisory consultant in a defined project, for example with a current-state analysis, a gap analysis or the design of a new process. We can also deliver third-party management as a more ongoing service, where we help with recurring supplier reviews, risk analyses, follow-up and maintenance of the register and decision support.

The support can, for example, include:

  • a current-state analysis of existing third-party management
  • a gap analysis against EBA, DORA, NIS2, GDPR or ISO 27001
  • developing policy, process and work instructions
  • supplier classification
  • supplier review and due diligence
  • risk analysis and risk assessment
  • templates for supplier questions and decision support
  • support with contract requirements and security annexes
  • ongoing reviews and annual follow-up
  • reporting to management, a risk committee or a steering group
  • support during an incident, renegotiation or exit

The goal is for third-party management to become practically usable: clear decisions, clear responsibility and a follow-up that can actually be carried out.

From requirements to working supplier governance

The regulations point in the same direction: organisations need to understand their supplier dependencies, assess the risks, set the right requirements and follow up over time.

It does not have to start big. Often it is enough to start with the most critical suppliers, create a clear classification and introduce a recurring follow-up.

What matters is moving away from a static supplier list and instead building governance that shows:

  • which suppliers are important
  • what risks they pose
  • which requirements apply
  • what has been reviewed
  • what needs to be followed up
  • who is responsible

Then third-party management becomes not just a regulatory requirement. It becomes part of the organisation’s actual resilience.

Would you like to know whether your third-party management holds up to the requirements in EBA, NIS2 or DORA? Read more about our work with information security and governance or contact us and we will have a first conversation about your current state, risks and next steps.

This is an overview and not legal advice. Every organisation needs to assess its requirements based on its operations, sector, supplier dependencies and regulatory scope.