In the Final Report, the EBA provides its response to feedback on its earlier consultation on the guidelines and sets out the final guidelines.
The guidelines are addressed to Member State competent authorities. They specify the internal governance arrangements, including sound risk management that institutions, investment firms that do not meet all the conditions to qualify as small and non-interconnected under Article 12(1) of the Investment Firms Regulation, payment institutions, electronic money institutions, issuers of asset-referenced tokens and creditors as defined in point (2) of Article 4 of the Mortgage Credit Directive which are financial institutions should implement when they rely on third-party service providers (TPSPs) to provide non-ICT services supporting functions with a particular focus on critical or important functions. The guidelines apply to non-ICT services provided by TPSPs, other than those within the scope of Chapter V of the Digital Operational Resilience Act.
The guidelines specify how the arrangements referred to in the previous paragraph should be reviewed and monitored by Member State competent authorities, in the context of Article 97 of the Capital Requirements Directive IV on supervisory review and evaluation process (SREP), Article 36 of the Investment Firms Directive, Article 9(3) of the Payment Services Directive 2, Article 5(5) of the Electronic Money Directive and Article 35(3) of the Markets in Crypto Assets Regulation thereby fulfilling the competent authorities’ duty to monitor the addressed entities’ continuous compliance with the conditions of their authorization.

