A running log of the dated regulator items that touch your third-party register — what each one did, and what it means for buyers. Free to read. No sign-up, no email required.
The one item that changes the most for the most people, still not published.
Consultation closed 8 October 2025. The final text was targeted for around April 2026 and remains unpublished as of 7 September 2026. It replaces the 2019 EBA Outsourcing Guidelines, introduces “third-party arrangements” in place of “outsourcing”, and widens scope beyond credit institutions and investment firms to payment and e-money institutions, ART issuers and mortgage creditors.
What it means for buyers. It mandates a register of non-ICT third-party arrangements — the direct sibling of the DORA Article 28 ICT register — on a comply-or-explain basis with roughly a two-year transition to amend contracts and populate it. Teams that have already built the ICT register discipline extend it; teams that have not will be doing both at once. Mapping your existing register structure to non-ICT arrangements is work that can be staged now rather than started on publication day.
Newest first. Each entry is what the regulator did, then the operational reading for anyone who owns a third-party register.
Simplified ESRS delegated act due. Under Omnibus I the Commission committed to adopting the revised ESRS within six months of the Amendment Directive entering into force. The amended standards cut datapoints by around 61%, and first reports under them cover FY2027. For buyers: CSRD scope has already narrowed by roughly 80%, taking most sub-1,000-employee firms out of mandatory reporting. If your supplier questionnaires still collect ESG datapoints on the old assumption, a large share of your suppliers no longer have to answer them.
Taxonomy disclosure simplification consultation closed. ESMA final technical advice is due end-October 2026. For buyers: disclosure-scope rather than third-party risk, so no register change. Worth tracking only if your sustainability team pulls supplier data through the same intake process you use for risk.
EU AI Act GPAI enforcement powers switched on. The AI Office can now request documentation, run evaluations, require measures and impose fines on providers of general-purpose AI models. Article 50 transparency obligations bind. For buyers: a three-question pass over your register — which suppliers embed generative AI in the service you buy, do you hold their Article 50 transparency documentation, and is that flagged anywhere a supervisor could find it. Most registers built before 2026 have no field for it.
Joint statement on ICT risk from frontier AI models (JC 2026 25). The three authorities call for a cross-sectoral, risk-based and consistent supervisory approach, anchored in DORA and the AI Act rather than a separate regime. For buyers: the clearest signal yet that AI-in-the-supply-chain will be examined through your existing DORA ICT third-party governance, not a parallel process. That is good news for anyone who has already done the Article 28 work.
Ninth MaRisk amendment published. The central outsourcing officer role becomes a central outsourcing management function. Sub-outsourcing reporting is tightened, anti-money-laundering becomes explicit in outsourcing decisions, and contingency planning is required where no viable exit exists. For buyers: a twelve-month grace period, and sub-outsourcing chain visibility is the hardest lift — most registers record the direct provider and stop there.
DORA critical ICT third-party provider oversight is live. The ESAs designated the first 19 critical ICT third-party providers on 18 November 2025, and Joint Examination Teams are working through the 2026 cycle with register-of-information quality in scope. For buyers: Article 28 registers are being inspected now, not in some future enforcement phase. The practical question is no longer whether you have one, but whether it survives someone reading it line by line.
Both supervisors put concentration and outsourcing risk near the top. The CBI’s 2026 supervisory priorities describe operational and outsourcing risk as a very high threat; BaFin’s 2026 Risks in Focus flags ICT concentration on non-EU hyperscalers. For buyers: concentration is now a quantified supervisory concern rather than a theoretical one — European Central Bank data has significant banks placing more than 30% of outsourcing spend with around ten providers. If your register cannot answer “how much of our critical estate sits with one provider”, that is the gap.
CSDDD transposition pushed to July 2028. Omnibus I moved the deadline out by two years, with Commission implementation guidance due July 2027. For buyers: due-diligence obligations that some programmes were resourcing for 2026 have moved. Worth checking that nobody is still building to the original date.
Practitioner observation, not legal advice. We link the primary source for every item so you can read it yourself and form your own view.
Procurement, compliance, and risk leaders at EU-regulated buyers. If you own the third-party register, or you own the answer to “walk us through how you decided this provider supports a critical or important function,” this is written for you.
If your role is regulator-facing at an EU financial institution, insurer, fund, payment firm, life sciences, critical-infrastructure, or NIS2-in-scope operator — this page is the short version of the reading you would otherwise do yourself.
No. There is no list, no email capture and no gate. The page is public and stays public. If you want to keep an eye on it, bookmark it.
Whenever something lands that touches third-party risk for EU-regulated buyers. We do not publish to a fixed calendar, because the regulatory week does not run to one — some weeks carry three items and some carry none. The date at the top of the page tells you when it was last touched, and every entry carries its own date.
A regulator brief. Every entry leads with what the regulator did and the operational reading for buyers. There is no “here is what FiorLab launched” section. The entries read the same whether you use FiorLab or a spreadsheet.
The FiorLab team, edited to a single voice. Editorial standards: no legal advice, no anonymous competitor swipes, no motive imputation to any regulator or vendor. Practitioner observation only, with the primary source linked so you can check us.
Tell us at hello@fiorlab.com and we will correct it. Regulatory timelines move, and a page like this is only worth reading if it is right.
Most of what is on this page ends up as a row in someone’s third-party register. We publish free templates for exactly that.
Or write to us at hello@fiorlab.com.