The Regulator's Desk

What EU regulators moved.

A running log of the dated regulator items that touch your third-party register — what each one did, and what it means for buyers. Free to read. No sign-up, no email required.

Last updated 7 Sep 2026·Free to read·No sign-up

On the watchlist.

The one item that changes the most for the most people, still not published.

Awaiting publication

EBA guidelines on third-party risk management (non-ICT)

Consultation closed 8 October 2025. The final text was targeted for around April 2026 and remains unpublished as of 7 September 2026. It replaces the 2019 EBA Outsourcing Guidelines, introduces “third-party arrangements” in place of “outsourcing”, and widens scope beyond credit institutions and investment firms to payment and e-money institutions, ART issuers and mortgage creditors.

What it means for buyers. It mandates a register of non-ICT third-party arrangements — the direct sibling of the DORA Article 28 ICT register — on a comply-or-explain basis with roughly a two-year transition to amend contracts and populate it. Teams that have already built the ICT register discipline extend it; teams that have not will be doing both at once. Mapping your existing register structure to non-ICT arrangements is work that can be staged now rather than started on publication day.

EBA consultation announcement

Latest updates.

Newest first. Each entry is what the regulator did, then the operational reading for anyone who owns a third-party register.

The board
EXPECTED ~18 SEP 2026 · European Commission · EU

Simplified ESRS delegated act due. Under Omnibus I the Commission committed to adopting the revised ESRS within six months of the Amendment Directive entering into force. The amended standards cut datapoints by around 61%, and first reports under them cover FY2027. For buyers: CSRD scope has already narrowed by roughly 80%, taking most sub-1,000-employee firms out of mandatory reporting. If your supplier questionnaires still collect ESG datapoints on the old assumption, a large share of your suppliers no longer have to answer them.

Omnibus I / CSRD simplification background

12 AUG 2026 · ESMA · EU

Taxonomy disclosure simplification consultation closed. ESMA final technical advice is due end-October 2026. For buyers: disclosure-scope rather than third-party risk, so no register change. Worth tracking only if your sustainability team pulls supplier data through the same intake process you use for risk.

ESMA consultation

2 AUG 2026 · European Commission / AI Office · EU

EU AI Act GPAI enforcement powers switched on. The AI Office can now request documentation, run evaluations, require measures and impose fines on providers of general-purpose AI models. Article 50 transparency obligations bind. For buyers: a three-question pass over your register — which suppliers embed generative AI in the service you buy, do you hold their Article 50 transparency documentation, and is that flagged anywhere a supervisor could find it. Most registers built before 2026 have no field for it.

Chapter V enforcement summary

31 JUL 2026 · EBA, EIOPA and ESMA · EU

Joint statement on ICT risk from frontier AI models (JC 2026 25). The three authorities call for a cross-sectoral, risk-based and consistent supervisory approach, anchored in DORA and the AI Act rather than a separate regime. For buyers: the clearest signal yet that AI-in-the-supply-chain will be examined through your existing DORA ICT third-party governance, not a parallel process. That is good news for anyone who has already done the Article 28 work.

Joint statement (PDF)

30 JUN 2026 · BaFin · Germany

Ninth MaRisk amendment published. The central outsourcing officer role becomes a central outsourcing management function. Sub-outsourcing reporting is tightened, anti-money-laundering becomes explicit in outsourcing decisions, and contingency planning is required where no viable exit exists. For buyers: a twelve-month grace period, and sub-outsourcing chain visibility is the hardest lift — most registers record the direct provider and stop there.

2026 SUPERVISORY CYCLE · ESAs · EU

DORA critical ICT third-party provider oversight is live. The ESAs designated the first 19 critical ICT third-party providers on 18 November 2025, and Joint Examination Teams are working through the 2026 cycle with register-of-information quality in scope. For buyers: Article 28 registers are being inspected now, not in some future enforcement phase. The practical question is no longer whether you have one, but whether it survives someone reading it line by line.

ESA designation announcement

2026 PRIORITIES · Central Bank of Ireland and BaFin · IE / DE

Both supervisors put concentration and outsourcing risk near the top. The CBI’s 2026 supervisory priorities describe operational and outsourcing risk as a very high threat; BaFin’s 2026 Risks in Focus flags ICT concentration on non-EU hyperscalers. For buyers: concentration is now a quantified supervisory concern rather than a theoretical one — European Central Bank data has significant banks placing more than 30% of outsourcing spend with around ten providers. If your register cannot answer “how much of our critical estate sits with one provider”, that is the gap.

CBI 2026 priorities · BaFin Risks in Focus 2026

DEC 2025 · Omnibus I · EU

CSDDD transposition pushed to July 2028. Omnibus I moved the deadline out by two years, with Commission implementation guidance due July 2027. For buyers: due-diligence obligations that some programmes were resourcing for 2026 have moved. Worth checking that nobody is still building to the original date.

Omnibus I in the Official Journal

Practitioner observation, not legal advice. We link the primary source for every item so you can read it yourself and form your own view.

Who this is for.

Procurement, compliance, and risk leaders at EU-regulated buyers. If you own the third-party register, or you own the answer to “walk us through how you decided this provider supports a critical or important function,” this is written for you.

If your role is regulator-facing at an EU financial institution, insurer, fund, payment firm, life sciences, critical-infrastructure, or NIS2-in-scope operator — this page is the short version of the reading you would otherwise do yourself.

Common questions.

Do I need to sign up?

No. There is no list, no email capture and no gate. The page is public and stays public. If you want to keep an eye on it, bookmark it.

How often is this updated?

Whenever something lands that touches third-party risk for EU-regulated buyers. We do not publish to a fixed calendar, because the regulatory week does not run to one — some weeks carry three items and some carry none. The date at the top of the page tells you when it was last touched, and every entry carries its own date.

Is this a product page or a regulator brief?

A regulator brief. Every entry leads with what the regulator did and the operational reading for buyers. There is no “here is what FiorLab launched” section. The entries read the same whether you use FiorLab or a spreadsheet.

Who writes it?

The FiorLab team, edited to a single voice. Editorial standards: no legal advice, no anonymous competitor swipes, no motive imputation to any regulator or vendor. Practitioner observation only, with the primary source linked so you can check us.

Something here is wrong or out of date.

Tell us at hello@fiorlab.com and we will correct it. Regulatory timelines move, and a page like this is only worth reading if it is right.

Turn the reading into a register.

Most of what is on this page ends up as a row in someone’s third-party register. We publish free templates for exactly that.

Free tools and templates

Or write to us at hello@fiorlab.com.