Third-party risk is no longer just a contract-management problem with better wording.
DORA has changed the tempo. The EBA's 18 March 2026 joint guidelines set out procedures and conditions for cooperation between the ESAs and competent authorities on oversight follow-up for critical ICT third-party service providers.
The EBA's operational resilience page also highlights a 14 January 2026 memorandum of understanding covering DORA oversight of critical ICT third-party providers in the EU and UK.
This is structured supervision, not casual coordination.
The implication for firms is simple enough. Registers, dependency mapping, evidence collection, remediation tracking and escalation paths all need to work as living processes.
Many still do not.
They rely on fragmented repositories, manual outreach and heroic follow-up when audits or incidents force the issue. (eiopa.europa.eu)
That is why this theme is so relevant for Tungsten.
The value is NOT in saying third-party risk matters. Everyone knows that already.
The value IS in making the supporting workflow visible and manageable: who has provided what, where the gaps are, what has changed, and how quickly the enterprise or team can answer with confidence when asked.
And that is much closer to the real pain.