NBU Strengthens Third-Party Risk Management Requirements Across the Financial Sector
As of 1 July 2026, new requirements introduced by the National Bank of Ukraine (NBU) on third-party risk management have entered into force. The changes, adopted through NBU Board Resolutions No. 70, No. 72 and No. 73, apply to banks, banking groups, payment service providers and insurance companies.
The new regulatory framework is designed to strengthen the operational resilience of Ukraine’s financial sector at a time when financial institutions increasingly rely on external service providers, technology partners, contractors, agents and other third parties to support critical business functions. The continuity of financial services, information security, cybersecurity and regulatory compliance increasingly depend on the reliability of these external partners.
Rather than regulating the activities of third-party providers themselves, the new requirements place greater responsibility on supervised financial institutions to manage the risks associated with outsourcing and external service delivery. Institutions are expected to assess the reliability of third parties before entering into contractual relationships, continuously monitor their performance and establish appropriate contingency measures should significant risks arise or critical services be disrupted. For insurance companies, the updated framework also introduces enhanced requirements for the outsourcing of important functions and for business continuity planning.
The regulatory changes reflect a broader evolution of financial supervision, where regulators are expanding their focus beyond the financial soundness of individual institutions to include the resilience of the wider ecosystem of critical service providers. The framework has been developed in line with international standards and European regulatory approaches, including the recommendations of the Basel Committee on Banking Supervision as well as EU frameworks governing payment services and the insurance sector.
For businesses, these developments signal a continued strengthening of expectations regarding corporate governance, operational resilience and risk management. While the immediate impact will fall on banks, payment institutions and insurers as they review their internal procedures and existing contractual arrangements, the changes will also be relevant for companies providing IT services, cybersecurity solutions, cloud infrastructure and other critical services to the financial sector. Demonstrating robust governance, operational reliability and effective risk management is likely to become an increasingly important factor in maintaining business relationships with regulated financial institutions.
Sources: Official communication of the National Bank of Ukraine; NBU Board Resolutions No. 70, No. 72 and No. 73 dated 30 June 2026
- Government and Business Develop New Support Mechanisms for Companies Following Russian Attacks
- Lobbying Reporting Campaign for the First Half of 2026 Completed
- The EU’s 21st Sanctions Package: From Expanding Restrictions to Strengthening Their Effectiveness
- GR Consulting UA Managing Partner Ihor Novosad Participated in the Anniversary ALDE Congress in Vienna
- Pulse Platform: Can Digital Feedback Become a Tool for Better Regulation?



