Newsfeed
October 8, 2026
On 18 September 2026, the European Banking Authority (“EBA”) published its final report on the Guidelines on the sound management of third-party risk regarding non-ICT services (the “Guidelines”). The report sets out the final Guidelines and provides further information on their interaction with, inter alia, the EBA Guidelines on outsourcing (the “Outsourcing Guidelines”) of 2019 and Regulation (EU) 2022/2554 (“DORA”).
The Outsourcing Guidelines established requirements governing outsourcing arrangements, including criteria for determining the criticality of outsourced functions. However, following the entry into force of several subsequent Union regulations and directives, the Outsourcing Guidelines required updating to reflect the evolving regulatory framework and to adopt a more holistic approach to the management of third-party risk.1
In this vein, the Guidelines only apply to the use of Third-Party Service Providers (“TPSPs”) that do not provide ICT services supporting critical or important functions (“CIFs”) under DORA. Conversely, where financial entities make use of ICT TPSPs, DORA shall continue to apply.
The scope of application of the Guidelines is broader than that under the Outsourcing Guidelines. It covers institutions subject to Directive 2013/36/EU (“CRD”); creditors as defined in point (2) of Article 4 of Directive 2014/17/EU (“MCD”) which are financial institutions; investment firms that do not meet all the conditions to qualify as small and non-interconnected under Article 12(1) of Regulation (EU) 2019/2033 (“IFR”); payment and electronic money institutions (collectively referred to as ‘payment institutions’ for the purposes of the Guidelines); and issuers of asset-referenced tokens subject to Regulation (EU) 2023/1114 (“MiCAR”).2,3
The date of application of the Guidelines has not yet been determined. The Guidelines nevertheless provide for transitional arrangements. In particular, firms within scope will be required to inform their competent authority where the review of third-party arrangements supporting CIFs has not been finalised within two years from the date of application of the Guidelines. For third-party arrangements that do not support CIFs, the review may be carried out upon renewal of the arrangement.4
The Guidelines clarify the relationship between the concept of a third-party arrangement and that of an outsourcing arrangement. In particular, outsourcing remains a distinct concept but is treated as a subset of third-party arrangements for the purposes of the Guidelines. Accordingly, outsourcing arrangements are still in scope of the Guidelines. An important consideration is that the Guidelines repeal the Outsourcing Guidelines.5 However, the date on which such repeal will take effect has not yet been specified.
The Guidelines require financial entities to determine whether their arrangements with TPSPs fall within the definition of a third-party arrangement for the purposes of the Guidelines. In making this determination, financial entities should consider, among other things, whether: (i) the services provided are non-ICT services; (ii) the services are provided on a recurrent or ongoing basis; and (iii) the function supported by the services constitutes a CIF.6 The Guidelines also identify a number of arrangements that fall outside their scope, including, but not limited to, services that are legally required to be performed by a TPSP, regulated financial services, payment network infrastructures and correspondent banking services, amongst others.7
Importantly, the assessment should focus not only on the nature of the service being provided, but also on the function that the service supports. In this context, the Guidelines provide criteria for determining whether a function is to be considered a CIF. A function should be considered a CIF where its disruption could materially impair: (a) the financial entity’s continuing compliance with the conditions and obligations of its authorisation, or with its other obligations under applicable financial services law; (b) its financial performance; or (c) the soundness or continuity of its services and activities.8 Accordingly, the Guidelines impose more stringent requirements on third-party arrangements supporting CIFs than on those that do not.
The requirements set out in the Guidelines are broadly aligned with those under the Outsourcing Guidelines and DORA. Consistent with both frameworks, the Guidelines require financial entities to maintain a sound risk management and governance framework in relation to their use of TPSPs.
Among other requirements, financial entities are expected to adopt a policy governing the use of non-ICT services supporting CIFs provided by TPSPs.9 They must also establish business continuity arrangements10 designed to ensure the continuity of functions supported by TPSPs in the event of disruption. The Guidelines further require financial entities to implement a structured process governing the full lifecycle of third-party arrangements.11 This encompasses the pre-contractual phase, including the assessment and classification of risks and due diligence, as well as the ongoing monitoring of the arrangement throughout its lifecycle. The contractual phase is also subject to specific requirements, including contractual elements that should be incorporated into relevant third-party arrangements.12 In addition, the Guidelines establish requirements relating to subcontracting and the management of associated risks.13
The Guidelines mandate that financial entities should maintain an up-to-date Register of Information (“RoI”) covering all third-party arrangements within scope.14 The Guidelines clarify that the RoI should be aligned with the register required under DORA in respect of arrangements with ICT TPSPs to avoid discrepancies.15 Financial entities may also combine the RoI provided by the Guidelines with the DORA RoI. The RoI should be made available to the competent authority upon request.16
Financial entities are also required to inform their competent authorities in a timely manner of any planned contractual arrangements with TPSPs supporting CIFs.17 Additionally, they should inform competent authorities when developments pertaining to such arrangements may have a material impact on the provision of the financial entities’ business activities.18 Competent authorities may also require financial entities to provide information on any arrangement, whether supporting a CIF or not.19
In summary, while the requirements set out in the Guidelines are broadly aligned with existing outsourcing and DORA requirements, the scope of application is broader, given the expanded concept of third-party arrangements. As a result, financial entities need to ensure that arrangements are appropriately identified and assessed. Against this backdrop, financial entities should begin their preparatory efforts proactively by, among other things, identifying and mapping their CIFs and the TPSPs supporting those functions. They should also review their existing arrangements, contracts and policies to assess and address any gaps against the requirements of the Guidelines.
1Guidelines, p.55
2Guidelines, para.9
3Certain exclusions to the scope apply. Financial entities are encouraged to review the Guidelines to assess whether they fall within its scope.
4Guidelines, para.21
5Guidelines, para.22
6Guidelines, para.31
7Guidelines, para.33
8Guidelines, para.34
9Guidelines, para.47
10Guidelines, section 8 – business continuity plans
11Guidelines, title IV – third-party arrangement process
12Guidelines, section 12 – contractual Phase
13Guidelines, section 12.1 – subcontracting of critical or important functions
14Guidelines, section 10 – documentation requirements
15Guidelines, para.61
16Ibid supra.
17Guidelines, para.65
18Guidelines, para.66
19Guidelines, para.121