-
EBA Guidelines on Sound Management of Third-Party Risk for Non-ICT Services
18 September 2026The European Banking Authority (EBA) has published its final guidelines on the sound management of third-party risk relating to non-ICT services (EBA/GL/2026/09), replacing the EBA's 2019 Guidelines on outsourcing arrangements. The guidelines establish a comprehensive framework for the governance, risk assessment, and oversight of third-party service providers (TPSPs) supplying non-ICT services to in-scope financial services entities, with a particular focus on services supporting "critical or important functions" (which are as defined in the EU Digital Operational Resilience Act (DORA)). The guidelines aim to harmonise the management of third-party risk and the use of TPSPs in relation to non-ICT services to a level more consistent with ICT services under DORA.
The guidelines’ application date is yet to be confirmed, but they will apply to all third-party arrangements entered into, reviewed or amended by in-scope entities from that date. In-scope entities are expected to review and amend their existing third-party arrangements to ensure they comply. For services relating to “critical and important functions”, that review must be completed within a two-year transitional period (beginning on the date the guidelines apply). Entities that fail to meet that deadline must notify their competent authority and set out a remediation plan. For arrangements supporting non-critical or non-important functions, the review and amendment of documentation may be deferred until the next renewal of the relevant arrangement.
In-scope entities include credit institutions and investment firms subject to the EU Capital Requirements Directive (CRD), third-country branches of credit institutions as defined under CRD, payment institutions and e-money institutions, Class 1 minus investment firms, Class 2 investment firms (i.e., those that don’t qualify as small and non-interconnected under the EU Investment Firms Directive), asset-referenced token issuers under the EU Markets in Crypto-Assets Regulation (MiCAR) and financial institutions that qualify as creditors under the EU Mortgage Credit Directive. The guidelines should be read in conjunction with existing guidelines on internal governance which already apply to these entities, including the EBA’s Guidelines on internal governance under CRD (the final revised version of which is yet to be published).
Key requirements include:
- a board-approved strategy and written policy on third-party risk management;
- pre-contractual due diligence and risk assessment of prospective TPSPs;
- a detailed set of mandatory contractual provisions for TPSP agreements, with additional provisions required for services relating to critical and important functions;
- business continuity planning and documented exit strategies for critical or important functions;
- maintenance of a register of all third-party arrangements, which may be combined with the register required under DORA.
Blog
