BCBS Third-Party Risk Principles: DORA and Outsourcing Rules
On 10 December 2025 the Basel Committee on Banking Supervision published its Principles for the sound management of third-party risk, a 22-page Guidelines publication setting out 12 principles for how banks and their supervisors handle the providers now sitting inside almost every banking process. For the banking sector it supersedes the 2005 Joint Forum paper on outsourcing in financial services, and it does so with a deliberate change of vocabulary. The unit of analysis is the third-party arrangement, a category the Committee draws wider than outsourcing on purpose.
The BCBS third-party risk principles set a common baseline for banks and supervisors. Their concrete effect in a jurisdiction depends on the applicable local legal and supervisory framework and on how the relevant authorities use the Basel guidance. The document is directed at large internationally active banks and their supervisors, is meant to be applied proportionately, and stays technology-agnostic so it does not date as tooling changes.
EU financial entities are already subject to binding DORA requirements for ICT third-party risk, while other third-party and outsourcing arrangements remain subject to the relevant sectoral and national frameworks. The Digital Operational Resilience Act (DORA) has governed ICT third-party risk since 17 January 2025, and the European Banking Authority is rewriting its 2019 outsourcing guidelines to cover the non-ICT providers DORA leaves out. Read together, the three texts are converging on the same idea, which is why the practitioner task is mapping rather than building from scratch.
Related reading: our guide to the DORA register of information.
The calendar behind the shift
The dates show a coordinated move across standard-setters and national regulators inside a single eighteen-month window.
- 9 July 2024: BCBS consults on the draft principles.
- 17 January 2025: DORA applies across EU financial entities.
- 1 January 2025: the UK critical third parties oversight regime rules take effect (applying once a designation order is in force).
- 8 July 2025: the EBA opens its consultation on third-party risk management for non-ICT services, closing 8 October 2025.
- 10 December 2025: BCBS publishes the final principles, superseding the 2005 Joint Forum outsourcing paper for banking.
None of these dates obliges a bank to send the Basel Committee anything. What they signal is the direction supervisory examinations are taking, and the reference points against which a third-party risk management framework will be assessed.
From outsourcing to third-party arrangements
The reframing is the part reporting and control teams should read first. The old concept, outsourcing, captured the case where a bank hands a provider an activity it would otherwise perform itself. The Committee’s definition of a third-party service provider (TPSP) arrangement is broader: a formal arrangement between a bank and a provider for one or more services, activities, functions, processes or tasks, which includes but is not limited to outsourcing.
That definition sweeps in arrangements that older outsourcing rules often missed, and it draws some deliberate boundaries. It includes services from an intragroup provider. It excludes financial-services transactions between a bank and its customers, employees or counterparties, such as taking deposits or providing financial market infrastructure services like clearing and settlement, while still capturing the services that support those transactions. It also excludes the arrangements a TPSP has with its own supply chain, because the bank has no direct relationship there. Those supply-chain providers are handled separately as nth parties.
Two more definitions carry weight for anyone tiering a provider inventory. A critical service is one whose failure or disruption could significantly impair a bank’s viability, its critical operations, or its ability to meet key legal and regulatory compliance obligations. A critical TPSP arrangement is one that materially supports or impacts a critical service. A key nth party is an nth party, including a subcontractor, that is essential to the ultimate delivery of a critical service. The vocabulary matters because the heightened expectations in the principles attach to these labels, so getting the classification wrong understates the controls a supervisor will expect.
A common misreading is that a broader definition means every vendor relationship now carries the full weight of the framework. Proportionality is embedded in all twelve principles, however, and controls are meant to scale with the risk and criticality of each arrangement. Proportionality is not an exemption, though, and the Committee is explicit that applying it does not release an arrangement from appropriate risk management.
The twelve principles, read across the life cycle
Principles 1 to 9 give banks guidance; Principles 10 to 12 speak to prudential supervisors. The nine bank principles are organised around the life cycle of an arrangement, with governance, risk management and strategy running through every stage. The stages are risk assessment, due diligence, contracting, onboarding and ongoing monitoring, and termination.
- Principle 1 puts ultimate responsibility for oversight of third-party risks on the board of directors, which approves the strategy and defines risk appetite and tolerance for disruption.
- Principle 2 requires the board to ensure senior management implements the third-party risk management framework, including reporting of provider performance and mitigating actions back to the board.
- Principle 3 calls for a full risk assessment before entering an arrangement and throughout its life.
- Principle 4 requires appropriate due diligence on a prospective provider before contracting.
- Principle 5 requires legally binding written contracts that describe the rights, obligations and expectations of all parties.
- Principle 6 asks banks to resource a smooth onboarding, including resolving issues found in due diligence.
- Principle 7 sets ongoing assessment and monitoring of performance, risk and criticality, with reporting to the board and senior management and a response to issues as they arise.
- Principle 8 expects business continuity management strong enough to keep the bank operating through a provider disruption.
- Principle 9 draws a distinction reporting teams should carry into their own documentation: exit plans for planned termination, and exit strategies for unplanned termination.
One operational detail anchors the framework and will feel familiar to any EU bank: the register. Principle 7 and the surrounding text expect banks to maintain complete, up-to-date registers of all TPSP arrangements and key nth parties, recording elements such as the criticality of the arrangement, the substitutability of the provider’s services, whether proprietary or confidential information is shared, the service location, and the legal entity identifier (LEI) where available. Registers are updated periodically or on a relevant change, and are used to map dependencies and to identify bank-level concentration risk. Supervisors can ask to see them.
The supervisory principles set expectations that go beyond any single bank. Principle 10 tells supervisors to assess third-party risk management as part of ongoing supervision. Principle 11 asks them to analyse available information to spot systemic risks, including concentration where one or several providers serve much of the banking sector. Principle 12 encourages coordination and dialogue across sectors and borders to monitor systemic risks from critical providers. That last principle is the hook for the direct-oversight regimes appearing at national level.
How the BCBS third-party risk principles sit alongside DORA
For an EU bank, the closest binding analogue is DORA, Regulation (EU) 2022/2554, which has applied since 17 January 2025. The overlap is real but the scope is narrower than the Basel text. DORA governs ICT third-party risk specifically, so a provider relationship that has nothing to do with information and communications technology falls outside it even though it can be a critical third-party arrangement under the BCBS principles.
Where the two texts meet, the mapping is close enough to reuse most of the plumbing. DORA’s register of information under Article 28 records all contractual arrangements for the use of ICT services, and supervisors can request it in full or in part. It performs a comparable inventory and dependency-mapping function, but DORA’s register is a specific statutory ICT register whereas the Basel Principles set broader, principles-based expectations for registers of TPSP arrangements and key nth parties. DORA’s Article 30 sets minimum contractual provisions for ICT-service arrangements. Article 30(2) applies minimum terms including service descriptions, service and data locations, incident assistance and termination rights; the additional access, inspection and audit rights and exit-strategy provisions in Article 30(3) apply to ICT services supporting critical or important functions. This broadly parallels Principle 5’s focus on legally binding contracts. Our explainer on the DORA register of information and supply-chain mapping covers the field-level detail that a Basel-aligned register would also need.
The concept alignment extends to criticality. DORA applies its own Article 3(22) definition of a ‘critical or important function’. Recital 70 states that this definition encompasses the BRRD Article 2(1)(35) concept of ‘critical functions’, so BRRD-critical functions are included but do not define the full DORA perimeter. The BCBS notion of a critical TPSP arrangement is closely aligned, though not drafted identically, so a bank that has already tiered its ICT estate for DORA has done much of the analysis the Basel principles ask for. Subcontracting maps too: DORA’s treatment of subcontractors that support critical or important functions is the ICT-specific version of the BCBS key nth party. Both frameworks also refuse to treat intragroup providers as automatically safer, a point worth checking against any policy that still waves intragroup arrangements through a lighter process.
The one place the texts diverge in tone is concentration. DORA deliberately avoids rigid caps on ICT exposures, favouring a flexible, gradual approach, and relies on its Oversight Framework for critical ICT third-party service providers, where a Lead Overseer from the EBA, ESMA or EIOPA can examine a designated provider directly. The Basel principles ask banks to monitor bank-level concentration and supervisors to watch systemic concentration, but they do not hand supervisors power over the provider itself. For the ICT incident and testing obligations that sit alongside all of this, our DORA ICT incident reporting guide sets out where the reporting lines actually run.
The non-ICT gap the EBA is closing
If DORA covers ICT and the Basel principles cover all third-party arrangements, the obvious question is what governs the non-ICT relationships in the EU. Until recently the answer was the EBA Guidelines on outsourcing arrangements (EBA/GL/2019/02), published on 4 March 2019 and applied from 30 September 2019 to credit institutions, investment firms, payment institutions and electronic money institutions. Those guidelines introduced the outsourcing register and the critical-or-important classification that many EU teams still run today.
On 8 July 2025 the EBA opened a consultation on draft Guidelines on third-party risk management with regard to non-ICT related services, which revise and update the 2019 outsourcing guidelines. The direction is the same reframing the Basel Committee has now confirmed, from outsourcing to the broader third-party arrangement, with the non-ICT side receiving treatment modelled on DORA. The EBA proposes aligning the register format with DORA’s register of information so a firm can hold consistent information for ICT and non-ICT services, potentially in a single register, and it envisages a two-year transitional period once the guidelines are final. The consultation closed on 8 October 2025.
For a reporting officer, the practical consequence is a consolidation project rather than a new form. The three registers a bank might run today, the EBA outsourcing register, the DORA register of information, and any home-grown vendor inventory, are being pushed toward a single, criticality-tiered view of every third-party arrangement and its key nth parties. The Basel principles provide a non-binding supervisory baseline. In the EU, DORA imposes binding ICT third-party-risk requirements, while EBA/GL/2019/02 remains relevant to outsourcing arrangements where applicable; the EBA’s proposed broader Guidelines for non-ICT third-party risk are not yet final.
National regimes and the move to oversee the provider
Paragraph 9 of the BCBS text notes that many jurisdictions have already developed their own third-party risk-management frameworks and standards, and the supervisory principles anticipate that reality rather than override it. Two features of the current landscape are worth naming because they change what a global bank has to reconcile.
The first is the arrival of direct oversight of the provider. The United Kingdom’s critical third parties regime, finalised by the Bank of England, PRA and FCA in November 2024 and effective from 1 January 2025 under powers in the Financial Services and Markets Act 2023, lets the regulators set minimum resilience standards for third parties that HM Treasury designates as critical to the financial sector. It sits parallel to, and does not replace, firm-level outsourcing expectations such as the PRA’s supervisory statement on outsourcing and third-party risk management (SS2/21). DORA’s Oversight Framework does the same job for designated critical ICT providers in the EU. The Basel principles do not grant this power, but Principle 12’s call for cross-border coordination is precisely about making these separate national and regional oversight regimes talk to each other.
The second is that the life-cycle model is now common currency. The United States interagency guidance on third-party relationships, finalised on 6 June 2023 by the Federal Reserve, FDIC and OCC, is built on the same stages the Basel principles use: planning, due diligence and selection, contract negotiation, ongoing monitoring, and termination. A bank operating across these jurisdictions is documenting one life cycle against several supervisory vocabularies, and the value of the Basel baseline is that it gives that documentation a common spine.
Turning the baseline into a work plan
The principles reward banks that already invested in DORA and outsourcing governance, and expose the gaps for those that treated third-party risk as a procurement afterthought. A few concrete moves follow directly from the text.
Start with classification, because everything downstream depends on it. Every arrangement needs a criticality decision against the Basel definition of a critical service, and every critical arrangement needs its key nth parties identified. The register fields the principles list, criticality, substitutability, contingent provider, information shared, service location, and LEI, are the columns to reconcile across the ICT and non-ICT registers now rather than after the EBA guidelines are final. My reading of the two-year transition the EBA has floated is that it is generous on paper and tight in practice, because register consolidation is slow work.
Then check the exits. Principle 9’s split between exit plans for planned termination and exit strategies for unplanned termination is a distinction that can be blurred into a single contractual clause. The principles expect the level of detail to scale with the criticality and substitutability of the service, and for unplanned exits to be based on plausible scenarios and reasonable assumptions, which means a tested playbook rather than a contractual right nobody has rehearsed. The same discipline applies to business continuity management, where the Basel text expects testing of the provider’s arrangements for critical services, an expectation the DORA resilience-testing rules already make concrete for ICT. For the wider Basel context on how supervisors read ICT dependency, our note on the BCBS range of practices for ICT risk management is a useful companion.
Frequently Asked Questions
Are the BCBS third-party risk principles binding on my bank?
Not directly. They are a common baseline addressed to large internationally active banks and their prudential supervisors, to be implemented through national frameworks. For an EU bank, DORA provides binding requirements for ICT third-party risk. Non-ICT outsourcing remains subject to applicable sectoral law, national supervisory requirements and the current EBA Guidelines on outsourcing arrangements (EBA/GL/2019/02) where applicable. As of 6 September 2026, the EBA’s proposed replacement Guidelines for non-ICT third-party risk have not been finalised; the consultation on them closed on 8 October 2025.
Does the document create a new register or return I have to submit to the Basel Committee?
No. The Basel Committee does not collect returns. The principles expect banks to maintain third-party registers and share them with their own supervisors on request. In the EU, the register that carries a legal obligation is the DORA register of information for ICT services.
How is a critical TPSP arrangement different from DORA’s critical or important function?
They are closely aligned in intent but not drafted identically. The Basel critical TPSP arrangement is one that materially supports or impacts a critical service, defined by impact on viability, critical operations or key compliance obligations. DORA’s trigger is an ICT service supporting a ‘critical or important function’ as defined independently in Article 3(22) of DORA. Recital 70 confirms that this definition encompasses functions classified as critical under Article 2(1)(35) BRRD. A bank should map, not assume, equivalence between the two labels.
Do the principles apply to intragroup providers?
Yes. The definition of a TPSP arrangement includes services provided by an intragroup provider, and the Committee is explicit that intragroup arrangements should not be treated as inherently less risky. Risk management is tailored to the group’s actual control and the criticality of the arrangement, not to the fact of common ownership.
Are cloud providers automatically critical third parties?
No. Criticality is assessed service by service under the principles, so a cloud relationship may or may not be a critical TPSP arrangement depending on what it supports. Separate designation regimes exist, such as the UK critical third parties regime and DORA’s Oversight Framework for critical ICT providers, but those designations are made by authorities and are distinct from a bank’s own criticality classification.
Do I have to map an entire supply chain of subcontractors?
The expectation is proportionate. Nth parties, including subcontractors, are managed where they matter, and the sharper obligation attaches to key nth parties that are essential to the delivery of a critical service. For those, banks are expected to cascade relevant contractual terms and secure information and incident rights.
My firm falls outside DORA’s scope for a given service. Does the Basel text still reach it?
The Basel principles are broader than DORA and cover non-ICT arrangements, but they bite through your supervisor rather than directly. In the EU, non-ICT arrangements remain subject to the applicable existing sectoral, national and outsourcing requirements. The EBA’s draft Guidelines would broaden and update the framework for non-ICT third-party arrangements if and when finalised; the consultation closed on 8 October 2025.
Related Articles
- DORA Register of Information: what the ICT third-party register must contain and how supervisors use it.
- DORA Supply Chain and the Register of Information: mapping nth parties and subcontractors into the ICT register.
- PRA SS2/21 Outsourcing and Notification Duties: the UK firm-level outsourcing and third-party expectations that sit under the critical third parties regime.
- DORA ICT Incident Reporting: how incidents at ICT providers flow into the EU reporting lines.
- DORA Resilience Testing for Smaller Firms: how the testing obligations scale with proportionality.
- BCBS Range of Practices for ICT Risk Management: the supervisory lens on bank dependency and operational risk.
Key Takeaways
- The BCBS published its third-party risk principles on 10 December 2025, with 12 principles that replace the 2005 Joint Forum outsourcing paper for banking.
- Principles 1 to 9 guide banks; Principles 10 to 12 set supervisory expectations, including systemic concentration monitoring and cross-border coordination.
- The scope shifts from outsourcing to the broader third-party arrangement, capturing intragroup providers and support services while excluding bank-customer transactions and FMI services.
- The principles are a supervisory baseline rather than a new Basel reporting return. In the EU, DORA supplies binding ICT third-party-risk requirements, while applicable existing outsourcing requirements remain relevant; the EBA’s proposed replacement Guidelines for non-ICT third-party risk are not yet final.
- DORA (applicable since 17 January 2025) covers only ICT third-party risk, so non-ICT critical arrangements fall to the EBA guidelines the EBA consulted on from 8 July 2025.
- Classify every arrangement against the critical-service test, identify key nth parties for critical arrangements, and reconcile register fields across ICT and non-ICT inventories.
- Separate exit plans for planned termination from exit strategies for unplanned termination, and scale the detail to criticality and substitutability.
- Direct oversight of the provider (UK critical third parties, DORA’s Oversight Framework) is a national and regional layer the Basel principles encourage supervisors to coordinate, not a power the principles themselves grant.
Sources and References
- Basel Committee on Banking Supervision, Principles for the sound management of third-party risk, December 2025: https://www.bis.org/bcbs/publ/d605.htm (PDF: https://www.bis.org/bcbs/publ/d605.pdf).
- BCBS press release, Basel Committee publishes principles for the sound management of third-party risk (10 December 2025): https://www.bis.org/press/p251210.htm.
- Regulation (EU) 2022/2554 (Digital Operational Resilience Act), EUR-Lex: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32022R2554.
- EBA Guidelines on outsourcing arrangements (EBA/GL/2019/02), applied 30 September 2019: https://www.eba.europa.eu/activities/single-rulebook/regulatory-activities/internal-governance/guidelines-outsourcing-arrangements.
- EBA press release, consultation on draft Guidelines on third-party risk management with regard to non-ICT related services (8 July 2025): https://www.eba.europa.eu/publications-and-media/press-releases/eba-launches-consultation-its-draft-guidelines-third-party-risk-management-regard-non-ict-related.
- FCA Policy Statement PS24/16, Operational resilience: Critical third parties to the UK financial sector (November 2024): https://www.fca.org.uk/publications/policy-statements/ps24-16-operational-resilience-critical-third-parties-uk-financial-sector.
- Interagency Guidance on Third-Party Relationships: Risk Management (Federal Reserve, FDIC, OCC), Federal Register, 9 June 2023: https://www.federalregister.gov/documents/2023/06/09/2023-12340/interagency-guidance-on-third-party-relationships-risk-management.
Where the baseline goes in 2026
The Basel principles set the destination, and the EU instruments are what get banks there. The next EU milestone is the EBA’s finalisation of its draft Guidelines on third-party risk management for non-ICT related services. As of 6 September 2026, the EBA has not yet published the final revision. The July 2025 proposal included a two-year transitional period for reviewing existing third-party arrangements and updating the non-ICT register, and sought consistency with the DORA register, including the possibility of using a single register. The work that pays off before then is unglamorous: reconcile the register fields, tag each arrangement’s critical and key nth parties, and separate the planned exits from the unplanned ones, so that when a supervisor next asks how the framework maps to the December 2025 baseline, the answer is already written down.
Disclaimer: The information on RegReportingDesk.com is for educational and informational purposes only. It does not constitute legal, regulatory, tax, or compliance advice. Always consult your compliance officer, legal counsel, or the relevant supervisory authority for guidance specific to your institution.
