EBA Third-Party Risk Guidelines: Non-ICT Scope and the Two-Year Clock

On 18 September 2026 the European Banking Authority published EBA/GL/2026/09, its final guidelines on the sound management of third-party risk relating to non-ICT services. The EBA third-party risk guidelines widen the governed perimeter beyond outsourcing, which remains a subset, to non-ICT third-party arrangements within the Guidelines’ defined scope, with particular focus on arrangements supporting critical or important functions. Once applicable, the new guidelines will repeal the 2019 outsourcing guidelines (EBA/GL/2019/02); until then, the 2019 guidelines remain applicable. The new framework is designed to align non-ICT third-party risk management with DORA.

For a reporting or compliance team the practical consequence is a mapping and documentation exercise, not a new supervisory return. Once the guidelines apply, in-scope firms get a two-year window to reassess which third-party arrangements support a critical or important function, to build or extend a register of those arrangements that lines up with the register already kept under DORA, and to re-paper the contracts that carry critical services. Miss the window on a critical arrangement and the guidelines require the firm to tell its competent authority why, and what it plans to do about it.

DORA governs third-party risk for ICT services within its scope. The EBA guidelines address non-ICT third-party arrangements within their defined scope, with particular focus on services supporting critical or important functions.

Related reading: the BCBS principles for the sound management of third-party risk

The calendar: one date is fixed, one is not

  • 18 September 2026: the EBA published the final guidelines, EBA/GL/2026/09.
  • 8 October 2025: the three-month public consultation on the draft closed, drawing 72 responses that shaped the final text.
  • Date of application: not yet fixed. The guidelines are final but awaiting translation into all EU official languages.
  • Two years after the date of application: the point by which the review and documentation of arrangements supporting critical or important functions should be complete.
  • Compliance-notification deadline: not yet populated on the EBA final-report page. Article 16(3) of Regulation (EU) No 1093/2010 requires each competent authority, within two months of issuance of a guideline, to confirm whether it complies or intends to comply, or otherwise state its reasons.
  • The date of application: the same day the 2019 outsourcing guidelines are repealed.

The clock has not started. The two-year period must be counted from the EBA’s stated date of application, not from the 18 September 2026 publication date and not automatically from the publication of translations. As of 19 September 2026, the EBA lists the final report as not yet applicable and leaves the application date blank. Firms can prepare against the final English text while awaiting that date.

What the EBA third-party risk guidelines actually cover

The guidelines rest on Article 74 of the Capital Requirements Directive (Directive 2013/36/EU), which requires institutions to run sound governance arrangements and to identify, manage, monitor and report all their risks. Article 74(3) gives the EBA its mandate to write guidelines in this area. The EBA also took account of Article 11 of PSD2 (Directive (EU) 2015/2366), Article 26 of the Investment Firms Directive (Directive (EU) 2019/2034), Article 16 of MiFID II (Directive 2014/65/EU), Article 34 of the Markets in Crypto-Assets Regulation (Regulation (EU) 2023/1114) and Article 16 of its own founding regulation. Third-party risk, in the EBA’s framing, is one specific element of the governance arrangements those instruments already demand.

The scope definition is where the reform is easiest to misread. These guidelines exclude ICT services provided by third parties, because those already sit inside DORA (Regulation (EU) 2022/2554). A cloud hosting contract, a software-as-a-service platform, a managed security service: these stay under DORA and its subcontracting standards, and our DORA operational resilience coverage tracks that side of the wall. What the new guidelines add is the non-ICT half of the picture, so that a financial entity can manage third-party risk across both service types under one governance framework rather than two disconnected ones.

Within that non-ICT space, the guidelines cover the whole life cycle of an arrangement: the pre-contractual risk assessment and due diligence, the contract itself, subcontracting, ongoing monitoring, documentation, and exit. The EBA keeps the 2019 definition of outsourcing and treats it as a subset of the broader category of third-party arrangements, so a service that used to be logged as outsourcing remains in scope, alongside services that were never captured before.

Who is in scope, and who is newly caught

The addressee list is broader than the outsourcing guidelines it replaces, and the additions are the part worth checking against your own entity type. The guidelines apply to credit institutions and to investment firms under the CRD, to third-country branches, to payment institutions and electronic money institutions, and now also to investment firms under the Investment Firms Directive, to issuers of asset-referenced tokens under MiCAR, and to certain mortgage-credit creditors under Directive 2014/17/EU that are financial institutions. Financial holding companies and mixed financial holding companies approved under Article 21a(1) of the CRD are addressed too.

Three carve-outs decide most of the borderline cases. Small and non-interconnected investment firms, the Class 3 firms defined in Article 12(1) of Regulation (EU) 2019/2033, fall outside, because the IFD governance article that anchors the guidelines does not apply to them. Account information service providers that only provide the service in point 8 of Annex I of PSD2 are excluded, consistent with Article 33 of that directive. Central securities depositories are out, because the CSDR framework governs their critical service providers separately.

UCITS management companies and alternative investment fund managers fall outside the direct addressee list. The guidelines reach them indirectly: under Article 109(2) of the CRD, they apply on a consolidated and sub-consolidated basis, which brings fund-management subsidiaries of a banking or investment-firm group within the same exercise. A group compliance function that excludes those entities on the ground that they are not directly named is applying the guidelines incorrectly.

The critical-or-important-function test

Everything stricter in these guidelines keys off one classification: whether a non-ICT service supports a critical or important function. The EBA defines that function as one whose disruption would materially impair a firm’s financial performance, or the soundness or continuity of its services and activities, or whose failure would materially impair the firm’s continuing compliance with the conditions of its authorisation. That wording is deliberately the same as the definition in Article 3(22) of DORA, so a firm should not run two different criticality tests for its ICT and non-ICT suppliers.

Two distinctions in the definition are easy to get wrong. First, a third-party provider supports a critical or important function; it does not establish one. The function belongs to the firm, and it is the firm, not the provider, that must judge criticality. Second, this definition differs from the definition of a critical function in Article 2(1), point (35) of the Bank Recovery and Resolution Directive, although the EBA notes that the guidelines’ definition encompasses those BRRD critical functions. Reusing a resolution-planning classification wholesale would under-count.

The classification then drives a two-tier regime. Arrangements supporting critical or important functions attract the full weight of the guidelines: stricter contract content, subcontracting controls, audit rights and exit planning. Other non-ICT arrangements are still managed, but on a risk-based footing proportionate to the firm. One helpful clarification from the consultation feedback is that paragraph 33 of the guidelines allows non-ICT services with an immaterial risk impact to be excluded from scope. That kind of edge case is exactly where the ICT and non-ICT boundary earns its keep.

The register of information: align it with DORA, do not duplicate it

For a reporting desk this is the operational heart of the guidelines. Firms must keep an updated register of information covering all in-scope third-party arrangements, held at individual level and, where relevant, at sub-consolidated and consolidated level, and distinguishing arrangements that support critical or important functions from the rest. There is no periodic submission built in; the firm makes the register, or specified sections of it, available to its competent authority on request.

The design instruction that saves duplicated effort is explicit. The register for non-ICT services should be consistent, so far as possible, with the register of information already required under Article 28(3) of DORA, and the EBA encourages firms to avoid discrepancies between the two. Firms may keep a single combined register. So the answer to “do we now run two registers” is that you should not want to. The cleaner build extends the DORA register schema to carry the non-ICT population, with a flag that separates the two service types.

The minimum fields for every arrangement include a reference number and the type of contractual arrangement (standalone, overarching, or subsequent or associated), start and renewal and end dates, a description of the function, whether the service supports a critical or important function and why, the provider’s name and identifier (LEI, EUID or an alternative), its registered address and ultimate parent, and the country where the critical or important function is performed. Arrangements that do support a critical or important function carry a heavier field set on top: the governing law, the dates of the most recent audits, the subcontractors underpinning material parts of the function, a substitutability assessment graded from easy to impossible, the recovery time and recovery point objectives, whether an exit plan exists, identified alternative providers, and the estimated annual budget cost with its currency. Groups and members of an institutional protection scheme may keep the register centrally at the highest level of consolidation.

Contracts, subcontracting and exit strategies

The contractual chapter is the slow, expensive part, and it is where the two-year clock bites, because renegotiating live agreements takes longer than updating a spreadsheet. For arrangements supporting critical or important functions, the written agreement has to specify quantitative or qualitative service levels, notice periods and reporting obligations, business contingency requirements, monitoring and audit rights, and an exit strategy with a mandatory transition period long enough for the firm to move to another provider or bring the service back in-house. The EBA aligned this content with Article 30(2) and (3) of DORA, so firms that built DORA-compliant ICT clauses have a template to reuse. For institutions under the CRD, the contract also has to reference the resolution authority’s powers, including Articles 68 and 71 of the BRRD.

Subcontracting is governed by materiality rather than by counting every link in the chain. The contract must state whether subcontracting of a critical or important function, or a material part of it, is permitted and on what conditions, and the firm has to focus on the subcontractors that effectively underpin the service, borrowing DORA’s own language. The provider must notify the firm of new subcontracting or material changes in good time, the firm gets a reasonable notice period to approve or object, and the guidelines set out termination triggers where a provider subcontracts a critical service without approval or against an objection. A point the EBA is firm on: using subcontractors never reduces the management body’s ultimate responsibility to manage the risk and meet the firm’s obligations.

Access and audit rights follow the same two-tier logic. For critical or important functions, the firm and its competent and resolution authorities need access to premises, the right to take copies, and unrestricted inspection and audit rights, and the firm cannot lean solely on the provider’s certifications or pooled audit reports to discharge those duties. For services that are not critical, the firm decides on a risk-based view whether to include access and audit rights, keeping in mind that a service can become critical over time. The broader shift in supervisory thinking on outsourced and third-party dependencies runs through parallel work such as the CPMI-IOSCO consultation on third-party risk at financial market infrastructures.

Proportionality, the management body and third-country providers

Proportionality scales the rules to a firm’s risk profile, nature, business model, and the complexity of its activities. The EBA points firms to the proportionality criteria in its internal governance guidelines rather than inventing a new test, which keeps this consistent with the wider governance reforms tracked in our CRD VI transposition coverage. Groups can centralise the governance arrangements and the register, provided each entity’s management body keeps its own responsibility for the arrangements it uses.

That responsibility has a hard edge the EBA states plainly: a firm’s use of third-party providers must not turn it into an empty shell that lacks the substance to remain authorised. The management body has to ensure adequate resources to oversee the risks, and the internal audit function has to be able to review outsourced and third-party services on a risk-based approach. The provision reflects a decade of supervisory concern that heavy reliance on providers can hollow out a licensed entity.

For providers located outside the EU, the guidelines expect firms to make sure that EU legal and regulatory requirements, from professional secrecy to access to information and data protection under Regulation (EU) 2016/679, are met, and that the competent authority can still supervise the firm effectively. The guidelines also sit alongside a growing body of international standards on the same theme, including the FSB toolkit of December 2023, the Basel Committee’s principles of December 2025, and ESMA’s Principles on third-party risks supervision of 12 June 2025, which provide a common supervisory basis to national competent authorities and ESMA.

Frequently Asked Questions

Do these guidelines replace DORA for our cloud and software contracts?

No. ICT services provided by third parties remain governed by DORA (Regulation (EU) 2022/2554), and the EBA has excluded them from these guidelines. The new guidelines apply to non-ICT services. The intent is that a firm manages both under one joined-up governance framework, using the same criticality test on each side.

We already maintain a DORA register of information. Do we now need a second, separate register?

The guidelines are written to avoid that. The register for non-ICT services should be consistent, so far as possible, with the register under Article 28(3) of DORA, and firms are allowed to keep both in one combined register. The practical build is to extend the existing DORA register to carry the non-ICT population with a field that distinguishes the two service types.

Does the two-year transitional period apply to every third-party arrangement?

No. The two-year window is aimed at arrangements supporting critical or important functions, which must be reviewed and documented within that period. For arrangements that do not support a critical or important function, the guidelines allow the review and documentation to be done at the point the arrangement is next renewed.

What happens if we cannot finish reviewing a critical arrangement within two years?

The guidelines require the firm to inform its competent authority of that fact, including the measures planned to complete the review or the possible exit strategy. The EBA built in this supervisory dialogue precisely because renegotiating multiple live contracts in parallel is not always achievable inside the window.

Is a market data feed such as Bloomberg or a rating agency service in scope as a non-ICT arrangement?

Following consultation feedback, paragraph 33 of the guidelines was clarified to allow non-ICT services with an immaterial risk impact to be excluded from scope. This is one of the clearer boundary calls between the ICT and non-ICT regimes.

Are UCITS management companies and AIFMs directly subject to these guidelines?

UCITS management companies and AIFMs fall outside the direct addressee list. Where one is a subsidiary within a banking or investment-firm group, the guidelines reach it through consolidated and sub-consolidated application under Article 109(2) of the CRD; group-level exercises should not carve it out automatically.

Do the detailed contractual clauses apply to arrangements that are not critical?

The heavy contractual content, subcontracting controls and mandatory exit strategy attach to arrangements supporting critical or important functions. For other arrangements, the firm applies access and audit provisions on a risk-based basis, factoring in that a service can become critical or important over time.

Key Takeaways

  • EBA/GL/2026/09 was published on 18 September 2026 and will repeal the 2019 outsourcing guidelines (EBA/GL/2019/02) with effect from its date of application.
  • The date of application is not yet set; the guidelines are awaiting translation, so the two-year clock and the repeal have not started running.
  • Scope extends beyond outsourcing to non-ICT third-party arrangements within the Guidelines’ defined perimeter; ICT services within DORA’s scope remain under DORA, and outsourcing remains a subset of the wider category.
  • Newly caught addressees include Class 1 minus and Class 2 investment firms, ART issuers under MiCAR, and mortgage-credit creditors that are financial institutions; Class 3 firms, PSD2 AISPs and CSDs are out.
  • Build the register of information to align with the DORA Article 28(3) register; a single combined register is permitted, with heavier fields for critical or important functions.
  • Critical-or-important arrangements must be reviewed and documented within two years of the date of application; where that slips, notify the competent authority with a plan or exit strategy.
  • Contracts for critical functions need aligned DORA-style clauses, subcontracting controls focused on providers that effectively underpin the service, audit rights and a mandatory exit transition period.
  • National competent authorities must confirm comply-or-explain to the EBA within two months of the guidelines being issued in all EU languages.

Sources and References

  • European Banking Authority, press release: The EBA publishes its final Guidelines on the management of third-party risk, delivering a more proportionate and consistent framework aligned with DORA (18 September 2026) – eba.europa.eu
  • EBA, Final report on Guidelines on the sound management of third-party risk relating to non-ICT services, EBA/GL/2026/09 (18 September 2026) – Final report (PDF)
  • EBA, Guidelines on outsourcing arrangements (EBA/GL/2019/02, being repealed) – eba.europa.eu
  • Directive 2013/36/EU (Capital Requirements Directive) – EUR-Lex
  • Regulation (EU) 2022/2554 (Digital Operational Resilience Act) – EUR-Lex
  • Commission Delegated Regulation (EU) 2025/532 (DORA subcontracting of ICT services supporting critical or important functions) – EUR-Lex
  • Basel Committee on Banking Supervision, Principles for the sound management of third-party risk (December 2025) – bis.org

What to put on the roadmap before the translations land

The useful work does not wait for the date of application. Against the final English text, a firm can already reconcile its DORA register with its outsourcing register, run the criticality test across its non-ICT providers, and flag which critical contracts will need re-papering and how long each renegotiation realistically takes. When the translated Guidelines are published, the two-month comply-or-explain period will start; firms should use the application date published by the EBA to determine the implementation timetable. The first artifact to produce is a single register that ties ICT and non-ICT arrangements to the same criticality flag, and the first decision to make is which critical contracts cannot be fixed inside two years, because those are the conversations the guidelines say to open with the supervisor.

Disclaimer: The information on RegReportingDesk.com is for educational and informational purposes only. It does not constitute legal, regulatory, tax, or compliance advice. Always consult your compliance officer, legal counsel, or the relevant supervisory authority for guidance specific to your institution.

Similar Posts