EBA Guidelines on Third-Party Risk 2026: What Financial Entities Now Need to Know about Non-ICT Service Providers
24 September 2026

What the EBA published on 18 September 2026
With the Final Report EBA/GL/2026/09, “Guidelines on the sound management of third-party risk regarding non-ICT services”, the European Banking Authority replaces its Outsourcing Guidelines of 25 February 2019 (EBA/GL/2019/02). The report runs to 98 pages: 128 paragraphs of guideline text, a cost-benefit analysis and the feedback statement on consultation EBA/CP/2025/12, which ran from 8 July to 8 October 2025 and attracted 72 responses. The core message is that third-party risk arising from non-ICT services will in future be managed along the same lines as ICT third-party risk under DORA — with a DORA-consistent definition of the critical or important function, a register modelled on the DORA register of information, and a complete lifecycle stretching from pre-contractual analysis to a tested exit strategy.
From outsourcing to third-party arrangement: the real regime change
The most important difference from 2019 lies in a single term. An outsourcing arrangement concerned a function the institution would otherwise have performed itself. The new third-party arrangement drops that criterion: it captures any agreement under which a third-party service provider supports a function on a recurring or ongoing basis — outsourcing is now merely a subset (para. 17). Services that never appeared in an outsourcing register are thereby brought within scope. The population of addressees has grown at the same time: beyond credit institutions and CRD investment firms, the guidelines apply to third-country branches, MiFID II investment firms (other than small and non-interconnected ones), payment and e-money institutions, issuers of asset-referenced tokens under MiCAR, MCD creditors that are financial institutions, and approved financial holding companies (para. 9). What falls outside is governed by the exclusion list in para. 33 — from statutory audit through payment networks and SWIFT to cleaning, catering and utilities.
The boundary with DORA — and the demand for a holistic approach
ICT services within the meaning of Art. 3(21) DORA remain excluded; they are governed by Chapter V of that Regulation (para. 7). In hybrid cases — non-ICT services with an ICT component — the financial entity itself decides whether the ICT component is material to the provision of the service; if so, DORA applies (para. 32). The EBA expressly expects a holistic approach spanning both worlds and permits three points of convergence: the oversight role may be combined with the DORA role under Art. 5(3) (fn. 46), the policy may be merged with the ICT policy under Art. 28(10) DORA provided it keeps four distinctions visible (para. 49), and the register may be consolidated with the DORA register of information into a single register (para. 61). Anyone who has implemented DORA in earnest therefore already holds most of the framework.
The register: 9 core fields, 8 additional fields, one data model
At the heart of the documentation requirements is a register of all non-ICT arrangements that distinguishes critical or important functions from the rest (para. 58). Nine core fields apply to every arrangement (para. 61): reference number and contract type, term dates, the entities using the service, any group or IPS context, a description of the function, criticality with reasoning, internal category, the service provider with identifier and parent company, and the country where the service is performed. For critical or important functions, eight additional fields follow (para. 62): governing law, date of the most recent audits, subcontractors of material parts with their rank in the chain, substitutability from “easy” to “impossible”, a reintegration assessment with RTO and RPO, exit plan yes/no, alternative service providers and the annual cost. On request, the competent authority receives the register in a processable electronic format — the format of the DORA Implementing Regulation (EU) 2024/2956 is expressly permitted (para. 63).
Contract, subcontracting and audit rights in brief
Every arrangement requires a written contract with ten minimum elements (para. 84 a–j); critical or important functions require six more (para. 85 a–f) — among them quantitative service levels, notification and reporting obligations, mandatory insurance, tested contingency plans, unrestricted access and audit rights, and an exit strategy with a binding transition phase. Where material parts are subcontracted, a notification-and-objection mechanism applies: the service provider gives timely notice of new or amended subcontracts, the institution assesses the impact and may object within the deadline, and the contract must allow the subcontract to be terminated if the provider proceeds regardless (para. 90–95). Third-party certificates and audit reports may be used — but for critical functions never permanently as the sole basis, and only under eight conditions ranging from an appropriate audit scope to a contractual right to conduct one’s own audits (para. 102–104).
Timelines: the date of application is still open — but the work starts now
In the Final Report the date of application is still a placeholder; it will be fixed once the translations into all official EU languages are published. From that day the guidelines apply to every arrangement that is newly concluded, reviewed or amended, and existing contracts must be brought into line (para. 18–19). Arrangements covering critical or important functions benefit from a two-year transitional period — anyone not finished by then must inform the competent authority of the measures planned or of a possible exit strategy (para. 20). Non-critical arrangements can be updated when the contract comes up for renewal (para. 21). Supervisors review third-party risk at least as part of the SREP (para. 119) and may go as far as forcing an exit from an arrangement (para. 126). Our recommendation: an inventory of all recurring non-ICT contracts, a three-stage test with documented criticality, and a reconciliation against the register fields — that is the first 90 days, and it costs effort rather than budget.
Perspective for the DACH region: MaRisk AT 9 already draws the line
In Germany, BaFin implements the 2019 Outsourcing Guidelines through module AT 9 of the MaRisk. The ninth MaRisk amendment (Circular 06/2026 (BA) of 30 June 2026) already expressly carves ICT services within the meaning of Art. 3(21) DORA out of AT 9 — the same boundary the EBA guidelines draw. The MaRisk, however, still recognise the “other external procurement of services” (sonstiger Fremdbezug von Leistungen) that does not amount to outsourcing, whereas the EBA captures every recurring non-ICT arrangement; that is precisely where the adjustment lies. EBA/GL/2026/09 is not yet reflected in the MaRisk, and as at 23 September 2026 our research found no BaFin statement on its application. In Austria, the FMA applies EBA guidelines directly; Switzerland sits outside the EU framework and regulates outsourcing through FINMA Circulars 2018/3 and 2023/1.
New on vamisec.com: knowledge page with three tools and a CISO whitepaper
We have worked through the complete Final Report and built a knowledge page that is more than a summary: 14 chapters citing every relevant paragraph, a Scope Navigator that leads to the applicable regime in five yes/no questions, a Register Builder with all 17 fields to tick off and a CSV export of the header row, and a Readiness Radar that measures maturity across five dimensions and names the biggest gaps with the relevant paragraph. The 30-page whitepaper “Third-Party Risk für CISOs” (German-language whitepaper) can be requested directly on the page — covering the integration architecture with DORA, a clause library, the register as a data model and a 24-month programme including a 90-day playbook. The page is available in English as well as German, French and Spanish, and is linked from our DORA knowledge page.
All links
Knowledge page with Scope Navigator, Register Builder and Readiness Radar: https://vamisec.com/en/wissen/grc/eba-third-party-risk-management · Request the whitepaper “Third-Party Risk für CISOs”: https://vamisec.com/en/wissen/grc/eba-third-party-risk-management#whitepaper · DORA knowledge page: https://vamisec.com/en/wissen/grc/dora · EBA Final Report EBA/GL/2026/09 (PDF): https://www.eba.europa.eu/sites/default/files/2026-09/dc9ccbb3-79b9-493d-b693-c21adeffbcc9/Final%20report%20on%20GL%20on%20third-party%20risk%20management.pdf · EBA press release of 18 September 2026: https://www.eba.europa.eu/publications-and-media/press-releases/eba-publishes-its-final-guidelines-management-third-party-risk-delivering-more-proportionate-and
Do you have questions about your organization's IT security?
Free Initial Consultation →