Guidelines EBA/GL/2026/09 replace the EBA Outsourcing Guidelines of 25 February 2019, which are repealed as of the date of application (para. 22). The shift in perspective is in the name: the subject is no longer merely the outsourcing of a function the institution would otherwise perform itself, but every third-party arrangement — any form of agreement with a third-party service provider (TPSP), including intra-group, for the recurrent or ongoing support of a function (para. 17). Outsourcing becomes just a subset; a function is any process, service or activity, or part thereof. The circle of addressees grows at the same time: alongside credit institutions, CRD investment firms and payment and e-money institutions, the Guidelines now also address IFD investment firms, ART issuers under MiCAR, MCD creditors that are financial institutions, and approved financial holding companies (para. 9). Formally, these are guidelines under Art. 16 of Regulation (EU) No 1093/2010: competent authorities and financial entities must make every effort to comply with them (para. 1). The legal basis lies in the governance mandates of the sectoral acts — Art. 74(3) CRD, Art. 26 IFD, Art. 34 MiCAR and Art. 11 PSD2. From the date of application, the Guidelines apply to all arrangements entered into, reviewed or amended thereafter; existing contracts must be brought into line (para. 18–21).
EBA Third-Party Risk Guidelines 2026: Managing non-ICT third-party providers under DORA logic
With EBA/GL/2026/09, the EBA replaces its 2019 Outsourcing Guidelines with a framework for the entire third-party risk arising from non-ICT services — focused on critical or important functions, a register modelled on the DORA register of information and a two-year transitional period. This page puts the Guidelines in context, draws the line to DORA and makes the requirements tangible with a Scope Navigator, a Register Builder and a Readiness Radar.
Last updated: September 2026 · Valeri Milke, ISO 27001 & ISO 42001 Lead Auditor
You will receive the download link immediately on the page and by e-mail.
On 18 September 2026, the European Banking Authority published the Final Report EBA/GL/2026/09 on the “Guidelines on the sound management of third-party risk regarding non-ICT services”. In doing so, the EBA follows through on DORA: since 17 January 2025, Regulation (EU) 2022/2554 has governed ICT third-party risk, while all other services have remained subject to the 2019 Outsourcing Guidelines until their repeal — with different terms, different register fields and a different logic. The new Guidelines close that gap, adopt the DORA definition of a critical or important function and explicitly expect financial entities to take a holistic approach across ICT and non-ICT (para. 7). The date of application has not yet been set; it will be fixed once the translations into all official EU languages are published. Anyone reviewing contracts, registers and exit plans today is making use of the two-year transitional period rather than being caught out by it. This page condenses the 128 paragraphs of the Guidelines into nine core concepts, links every statement to its paragraph and offers three interactive tools for classifying your own arrangements. For a deeper dive, the whitepaper “Third-Party Risk für CISOs” (German-language whitepaper) sets out the integration architecture with DORA, a clause library and a 24-month programme.
From the cloud recommendations to a third-party risk framework
Nine years of European regulation of third-party risk — the milestones leading to EBA/GL/2026/09. The date of application will only be set once the translations are published.
EBA Recommendations on cloud outsourcing
EBA/REC/2017/03 sets out expectations for institutions’ use of the cloud for the first time — applicable from 1 July 2018 and later integrated into the Outsourcing Guidelines.
EBA Outsourcing Guidelines EBA/GL/2019/02
The previous framework for outsourcing by credit institutions and CRD investment firms, payment and e-money institutions, applicable from 30 September 2019. It is repealed as of the date of application of the new Guidelines (para. 22).
DORA enters into force
Regulation (EU) 2022/2554 creates a dedicated framework for ICT third-party risk — non-ICT services remain with the Outsourcing Guidelines.
DORA applies
From now on, the register of information, the policy under Art. 28(10) and the contractual requirements apply to ICT service providers. The gap on the non-ICT side becomes visible.
Consultation EBA/CP/2025/12 launched
The EBA puts the draft Guidelines out for a three-month consultation; public hearing on 5 September 2025.
Consultation closes — 72 responses
Criticism of the mandate, double regulation and proportionality leads to refinements: focus on critical or important functions, a proportionate register, supervisory dialogue instead of a rigid deadline.
BCBS Principles for the sound management of third-party risk
The Basel Committee publishes the international principles that the EBA refers to in its cost-benefit analysis.
Final Report EBA/GL/2026/09
The EBA publishes the final Guidelines. Status: final, translations pending — the date of application is still open, after which the two-year transitional period runs.
Nine core concepts of the EBA Guidelines
Click a card to read the core concept with paragraph references — the order follows the structure of the Guidelines, from scope to supervision.
ICT services within the meaning of Art. 3(21) DORA are excluded from the scope — they fall under Chapter V of Regulation (EU) 2022/2554 (para. 7). The Guidelines therefore cover non-ICT services only, but explicitly expect a holistic approach that brings both worlds together in one framework. The dividing line is not always sharp: where a non-ICT service provider itself relies on ICT services to deliver its service, the financial entity must decide whether that ICT component is material to the provision of the service — if so, DORA applies (para. 32, with reference to the ESAs’ Q&As DORA030 and DORA095 in the Feedback Statement). Where an arrangement covers several functions, all aspects are to be assessed together. Under para. 33, the exclusions include, among others, services required by law such as the statutory audit, regulated financial services provided by other supervised entities (custody, trading venues), market information services, interbank and central bank operations, payment networks such as Visa, Mastercard or Wero, clearing and settlement, SWIFT, correspondent banking, services without a material impact on risk or resilience (architects, printing, legal opinions, cleaning, catering, fleet), the procurement of goods and utilities. As fn. 41 makes clear, appropriate risk management is still expected for excluded services.
Whether a contract is a third-party arrangement within the meaning of the Guidelines at all is settled by the three-step test in para. 31: (a) Are the services non-ICT services? (b) Does the third-party service provider thereby support a function on a recurrent or ongoing basis? (c) Is that function critical or important? The definition of a critical or important function (para. 17) is modelled word for word on Art. 3(22) DORA: a disruption would materially impair financial performance, the soundness or continuity of services, or continuing compliance with the conditions of authorisation. According to fn. 35, it is deliberately not identical to the “critical functions” under Art. 2(1)(35) BRRD. Para. 34 names three situations in which a function is always critical or important; para. 35 classifies operational tasks of internal control functions as such in principle, unless the assessment shows otherwise; para. 36 automatically makes banking activities requiring authorisation, payment services and ART issuance critical. Institutions under the BRRD additionally examine the link to critical functions and core business lines under Art. 6 and 7 of Delegated Regulation (EU) 2016/778 (para. 37). Criticality is not a one-off judgement: it must be reassessed whenever material changes occur (para. 110).
The management body defines, approves and regularly reviews a third-party risk strategy that includes a policy; integrated or separate strategies for ICT and non-ICT are permissible (para. 38). Its responsibility cannot be delegated: the financial entity remains fully accountable and must be able to oversee and challenge the performance of its service providers (para. 41). Para. 42 lists eight non-transferable duties — from the conditions of authorisation and conflict-of-interest policies through to the business continuity policy and audit plans. Under para. 44, responsibilities must be clearly assigned, sufficient resources provided and a role or a member of senior management designated with direct accountability to the management body for overseeing all arrangements; fn. 46 expressly allows this to be combined with the DORA role under Art. 5(3). Less complex institutions ensure at least a clear division of tasks and may assign the role to a member of the management body. Para. 45 sets out the empty-shell ban: financial entities must at all times retain enough substance to meet the conditions of authorisation, remain auditable and supervisable, and oversee outsourced control tasks. Para. 46 further requires that decisions are taken in-house and that critical functions can be transferred, reintegrated or discontinued within a reasonable time.
Anyone who receives, or intends to receive, non-ICT services for critical or important functions needs a written policy approved by the management body, reviewed at least annually and updated where necessary; changes must be reflected in the contracts without undue delay (para. 47). The policy follows the life cycle of a contract and, under para. 48, covers at least seven areas: the responsibility of the management body, the involvement of business lines and control functions, the oversight role with reporting lines, planning (classification, requirements, criticality criteria, risk analysis, due diligence, conflicts of interest, business continuity, approval process), ongoing management (performance monitoring, response to changes, independent review, renewal), documentation, and exit strategies with a documented exit plan. The most important sentence in practice is in para. 49: the policy may be merged with the DORA policy under Art. 28(10), whose content is prescribed by Delegated Regulation (EU) 2024/1773. The condition is that it makes four distinctions visible — ICT versus non-ICT services, supervised versus non-supervised service providers, intra-group versus external, and Member State versus third country. Finally, para. 50 requires the policy to factor the impact on risk profile, supervisability, business continuity and business activities into the decision.
Financial entities maintain an up-to-date register of all third-party arrangements within scope — at individual and, where applicable, sub-consolidated and consolidated level — and distinguish arrangements supporting critical or important functions from the rest (para. 58). Notably, ICT subcontractors of a non-ICT service provider that effectively underpin its service for a critical function belong in the register too. Terminated arrangements remain documented for an appropriate period (para. 59); groups and institutional protection schemes may keep the register centrally (para. 60). Para. 61 requires consistency with the DORA register of information under Art. 28(3) as far as possible and expressly allows the two to be merged into a single register. Nine minimum fields apply to all arrangements (para. 61 a–i): reference number and contract type, term dates, group entities using the service, group membership, description of the function, criticality with reasoning, internal category, service provider data with LEI or EUID and ultimate parent, and the countries of service provision. For critical or important functions, eight further fields are added (para. 62 a–h): governing law, latest audits, subcontractors with their rank in the chain, substitutability in four grades, reintegration assessment with RTO and RPO, exit plan yes/no, alternative service providers and annual costs. The competent authority receives the register on request in a processable electronic format — the format of the DORA ITS, such as CSV, is permissible (para. 63).
Five steps precede every arrangement (para. 68): criticality assessment, check of the supervisory conditions, risk analysis, due diligence and conflicts of interest. Functions requiring authorisation — banking activities, payment services, ART issuance, investment services — may only go to service providers that are authorised or registered for them or entitled to provide them under national law (para. 69). If such a provider is located in a third country, it must be authorised and supervised there, and a cooperation agreement securing information, access and enforcement rights must exist between the competent authorities (para. 70). The risk analysis considers operational, reputational, legal and concentration risk (para. 71), substitutability, reintegrability, scalability and data protection (para. 72), and works with scenarios including severe events — qualitatively for smaller institutions, with loss data for large ones (para. 73). Para. 74 requires a cost-benefit assessment with regard to concentration, aggregated risks and, for significant institutions, step-in risk; para. 75 and 76 add subcontracting chains, location, political stability, and data protection, law enforcement and insolvency law. Due diligence is proportionate to criticality (para. 77) and examines business model, financial strength, ownership, track record and supervision (para. 78); for critical functions it additionally covers resources, internal controls including supply chain risks, geographical dependencies, contingency plans, authorisations and on-site auditability (para. 79). For third-country service providers, para. 82 expects ethical conduct including ESG risks, human rights and the prohibition of child labour.
Rights and obligations are set out in a written contract (para. 83) with ten minimum contents (para. 84 a–j): description of the service including the subcontracting rule, locations of service provision with a duty to notify changes, governing law, location of data processing and storage, protection of availability, authenticity, integrity and confidentiality, return of data on insolvency, resolution or termination, service levels, cooperation with competent and resolution authorities, termination rights with notice periods, and — for CRD institutions — a reference to the resolution powers under Art. 68 and 71 BRRD. For critical or important functions, six elements are added (para. 85): measurable SLA targets, notification and reporting duties including the service provider’s internal audit reports, mandatory insurance, tested contingency plans, ongoing monitoring with unrestricted access and audit rights, and an exit strategy with a mandatory transition period. Subcontracting is only permissible if the contract allows and governs it (para. 87); para. 89 requires, among other things, equivalent audit rights vis-à-vis subcontractors and continuity along the chain. New or amended subcontracts must be notified with an appropriate notice period, the financial entity may object, and implementation follows only after approval or expiry of the period (para. 90–93); in the event of breaches, the subcontract must be terminable (para. 95). Audit rights encompass access to business premises and unrestricted audits for the institution, the competent authority and the resolution authority (para. 98). Termination rights exist, among other cases, on breach of law, change of subcontractor, proven security weaknesses and loss of supervisability (para. 108).
Monitoring follows a risk-based approach and is ongoing for critical or important functions (para. 110): the risk analysis is updated regularly, the management body is informed periodically, and criticality is reassessed whenever material changes occur. Internal concentration risks — including those arising from subcontractors — must be actively managed (para. 111). As tools, para. 112 names service provider reports, key performance indicators, key control indicators, service delivery reports, self-certifications and independent reviews; deficiencies trigger remedial action or termination (para. 113). For critical or important functions, a documented exit strategy is mandatory, covering termination, failure of the service provider, concentration risk, deterioration in quality, material risks and breaches of law (para. 114). Exit plans must be realistic, documented and, where appropriate, tested; alternative solutions and transition plans form part of them (para. 115). Para. 116 requires objectives, roles, resources, success criteria and indicators with thresholds that trigger the exit. Title V is addressed to competent authorities: they analyse third-party risk at least as part of the SREP (para. 119), may request risk analyses, contingency plans and exit strategies (para. 120), examine resources and conflicts of interest (para. 122), watch for empty-shell structures including back-to-back transfers to non-EEA entities (para. 123), assess concentration within the institution and across the sector (para. 124) and may restrict arrangements or order an exit (para. 126).
The life cycle of a third-party arrangement
Titles II and IV of the Guidelines follow the contract cycle — from classification to exit. Select a phase to see the core requirements with paragraph references.
- The three-step test determines whether a contract is a third-party arrangement at all: non-ICT, recurrent or ongoing, support of a function (para. 31).
- For non-ICT services with an ICT component, the financial entity decides whether the ICT component is material — if so, DORA applies (para. 32).
- The exclusion list in para. 33 removes, among others, the statutory audit, payment networks, SWIFT, the procurement of goods and utilities from the scope.
- Always critical or important: functions whose disruption would materially impair the conditions of authorisation, financial performance or continuity (para. 34), operational tasks of internal control functions (para. 35) and activities requiring authorisation (para. 36).
- BRRD institutions additionally examine the link to critical functions and core business lines (para. 37).
- Five steps before signing: criticality, supervisory conditions, risk analysis, due diligence, conflicts of interest (para. 68).
- Functions requiring authorisation only to authorised or registered service providers; in third countries, additionally supervision and a cooperation agreement between the authorities (para. 69–70).
- The risk analysis covers operational, reputational, legal and concentration risk, works with scenarios and weighs costs against benefits (para. 71–74).
- Location factors count: EU or third country, political stability, data protection, law enforcement and insolvency law (para. 76).
- Due diligence proportionate to criticality — extending to supply chain risks, contingency plans and on-site auditability; for third-country providers also ESG and human rights (para. 77–82).
- Written form with a clear allocation of rights and obligations (para. 83).
- Ten minimum contents for every arrangement — from service description and data location to termination rights and cooperation with authorities (para. 84 a–j).
- CRD institutions refer to the resolution powers under Art. 68 and 71 BRRD and describe the “substantive obligations” (para. 84 j).
- Critical or important functions: measurable SLA targets, reporting duties, insurance, BCP testing, unrestricted audit rights, exit strategy with transition period (para. 85 a–f).
- For third-country service providers, diverging data protection rules and banking secrecy must be secured contractually (para. 86).
- The contract sets out whether and under what conditions critical functions or material parts thereof may be subcontracted (para. 87).
- Focus on subcontractors that effectively underpin the service — they belong in the register (para. 88).
- Ten contractual contents for the chain, including equivalent access and audit rights vis-à-vis subcontractors and the service provider’s continuity obligation (para. 89 a–j).
- New or amended subcontracts: notification with an appropriate notice period, right to object, implementation only after approval or expiry of the period (para. 90–93).
- The subcontract must be terminable if the service provider subcontracts despite an objection, before the period expires or without permission (para. 95).
- The internal audit function must be able to review the outsourced function on a risk-based approach (para. 96); CRD institutions refer to the authorities’ investigatory powers regardless of criticality (para. 97).
- For critical or important functions: access to business premises, copies and unrestricted audit rights for institution, competent authority and resolution authority (para. 98); non-critical arrangements on a risk-based approach (para. 99).
- Pooled audits and certificates or audit reports are permissible, but never exclusively on a permanent basis — eight conditions including scope extension and the right to individual audits (para. 102–104).
- Ongoing monitoring of critical functions with KPIs, key control indicators, service delivery reports, self-certifications and independent reviews (para. 110–112).
- In the event of deficiencies: remedial action or termination (para. 113).
- Termination rights on serious breach of law or contract, circumstances that alter performance, material changes such as a change of subcontractor, security weaknesses and loss of supervisability (para. 108).
- The contract facilitates transfer or reintegration: service provider obligations, transition period, duty to support (para. 109).
- Documented exit strategy for critical or important functions with six scenarios from termination to breach of law (para. 114).
- Exit plans realistic, documented and, where appropriate, tested; alternative solutions and transition plans included (para. 115).
- Objectives, roles, resources, success criteria and indicators with trigger thresholds for the exit (para. 116).
Scope Navigator: which regime applies to your arrangement?
Five questions along para. 31–37 — from the DORA boundary to subcontracting. The result shows which requirements of the Guidelines apply to your arrangement.
- 1?
1: Is the service an ICT service within the meaning of Art. 3(21) DORA — or is its ICT component material to its provision?
Is the service an ICT service within the meaning of Art. 3(21) DORA — or is its ICT component material to its provision?
ICT services fall under DORA Chapter V, not under the Guidelines (para. 7). For non-ICT services with an ICT component, you decide yourself whether that component is material to the provision of the service (para. 32, ESAs’ Q&As DORA030/095).
Your arrangement falls under DORA, not under the EBA Guidelines
ICT services under Art. 3(21) DORA are excluded from the scope of the Guidelines (para. 7). Where the ICT component of a non-ICT service is material to its provision, the DORA framework likewise applies (para. 32). Keep a documented record of this decision — the Guidelines still expect a holistic approach across both worlds.
- Apply the requirements of Art. 28–30 DORA on policy, contractual contents and risk analysis.
- Record the arrangement in the DORA register of information under Art. 28(3) using the templates of Implementing Regulation (EU) 2024/2956.
- Document the materiality decision under para. 32 so that the supervisor and internal audit can follow the delineation.
- For critical ICT third-party service providers, also keep the oversight regime under Art. 31–44 DORA in view.
No recurrent support — the Guidelines do not apply
Under para. 17, a third-party arrangement presupposes an agreement to support a function on a recurrent or ongoing basis. One-off or occasional services do not meet this definition and therefore already fail at step (b) of the three-step test set out in para. 31.
- Briefly document the classification — in particular why there is no recurrent or ongoing support.
- If the one-off service turns into a lasting relationship, run the three-step test again.
- General duties of care in risk management and data protection continue to apply independently of the Guidelines.
Excluded service — still manage the risks appropriately
The service falls under the exclusion list in para. 33 and therefore outside the Guidelines. However, fn. 41 makes clear that the exclusions do not mean financial entities should refrain from taking appropriate steps to manage the risks of these agreements — the risks must still be managed appropriately.
- Record in writing which specific exclusion in para. 33 applies.
- Take the risks into account in general operational risk management and in the business impact analysis (para. 55).
- Check whether the service really has no material impact on risk and resilience — otherwise the exclusion does not apply.
Third-party arrangement without a critical or important function
Your arrangement is within scope but does not support a critical or important function. The basic regime applies: a register with the nine minimum fields, risk-based audit rights, termination rights — and the duty to keep criticality under review.
- Record it in the non-ICT register with the basic fields of para. 61 a–i, including the criticality decision with a brief reasoning.
- Agree access and audit rights on a risk-based approach — depending on the nature of the function, scalability and contract duration (para. 99).
- Anchor termination rights and notice periods under para. 84 i and para. 108 in the contract.
- Review and documentation of existing arrangements can take place at contract renewal (para. 21).
- Reassess criticality whenever risk, nature or scope changes materially — functions can become critical (para. 99, 110).
Critical or important function — the full set of requirements
Your arrangement supports a critical or important function. The stricter provisions of the Guidelines therefore apply across the entire life cycle — from policy through register, contract and audit rights to a tested exit strategy and dialogue with the competent authority.
- Apply the policy under para. 47–50 and review it at least annually — optionally merged with the DORA policy under Art. 28(10).
- Maintain the register with all 9 basic fields (para. 61) and 8 additional fields (para. 62), including substitutability, RTO/RPO and annual costs.
- Complete the full pre-contractual analysis: supervisory conditions, risk analysis, due diligence, conflicts of interest (para. 68–82).
- Contract with the minimum contents of para. 84 and the additional clauses of para. 85 — including unrestricted access and audit rights (para. 98).
- Documented and, where appropriate, tested exit strategy with trigger indicators (para. 114–116).
- Inform the competent authority in good time and engage in supervisory dialogue where necessary (para. 65); review existing arrangements within two years of the date of application (para. 20).
Critical function with subcontracting or a third-country dimension
On top of the full regime for critical or important functions come the requirements for subcontracting chains and third-country service providers. This is where the Guidelines demand the most contractual work — and the competent authority must be satisfied that it can supervise effectively outside the EEA as well (para. 127).
- All requirements of the full regime: policy (para. 47–50), register (para. 61+62), pre-contractual analysis (para. 68–82), contract (para. 84+85), audit rights (para. 98), exit (para. 114–116).
- Govern subcontracting contractually: notification duty with notice period, right to object, implementation only after approval, equivalent audit rights along the chain, termination of the subcontract (para. 87–95).
- Functions requiring authorisation in a third country only where the service provider is authorised and supervised there and the authorities have a cooperation agreement (para. 70).
- Assess location risks: political stability, data protection law, law enforcement, insolvency law (para. 76).
- Check ESG risks, human rights and the prohibition of child labour for third-country service providers and their subcontractors (para. 82).
- Record subcontractors of material parts in the register with country, identifier, rank in the chain and location of service provision (para. 62 c).
- Is the service an ICT service within the meaning of Art. 3(21) DORA — or is its ICT component material to its provision?
- Does the service provider deliver the service on a recurrent or ongoing basis, and does it support a function of your institution?
- Does the service fall under an exclusion in para. 33 (e.g. statutory audit, payment networks, SWIFT, cleaning, utilities, procurement of goods)?
- Does the service support a critical or important function (para. 34–37)?
- Is subcontracting of material parts envisaged, or is the service provider (or a subcontractor) located in a third country?
Register Builder: which fields your non-ICT register needs
Para. 61 requires nine minimum fields for all arrangements, para. 62 eight additional fields for critical or important functions. Tick off what your register covers today — and copy the header row for your CSV template.
EBA/GL/2026/09 in Detail: The Guidelines Chapter by Chapter
Scope, criticality, governance, policy, register, contract, subcontracting, audit rights, monitoring, exit, supervision, DORA integration and implementation programme — every statement referenced to the paragraph (para.) of the Final Report of 18 September 2026.
From the Outsourcing Guidelines 2019 to the Third-Party Risk Framework 2026
On 18 September 2026 the EBA published the Final Report on EBA/GL/2026/09. The Guidelines replace the Outsourcing Guidelines of 25 February 2019 and widen the lens to third-party risk as a whole — confined to non-ICT services, because ICT services have fallen under DORA since 17 January 2025.
Financial entities rely ever more heavily on third-party service providers (TPSPs) — and in doing so increase the risks to themselves, their clients and, in individual cases, the financial system (p. 4). The EBA draws two conclusions: outsourcing becomes a subset of the broader third-party arrangement (para. 17), and the gap to DORA is closed — DORA governs ICT third-party risk, the Guidelines govern non-ICT third-party risk, with the expectation of a holistic approach spanning both worlds (para. 7; Background section para. 11).
The legal basis lies in the governance mandates of the sectoral legal acts: Art. 74(3) CRD, Art. 26 IFD, Art. 34 MiCAR and Art. 11 PSD2 (Background section para. 15; Feedback p. 67). Formally, these are guidelines under Art. 16 of Regulation (EU) No 1093/2010: competent authorities and financial entities must make every effort to comply with them, and each competent authority declares within two months whether it applies the Guidelines (paras. 1–3; Feedback p. 68).
| Feature | EBA/GL/2019/02 (Outsourcing) | EBA/GL/2026/09 (Third-Party Risk) |
|---|---|---|
| Date | 25 February 2019, applicable from 30 September 2019 | 18 September 2026; date of application follows publication of the translations (date open) |
| Subject matter | Outsourcing of functions, including cloud (EBA/REC/2017/03 integrated) | All recurrent or ongoing non-ICT third-party arrangements; outsourcing as a subset (para. 17) |
| ICT | Covered | Excluded — ICT services under Art. 3(21) DORA fall under Chapter V DORA (para. 7) |
| Addressees | CRD institutions, payment and e-money institutions | Additionally IFD investment firms (Class 1 minus, Class 2), MCD creditors and ART issuers (para. 9) |
| Register | Register of all outsourcing arrangements | 9 basic fields for all non-ICT arrangements plus 8 additional fields for critical or important functions; merger with the DORA register of information permitted (paras. 61–62) |
| Status | Repealed as of the date of application of the new Guidelines (para. 22) | Final; translation into the official EU languages under way |
Sources: Final Report p. 55, paras. 9, 17, 22, 61–62; EBA press release of 18 September 2026.
Internationally, the EBA builds on the FSB toolkit of 4 December 2023 and the BCBS Principles for the sound management of third-party risk of 10 December 2025, which the definition of the third-party arrangement follows (pp. 55, 59; Feedback p. 75); the ESMA Principles on third-party risks of 12 June 2025 are addressed to national competent authorities only (Feedback p. 66).
The consultation on EBA/CP/2025/12 ran from 8 July to 8 October 2025 and drew 72 responses (Feedback p. 65). The EBA rejected criticism of its mandate and allegations of double regulation (pp. 67–68); on proportionality it gave ground — a focus on critical or important functions, a leaner register, proportionality criteria in Title I (pp. 68–69). It answered the call for a lead time of nine to eighteen months with the two-year transitional period; those who cannot complete in time inform the competent authority (p. 78; para. 20).
The date of application is a placeholder in the Final Report: the Guidelines apply from a date set upon publication of the translations to all arrangements entered into, reviewed or amended on or after that day (para. 18); existing arrangements must be reviewed and adapted (para. 19).
Scope: Addressees, Non-ICT, Exclusions, Hybrid Cases
The Guidelines address a markedly wider circle of addressees than in 2019 and capture every recurrent or ongoing non-ICT service that supports a function. Just as important is what they do not capture: ICT services, services required by law and a long list of low-risk purchases.
The subject matter is the governance arrangements that apply where third-party service providers deliver non-ICT services in support of functions — with a focus on critical or important functions (para. 5); “support” includes the full performance of the function (fn. 20). ICT services under Art. 3(21) DORA are excluded because they fall under Chapter V DORA (para. 7). Competent authorities review the arrangements in the SREP under Art. 97 CRD and its counterparts in the IFD, PSD2, EMD and MiCAR (para. 6).
| Addressee | Basis | Level of application |
|---|---|---|
| Credit institutions and CRD investment firms (institutions under Art. 4(1)(3) CRR) | Para. 9; Art. 74 CRD | Individual, sub-consolidated and consolidated level; waiver under Art. 21 or 109(1) CRD possible (para. 13) |
| Third-country branches under Art. 47 CRD | Paras. 9–10 | Proportionate; instead of a contract with the head office, SLAs or policies suffice (para. 10) |
| MiFID II investment firms other than small and non-interconnected firms under Art. 12(1) IFR | Para. 9; Art. 26 IFD | Class 1 minus and Class 2: individual, sub-consolidated and consolidated where relevant; Class 2 consolidated under Art. 25 IFD (para. 13) |
| Payment and e-money institutions | Paras. 9, 12; Art. 11 PSD2 | Individual level (para. 14) |
| Issuers of asset-referenced tokens (ART) | Para. 9; Art. 34 MiCAR | Individual level, group-wide where relevant (para. 15) |
| MCD creditors that are financial institutions | Para. 9; Art. 4(2) MCD | Not separately regulated (paras. 13–15) |
| Financial holding companies and mixed financial holding companies approved under Art. 21a CRD | Para. 9; Art. 3(3) CRD | Not separately regulated (para. 9) |
| Not addressed | Para. 11; Background section para. 9; Feedback pp. 68, 75 | Pure account information service providers, credit intermediaries, crypto-asset service providers (CASPs; Art. 73 MiCAR applies), central securities depositories (CSDR) |
What is not captured: the exclusions in para. 33
- Services that must by law be provided by a third party — such as the statutory audit
- Regulated financial services that are required by law to be provided by another financial entity regulated under EU law, for example custody or trading venues
- Market information services — added at the request of consultation respondents (Feedback p. 79)
- Financial transactions between financial institutions as counterparties and with central banks
- Payment network infrastructures such as Visa, Mastercard, Wero or GIE CB, as well as clearing and settlement arrangements between clearing houses, central counterparties, settlement institutions and their members
- Global financial messaging infrastructures under regulatory oversight, such as SWIFT, as well as correspondent banking
- Services with no material impact on risk or resilience: architects, printing, legal opinions, legal representation, PR, cleaning, building maintenance, medical services, fleet management, catering, canteen, office, travel, postal and reception services
- Procurement of goods (plastic cards, card readers, office supplies, PCs, furniture) and utilities (electricity, gas, water, telephone)
It is the service that is excluded, not the provider: a supervised financial entity that delivers other services is a TPSP like any other; its supervised status feeds into proportionality and the risk analysis (pp. 69–71). Nor do the exclusions dispense with risk management — appropriate steps remain expected (fn. 41).
Intra-group service providers and central service providers of an institutional protection scheme (IPS) are TPSPs — with no special regime, since intra-group arrangements are not per se lower-risk (Background section para. 19; Feedback p. 71); flexibility comes from centralised functions under paras. 26–30. An intra-group TPSP located in a third country is to be treated as a third-country TPSP in the risk analysis (Feedback p. 75).
The Three-Step Test and the Critical or Important Function
Whether an arrangement falls under the full regime is decided by a three-step test — and, at its core, by the question of whether the supported function is critical or important. The definition mirrors DORA word for word; the EBA adds three presumption rules that tip the balance in practice.
The test belongs within holistic risk management across all business lines and internal units (para. 31). It is run before every engagement (para. 68 a) and must be anchored in the policy as a planning step (para. 48 d).
- 1Step 1Is this a non-ICT service?
If the service is an ICT service under Art. 3(21) DORA, or if its ICT component is material to its provision, DORA applies (paras. 31 a, 32). Everything else stays in the test.
- 2Step 2Is a function supported on a recurrent or ongoing basis?
A function is any process, service or activity — or part thereof (para. 17). One-off purchases are not a third-party arrangement (para. 31 b). Then check the exclusions under para. 33.
- 3Step 3Is the function critical or important?
Only then do the policy (para. 47), the additional register fields (para. 62), enhanced due diligence (para. 79), enhanced contractual clauses (para. 85), unrestricted audit rights (para. 98) and the exit plan (para. 114) apply. All other arrangements are subject to the basic regime (para. 31 c).
A function is critical or important where its disruption would materially impair the financial performance of the financial entity, the soundness or continuity of its services and activities, or its continuing compliance with the conditions of its authorisation and other obligations under financial services law (para. 17). The wording corresponds to Art. 3(22) DORA (Background section para. 13). It is not identical to the “critical functions” under Art. 2(1)(35) BRRD, but encompasses them (fn. 35; Background section para. 13).
| Criterion | Rule in the Guidelines | Relationship to DORA |
|---|---|---|
| Basic definition | Material impairment of the conditions of authorisation, financial performance, or soundness and continuity (paras. 17, 34 a–c) | Verbatim Art. 3(22) DORA |
| Operational tasks of internal control functions | Always critical or important — unless the assessment demonstrates that a failure would not impair the effectiveness of the control function (para. 35) | EBA presumption rule for non-ICT |
| Functions requiring authorisation | Banking activities, payment services or ART issuance on a scale requiring authorisation: automatically critical or important (para. 36) | EBA presumption rule; linked to the supervisory conditions in Section 11.1 (paras. 69–70) |
| Resolution relevance (BRRD institutions) | Functions underpinning critical functions or core business lines (criteria of Delegated Regulation (EU) 2016/778, Arts. 6–7) are deemed critical or important unless the assessment demonstrates no material impact (para. 37) | EBA presumption rule; resolvability must not be impaired (Background section para. 27) |
| Sub-functions | Part of a function can also be critical or important (para. 17; Feedback p. 76) | Assessment by the financial entity itself (Feedback p. 77) |
| Methodology | The financial entity sets the criteria or methodology (Background section para. 16; para. 48 d iii); the result and a brief rationale are recorded in the register (para. 61 f) | No rigid catalogue of criteria — option C of the cost-benefit analysis, to avoid tick-the-box (p. 61) |
An arrangement covering several functions — for instance operational tasks of risk management and regulatory reporting — must be assessed jointly in all its aspects (para. 32).
Governance: Management Body, Role, Empty-Shell Ban, Proportionality, Groups and IPS
The Guidelines rest on a simple principle: responsibility cannot be outsourced. The management body remains fully responsible for every arrangement, needs a designated role for oversight — and must not let the entity become an empty shell.
The management body defines, approves and regularly reviews a third-party risk strategy that includes the policy under Section 6 and complements operational risk management and operational resilience; integrated or separate strategies for ICT and non-ICT are permitted (para. 38; Feedback p. 83). The use of TPSPs never results in a delegation of responsibility (para. 41) and lowers neither the suitability requirements for the management body and senior management nor the need for competent resources (para. 43). Para. 42 a–h lists what the management body remains responsible for at all times — from the conditions of authorisation through strategies, risk appetite and conflict-of-interest policies to the oversight of all third-party risks, the business continuity policy and the audit plans of internal audit.
The role (para. 44 c)
A role to oversee all third-party arrangements, or a member of senior management directly accountable to the management body. It may be combined with the role for ICT third parties under Art. 5(3) DORA (fn. 46). Less complex entities ensure at least a clear division of tasks and may assign the role to a member of the management body. Typical holders are the risk management or compliance function (Feedback pp. 84–85).
Empty-shell ban (para. 45)
Financial entities must retain sufficient substance at all times and must not become “empty shells” or “letter-box entities”: meeting the conditions of authorisation, maintaining a transparent organisational structure that can be audited and supervised, effectively overseeing outsourced tasks of the control functions — including intra-group — and holding the knowledge, resources and capacity to do so (para. 45 a–d).
Minimum safeguards (para. 46)
Taking decisions on the business and critical functions itself; preserving the orderly conduct of banking, investment and payment services; identifying and managing risks; ensuring confidentiality; maintaining the flow of information with the TPSP; being able to transfer or reintegrate critical or important functions within an appropriate timeframe, or to discontinue the dependent business; GDPR compliance within the EU and in third countries (para. 46 a–g).
Proportionality and group structures
Proportionality means that governance arrangements must fit the risk profile, nature, business model, scale and complexity of the activities (para. 23). The yardstick for each arrangement is the complexity of the function, the risks, criticality and the impact on continuity (para. 24); the criteria in Title I of the EBA governance guidelines under the CRD, IFD and MiCAR apply accordingly (para. 25).
| Situation | Requirement | Para. |
|---|---|---|
| Group under Art. 109(2) CRD | Application also at consolidated and sub-consolidated level; the parent undertaking ensures consistent, integrated arrangements across all subsidiaries — including payment institutions, investment firms and ART issuers | 26 |
| Intra-group or intra-IPS TPSPs | The management body of each financial entity remains fully responsible; outsourced operational tasks of the control functions must be performed effectively, evidenced by appropriate reports | 27 |
| Centralised monitoring | For critical or important functions: independent monitoring plus each institution’s own oversight; at least annual reports on risk assessment and performance; summary of the audit reports, the full report on request; information to the management body on planned changes | 28 a–b |
| Centralised pre-contractual analysis, central register, central exit plan | Each institution receives a summary and takes its own structure into account; the individual register must be retrievable without delay; the exit plan must actually be executable | 28 c–e |
| Waiver under Art. 21 or 109(1) CRD in conjunction with Art. 7 CRR | Application by the parent undertaking for itself and its subsidiaries, or by the central body together with its members as a whole; without a waiver, application at individual level | 29–30 |
The Policy along the Lifecycle — and How It Merges with the DORA Policy
For non-ICT services supporting critical or important functions, the EBA requires a written policy approved by the management body that covers the entire lifecycle. It may be merged with the DORA policy under Art. 28(10) DORA — but must then make four distinctions visible.
The policy must be reviewed at least annually and updated where necessary; changes are to be implemented in the contractual relationships promptly and as soon as possible, and the management body ensures implementation at individual, sub-consolidated and consolidated level (para. 47). The EBA rejected the request to drop the annual cycle — it is not burdensome where nothing has changed, and it is consistent with DORA (Feedback p. 85). Whether the 2019 outsourcing policy and the new policy form a single document is left to the financial entity.
| Lifecycle phase | Minimum content of the policy | Para. 48 |
|---|---|---|
| Responsibility | Tasks of the management body under paras. 38 and 42, including its involvement in decisions on critical or important functions | a |
| Participants | Involvement of business lines, internal control functions and other persons | b |
| Role | Designation of the role or the senior management member responsible for monitoring, cooperation with the control functions, reporting lines to the management body with content, documents and frequency | c |
| Planning | Scope test, business requirements, criteria and process for critical or important functions, risk analysis (Section 11.2), due diligence (Section 11.3), conflicts of interest (Section 7), business continuity (Section 8), approval process | d i–viii |
| Operation | Performance monitoring (Section 13), procedures for notifying and responding to changes — financial situation, ownership structure, subcontracting —, independent review, renewal processes | e i–iv |
| Documentation | Register and record-keeping under Section 10 | f |
| Exit | Exit strategies and termination processes, including a documented exit plan for each critical or important arrangement (Section 14) | g |
In addition, the policy must capture the impact of critical or important functions placed with TPSPs on four areas and feed it into decision-making: the risk profile, the ability to oversee the TPSP and manage risks, business continuity measures and business performance (para. 50).
Common core
Governance, the role under para. 44 c and Art. 5(3) DORA, lifecycle, reporting lines and register governance — written once, valid for both worlds.
ICT module
The content of Delegated Regulation (EU) 2024/1773 for ICT services supporting critical or important functions.
Non-ICT module
The content under para. 48 a–g, the supervisory conditions under Section 11.1 and the exclusion test under para. 33.
Differentiation matrix
For each rule, state whether it applies identically or differently to ICT and non-ICT, supervised and unsupervised, internal and external, and EU and third-country TPSPs — this is the evidence for para. 49.
Three adjacent sections belong to the policy in substance. Conflicts of interest must be identified, assessed and managed; for intra-group TPSPs the terms, including the price, must be objective, and synergies may be priced in as long as the TPSP remains viable on a standalone basis — within a group, independently of the failure of other group entities (paras. 51–53). Business continuity requires regularly tested plans that involve the TPSP and a business impact analysis with quantitative and qualitative criteria, scenario analysis and a view on substitutability (paras. 54–55). Internal audit reviews on a risk-based approach, includes critical arrangements in the audit plan, assesses the framework, the criticality and risk assessments, the involvement of governing bodies and monitoring, and runs a formal follow-up process for findings (paras. 56–57).
The Non-ICT Register: 9 + 8 Fields, Consistency with DORA, Provision to Supervisors
The register is the data model of the Guidelines: nine basic fields for every non-ICT arrangement, eight additional fields for critical or important functions — as consistent as possible with the DORA register of information, with which it may be merged.
The register covers all third-party arrangements within scope — at individual, sub-consolidated and consolidated level — and distinguishes critical or important functions from the rest; ICT subcontractors of a non-ICT TPSP that effectively underpin a critical or important service belong in it (para. 58). Terminated arrangements remain documented for an appropriate period; the five-year retention period originally planned was aligned with DORA (para. 59; Feedback p. 90). Groups and IPSs may maintain the register centrally, provided each institution receives its individual register without delay (paras. 60, 28 d).
| Field | Content | Applies to | Para. |
|---|---|---|---|
| Reference and contract type | Reference number; contract type “Standalone arrangement”, “Overarching arrangement” or “Subsequent or associated arrangement” — the latter with the reference number of the framework agreement | All | 61 a |
| Duration | Start date, next renewal date, end date with reason for termination | All | 61 b |
| Using entities | For a central register: financial entities within the scope of consolidation or the IPS that use the TPSP (para. 60) | All | 61 c |
| Group link | Whether the TPSP or subcontractor belongs to the group or IPS, or is owned by group entities or IPS members | All | 61 d |
| Function description | Brief description of the functions provided by the TPSP | All | 61 e |
| Criticality | Yes/no: critical or important function — with a brief rationale where applicable | All | 61 f |
| Category | Internal category of the function; several categories where several functions are covered | All | 61 g |
| Service provider | Name, identifier (LEI, EUID or alternative), company registration number, address, contact details, ultimate parent undertaking with identifier | All | 61 h |
| Place of provision | Country or countries where the service is provided (wording: of the critical or important function) | All | 61 i |
| Governing law | Law governing the arrangement | Critical/important | 62 a |
| Audits | Dates of the most recent audits — internal audits; for audits by the TPSP, the most recent one (Feedback p. 91) | Critical/important | 62 b |
| Subcontractors | For material parts: name, country of registration, identifier, subcontracted part, rank in the chain, place of provision | Critical/important | 62 c |
| Substitutability | Result and date of the last assessment: “easy”, “medium”, “highly complex” or “impossible to substitute” | Critical/important | 62 d |
| Reintegration and RTO/RPO | Summary and date of the last assessment on reintegration or discontinuation — with the RTO and RPO of the function | Critical/important | 62 e |
| Exit plan | Yes/no: exit plan in place | Critical/important | 62 f |
| Alternatives | Alternative TPSPs, where possible | Critical/important | 62 g |
| Costs | Estimated annual costs of the previous year, with currency | Critical/important | 62 h |
Contract types and substitutability levels follow the wording of the Final Report; fields aligned with DORA and Implementing Regulation (EU) 2024/2956 (Feedback pp. 89–91).
Provision to supervisors and notifications
On request, the competent authority receives the register in full or in part in a processable electronic format — the format of the DORA ITS, such as a database format or CSV, is permitted (para. 63) — together with all necessary information, up to and including copies of contracts (para. 64). Planned arrangements supporting critical or important functions, and any case in which a function becomes critical or important, must be notified in good time, where appropriate within the supervisory dialogue, with at least the information set out in paras. 61 and 62 (para. 65); the same applies to material changes and severe events (para. 66). Assessments and monitoring results must be documented (para. 67). The Guidelines set no deadline; centralised notifications from groups are possible (Feedback pp. 77–78, 92).
Pre-Contractual Analysis: Supervisory Conditions, Risk Analysis, Due Diligence
Before a contract is signed, the Guidelines require five assessment steps: criticality, supervisory conditions, risk analysis, due diligence and conflicts of interest (para. 68). For third-country service providers, strict authorisation and cooperation conditions are added.
Functions requiring authorisation — banking activities, payment services, the issuance of ART or investment services under Art. 4(2) MiFID II on a scale that requires authorisation or registration — may only be entrusted to a TPSP that is authorised or registered for them, or otherwise permitted to perform them under national law (para. 69; Section 11.1). If the TPSP is located in a third country, three cumulative conditions apply (para. 70):
- 1Condition 1Authorisation and supervision in the third country
The TPSP is authorised or registered for the activity in the third country and is supervised there by a competent authority (para. 70 a).
- 2Condition 2Cooperation agreement between the authorities
An appropriate cooperation agreement exists between the financial entity’s competent authority and the third-country supervisor, such as a memorandum of understanding or a college agreement (para. 70 b).
- 3Condition 3Four minimum rights for the supervisor
The agreement secures for the EU supervisor at least: information on request, access to data, documents, premises and personnel in the third country, the earliest possible notification of suspected breaches, and cooperation in enforcement (para. 70 c).
Risk analysis (Section 11.2)
| Dimension | What to assess | Para. |
|---|---|---|
| Risk types | Operational, reputational, legal and concentration risk at the level of the financial entity; the result feeds into the decision whether to entrust the function to a third party at all | 71 |
| Own capabilities | Impact on risk identification, compliance and auditability; on services to clients; size and complexity of the business area concerned; scalability without a new contract | 72 a–d |
| Substitutability and reintegration | Transferability to another TPSP — contractually and in practice — with risks, obstacles, costs and timeframe; possibility of bringing the function back in-house | 72 e–f |
| Data | Confidentiality, availability and integrity; GDPR compliance | 72 g |
| Scenarios | Scenario analysis including severe operational events; smaller entities qualitatively, large ones with internal and external loss data; documentation and net effect on the risk level | 73 |
| Costs, benefits, concentration | A TPSP that is hard to replace, several contracts with the same or affiliated TPSPs, aggregated risks also at consolidated level or within the IPS, step-in risk for significant institutions, mitigating measures on both sides | 74 |
| Subcontracting | Additional risks from subcontractors in third countries or in countries other than the TPSP’s; long chains reduce the ability to monitor and supervise | 75 |
| Location | EU or non-EU; political stability and security situation; data protection law at GDPR level, law enforcement, insolvency law and obstacles to an urgent recovery; group membership and ability to exert influence | 76 |
Due diligence (Section 11.3)
- The depth of the review is proportionate to the criticality of the function (para. 77).
- For every TPSP: business model, size, complexity, financial strength, ownership and group structure; operational and technical capability and track record; group membership; supervisory status (para. 78).
- For critical or important functions, additionally: reputation, expertise, capacity and resources; internal controls and risk management including supply chain risks; geographical dependencies; business continuity, contingency and disaster recovery plans; required authorisations over the term of the contract; effective auditability, including on site, by the institution, its appointees and the competent authority (para. 79).
- The planned use of subcontractors for material parts must be taken into account (para. 80); where personal or confidential data are involved, the TPSP’s technical and organisational measures must be reviewed (para. 81).
The fifth assessment step — conflicts of interest — follows Section 7 (paras. 51–53) and must be documented with particular care for intra-group TPSPs.
The Contract: Minimum Content for All Arrangements and for Critical Functions
Section 12 of the Guidelines (para. 83–86) sets out what every written third-party arrangement must contain — and which clauses are added as soon as a critical or important function is involved. For CRD institutions there is also a resolution dimension that many contract templates have yet to accommodate.
Para. 83 requires the rights and obligations of the financial entity and the third-party service provider (TPSP) to be clearly allocated and set out in writing. The consequence: framework agreement, individual call-off and service schedule must together cover the minimum content of para. 84 — for every arrangement within scope, regardless of criticality.
Ten mandatory elements for every arrangement (para. 84 a–j)
| Letter | Contractual content under para. 84 | Practical pointer |
|---|---|---|
| a | A clear and comprehensive description of the non-ICT service; whether subcontracting of a critical or important function, or material parts thereof, is permitted and under which conditions pursuant to Section 12.1 | Link the service description to the subcontracting rule |
| b | Locations (regions or countries) where the service is provided, with the applicable conditions; obligation of the TPSP to notify any intended change of location | Location clause with a notice period |
| c | Governing law of the contract | also register field para. 62 a |
| d | Location of data processing, including storage | Data map per arrangement |
| e | Provisions on the availability, authenticity, integrity and confidentiality of data, including personal data | Name the protection objectives explicitly |
| f | Access to, recovery and return of the entity's own data on the TPSP's insolvency, resolution or discontinuation of business, and on contract termination | Specify return format and deadline |
| g | Service level descriptions, including updates and revisions | Version-control the SLA |
| h | Obligation of the TPSP to cooperate fully with the competent and resolution authorities of the financial entity and with the persons appointed by them | Cooperation clause without reservation |
| i | Termination rights and associated notice periods pursuant to Section 12.3 | see Chapter 11 |
| j | For CRD institutions: a clear reference to the powers of the national resolution authority, in particular Art. 68 and 71 BRRD, and a description of the contract's “substantive obligations” within the meaning of Art. 68 BRRD | Add the resolution clause to the template |
Six additional clauses for critical or important functions (para. 85 a–f)
| Letter | Additional clause under para. 85 | What matters |
|---|---|---|
| a | Agreed service levels with precise quantitative and/or qualitative performance targets so that the financial entity can monitor promptly and correct any shortfall without undue delay | measurable targets instead of best-efforts clauses |
| b | Notification periods and reporting obligations of the TPSP, including notification of any development that may materially affect its ability to perform; where appropriate, provision of its internal audit reports | define reporting thresholds and cadence |
| c | Whether the TPSP must take out mandatory insurance against certain risks, and the level of cover | state the sum insured |
| d | Obligation of the TPSP to implement and test business continuity plans | request test evidence |
| e | Right to ongoing monitoring: unrestricted access and audit rights for the financial entity and competent authorities under Section 12.2, alternative assurance levels where other clients are affected, duty to cooperate in on-site inspections, details of scope, procedures and frequency | no restriction on multi-client grounds |
| f | Exit strategy with a mandatory appropriate transition period during which the TPSP continues to perform so that the financial entity can migrate or bring the function back in-house | Tie the transition period to complexity |
Para. 86 adds, in particular for TPSPs in third countries: without prejudice to the GDPR (Regulation (EU) 2016/679), differences in national data protection law must be taken into account. The contract obliges the TPSP to protect confidential, personal and otherwise sensitive information and to comply with all data protection obligations that apply to the financial entity itself — expressly including banking secrecy and comparable duties of confidentiality towards clients.
Maintain elements a–j and a–f as a clause checklist per contract, linked to the register fields (para. 61–62). Missing elements in legacy contracts are precisely what has to be renegotiated during the two-year transitional period (para. 19–20).
Subcontracting: Notification, Objection, Chain Rights, Termination Triggers
Section 12.1 (para. 87–95) governs the conditions under which a third-party service provider may subcontract critical or important functions, in whole or in material parts. The mechanism is a procedure of notification, deadline and decision with clear termination triggers — and it extends to the last link in the chain.
Para. 87 sets the frame: the arrangement specifies whether subcontracting is permitted and under which conditions. Subcontractors do not diminish the ultimate responsibility of the management body. Financial entities need a “clear and holistic view” of the chain and focus on those subcontractors that effectively underpin the non-ICT service — whoever does so is recorded in the register under para. 88 (para. 62 c).
What the contract must stipulate on subcontracting (para. 89 a–j)
- a — activities excluded from subcontracting
- b — conditions to be complied with in the event of subcontracting
- c — obligation of the TPSP to assess and manage the location risks of current or potential subcontractors, their parent company and the place of service provision
- d — obligation of the TPSP to monitor subcontracted functions so that all contractual obligations continue to be met
- e — reporting obligations of the TPSP regarding subcontractors of critical or important functions
- f — obligation of the TPSP to embed in its subcontracts the subcontractors' monitoring and reporting duties towards it and, where agreed, towards the financial entity
- g — continuity obligation: the TPSP secures the function across the entire chain, even where a subcontractor breaches its obligations
- h — chain rights: the subcontractor grants the financial entity and the competent and resolution authorities the same access, inspection and audit rights as the TPSP
- i — contractual amendments required to comply with EU law and these Guidelines are implemented by the subcontractor in a timely manner
- j — the financial entity documents and communicates the timetable for such amendments
The procedure: notification, deadline, decision (para. 90–94)
- 1Step 1Notification by the TPSPpara. 90
The TPSP notifies new subcontracts and intended material changes early enough for the financial entity to assess the impact on its risks and on the TPSP's ability to perform the contract.
- 2Step 2Appropriate notice periodpara. 91
The contract contains an appropriate notice period within which the financial entity may approve or object.
- 3Step 3Assessment against risk tolerancepara. 93
Where the subcontracting or the change exceeds the risk tolerance, the financial entity informs the TPSP before the deadline expires, objects and requests amendments — before the subcontract is concluded or the change is implemented.
- 4Step 4Implementation only after approval or expiry of the deadlinepara. 92
The TPSP may conclude the subcontract or implement the change only once the financial entity has approved, or has not objected by the end of the notice period.
- 5Step 5Ongoing identification and monitoringpara. 94
The TPSP identifies all subcontractors and monitors those providing critical or important functions or material parts thereof.
The chain thereby becomes an object of scrutiny. Para. 75 already requires the risk analysis to treat subcontractors in third countries and long, complex chains as a risk in their own right, because they reduce the ability of financial entities and supervisors to monitor. The register lists the subcontractors of material parts together with their rank in the chain (para. 62 c; for the fields see Chapter 6). Whoever does not receive this data does not have a chain problem but a contract problem.
Borderline case with DORA: ICT subcontractors of a non-ICT service provider that effectively underpin its service for a critical or important function also belong in the non-ICT register under para. 58 — the boundary runs along the main service, not along the chain.
Access, Information and Audit Rights: Pooled Audits, Certificates, Limits
Section 12.2 (para. 96–107) ensures that financial entities, competent and resolution authorities can actually audit a third-party service provider. Certificates, audit reports and joint audits are permitted — but only under eight conditions and never as a permanent substitute for the entity's own audits.
Para. 96 starts with the entity's own organisation: the contract must enable the internal audit function to review the function performed by the TPSP on a risk-based approach. Para. 97 applies to CRD institutions regardless of criticality: every contract refers to the information and investigatory powers of the competent and resolution authorities under Article 63(1)(a) BRRD and Article 65(3) CRD — for TPSPs in a Member State and in third countries alike.
Access and information rights (para. 98 a)
For critical or important functions, the TPSP grants the financial entity, its competent and resolution authorities and any person appointed by them access to all relevant business premises, together with the right to obtain copies of relevant information and documents where these are critical to the TPSP's operations.
Audit rights (para. 98 b)
In addition, there are unrestricted rights of inspection and audit in relation to the arrangement, in order to monitor it and ensure compliance with all regulatory and contractual requirements. Para. 100 prohibits any contractual design that impedes or restricts the effective exercise of these rights.
Non-critical functions (para. 99)
For other services, the same rights are to be considered on a risk-based approach — by nature of the function, operational and reputational risks, scalability, impact on continuing operations and contract duration. Express reminder: functions may become critical or important over time.
Under para. 101, financial entities determine audit frequency and scope on a risk-based approach and follow recognised audit standards. To use audit resources more efficiently, para. 102 permits two tools: pooled audits together with other clients of the same TPSP or by a jointly appointed third party, and third-party certifications and audit reports or reports of the TPSP's internal audit function.
The eight conditions for certificates and audit reports (para. 104 a–h)
| Condition | Requirement for the financial entity |
|---|---|
| a | It is satisfied with the audit plan for the TPSP's services. |
| b | The scope covers the identified systems — processes, applications, infrastructure, data centres — and key controls, as well as compliance with regulatory requirements. |
| c | It thoroughly assesses the content on an ongoing basis and ensures that certificates and reports are not obsolete. |
| d | Key systems and controls remain covered in future versions. |
| e | It is satisfied with the aptitude of the auditing party — rotation, qualification, expertise, re-performance of evidence in the audit file. |
| f | Certificates and audits are issued against widely recognised professional standards and test the operational effectiveness of key controls. |
| g | It has the contractual right to request an expansion of scope to other systems and controls; the number and frequency of such requests must be reasonable from a risk perspective. |
| h | It retains the contractual right to perform individual audits at its discretion for critical or important functions. |
For pooled audits, para. 103 b additionally requires sufficient information and involvement in scoping, planning, execution and reporting.
Before planned on-site visits, the TPSP receives reasonable notice, except in emergency or crisis situations or where notice would render the audit ineffective (para. 105). In multi-client environments, risks to other clients — service levels, data availability, confidentiality — are to be avoided or mitigated (para. 106). Where complexity is high, the financial entity must verify that its own internal audit function, the audit pool or appointed external parties have the necessary skills; the same applies to the staff who evaluate certificates and third-party audits (para. 107).
Monitoring, Termination Rights and Exit Strategies
Sections 12.3, 13 and 14 (para. 108–116) close the lifecycle: those who measure continuously can terminate in time — and those who can terminate need a tested way out. The Guidelines require indicators with trigger thresholds that set the exit in motion.
Under para. 108, termination rights must exist, in line with applicable law, in five situations among others. For critical or important functions, para. 109 requires the contract to facilitate the transfer to another TPSP or reintegration: the obligations of the existing TPSP in the event of a transfer, including the handling of data, an appropriate transition period during which it continues to perform after termination, and a duty to support an orderly transition.
- para. 108 a — a material breach by the TPSP of applicable laws, regulations or contractual provisions
- para. 108 b — circumstances identified through monitoring that may alter the performance of the service
- para. 108 c — material changes such as subcontracting or a change of subcontractors
- para. 108 d — evidenced weaknesses in the TPSP's risk management or in the security of confidential, personal, otherwise sensitive or non-personal data
- para. 108 e — the competent authority can no longer effectively supervise the financial entity as a result of the contractual terms
Under para. 110, monitoring is risk-based and, for critical or important functions, ongoing. The risk analysis under Section 11.2 is updated regularly, the management body receives periodic risk reports, and where the risk, nature or scope of a function changes materially, its criticality is reassessed. Para. 111 requires internal concentration risks to be monitored — including subcontractors. Where deficiencies are identified or anticipated, corrective measures are to be taken or the contract is to be terminated (para. 113).
| Instrument (para. 112) | Purpose | Practical example |
|---|---|---|
| Reports from the TPSP (para. 112 a) | regular information base | performance report with SLA status and incidents |
| Key performance indicators | make the SLA performance targets (para. 85 a) measurable | on-time delivery, processing rate, error rate |
| Key control indicators | track the effectiveness of the TPSP's controls | closed findings, subcontractor notifications made on time |
| Service delivery reports | document delivery quality and capacity | volumes, backlog, escalations |
| Self-certifications | confirmation of contractual and regulatory compliance | annual compliance statement with notification of changes |
| Independent reviews | external validation of controls | audit report under para. 104 with scope reconciliation |
| BCP reports and tests (para. 112 c) | demonstrate resilience in the event of disruption | test record with recovery times achieved |
The examples are VamiSec suggestions — the Guidelines name the instruments, not the metrics.
Under para. 114, exit strategies are to be documented for all critical or important functions, in line with the strategy and business continuity plans, and consider at least six scenarios. Para. 115 requires an exit without undue disruption to the business, without limiting compliance and without detriment to clients: exit plans are realistic, feasible, based on plausible scenarios, documented and, where appropriate, sufficiently tested — for instance through a cost, impact, resource and timing analysis of a transfer. Alternative solutions and transition plans take account of data location and ensure continuity during the transition period.
- para. 114 a — termination of the third-party arrangement
- para. 114 b — failure of the TPSP
- para. 114 c — concentration risk at entity level and a potentially difficult exit
- para. 114 d — deterioration of quality and actual or potential business disruption caused by failed service delivery
- para. 114 e — material risks to the continuous provision of the function
- para. 114 f — a material breach by the TPSP of laws, regulations or contractual terms
Para. 116 also requires the scenario analysis under para. 73 to be incorporated, the objectives of the exit strategy to be defined, roles, responsibilities and sufficient resources to be assigned, and success criteria to be set for the transfer of the services and of the data held by the TPSP.
What Supervisors Assess: SREP, Concentration, Empty Shell, Intervention Powers
Title V (para. 117–128) is addressed to competent authorities — and is therefore the best mirror of what financial entities can expect in the SREP dialogue. Supervisors assess substance, resources and concentrations, and may intervene up to and including a forced exit.
Three questions come first: does an arrangement amount to a material change in the conditions of the initial authorisation (para. 117)? Can the authority effectively supervise the financial entity — in particular because the contracts require the TPSP to grant access and audit rights under Section 12.2 (para. 118)? And where does the analysis take place? At least in the SREP; for payment institutions, in other supervisory processes such as ad hoc requests or on-site inspections (para. 119).
Detailed risk analysis (para. 120 a)
Beyond the register, supervisors may request the detailed risk analysis of arrangements for critical or important functions — that is, the analysis under Section 11.2 with scenarios (para. 73) and concentration risks (para. 74).
Business continuity plan of the TPSP (para. 120 b)
The question is whether the TPSP has a business continuity plan that is suitable for the services provided to the financial entity.
Exit strategy (para. 120 c)
The exit strategy for the event that either party terminates or the provision of the service is interrupted.
Resources and monitoring (para. 120 d, 121)
The resources and measures with which the financial entity monitors the TPSP. Under para. 121, supervisors may request details of any arrangement — including non-critical ones.
| Area of review | What supervisors assess on a risk-based approach | Para. |
|---|---|---|
| Governance | Are arrangements — above all for critical or important functions — adequately monitored and managed? | 122 a |
| Resources | Are the resources sufficient to monitor and manage critical arrangements? | 122 b |
| Risk identification | Are all relevant risks identified and managed? | 122 c |
| Conflicts of interest | Are conflicts identified and managed, for instance in intra-group or IPS-internal arrangements? | 122 d, 124 g |
| Operational and reputational risks | Risks arising from the arrangement for operations and reputation | 124 a–b |
| Step-in risk | For significant institutions: would the institution have to support a TPSP in distress? | 124 c |
| Concentration within the institution | Several arrangements with one TPSP, closely connected TPSPs or in the same business area — also on a consolidated basis | 124 d |
| Concentration within the sector | Do several financial entities use the same TPSP or a small group of TPSPs? | 124 e |
| Control over the TPSP | To what extent does the financial entity control or influence the TPSP; is it included in consolidated supervision? | 124 f |
Supervisors keep identified concentration risks under observation and assess their impact on other financial entities and on the stability of the financial system; they notify the resolution authority of new potentially critical functions within the meaning of the BRRD (para. 125). Where critical or important functions are performed outside the EU/EEA, the authority must be satisfied of its ability to supervise effectively (para. 127). Authorities cooperate closely and exchange information in a timely manner — particularly on sectoral concentration (para. 128).
Intervention powers are graduated (para. 126): where robust governance or regulatory compliance is lacking, supervisors may limit the scope of non-ICT services for critical or important functions or require the exit from one or more arrangements. Where effective supervision cannot otherwise be ensured, termination or temporary suspension of contracts comes into consideration — taking into account the need to continue operations.
For the SREP dialogue: the EBA decided against ex-ante approval (cost-benefit analysis, Option B: high-level principles). Instead, timely information and, where appropriate, supervisory dialogue on planned critical arrangements apply (para. 65), together with the register in a processable electronic format on request (para. 63).
One Framework for ICT and Non-ICT: the Integration Architecture
The Guidelines expressly aim for a holistic approach across ICT and non-ICT service providers. Anyone who has implemented DORA since 17 January 2025 already has the role, policy, register, contractual clauses and exit tests in place — the question is how much of it can be reused for non-ICT.
The Executive Summary states the objective: closing the gap with DORA, enabling a holistic approach and aligning both frameworks closely — for a level playing field and supervisory convergence (p. 4). The definition of the critical or important function is “fully consistent” with DORA (p. 5, para. 17). Three passages expressly permit consolidation (role, policy, register); two further building blocks follow from the parallelism of the two regimes.
One role (para. 44 c, fn. 46)
The role for overseeing all non-ICT arrangements may be combined with the function that oversees ICT third-party arrangements under Article 5(3) DORA. One mandate, two rulebooks.
One policy (para. 49)
The non-ICT policy may be merged with the policy under Article 28(10) DORA (RTS, Delegated Regulation (EU) 2024/1773) — but must distinguish between ICT and non-ICT, supervised and non-supervised TPSPs, intra-group and external, and Member State and third country.
One register (para. 61, 63)
The non-ICT register should be consistent, as far as possible, with the register of information under Article 28(3) DORA; the two may be combined into a single register. For submission, the format of the DORA ITS (Implementing Regulation (EU) 2024/2956) is permitted.
One clause library (para. 84–85, Article 30 DORA)
Both regimes define minimum contractual content. A shared library with non-ICT modules (BRRD reference, mandatory insurance, subcontracting notification) saves negotiation rounds.
One exit test calendar (para. 115, Article 28 DORA)
Exit strategies for ICT and non-ICT can be run in a single test calendar that reveals concentrations across both worlds.
| Topic | DORA (ICT) | EBA/GL/2026/09 (non-ICT) | Same / Different |
|---|---|---|---|
| Legal nature | Regulation (EU) 2022/2554, applicable since 17 January 2025 | Guidelines; authorities declare within two months whether they comply or intend to comply (p. 68); date of application follows publication of the translations (date open) | Different |
| Subject matter | ICT services under Article 3(21) DORA | Non-ICT services (para. 5–7); hybrid cases by materiality of the ICT component (para. 32) | Different — complementary |
| Critical or important function | Article 3(22) DORA | Para. 17, consistent with DORA | Same |
| Role | Article 5(3) DORA | Para. 44 c, may be combined (fn. 46) | Same |
| Policy | Article 28(10) DORA, RTS Delegated Regulation (EU) 2024/1773 | Para. 47–50, may be merged subject to four distinctions (para. 49) | Same with additions |
| Register | Register of information, Article 28(3) DORA, templates of Implementing Regulation (EU) 2024/2956 | Non-ICT register with 9 + 8 fields (para. 61–62), consolidation optional, DORA ITS format permitted (para. 63) | Same structure, different fields |
| Direct oversight of service providers | Oversight of critical ICT third-party service providers, Articles 31–44 DORA | No counterpart — Title V governs the supervision of financial entities, not of TPSPs (para. 117–128) | Different |
Methodologically, ISO/IEC 27001:2022 with controls A.5.19 to A.5.23 (supplier relationships, security in supplier agreements, ICT supply chain, monitoring and change management of supplier services, cloud usage) and ISO/IEC 27036 (information security for supplier relationships) provide the control framework for mapping both regimes in a single management system — in platforms such as VamiGRC as one data model with two views.
Consolidation is an option, not an obligation (para. 49, 61). Anyone maintaining two registers should avoid discrepancies (para. 61) — in practice, that means a single data source.
The Implementation Programme: 2-Year Roadmap, 90-Day Start, KPIs, Transitional Period
The Guidelines apply from a date that will only be set once the translations are published; from then on, two years run for the review of critical or important arrangements (para. 18–20). This chapter translates the deadline logic into five phases, measurable KPIs and a prepared supervisory dialogue.
From the date of application, the Guidelines apply to all arrangements entered into, reviewed or amended on or after that date (para. 18); existing arrangements are to be reviewed and amended (para. 19). For critical or important functions, a two-year transitional period applies — anyone not finished by then informs the competent authority of the planned measures or a possible exit strategy (para. 20). Non-critical arrangements are reviewed only upon renewal (para. 21). The EBA deliberately chose this Option B2 to reduce renegotiation pressure (pp. 58–59).
- 1Phase 0Mobilisation — before the date of applicationpara. 38–44
Mandate from the management body, role under para. 44 c (combined with the DORA role), inventory of all non-ICT contracts, gap analysis against para. 84–85, 61–62 and 48–49, decision on the integration architecture.
- 2Phase 1The first 90 days from the date of applicationpara. 31–37, 61
Three-step test and criticality for all arrangements, basic register fields (para. 61), prioritisation of critical contracts by renewal date, approved policy (para. 47), process for new arrangements — para. 18 applies to them immediately — and reporting channel to the competent authority (para. 65).
- 3Phase 2Months 4–12: contract and chainpara. 84–95, 98
Renegotiation of critical arrangements: clause set para. 84–85, subcontracting rules para. 89–95, audit rights para. 98, subcontractor data para. 62 c, updated due diligence (para. 77–82), additional register fields (para. 62), KPI/KCI reporting (para. 112).
- 4Phase 3Months 13–24: exit tests and evidencepara. 56, 101–104, 115
Test exit plans where appropriate (para. 115), internal audit plan (para. 56), first own or pooled audits (para. 101–104), reports to the management body (para. 110) — and where the review will not finish in time, supervisory dialogue before month 24 (para. 20).
- 5Phase 4From month 24: steady statepara. 21, 47, 110, 119
Bring non-critical arrangements into line upon renewal (para. 21), review the policy annually (para. 47), reassess criticality upon material changes (para. 110), deliver the register electronically on request (para. 63), SREP readiness (para. 119).
| KPI | Target | Reference |
|---|---|---|
| Arrangements with a documented three-step test | 100% | para. 31, 58 |
| Register coverage, basic fields (9) | 100% | para. 61 |
| Register coverage, additional fields (8) for critical/important | 100% before the end of the transitional period | para. 62, 20 |
| Critical arrangements with the complete clause set | 100% within 24 months | para. 84–85, 19–20 |
| Critical arrangements with unrestricted audit rights incl. chain | 100% | para. 98, 89 h |
| Exit plans in place / tested | 100% / by risk priority | para. 62 f, 115 |
| Subcontractor notifications assessed on time | 100% | para. 90–93 |
| Open audit findings past the follow-up deadline | 0 | para. 57 |
Targets are VamiSec programme objectives derived from the completeness logic of the Guidelines — not EBA requirements.
The programme scales with proportionality: less complex financial entities may assign the role to a member of the management body (para. 44 c), use qualitative risk analyses (para. 73) and maintain the register centrally within the group or IPS (para. 60).
Date of application: the Final Report contains the placeholder “[date]” (para. 18, 20, 22); the EBA lists the Guidelines as “final and awaiting translation”. Until the translations are published, month 0 is unknown — plan relative to the date of application and use the time for Phase 0.
Readiness Radar: how far along is your non-ICT third-party management?
Ten questions across five dimensions of the Guidelines. Each question is linked to the paragraph from which the requirement derives — the result shows your maturity level and biggest gaps.
- 01Governance & policypara. 38, 47Has your management body approved a third-party risk strategy including a written policy for non-ICT services supporting critical or important functions — and is it reviewed at least annually?
- 02Governance & policypara. 44Is there a designated role or member of senior management directly accountable to the management body for overseeing all third-party arrangements — with sufficient resources?
- 03Criticality & registerpara. 31–37Have you classified all non-ICT service providers using the three-step test and documented the reasoning for the criticality of each function?
- 04Criticality & registerpara. 58–63Do you maintain a register of all non-ICT arrangements with the nine basic fields and the eight additional fields for critical functions — consistent with the DORA register of information?
- 05Pre-contractual reviewpara. 68–79Before every new arrangement, do you run the pre-contractual analysis — criticality, supervisory conditions, risk analysis including concentration risk, due diligence, conflicts of interest?
- 06Pre-contractual reviewpara. 70, 76, 82For service providers in third countries, do you check authorisation, supervision, the cooperation agreement between the authorities, location risks, and ESG and human rights aspects?
- 07Contract & chainpara. 84–85, 98Do your contracts for critical or important functions contain all minimum contents of para. 84 and 85 — including unrestricted access and audit rights and an exit strategy with a transition period?
- 08Contract & chainpara. 87–95Do your contracts govern subcontracting with a notification duty, notice period, right to object, equivalent audit rights along the chain and a termination right for the subcontract?
- 09Monitoring & exitpara. 110–113Do you monitor critical arrangements on an ongoing basis with KPIs, key control indicators, reports and independent reviews — and report periodically to the management body?
- 10Monitoring & exitpara. 114–116Is there a documented and, where appropriate, tested exit strategy with alternative solutions and trigger indicators for every critical or important function?
Answer all ten questions — your result will appear here.
Your third-party management is still tailored to the 2019 outsourcing logic. Use the transitional period: start with the criticality methodology, the register and the oversight role — these are the foundations on which contract, monitoring and exit are built.
Governance and classification are largely in place; the gaps usually lie in contractual clauses, subcontracting and tested exit plans. Prioritise the arrangements supporting critical or important functions and bring their contracts into line first.
Your framework covers the core requirements. What counts now is integration with DORA — a shared role, policy and register — and the evidence: documented exit tests, a KPI history and a clean register export for the SREP.
No gaps — document your position for the SREP dialogue.
Third-Party Risk für CISOs — EBA Non-ICT Guidelines 2026
30 pages on EBA/GL/2026/09: what changes compared with the 2019 Outsourcing Guidelines, how non-ICT and DORA converge in a single framework and how you translate the two-year transitional period into a programme (German-language whitepaper).

- Ten key messages of the Guidelines with paragraph references — for the board paper
- Integration architecture: shared role, policy, register and exit tests for ICT and non-ICT
- Clause library under para. 84, 85 and 89 and the register data model with 9 + 8 fields
- 24-month programme with 90-day playbook, KPIs and supervisory dialogue under para. 20 and 65
The CISO whitepaper: Third-Party Risk für CISOs
Integration architecture with DORA
A shared oversight role under Art. 5(3) DORA and para. 44 c, a merged policy with the four distinctions of para. 49, a combined register under para. 61 — and the points where the regimes deliberately diverge.
Clause library for contracts
The minimum contents of para. 84 a–j and 85 a–f, the subcontracting clauses of para. 89–95 and the audit rights of para. 98 as building blocks for new contracts and addenda — including the BRRD reference for CRD institutions.
The register as a data model
The 9 + 8 fields of para. 61 and 62 as a field table with reference to the DORA ITS templates and the export format under para. 63 — as the basis for a spreadsheet, GRC tool or database.
24-month programme and 90-day playbook
Phases from stocktake to supervisory dialogue under para. 20 and 65, KPIs for tracking progress and the first 90 days as a concrete task list — with objections and answers for the board discussion.
Frequently asked questions on the EBA Third-Party Risk Guidelines
Answers to the questions financial entities have asked most often since publication — with paragraph references for further reading.
The date of application is still a placeholder in the Final Report: the Guidelines apply from a date to be set upon publication of the translations into all official EU languages (para. 18). The EBA currently lists them as final but not yet applicable. From the date of application, they cover all arrangements entered into, reviewed or amended thereafter; existing contracts must be adapted (para. 19). Competent authorities must notify the EBA within two months of publication whether they comply with the Guidelines. In Germany, the MaRisk as amended on 30 June 2026 still implement the 2019 Outsourcing Guidelines; an amendment of AT 9 is therefore still outstanding.
Yes — the circle of addressees has grown compared with 2019. Alongside credit institutions and CRD investment firms, the Guidelines address third-country branches, investment firms under MiFID II with the exception of small and non-interconnected firms under Art. 12(1) IFR, payment and e-money institutions, issuers of asset-referenced tokens (ARTs) under MiCAR, MCD creditors that are financial institutions, and approved financial holding companies (para. 9). Pure account information service providers are exempt (para. 11). Payment institutions apply the Guidelines on an individual basis (para. 14), ART issuers on an individual and, where applicable, group basis (para. 15). The cost-benefit analysis expects limited additional costs for the new addressees, because MiFID II, IFD and MiCAR already contain outsourcing requirements and all addressees are subject to DORA in any event.
Both definitions in para. 17 presuppose a recurrent or ongoing service; the difference lies in a single criterion: an outsourcing arrangement concerns a function the financial entity would otherwise perform itself — the third-party arrangement dispenses with that criterion. This brings services into scope that never appeared in an outsourcing register. In the Feedback Statement, the EBA notes that the outsourcing definition follows the 2019 Guidelines and the FSB toolkit, while the definition of a third-party arrangement follows the BCBS principles — DORA itself has no concept of outsourcing (p. 75). The Guidelines do not require outsourcing to be flagged separately; the register fields of para. 61 ask about criticality, not outsourcing status. The MaRisk distinction between outsourcing and other external procurement has no counterpart in the Guidelines.
No. Para. 61 expressly allows the non-ICT register and the register of information under Art. 28(3) DORA to be merged into a single register; the cost-benefit analysis deliberately opened up this option D (pp. 60–61). In the Feedback Statement, the EBA clarifies that the non-ICT register has fewer data points than the DORA register but should remain consistent for the information they share; the Guidelines do not go into the level of detail of Implementing Regulation (EU) 2024/2956, but their wording has been aligned with DORA (pp. 88–89). Those who keep two registers should avoid discrepancies (para. 61). In any case, the register must distinguish critical or important functions from the rest (para. 58) and keep terminated arrangements documented for an appropriate period — the five-year retention period envisaged in the draft was aligned with DORA (para. 59; p. 90).
As a building block, yes; as a substitute, no. Para. 102 allows certifications, the service provider’s internal or external audit reports and pooled audits to be used. For critical or important functions, however, financial entities must assess whether this evidence is sufficient and may not rely on it exclusively over time (para. 103). Para. 104 attaches eight conditions to its use: the audit scope must cover the systems and key controls identified by the institution, the reports must not be out of date, the auditors must be suitable, the audit must test the effectiveness of the controls, and the institution needs the contractual right to extend the scope and to conduct its own audits. A certificate therefore does not replace the unrestricted audit right under para. 98.
Intra-group arrangements are subject to the same framework as external ones — in the background section of the Final Report, the EBA stresses that they are not automatically less risky. The selection of a group entity must rest on objective grounds, and the terms, including prices, must be set objectively; synergies may be priced in as long as the service provider remains independently viable (para. 53). Conflicts of interest must be expressly managed (para. 52). Relief is available on the organisational side: registers, pre-contractual analysis, business continuity plans and exit plans may be kept centrally within the group or the institutional protection scheme, provided each financial entity receives summaries and, on request, the complete documentation (para. 28, 54, 60). The greater control over a group entity may be taken into account in the risk analysis (para. 76 e).
The third-country dimension shapes the entire life cycle — beyond the pre-contractual conditions of para. 70, 76 and 82. The policy distinguishes service providers in Member States from those in third countries (para. 49 d). The contract names the locations of service provision with a duty to notify changes (para. 84 b) and commits the service provider to your level of data protection and banking secrecy (para. 86); in the event of subcontracting, it assesses the location risks of its own subcontractors (para. 89 c). For CRD institutions, the reference to the authorities’ investigatory powers applies to third-country service providers as well (para. 97). The register records the country of service provision and the subcontractors’ country of registration (para. 61 i, 62 c). The competent authority must be able to supervise effectively where critical functions are performed outside the EEA (para. 127) — the background section calls for additional safeguards to that end (Background para. 22).
The Guidelines do not provide for an automatic breach, but for supervisory dialogue. If the review and documentation of arrangements supporting critical or important functions have not been completed two years after the date of application, the financial entity informs its competent authority accordingly — including the measures planned to complete them or a possible exit strategy (para. 20). The EBA deliberately chose this variant in the cost-benefit analysis because contracts cannot always be renegotiated within a rigid deadline. There is no deadline for non-critical arrangements; review and documentation can take place at renewal (para. 21). Recommendation: prioritise the critical arrangements by remaining contract term and negotiating power, and document progress continuously.
Standards & Sources
The content on this page is based on the following publicly available guides and studies.
Final Report on Guidelines on the sound management of third-party risk regarding non-ICT services (EBA/GL/2026/09) ↗
Primary source for this page — 98 pages including the cost-benefit analysis and the Feedback Statement on consultation EBA/CP/2025/12
Press release: The EBA publishes its final Guidelines on the management of third-party risk ↗
18 September 2026 — status “final and awaiting translation”, two-year transitional period
Consultation Paper EBA/CP/2025/12 — Draft Guidelines on the sound management of third-party risk ↗
Consultation from 8 July to 8 October 2025, public hearing on 5 September 2025, 72 responses
Guidelines on outsourcing arrangements (EBA/GL/2019/02) ↗
Previous framework of 25 February 2019, applicable from 30 September 2019 — repealed as of the date of application of the new Guidelines (para. 22)
Regulation (EU) 2022/2554 ↗
DORA — framework for ICT third-party risk (Art. 28–30), register of information (Art. 28(3)), applicable since 17 January 2025
Delegated Regulation (EU) 2024/1773 ↗
RTS on the content of the policy on ICT services supporting critical or important functions (Art. 28(10) DORA) — reference point for the merger under para. 49
Directive 2013/36/EU ↗
CRD — Art. 74(3) as the EBA’s mandate for guidelines on institutions’ governance arrangements
Regulation (EU) 2023/1114 ↗
MiCAR — addressees: issuers of asset-referenced tokens (ARTs); EBA mandate under Art. 34
Directive (EU) 2015/2366 ↗
PSD2 — payment institutions as addressees; mandate under Art. 11, notification duty under Art. 19(6)
Principles for the sound management of third-party risk ↗
Published on 10 December 2025 — international reference framework according to the EBA’s cost-benefit analysis
Enhancing Third-Party Risk Management and Oversight: A toolkit for financial institutions and financial authorities ↗
Final Report of 4 December 2023 — taken into account by the EBA in the cost-benefit analysis
Principles on third-party risks supervision ↗
12 June 2025 — supervisory principles addressed to ESMA and national competent authorities, non-binding
Want to manage non-ICT third-party risk and DORA in a single framework?
VamiSec supports financial entities with criticality assessments, registers, contract remediation and exit testing — for ICT and non-ICT service providers within one shared framework.