Book an Appointment

EBA Third-Party Risk Guidelines 2026: Managing non-ICT third-party providers under DORA logic

With EBA/GL/2026/09, the EBA replaces its 2019 Outsourcing Guidelines with a framework for the entire third-party risk arising from non-ICT services — focused on critical or important functions, a register modelled on the DORA register of information and a two-year transitional period. This page puts the Guidelines in context, draws the line to DORA and makes the requirements tangible with a Scope Navigator, a Register Builder and a Readiness Radar.

Last updated: September 2026 · Valeri Milke, ISO 27001 & ISO 42001 Lead Auditor

You will receive the download link immediately on the page and by e-mail.

2 yearsTransitional period from the date of application for reviewing and documenting arrangements supporting critical or important functions (para. 20)
72Responses to consultation EBA/CP/2025/12 — consultation closed on 8 October 2025, plus the opinion of the Banking Stakeholder Group
17Minimum fields in the non-ICT register for critical or important functions: 9 basic fields (para. 61) plus 8 additional fields (para. 62)
2019The EBA Outsourcing Guidelines of 25 February 2019 are repealed as of the date of application (para. 22)

On 18 September 2026, the European Banking Authority published the Final Report EBA/GL/2026/09 on the “Guidelines on the sound management of third-party risk regarding non-ICT services”. In doing so, the EBA follows through on DORA: since 17 January 2025, Regulation (EU) 2022/2554 has governed ICT third-party risk, while all other services have remained subject to the 2019 Outsourcing Guidelines until their repeal — with different terms, different register fields and a different logic. The new Guidelines close that gap, adopt the DORA definition of a critical or important function and explicitly expect financial entities to take a holistic approach across ICT and non-ICT (para. 7). The date of application has not yet been set; it will be fixed once the translations into all official EU languages are published. Anyone reviewing contracts, registers and exit plans today is making use of the two-year transitional period rather than being caught out by it. This page condenses the 128 paragraphs of the Guidelines into nine core concepts, links every statement to its paragraph and offers three interactive tools for classifying your own arrangements. For a deeper dive, the whitepaper “Third-Party Risk für CISOs” (German-language whitepaper) sets out the integration architecture with DORA, a clause library and a 24-month programme.

From the cloud recommendations to a third-party risk framework

Nine years of European regulation of third-party risk — the milestones leading to EBA/GL/2026/09. The date of application will only be set once the translations are published.

Nine core concepts of the EBA Guidelines

Click a card to read the core concept with paragraph references — the order follows the structure of the Guidelines, from scope to supervision.

The life cycle of a third-party arrangement

Titles II and IV of the Guidelines follow the contract cycle — from classification to exit. Select a phase to see the core requirements with paragraph references.

para. 31–37
  • The three-step test determines whether a contract is a third-party arrangement at all: non-ICT, recurrent or ongoing, support of a function (para. 31).
  • For non-ICT services with an ICT component, the financial entity decides whether the ICT component is material — if so, DORA applies (para. 32).
  • The exclusion list in para. 33 removes, among others, the statutory audit, payment networks, SWIFT, the procurement of goods and utilities from the scope.
  • Always critical or important: functions whose disruption would materially impair the conditions of authorisation, financial performance or continuity (para. 34), operational tasks of internal control functions (para. 35) and activities requiring authorisation (para. 36).
  • BRRD institutions additionally examine the link to critical functions and core business lines (para. 37).
Three-step testArt. 3(22) DORApara. 33 exclusionsControl functions
Interactive

Scope Navigator: which regime applies to your arrangement?

Five questions along para. 31–37 — from the DORA boundary to subcontracting. The result shows which requirements of the Guidelines apply to your arrangement.

Your path
  1. ?

1: Is the service an ICT service within the meaning of Art. 3(21) DORA — or is its ICT component material to its provision?

1

Is the service an ICT service within the meaning of Art. 3(21) DORA — or is its ICT component material to its provision?

ICT services fall under DORA Chapter V, not under the Guidelines (para. 7). For non-ICT services with an ICT component, you decide yourself whether that component is material to the provision of the service (para. 32, ESAs’ Q&As DORA030/095).

Interactive

Register Builder: which fields your non-ICT register needs

Para. 61 requires nine minimum fields for all arrangements, para. 62 eight additional fields for critical or important functions. Tick off what your register covers today — and copy the header row for your CSV template.

Mandatory fields for all arrangements (para. 61)

Applies to every third-party arrangement within scope — including non-critical ones. Consistency with the DORA register of information under Art. 28(3) is to be ensured as far as possible; both registers may be merged into one.

Additional fields for critical or important functions (para. 62)

Only for arrangements supporting critical or important functions — in addition to the nine basic fields. These fields feed directly into the substitutability and exit assessment and answer the questions supervisors typically ask.

Deep Dive · 14 Chapters

EBA/GL/2026/09 in Detail: The Guidelines Chapter by Chapter

Scope, criticality, governance, policy, register, contract, subcontracting, audit rights, monitoring, exit, supervision, DORA integration and implementation programme — every statement referenced to the paragraph (para.) of the Final Report of 18 September 2026.

01Chapter 1

From the Outsourcing Guidelines 2019 to the Third-Party Risk Framework 2026

On 18 September 2026 the EBA published the Final Report on EBA/GL/2026/09. The Guidelines replace the Outsourcing Guidelines of 25 February 2019 and widen the lens to third-party risk as a whole — confined to non-ICT services, because ICT services have fallen under DORA since 17 January 2025.

Financial entities rely ever more heavily on third-party service providers (TPSPs) — and in doing so increase the risks to themselves, their clients and, in individual cases, the financial system (p. 4). The EBA draws two conclusions: outsourcing becomes a subset of the broader third-party arrangement (para. 17), and the gap to DORA is closed — DORA governs ICT third-party risk, the Guidelines govern non-ICT third-party risk, with the expectation of a holistic approach spanning both worlds (para. 7; Background section para. 11).

The legal basis lies in the governance mandates of the sectoral legal acts: Art. 74(3) CRD, Art. 26 IFD, Art. 34 MiCAR and Art. 11 PSD2 (Background section para. 15; Feedback p. 67). Formally, these are guidelines under Art. 16 of Regulation (EU) No 1093/2010: competent authorities and financial entities must make every effort to comply with them, and each competent authority declares within two months whether it applies the Guidelines (paras. 1–3; Feedback p. 68).

FeatureEBA/GL/2019/02 (Outsourcing)EBA/GL/2026/09 (Third-Party Risk)
Date25 February 2019, applicable from 30 September 201918 September 2026; date of application follows publication of the translations (date open)
Subject matterOutsourcing of functions, including cloud (EBA/REC/2017/03 integrated)All recurrent or ongoing non-ICT third-party arrangements; outsourcing as a subset (para. 17)
ICTCoveredExcluded — ICT services under Art. 3(21) DORA fall under Chapter V DORA (para. 7)
AddresseesCRD institutions, payment and e-money institutionsAdditionally IFD investment firms (Class 1 minus, Class 2), MCD creditors and ART issuers (para. 9)
RegisterRegister of all outsourcing arrangements9 basic fields for all non-ICT arrangements plus 8 additional fields for critical or important functions; merger with the DORA register of information permitted (paras. 61–62)
StatusRepealed as of the date of application of the new Guidelines (para. 22)Final; translation into the official EU languages under way

Sources: Final Report p. 55, paras. 9, 17, 22, 61–62; EBA press release of 18 September 2026.

Internationally, the EBA builds on the FSB toolkit of 4 December 2023 and the BCBS Principles for the sound management of third-party risk of 10 December 2025, which the definition of the third-party arrangement follows (pp. 55, 59; Feedback p. 75); the ESMA Principles on third-party risks of 12 June 2025 are addressed to national competent authorities only (Feedback p. 66).

The consultation on EBA/CP/2025/12 ran from 8 July to 8 October 2025 and drew 72 responses (Feedback p. 65). The EBA rejected criticism of its mandate and allegations of double regulation (pp. 67–68); on proportionality it gave ground — a focus on critical or important functions, a leaner register, proportionality criteria in Title I (pp. 68–69). It answered the call for a lead time of nine to eighteen months with the two-year transitional period; those who cannot complete in time inform the competent authority (p. 78; para. 20).

The date of application is a placeholder in the Final Report: the Guidelines apply from a date set upon publication of the translations to all arrangements entered into, reviewed or amended on or after that day (para. 18); existing arrangements must be reviewed and adapted (para. 19).

02Chapter 2

Scope: Addressees, Non-ICT, Exclusions, Hybrid Cases

The Guidelines address a markedly wider circle of addressees than in 2019 and capture every recurrent or ongoing non-ICT service that supports a function. Just as important is what they do not capture: ICT services, services required by law and a long list of low-risk purchases.

The subject matter is the governance arrangements that apply where third-party service providers deliver non-ICT services in support of functions — with a focus on critical or important functions (para. 5); “support” includes the full performance of the function (fn. 20). ICT services under Art. 3(21) DORA are excluded because they fall under Chapter V DORA (para. 7). Competent authorities review the arrangements in the SREP under Art. 97 CRD and its counterparts in the IFD, PSD2, EMD and MiCAR (para. 6).

AddresseeBasisLevel of application
Credit institutions and CRD investment firms (institutions under Art. 4(1)(3) CRR)Para. 9; Art. 74 CRDIndividual, sub-consolidated and consolidated level; waiver under Art. 21 or 109(1) CRD possible (para. 13)
Third-country branches under Art. 47 CRDParas. 9–10Proportionate; instead of a contract with the head office, SLAs or policies suffice (para. 10)
MiFID II investment firms other than small and non-interconnected firms under Art. 12(1) IFRPara. 9; Art. 26 IFDClass 1 minus and Class 2: individual, sub-consolidated and consolidated where relevant; Class 2 consolidated under Art. 25 IFD (para. 13)
Payment and e-money institutionsParas. 9, 12; Art. 11 PSD2Individual level (para. 14)
Issuers of asset-referenced tokens (ART)Para. 9; Art. 34 MiCARIndividual level, group-wide where relevant (para. 15)
MCD creditors that are financial institutionsPara. 9; Art. 4(2) MCDNot separately regulated (paras. 13–15)
Financial holding companies and mixed financial holding companies approved under Art. 21a CRDPara. 9; Art. 3(3) CRDNot separately regulated (para. 9)
Not addressedPara. 11; Background section para. 9; Feedback pp. 68, 75Pure account information service providers, credit intermediaries, crypto-asset service providers (CASPs; Art. 73 MiCAR applies), central securities depositories (CSDR)

What is not captured: the exclusions in para. 33

  • Services that must by law be provided by a third party — such as the statutory audit
  • Regulated financial services that are required by law to be provided by another financial entity regulated under EU law, for example custody or trading venues
  • Market information services — added at the request of consultation respondents (Feedback p. 79)
  • Financial transactions between financial institutions as counterparties and with central banks
  • Payment network infrastructures such as Visa, Mastercard, Wero or GIE CB, as well as clearing and settlement arrangements between clearing houses, central counterparties, settlement institutions and their members
  • Global financial messaging infrastructures under regulatory oversight, such as SWIFT, as well as correspondent banking
  • Services with no material impact on risk or resilience: architects, printing, legal opinions, legal representation, PR, cleaning, building maintenance, medical services, fleet management, catering, canteen, office, travel, postal and reception services
  • Procurement of goods (plastic cards, card readers, office supplies, PCs, furniture) and utilities (electricity, gas, water, telephone)

It is the service that is excluded, not the provider: a supervised financial entity that delivers other services is a TPSP like any other; its supervised status feeds into proportionality and the risk analysis (pp. 69–71). Nor do the exclusions dispense with risk management — appropriate steps remain expected (fn. 41).

Intra-group service providers and central service providers of an institutional protection scheme (IPS) are TPSPs — with no special regime, since intra-group arrangements are not per se lower-risk (Background section para. 19; Feedback p. 71); flexibility comes from centralised functions under paras. 26–30. An intra-group TPSP located in a third country is to be treated as a third-country TPSP in the risk analysis (Feedback p. 75).

03Chapter 3

The Three-Step Test and the Critical or Important Function

Whether an arrangement falls under the full regime is decided by a three-step test — and, at its core, by the question of whether the supported function is critical or important. The definition mirrors DORA word for word; the EBA adds three presumption rules that tip the balance in practice.

The test belongs within holistic risk management across all business lines and internal units (para. 31). It is run before every engagement (para. 68 a) and must be anchored in the policy as a planning step (para. 48 d).

  1. Step 1Is this a non-ICT service?

    If the service is an ICT service under Art. 3(21) DORA, or if its ICT component is material to its provision, DORA applies (paras. 31 a, 32). Everything else stays in the test.

  2. Step 2Is a function supported on a recurrent or ongoing basis?

    A function is any process, service or activity — or part thereof (para. 17). One-off purchases are not a third-party arrangement (para. 31 b). Then check the exclusions under para. 33.

  3. Step 3Is the function critical or important?

    Only then do the policy (para. 47), the additional register fields (para. 62), enhanced due diligence (para. 79), enhanced contractual clauses (para. 85), unrestricted audit rights (para. 98) and the exit plan (para. 114) apply. All other arrangements are subject to the basic regime (para. 31 c).

A function is critical or important where its disruption would materially impair the financial performance of the financial entity, the soundness or continuity of its services and activities, or its continuing compliance with the conditions of its authorisation and other obligations under financial services law (para. 17). The wording corresponds to Art. 3(22) DORA (Background section para. 13). It is not identical to the “critical functions” under Art. 2(1)(35) BRRD, but encompasses them (fn. 35; Background section para. 13).

CriterionRule in the GuidelinesRelationship to DORA
Basic definitionMaterial impairment of the conditions of authorisation, financial performance, or soundness and continuity (paras. 17, 34 a–c)Verbatim Art. 3(22) DORA
Operational tasks of internal control functionsAlways critical or important — unless the assessment demonstrates that a failure would not impair the effectiveness of the control function (para. 35)EBA presumption rule for non-ICT
Functions requiring authorisationBanking activities, payment services or ART issuance on a scale requiring authorisation: automatically critical or important (para. 36)EBA presumption rule; linked to the supervisory conditions in Section 11.1 (paras. 69–70)
Resolution relevance (BRRD institutions)Functions underpinning critical functions or core business lines (criteria of Delegated Regulation (EU) 2016/778, Arts. 6–7) are deemed critical or important unless the assessment demonstrates no material impact (para. 37)EBA presumption rule; resolvability must not be impaired (Background section para. 27)
Sub-functionsPart of a function can also be critical or important (para. 17; Feedback p. 76)Assessment by the financial entity itself (Feedback p. 77)
MethodologyThe financial entity sets the criteria or methodology (Background section para. 16; para. 48 d iii); the result and a brief rationale are recorded in the register (para. 61 f)No rigid catalogue of criteria — option C of the cost-benefit analysis, to avoid tick-the-box (p. 61)

An arrangement covering several functions — for instance operational tasks of risk management and regulatory reporting — must be assessed jointly in all its aspects (para. 32).

04Chapter 4

Governance: Management Body, Role, Empty-Shell Ban, Proportionality, Groups and IPS

The Guidelines rest on a simple principle: responsibility cannot be outsourced. The management body remains fully responsible for every arrangement, needs a designated role for oversight — and must not let the entity become an empty shell.

The management body defines, approves and regularly reviews a third-party risk strategy that includes the policy under Section 6 and complements operational risk management and operational resilience; integrated or separate strategies for ICT and non-ICT are permitted (para. 38; Feedback p. 83). The use of TPSPs never results in a delegation of responsibility (para. 41) and lowers neither the suitability requirements for the management body and senior management nor the need for competent resources (para. 43). Para. 42 a–h lists what the management body remains responsible for at all times — from the conditions of authorisation through strategies, risk appetite and conflict-of-interest policies to the oversight of all third-party risks, the business continuity policy and the audit plans of internal audit.

The role (para. 44 c)

A role to oversee all third-party arrangements, or a member of senior management directly accountable to the management body. It may be combined with the role for ICT third parties under Art. 5(3) DORA (fn. 46). Less complex entities ensure at least a clear division of tasks and may assign the role to a member of the management body. Typical holders are the risk management or compliance function (Feedback pp. 84–85).

Empty-shell ban (para. 45)

Financial entities must retain sufficient substance at all times and must not become “empty shells” or “letter-box entities”: meeting the conditions of authorisation, maintaining a transparent organisational structure that can be audited and supervised, effectively overseeing outsourced tasks of the control functions — including intra-group — and holding the knowledge, resources and capacity to do so (para. 45 a–d).

Minimum safeguards (para. 46)

Taking decisions on the business and critical functions itself; preserving the orderly conduct of banking, investment and payment services; identifying and managing risks; ensuring confidentiality; maintaining the flow of information with the TPSP; being able to transfer or reintegrate critical or important functions within an appropriate timeframe, or to discontinue the dependent business; GDPR compliance within the EU and in third countries (para. 46 a–g).

Proportionality and group structures

Proportionality means that governance arrangements must fit the risk profile, nature, business model, scale and complexity of the activities (para. 23). The yardstick for each arrangement is the complexity of the function, the risks, criticality and the impact on continuity (para. 24); the criteria in Title I of the EBA governance guidelines under the CRD, IFD and MiCAR apply accordingly (para. 25).

SituationRequirementPara.
Group under Art. 109(2) CRDApplication also at consolidated and sub-consolidated level; the parent undertaking ensures consistent, integrated arrangements across all subsidiaries — including payment institutions, investment firms and ART issuers26
Intra-group or intra-IPS TPSPsThe management body of each financial entity remains fully responsible; outsourced operational tasks of the control functions must be performed effectively, evidenced by appropriate reports27
Centralised monitoringFor critical or important functions: independent monitoring plus each institution’s own oversight; at least annual reports on risk assessment and performance; summary of the audit reports, the full report on request; information to the management body on planned changes28 a–b
Centralised pre-contractual analysis, central register, central exit planEach institution receives a summary and takes its own structure into account; the individual register must be retrievable without delay; the exit plan must actually be executable28 c–e
Waiver under Art. 21 or 109(1) CRD in conjunction with Art. 7 CRRApplication by the parent undertaking for itself and its subsidiaries, or by the central body together with its members as a whole; without a waiver, application at individual level29–30
05Chapter 5

The Policy along the Lifecycle — and How It Merges with the DORA Policy

For non-ICT services supporting critical or important functions, the EBA requires a written policy approved by the management body that covers the entire lifecycle. It may be merged with the DORA policy under Art. 28(10) DORA — but must then make four distinctions visible.

The policy must be reviewed at least annually and updated where necessary; changes are to be implemented in the contractual relationships promptly and as soon as possible, and the management body ensures implementation at individual, sub-consolidated and consolidated level (para. 47). The EBA rejected the request to drop the annual cycle — it is not burdensome where nothing has changed, and it is consistent with DORA (Feedback p. 85). Whether the 2019 outsourcing policy and the new policy form a single document is left to the financial entity.

Lifecycle phaseMinimum content of the policyPara. 48
ResponsibilityTasks of the management body under paras. 38 and 42, including its involvement in decisions on critical or important functionsa
ParticipantsInvolvement of business lines, internal control functions and other personsb
RoleDesignation of the role or the senior management member responsible for monitoring, cooperation with the control functions, reporting lines to the management body with content, documents and frequencyc
PlanningScope test, business requirements, criteria and process for critical or important functions, risk analysis (Section 11.2), due diligence (Section 11.3), conflicts of interest (Section 7), business continuity (Section 8), approval processd i–viii
OperationPerformance monitoring (Section 13), procedures for notifying and responding to changes — financial situation, ownership structure, subcontracting —, independent review, renewal processese i–iv
DocumentationRegister and record-keeping under Section 10f
ExitExit strategies and termination processes, including a documented exit plan for each critical or important arrangement (Section 14)g

In addition, the policy must capture the impact of critical or important functions placed with TPSPs on four areas and feed it into decision-making: the risk profile, the ability to oversee the TPSP and manage risks, business continuity measures and business performance (para. 50).

Common core

Governance, the role under para. 44 c and Art. 5(3) DORA, lifecycle, reporting lines and register governance — written once, valid for both worlds.

ICT module

The content of Delegated Regulation (EU) 2024/1773 for ICT services supporting critical or important functions.

Non-ICT module

The content under para. 48 a–g, the supervisory conditions under Section 11.1 and the exclusion test under para. 33.

Differentiation matrix

For each rule, state whether it applies identically or differently to ICT and non-ICT, supervised and unsupervised, internal and external, and EU and third-country TPSPs — this is the evidence for para. 49.

Three adjacent sections belong to the policy in substance. Conflicts of interest must be identified, assessed and managed; for intra-group TPSPs the terms, including the price, must be objective, and synergies may be priced in as long as the TPSP remains viable on a standalone basis — within a group, independently of the failure of other group entities (paras. 51–53). Business continuity requires regularly tested plans that involve the TPSP and a business impact analysis with quantitative and qualitative criteria, scenario analysis and a view on substitutability (paras. 54–55). Internal audit reviews on a risk-based approach, includes critical arrangements in the audit plan, assesses the framework, the criticality and risk assessments, the involvement of governing bodies and monitoring, and runs a formal follow-up process for findings (paras. 56–57).

06Chapter 6

The Non-ICT Register: 9 + 8 Fields, Consistency with DORA, Provision to Supervisors

The register is the data model of the Guidelines: nine basic fields for every non-ICT arrangement, eight additional fields for critical or important functions — as consistent as possible with the DORA register of information, with which it may be merged.

The register covers all third-party arrangements within scope — at individual, sub-consolidated and consolidated level — and distinguishes critical or important functions from the rest; ICT subcontractors of a non-ICT TPSP that effectively underpin a critical or important service belong in it (para. 58). Terminated arrangements remain documented for an appropriate period; the five-year retention period originally planned was aligned with DORA (para. 59; Feedback p. 90). Groups and IPSs may maintain the register centrally, provided each institution receives its individual register without delay (paras. 60, 28 d).

FieldContentApplies toPara.
Reference and contract typeReference number; contract type “Standalone arrangement”, “Overarching arrangement” or “Subsequent or associated arrangement” — the latter with the reference number of the framework agreementAll61 a
DurationStart date, next renewal date, end date with reason for terminationAll61 b
Using entitiesFor a central register: financial entities within the scope of consolidation or the IPS that use the TPSP (para. 60)All61 c
Group linkWhether the TPSP or subcontractor belongs to the group or IPS, or is owned by group entities or IPS membersAll61 d
Function descriptionBrief description of the functions provided by the TPSPAll61 e
CriticalityYes/no: critical or important function — with a brief rationale where applicableAll61 f
CategoryInternal category of the function; several categories where several functions are coveredAll61 g
Service providerName, identifier (LEI, EUID or alternative), company registration number, address, contact details, ultimate parent undertaking with identifierAll61 h
Place of provisionCountry or countries where the service is provided (wording: of the critical or important function)All61 i
Governing lawLaw governing the arrangementCritical/important62 a
AuditsDates of the most recent audits — internal audits; for audits by the TPSP, the most recent one (Feedback p. 91)Critical/important62 b
SubcontractorsFor material parts: name, country of registration, identifier, subcontracted part, rank in the chain, place of provisionCritical/important62 c
SubstitutabilityResult and date of the last assessment: “easy”, “medium”, “highly complex” or “impossible to substitute”Critical/important62 d
Reintegration and RTO/RPOSummary and date of the last assessment on reintegration or discontinuation — with the RTO and RPO of the functionCritical/important62 e
Exit planYes/no: exit plan in placeCritical/important62 f
AlternativesAlternative TPSPs, where possibleCritical/important62 g
CostsEstimated annual costs of the previous year, with currencyCritical/important62 h

Contract types and substitutability levels follow the wording of the Final Report; fields aligned with DORA and Implementing Regulation (EU) 2024/2956 (Feedback pp. 89–91).

Provision to supervisors and notifications

On request, the competent authority receives the register in full or in part in a processable electronic format — the format of the DORA ITS, such as a database format or CSV, is permitted (para. 63) — together with all necessary information, up to and including copies of contracts (para. 64). Planned arrangements supporting critical or important functions, and any case in which a function becomes critical or important, must be notified in good time, where appropriate within the supervisory dialogue, with at least the information set out in paras. 61 and 62 (para. 65); the same applies to material changes and severe events (para. 66). Assessments and monitoring results must be documented (para. 67). The Guidelines set no deadline; centralised notifications from groups are possible (Feedback pp. 77–78, 92).

07Chapter 7

Pre-Contractual Analysis: Supervisory Conditions, Risk Analysis, Due Diligence

Before a contract is signed, the Guidelines require five assessment steps: criticality, supervisory conditions, risk analysis, due diligence and conflicts of interest (para. 68). For third-country service providers, strict authorisation and cooperation conditions are added.

Functions requiring authorisation — banking activities, payment services, the issuance of ART or investment services under Art. 4(2) MiFID II on a scale that requires authorisation or registration — may only be entrusted to a TPSP that is authorised or registered for them, or otherwise permitted to perform them under national law (para. 69; Section 11.1). If the TPSP is located in a third country, three cumulative conditions apply (para. 70):

  1. Condition 1Authorisation and supervision in the third country

    The TPSP is authorised or registered for the activity in the third country and is supervised there by a competent authority (para. 70 a).

  2. Condition 2Cooperation agreement between the authorities

    An appropriate cooperation agreement exists between the financial entity’s competent authority and the third-country supervisor, such as a memorandum of understanding or a college agreement (para. 70 b).

  3. Condition 3Four minimum rights for the supervisor

    The agreement secures for the EU supervisor at least: information on request, access to data, documents, premises and personnel in the third country, the earliest possible notification of suspected breaches, and cooperation in enforcement (para. 70 c).

Risk analysis (Section 11.2)

DimensionWhat to assessPara.
Risk typesOperational, reputational, legal and concentration risk at the level of the financial entity; the result feeds into the decision whether to entrust the function to a third party at all71
Own capabilitiesImpact on risk identification, compliance and auditability; on services to clients; size and complexity of the business area concerned; scalability without a new contract72 a–d
Substitutability and reintegrationTransferability to another TPSP — contractually and in practice — with risks, obstacles, costs and timeframe; possibility of bringing the function back in-house72 e–f
DataConfidentiality, availability and integrity; GDPR compliance72 g
ScenariosScenario analysis including severe operational events; smaller entities qualitatively, large ones with internal and external loss data; documentation and net effect on the risk level73
Costs, benefits, concentrationA TPSP that is hard to replace, several contracts with the same or affiliated TPSPs, aggregated risks also at consolidated level or within the IPS, step-in risk for significant institutions, mitigating measures on both sides74
SubcontractingAdditional risks from subcontractors in third countries or in countries other than the TPSP’s; long chains reduce the ability to monitor and supervise75
LocationEU or non-EU; political stability and security situation; data protection law at GDPR level, law enforcement, insolvency law and obstacles to an urgent recovery; group membership and ability to exert influence76

Due diligence (Section 11.3)

  • The depth of the review is proportionate to the criticality of the function (para. 77).
  • For every TPSP: business model, size, complexity, financial strength, ownership and group structure; operational and technical capability and track record; group membership; supervisory status (para. 78).
  • For critical or important functions, additionally: reputation, expertise, capacity and resources; internal controls and risk management including supply chain risks; geographical dependencies; business continuity, contingency and disaster recovery plans; required authorisations over the term of the contract; effective auditability, including on site, by the institution, its appointees and the competent authority (para. 79).
  • The planned use of subcontractors for material parts must be taken into account (para. 80); where personal or confidential data are involved, the TPSP’s technical and organisational measures must be reviewed (para. 81).

The fifth assessment step — conflicts of interest — follows Section 7 (paras. 51–53) and must be documented with particular care for intra-group TPSPs.

08Chapter 8

The Contract: Minimum Content for All Arrangements and for Critical Functions

Section 12 of the Guidelines (para. 83–86) sets out what every written third-party arrangement must contain — and which clauses are added as soon as a critical or important function is involved. For CRD institutions there is also a resolution dimension that many contract templates have yet to accommodate.

Para. 83 requires the rights and obligations of the financial entity and the third-party service provider (TPSP) to be clearly allocated and set out in writing. The consequence: framework agreement, individual call-off and service schedule must together cover the minimum content of para. 84 — for every arrangement within scope, regardless of criticality.

Ten mandatory elements for every arrangement (para. 84 a–j)

LetterContractual content under para. 84Practical pointer
aA clear and comprehensive description of the non-ICT service; whether subcontracting of a critical or important function, or material parts thereof, is permitted and under which conditions pursuant to Section 12.1Link the service description to the subcontracting rule
bLocations (regions or countries) where the service is provided, with the applicable conditions; obligation of the TPSP to notify any intended change of locationLocation clause with a notice period
cGoverning law of the contractalso register field para. 62 a
dLocation of data processing, including storageData map per arrangement
eProvisions on the availability, authenticity, integrity and confidentiality of data, including personal dataName the protection objectives explicitly
fAccess to, recovery and return of the entity's own data on the TPSP's insolvency, resolution or discontinuation of business, and on contract terminationSpecify return format and deadline
gService level descriptions, including updates and revisionsVersion-control the SLA
hObligation of the TPSP to cooperate fully with the competent and resolution authorities of the financial entity and with the persons appointed by themCooperation clause without reservation
iTermination rights and associated notice periods pursuant to Section 12.3see Chapter 11
jFor CRD institutions: a clear reference to the powers of the national resolution authority, in particular Art. 68 and 71 BRRD, and a description of the contract's “substantive obligations” within the meaning of Art. 68 BRRDAdd the resolution clause to the template

Six additional clauses for critical or important functions (para. 85 a–f)

LetterAdditional clause under para. 85What matters
aAgreed service levels with precise quantitative and/or qualitative performance targets so that the financial entity can monitor promptly and correct any shortfall without undue delaymeasurable targets instead of best-efforts clauses
bNotification periods and reporting obligations of the TPSP, including notification of any development that may materially affect its ability to perform; where appropriate, provision of its internal audit reportsdefine reporting thresholds and cadence
cWhether the TPSP must take out mandatory insurance against certain risks, and the level of coverstate the sum insured
dObligation of the TPSP to implement and test business continuity plansrequest test evidence
eRight to ongoing monitoring: unrestricted access and audit rights for the financial entity and competent authorities under Section 12.2, alternative assurance levels where other clients are affected, duty to cooperate in on-site inspections, details of scope, procedures and frequencyno restriction on multi-client grounds
fExit strategy with a mandatory appropriate transition period during which the TPSP continues to perform so that the financial entity can migrate or bring the function back in-houseTie the transition period to complexity

Para. 86 adds, in particular for TPSPs in third countries: without prejudice to the GDPR (Regulation (EU) 2016/679), differences in national data protection law must be taken into account. The contract obliges the TPSP to protect confidential, personal and otherwise sensitive information and to comply with all data protection obligations that apply to the financial entity itself — expressly including banking secrecy and comparable duties of confidentiality towards clients.

Maintain elements a–j and a–f as a clause checklist per contract, linked to the register fields (para. 61–62). Missing elements in legacy contracts are precisely what has to be renegotiated during the two-year transitional period (para. 19–20).

09Chapter 9

Subcontracting: Notification, Objection, Chain Rights, Termination Triggers

Section 12.1 (para. 87–95) governs the conditions under which a third-party service provider may subcontract critical or important functions, in whole or in material parts. The mechanism is a procedure of notification, deadline and decision with clear termination triggers — and it extends to the last link in the chain.

Para. 87 sets the frame: the arrangement specifies whether subcontracting is permitted and under which conditions. Subcontractors do not diminish the ultimate responsibility of the management body. Financial entities need a “clear and holistic view” of the chain and focus on those subcontractors that effectively underpin the non-ICT service — whoever does so is recorded in the register under para. 88 (para. 62 c).

What the contract must stipulate on subcontracting (para. 89 a–j)

  • a — activities excluded from subcontracting
  • b — conditions to be complied with in the event of subcontracting
  • c — obligation of the TPSP to assess and manage the location risks of current or potential subcontractors, their parent company and the place of service provision
  • d — obligation of the TPSP to monitor subcontracted functions so that all contractual obligations continue to be met
  • e — reporting obligations of the TPSP regarding subcontractors of critical or important functions
  • f — obligation of the TPSP to embed in its subcontracts the subcontractors' monitoring and reporting duties towards it and, where agreed, towards the financial entity
  • g — continuity obligation: the TPSP secures the function across the entire chain, even where a subcontractor breaches its obligations
  • h — chain rights: the subcontractor grants the financial entity and the competent and resolution authorities the same access, inspection and audit rights as the TPSP
  • i — contractual amendments required to comply with EU law and these Guidelines are implemented by the subcontractor in a timely manner
  • j — the financial entity documents and communicates the timetable for such amendments

The procedure: notification, deadline, decision (para. 90–94)

  1. Step 1Notification by the TPSPpara. 90

    The TPSP notifies new subcontracts and intended material changes early enough for the financial entity to assess the impact on its risks and on the TPSP's ability to perform the contract.

  2. Step 2Appropriate notice periodpara. 91

    The contract contains an appropriate notice period within which the financial entity may approve or object.

  3. Step 3Assessment against risk tolerancepara. 93

    Where the subcontracting or the change exceeds the risk tolerance, the financial entity informs the TPSP before the deadline expires, objects and requests amendments — before the subcontract is concluded or the change is implemented.

  4. Step 4Implementation only after approval or expiry of the deadlinepara. 92

    The TPSP may conclude the subcontract or implement the change only once the financial entity has approved, or has not objected by the end of the notice period.

  5. Step 5Ongoing identification and monitoringpara. 94

    The TPSP identifies all subcontractors and monitors those providing critical or important functions or material parts thereof.

The chain thereby becomes an object of scrutiny. Para. 75 already requires the risk analysis to treat subcontractors in third countries and long, complex chains as a risk in their own right, because they reduce the ability of financial entities and supervisors to monitor. The register lists the subcontractors of material parts together with their rank in the chain (para. 62 c; for the fields see Chapter 6). Whoever does not receive this data does not have a chain problem but a contract problem.

Borderline case with DORA: ICT subcontractors of a non-ICT service provider that effectively underpin its service for a critical or important function also belong in the non-ICT register under para. 58 — the boundary runs along the main service, not along the chain.

10Chapter 10

Access, Information and Audit Rights: Pooled Audits, Certificates, Limits

Section 12.2 (para. 96–107) ensures that financial entities, competent and resolution authorities can actually audit a third-party service provider. Certificates, audit reports and joint audits are permitted — but only under eight conditions and never as a permanent substitute for the entity's own audits.

Para. 96 starts with the entity's own organisation: the contract must enable the internal audit function to review the function performed by the TPSP on a risk-based approach. Para. 97 applies to CRD institutions regardless of criticality: every contract refers to the information and investigatory powers of the competent and resolution authorities under Article 63(1)(a) BRRD and Article 65(3) CRD — for TPSPs in a Member State and in third countries alike.

Access and information rights (para. 98 a)

For critical or important functions, the TPSP grants the financial entity, its competent and resolution authorities and any person appointed by them access to all relevant business premises, together with the right to obtain copies of relevant information and documents where these are critical to the TPSP's operations.

Audit rights (para. 98 b)

In addition, there are unrestricted rights of inspection and audit in relation to the arrangement, in order to monitor it and ensure compliance with all regulatory and contractual requirements. Para. 100 prohibits any contractual design that impedes or restricts the effective exercise of these rights.

Non-critical functions (para. 99)

For other services, the same rights are to be considered on a risk-based approach — by nature of the function, operational and reputational risks, scalability, impact on continuing operations and contract duration. Express reminder: functions may become critical or important over time.

Under para. 101, financial entities determine audit frequency and scope on a risk-based approach and follow recognised audit standards. To use audit resources more efficiently, para. 102 permits two tools: pooled audits together with other clients of the same TPSP or by a jointly appointed third party, and third-party certifications and audit reports or reports of the TPSP's internal audit function.

The eight conditions for certificates and audit reports (para. 104 a–h)

ConditionRequirement for the financial entity
aIt is satisfied with the audit plan for the TPSP's services.
bThe scope covers the identified systems — processes, applications, infrastructure, data centres — and key controls, as well as compliance with regulatory requirements.
cIt thoroughly assesses the content on an ongoing basis and ensures that certificates and reports are not obsolete.
dKey systems and controls remain covered in future versions.
eIt is satisfied with the aptitude of the auditing party — rotation, qualification, expertise, re-performance of evidence in the audit file.
fCertificates and audits are issued against widely recognised professional standards and test the operational effectiveness of key controls.
gIt has the contractual right to request an expansion of scope to other systems and controls; the number and frequency of such requests must be reasonable from a risk perspective.
hIt retains the contractual right to perform individual audits at its discretion for critical or important functions.

For pooled audits, para. 103 b additionally requires sufficient information and involvement in scoping, planning, execution and reporting.

Before planned on-site visits, the TPSP receives reasonable notice, except in emergency or crisis situations or where notice would render the audit ineffective (para. 105). In multi-client environments, risks to other clients — service levels, data availability, confidentiality — are to be avoided or mitigated (para. 106). Where complexity is high, the financial entity must verify that its own internal audit function, the audit pool or appointed external parties have the necessary skills; the same applies to the staff who evaluate certificates and third-party audits (para. 107).

11Chapter 11

Monitoring, Termination Rights and Exit Strategies

Sections 12.3, 13 and 14 (para. 108–116) close the lifecycle: those who measure continuously can terminate in time — and those who can terminate need a tested way out. The Guidelines require indicators with trigger thresholds that set the exit in motion.

Under para. 108, termination rights must exist, in line with applicable law, in five situations among others. For critical or important functions, para. 109 requires the contract to facilitate the transfer to another TPSP or reintegration: the obligations of the existing TPSP in the event of a transfer, including the handling of data, an appropriate transition period during which it continues to perform after termination, and a duty to support an orderly transition.

  • para. 108 a — a material breach by the TPSP of applicable laws, regulations or contractual provisions
  • para. 108 b — circumstances identified through monitoring that may alter the performance of the service
  • para. 108 c — material changes such as subcontracting or a change of subcontractors
  • para. 108 d — evidenced weaknesses in the TPSP's risk management or in the security of confidential, personal, otherwise sensitive or non-personal data
  • para. 108 e — the competent authority can no longer effectively supervise the financial entity as a result of the contractual terms

Under para. 110, monitoring is risk-based and, for critical or important functions, ongoing. The risk analysis under Section 11.2 is updated regularly, the management body receives periodic risk reports, and where the risk, nature or scope of a function changes materially, its criticality is reassessed. Para. 111 requires internal concentration risks to be monitored — including subcontractors. Where deficiencies are identified or anticipated, corrective measures are to be taken or the contract is to be terminated (para. 113).

Instrument (para. 112)PurposePractical example
Reports from the TPSP (para. 112 a)regular information baseperformance report with SLA status and incidents
Key performance indicatorsmake the SLA performance targets (para. 85 a) measurableon-time delivery, processing rate, error rate
Key control indicatorstrack the effectiveness of the TPSP's controlsclosed findings, subcontractor notifications made on time
Service delivery reportsdocument delivery quality and capacityvolumes, backlog, escalations
Self-certificationsconfirmation of contractual and regulatory complianceannual compliance statement with notification of changes
Independent reviewsexternal validation of controlsaudit report under para. 104 with scope reconciliation
BCP reports and tests (para. 112 c)demonstrate resilience in the event of disruptiontest record with recovery times achieved

The examples are VamiSec suggestions — the Guidelines name the instruments, not the metrics.

Under para. 114, exit strategies are to be documented for all critical or important functions, in line with the strategy and business continuity plans, and consider at least six scenarios. Para. 115 requires an exit without undue disruption to the business, without limiting compliance and without detriment to clients: exit plans are realistic, feasible, based on plausible scenarios, documented and, where appropriate, sufficiently tested — for instance through a cost, impact, resource and timing analysis of a transfer. Alternative solutions and transition plans take account of data location and ensure continuity during the transition period.

  • para. 114 a — termination of the third-party arrangement
  • para. 114 b — failure of the TPSP
  • para. 114 c — concentration risk at entity level and a potentially difficult exit
  • para. 114 d — deterioration of quality and actual or potential business disruption caused by failed service delivery
  • para. 114 e — material risks to the continuous provision of the function
  • para. 114 f — a material breach by the TPSP of laws, regulations or contractual terms

Para. 116 also requires the scenario analysis under para. 73 to be incorporated, the objectives of the exit strategy to be defined, roles, responsibilities and sufficient resources to be assigned, and success criteria to be set for the transfer of the services and of the data held by the TPSP.

12Chapter 12

What Supervisors Assess: SREP, Concentration, Empty Shell, Intervention Powers

Title V (para. 117–128) is addressed to competent authorities — and is therefore the best mirror of what financial entities can expect in the SREP dialogue. Supervisors assess substance, resources and concentrations, and may intervene up to and including a forced exit.

Three questions come first: does an arrangement amount to a material change in the conditions of the initial authorisation (para. 117)? Can the authority effectively supervise the financial entity — in particular because the contracts require the TPSP to grant access and audit rights under Section 12.2 (para. 118)? And where does the analysis take place? At least in the SREP; for payment institutions, in other supervisory processes such as ad hoc requests or on-site inspections (para. 119).

Detailed risk analysis (para. 120 a)

Beyond the register, supervisors may request the detailed risk analysis of arrangements for critical or important functions — that is, the analysis under Section 11.2 with scenarios (para. 73) and concentration risks (para. 74).

Business continuity plan of the TPSP (para. 120 b)

The question is whether the TPSP has a business continuity plan that is suitable for the services provided to the financial entity.

Exit strategy (para. 120 c)

The exit strategy for the event that either party terminates or the provision of the service is interrupted.

Resources and monitoring (para. 120 d, 121)

The resources and measures with which the financial entity monitors the TPSP. Under para. 121, supervisors may request details of any arrangement — including non-critical ones.

Area of reviewWhat supervisors assess on a risk-based approachPara.
GovernanceAre arrangements — above all for critical or important functions — adequately monitored and managed?122 a
ResourcesAre the resources sufficient to monitor and manage critical arrangements?122 b
Risk identificationAre all relevant risks identified and managed?122 c
Conflicts of interestAre conflicts identified and managed, for instance in intra-group or IPS-internal arrangements?122 d, 124 g
Operational and reputational risksRisks arising from the arrangement for operations and reputation124 a–b
Step-in riskFor significant institutions: would the institution have to support a TPSP in distress?124 c
Concentration within the institutionSeveral arrangements with one TPSP, closely connected TPSPs or in the same business area — also on a consolidated basis124 d
Concentration within the sectorDo several financial entities use the same TPSP or a small group of TPSPs?124 e
Control over the TPSPTo what extent does the financial entity control or influence the TPSP; is it included in consolidated supervision?124 f

Supervisors keep identified concentration risks under observation and assess their impact on other financial entities and on the stability of the financial system; they notify the resolution authority of new potentially critical functions within the meaning of the BRRD (para. 125). Where critical or important functions are performed outside the EU/EEA, the authority must be satisfied of its ability to supervise effectively (para. 127). Authorities cooperate closely and exchange information in a timely manner — particularly on sectoral concentration (para. 128).

Intervention powers are graduated (para. 126): where robust governance or regulatory compliance is lacking, supervisors may limit the scope of non-ICT services for critical or important functions or require the exit from one or more arrangements. Where effective supervision cannot otherwise be ensured, termination or temporary suspension of contracts comes into consideration — taking into account the need to continue operations.

For the SREP dialogue: the EBA decided against ex-ante approval (cost-benefit analysis, Option B: high-level principles). Instead, timely information and, where appropriate, supervisory dialogue on planned critical arrangements apply (para. 65), together with the register in a processable electronic format on request (para. 63).

13Chapter 13

One Framework for ICT and Non-ICT: the Integration Architecture

The Guidelines expressly aim for a holistic approach across ICT and non-ICT service providers. Anyone who has implemented DORA since 17 January 2025 already has the role, policy, register, contractual clauses and exit tests in place — the question is how much of it can be reused for non-ICT.

The Executive Summary states the objective: closing the gap with DORA, enabling a holistic approach and aligning both frameworks closely — for a level playing field and supervisory convergence (p. 4). The definition of the critical or important function is “fully consistent” with DORA (p. 5, para. 17). Three passages expressly permit consolidation (role, policy, register); two further building blocks follow from the parallelism of the two regimes.

One role (para. 44 c, fn. 46)

The role for overseeing all non-ICT arrangements may be combined with the function that oversees ICT third-party arrangements under Article 5(3) DORA. One mandate, two rulebooks.

One policy (para. 49)

The non-ICT policy may be merged with the policy under Article 28(10) DORA (RTS, Delegated Regulation (EU) 2024/1773) — but must distinguish between ICT and non-ICT, supervised and non-supervised TPSPs, intra-group and external, and Member State and third country.

One register (para. 61, 63)

The non-ICT register should be consistent, as far as possible, with the register of information under Article 28(3) DORA; the two may be combined into a single register. For submission, the format of the DORA ITS (Implementing Regulation (EU) 2024/2956) is permitted.

One clause library (para. 84–85, Article 30 DORA)

Both regimes define minimum contractual content. A shared library with non-ICT modules (BRRD reference, mandatory insurance, subcontracting notification) saves negotiation rounds.

One exit test calendar (para. 115, Article 28 DORA)

Exit strategies for ICT and non-ICT can be run in a single test calendar that reveals concentrations across both worlds.

TopicDORA (ICT)EBA/GL/2026/09 (non-ICT)Same / Different
Legal natureRegulation (EU) 2022/2554, applicable since 17 January 2025Guidelines; authorities declare within two months whether they comply or intend to comply (p. 68); date of application follows publication of the translations (date open)Different
Subject matterICT services under Article 3(21) DORANon-ICT services (para. 5–7); hybrid cases by materiality of the ICT component (para. 32)Different — complementary
Critical or important functionArticle 3(22) DORAPara. 17, consistent with DORASame
RoleArticle 5(3) DORAPara. 44 c, may be combined (fn. 46)Same
PolicyArticle 28(10) DORA, RTS Delegated Regulation (EU) 2024/1773Para. 47–50, may be merged subject to four distinctions (para. 49)Same with additions
RegisterRegister of information, Article 28(3) DORA, templates of Implementing Regulation (EU) 2024/2956Non-ICT register with 9 + 8 fields (para. 61–62), consolidation optional, DORA ITS format permitted (para. 63)Same structure, different fields
Direct oversight of service providersOversight of critical ICT third-party service providers, Articles 31–44 DORANo counterpart — Title V governs the supervision of financial entities, not of TPSPs (para. 117–128)Different

Methodologically, ISO/IEC 27001:2022 with controls A.5.19 to A.5.23 (supplier relationships, security in supplier agreements, ICT supply chain, monitoring and change management of supplier services, cloud usage) and ISO/IEC 27036 (information security for supplier relationships) provide the control framework for mapping both regimes in a single management system — in platforms such as VamiGRC as one data model with two views.

Consolidation is an option, not an obligation (para. 49, 61). Anyone maintaining two registers should avoid discrepancies (para. 61) — in practice, that means a single data source.

14Chapter 14

The Implementation Programme: 2-Year Roadmap, 90-Day Start, KPIs, Transitional Period

The Guidelines apply from a date that will only be set once the translations are published; from then on, two years run for the review of critical or important arrangements (para. 18–20). This chapter translates the deadline logic into five phases, measurable KPIs and a prepared supervisory dialogue.

From the date of application, the Guidelines apply to all arrangements entered into, reviewed or amended on or after that date (para. 18); existing arrangements are to be reviewed and amended (para. 19). For critical or important functions, a two-year transitional period applies — anyone not finished by then informs the competent authority of the planned measures or a possible exit strategy (para. 20). Non-critical arrangements are reviewed only upon renewal (para. 21). The EBA deliberately chose this Option B2 to reduce renegotiation pressure (pp. 58–59).

  1. Phase 0Mobilisation — before the date of applicationpara. 38–44

    Mandate from the management body, role under para. 44 c (combined with the DORA role), inventory of all non-ICT contracts, gap analysis against para. 84–85, 61–62 and 48–49, decision on the integration architecture.

  2. Phase 1The first 90 days from the date of applicationpara. 31–37, 61

    Three-step test and criticality for all arrangements, basic register fields (para. 61), prioritisation of critical contracts by renewal date, approved policy (para. 47), process for new arrangements — para. 18 applies to them immediately — and reporting channel to the competent authority (para. 65).

  3. Phase 2Months 4–12: contract and chainpara. 84–95, 98

    Renegotiation of critical arrangements: clause set para. 84–85, subcontracting rules para. 89–95, audit rights para. 98, subcontractor data para. 62 c, updated due diligence (para. 77–82), additional register fields (para. 62), KPI/KCI reporting (para. 112).

  4. Phase 3Months 13–24: exit tests and evidencepara. 56, 101–104, 115

    Test exit plans where appropriate (para. 115), internal audit plan (para. 56), first own or pooled audits (para. 101–104), reports to the management body (para. 110) — and where the review will not finish in time, supervisory dialogue before month 24 (para. 20).

  5. Phase 4From month 24: steady statepara. 21, 47, 110, 119

    Bring non-critical arrangements into line upon renewal (para. 21), review the policy annually (para. 47), reassess criticality upon material changes (para. 110), deliver the register electronically on request (para. 63), SREP readiness (para. 119).

KPITargetReference
Arrangements with a documented three-step test100%para. 31, 58
Register coverage, basic fields (9)100%para. 61
Register coverage, additional fields (8) for critical/important100% before the end of the transitional periodpara. 62, 20
Critical arrangements with the complete clause set100% within 24 monthspara. 84–85, 19–20
Critical arrangements with unrestricted audit rights incl. chain100%para. 98, 89 h
Exit plans in place / tested100% / by risk prioritypara. 62 f, 115
Subcontractor notifications assessed on time100%para. 90–93
Open audit findings past the follow-up deadline0para. 57

Targets are VamiSec programme objectives derived from the completeness logic of the Guidelines — not EBA requirements.

The programme scales with proportionality: less complex financial entities may assign the role to a member of the management body (para. 44 c), use qualitative risk analyses (para. 73) and maintain the register centrally within the group or IPS (para. 60).

Date of application: the Final Report contains the placeholder “[date]” (para. 18, 20, 22); the EBA lists the Guidelines as “final and awaiting translation”. Until the translations are published, month 0 is unknown — plan relative to the date of application and use the time for Phase 0.

Self-check

Readiness Radar: how far along is your non-ICT third-party management?

Ten questions across five dimensions of the Guidelines. Each question is linked to the paragraph from which the requirement derives — the result shows your maturity level and biggest gaps.

  1. Governance & policypara. 38, 47
    Has your management body approved a third-party risk strategy including a written policy for non-ICT services supporting critical or important functions — and is it reviewed at least annually?
  2. Governance & policypara. 44
    Is there a designated role or member of senior management directly accountable to the management body for overseeing all third-party arrangements — with sufficient resources?
  3. Criticality & registerpara. 31–37
    Have you classified all non-ICT service providers using the three-step test and documented the reasoning for the criticality of each function?
  4. Criticality & registerpara. 58–63
    Do you maintain a register of all non-ICT arrangements with the nine basic fields and the eight additional fields for critical functions — consistent with the DORA register of information?
  5. Pre-contractual reviewpara. 68–79
    Before every new arrangement, do you run the pre-contractual analysis — criticality, supervisory conditions, risk analysis including concentration risk, due diligence, conflicts of interest?
  6. Pre-contractual reviewpara. 70, 76, 82
    For service providers in third countries, do you check authorisation, supervision, the cooperation agreement between the authorities, location risks, and ESG and human rights aspects?
  7. Contract & chainpara. 84–85, 98
    Do your contracts for critical or important functions contain all minimum contents of para. 84 and 85 — including unrestricted access and audit rights and an exit strategy with a transition period?
  8. Contract & chainpara. 87–95
    Do your contracts govern subcontracting with a notification duty, notice period, right to object, equivalent audit rights along the chain and a termination right for the subcontract?
  9. Monitoring & exitpara. 110–113
    Do you monitor critical arrangements on an ongoing basis with KPIs, key control indicators, reports and independent reviews — and report periodically to the management body?
  10. Monitoring & exitpara. 114–116
    Is there a documented and, where appropriate, tested exit strategy with alternative solutions and trigger indicators for every critical or important function?
Governance& policyCriticality& registerPre-contractualreviewContract& chainMonitoring& exit
Governance & policy0 %Criticality & register0 %Pre-contractual review0 %Contract & chain0 %Monitoring & exit0 %

Answer all ten questions — your result will appear here.

Free whitepaper

Third-Party Risk für CISOs — EBA Non-ICT Guidelines 2026

30 pages on EBA/GL/2026/09: what changes compared with the 2019 Outsourcing Guidelines, how non-ICT and DORA converge in a single framework and how you translate the two-year transitional period into a programme (German-language whitepaper).

Cover of the VamiSec whitepaper Third-Party Risk für CISOs
30 pagesPDF, free of chargeGerman · PDFAs of 09/2026
  • Ten key messages of the Guidelines with paragraph references — for the board paper
  • Integration architecture: shared role, policy, register and exit tests for ICT and non-ICT
  • Clause library under para. 84, 85 and 89 and the register data model with 9 + 8 fields
  • 24-month programme with 90-day playbook, KPIs and supervisory dialogue under para. 20 and 65
Free Download

Request Whitepaper

Third-Party Risk für CISOs — EBA Non-ICT Guidelines (EBA/GL/2026/09)

The CISO whitepaper: Third-Party Risk für CISOs

Integration architecture with DORA

A shared oversight role under Art. 5(3) DORA and para. 44 c, a merged policy with the four distinctions of para. 49, a combined register under para. 61 — and the points where the regimes deliberately diverge.

Clause library for contracts

The minimum contents of para. 84 a–j and 85 a–f, the subcontracting clauses of para. 89–95 and the audit rights of para. 98 as building blocks for new contracts and addenda — including the BRRD reference for CRD institutions.

The register as a data model

The 9 + 8 fields of para. 61 and 62 as a field table with reference to the DORA ITS templates and the export format under para. 63 — as the basis for a spreadsheet, GRC tool or database.

24-month programme and 90-day playbook

Phases from stocktake to supervisory dialogue under para. 20 and 65, KPIs for tracking progress and the first 90 days as a concrete task list — with objections and answers for the board discussion.

FAQ

Frequently asked questions on the EBA Third-Party Risk Guidelines

Answers to the questions financial entities have asked most often since publication — with paragraph references for further reading.

The date of application is still a placeholder in the Final Report: the Guidelines apply from a date to be set upon publication of the translations into all official EU languages (para. 18). The EBA currently lists them as final but not yet applicable. From the date of application, they cover all arrangements entered into, reviewed or amended thereafter; existing contracts must be adapted (para. 19). Competent authorities must notify the EBA within two months of publication whether they comply with the Guidelines. In Germany, the MaRisk as amended on 30 June 2026 still implement the 2019 Outsourcing Guidelines; an amendment of AT 9 is therefore still outstanding.

Yes — the circle of addressees has grown compared with 2019. Alongside credit institutions and CRD investment firms, the Guidelines address third-country branches, investment firms under MiFID II with the exception of small and non-interconnected firms under Art. 12(1) IFR, payment and e-money institutions, issuers of asset-referenced tokens (ARTs) under MiCAR, MCD creditors that are financial institutions, and approved financial holding companies (para. 9). Pure account information service providers are exempt (para. 11). Payment institutions apply the Guidelines on an individual basis (para. 14), ART issuers on an individual and, where applicable, group basis (para. 15). The cost-benefit analysis expects limited additional costs for the new addressees, because MiFID II, IFD and MiCAR already contain outsourcing requirements and all addressees are subject to DORA in any event.

Both definitions in para. 17 presuppose a recurrent or ongoing service; the difference lies in a single criterion: an outsourcing arrangement concerns a function the financial entity would otherwise perform itself — the third-party arrangement dispenses with that criterion. This brings services into scope that never appeared in an outsourcing register. In the Feedback Statement, the EBA notes that the outsourcing definition follows the 2019 Guidelines and the FSB toolkit, while the definition of a third-party arrangement follows the BCBS principles — DORA itself has no concept of outsourcing (p. 75). The Guidelines do not require outsourcing to be flagged separately; the register fields of para. 61 ask about criticality, not outsourcing status. The MaRisk distinction between outsourcing and other external procurement has no counterpart in the Guidelines.

No. Para. 61 expressly allows the non-ICT register and the register of information under Art. 28(3) DORA to be merged into a single register; the cost-benefit analysis deliberately opened up this option D (pp. 60–61). In the Feedback Statement, the EBA clarifies that the non-ICT register has fewer data points than the DORA register but should remain consistent for the information they share; the Guidelines do not go into the level of detail of Implementing Regulation (EU) 2024/2956, but their wording has been aligned with DORA (pp. 88–89). Those who keep two registers should avoid discrepancies (para. 61). In any case, the register must distinguish critical or important functions from the rest (para. 58) and keep terminated arrangements documented for an appropriate period — the five-year retention period envisaged in the draft was aligned with DORA (para. 59; p. 90).

As a building block, yes; as a substitute, no. Para. 102 allows certifications, the service provider’s internal or external audit reports and pooled audits to be used. For critical or important functions, however, financial entities must assess whether this evidence is sufficient and may not rely on it exclusively over time (para. 103). Para. 104 attaches eight conditions to its use: the audit scope must cover the systems and key controls identified by the institution, the reports must not be out of date, the auditors must be suitable, the audit must test the effectiveness of the controls, and the institution needs the contractual right to extend the scope and to conduct its own audits. A certificate therefore does not replace the unrestricted audit right under para. 98.

Intra-group arrangements are subject to the same framework as external ones — in the background section of the Final Report, the EBA stresses that they are not automatically less risky. The selection of a group entity must rest on objective grounds, and the terms, including prices, must be set objectively; synergies may be priced in as long as the service provider remains independently viable (para. 53). Conflicts of interest must be expressly managed (para. 52). Relief is available on the organisational side: registers, pre-contractual analysis, business continuity plans and exit plans may be kept centrally within the group or the institutional protection scheme, provided each financial entity receives summaries and, on request, the complete documentation (para. 28, 54, 60). The greater control over a group entity may be taken into account in the risk analysis (para. 76 e).

The third-country dimension shapes the entire life cycle — beyond the pre-contractual conditions of para. 70, 76 and 82. The policy distinguishes service providers in Member States from those in third countries (para. 49 d). The contract names the locations of service provision with a duty to notify changes (para. 84 b) and commits the service provider to your level of data protection and banking secrecy (para. 86); in the event of subcontracting, it assesses the location risks of its own subcontractors (para. 89 c). For CRD institutions, the reference to the authorities’ investigatory powers applies to third-country service providers as well (para. 97). The register records the country of service provision and the subcontractors’ country of registration (para. 61 i, 62 c). The competent authority must be able to supervise effectively where critical functions are performed outside the EEA (para. 127) — the background section calls for additional safeguards to that end (Background para. 22).

The Guidelines do not provide for an automatic breach, but for supervisory dialogue. If the review and documentation of arrangements supporting critical or important functions have not been completed two years after the date of application, the financial entity informs its competent authority accordingly — including the measures planned to complete them or a possible exit strategy (para. 20). The EBA deliberately chose this variant in the cost-benefit analysis because contracts cannot always be renegotiated within a rigid deadline. There is no deadline for non-critical arrangements; review and documentation can take place at renewal (para. 21). Recommendation: prioritise the critical arrangements by remaining contract term and negotiating power, and document progress continuously.

Standards & Sources

The content on this page is based on the following publicly available guides and studies.

European Banking Authority · 2026

Final Report on Guidelines on the sound management of third-party risk regarding non-ICT services (EBA/GL/2026/09)

Primary source for this page — 98 pages including the cost-benefit analysis and the Feedback Statement on consultation EBA/CP/2025/12

European Banking Authority · 2026

Press release: The EBA publishes its final Guidelines on the management of third-party risk

18 September 2026 — status “final and awaiting translation”, two-year transitional period

European Banking Authority · 2025

Consultation Paper EBA/CP/2025/12 — Draft Guidelines on the sound management of third-party risk

Consultation from 8 July to 8 October 2025, public hearing on 5 September 2025, 72 responses

European Banking Authority · 2019

Guidelines on outsourcing arrangements (EBA/GL/2019/02)

Previous framework of 25 February 2019, applicable from 30 September 2019 — repealed as of the date of application of the new Guidelines (para. 22)

European Parliament and Council · 2022

Regulation (EU) 2022/2554

DORA — framework for ICT third-party risk (Art. 28–30), register of information (Art. 28(3)), applicable since 17 January 2025

European Commission · 2024

Delegated Regulation (EU) 2024/1773

RTS on the content of the policy on ICT services supporting critical or important functions (Art. 28(10) DORA) — reference point for the merger under para. 49

European Parliament and Council · 2013

Directive 2013/36/EU

CRD — Art. 74(3) as the EBA’s mandate for guidelines on institutions’ governance arrangements

European Parliament and Council · 2023

Regulation (EU) 2023/1114

MiCAR — addressees: issuers of asset-referenced tokens (ARTs); EBA mandate under Art. 34

European Parliament and Council · 2015

Directive (EU) 2015/2366

PSD2 — payment institutions as addressees; mandate under Art. 11, notification duty under Art. 19(6)

Basel Committee on Banking Supervision · 2025

Principles for the sound management of third-party risk

Published on 10 December 2025 — international reference framework according to the EBA’s cost-benefit analysis

Financial Stability Board · 2023

Enhancing Third-Party Risk Management and Oversight: A toolkit for financial institutions and financial authorities

Final Report of 4 December 2023 — taken into account by the EBA in the cost-benefit analysis

European Securities and Markets Authority · 2025

Principles on third-party risks supervision

12 June 2025 — supervisory principles addressed to ESMA and national competent authorities, non-binding

Want to manage non-ICT third-party risk and DORA in a single framework?

VamiSec supports financial entities with criticality assessments, registers, contract remediation and exit testing — for ICT and non-ICT service providers within one shared framework.