This browser is not actively supported anymore. For the best passle experience, we strongly recommend you upgrade your browser.
| 2 minute read

EBA finalises guidelines for managing non-ICT third party risk

In recent years financial entities have updated their outsourcing arrangements to align with European Banking Authority guidelines and their ICT service contracts to meet the EU’s Digital Operational Resilience Act. Further change is on the way as the EBA replaces its outsourcing guidelines with a broader non-ICT third party risk framework, of which outsourcing is now a subset. In-scope firms will need to review their contracts with third parties, update them where necessary and build out their registers of information.

Scope

DORA requires EU financial entities to include certain terms in their contracts with third party ICT service providers and to keep a register of information about those contracts. Once DORA started to apply, the EBA moved to update its 2019 outsourcing guidelines and proposed changes in a July 2025 consultation

The EBA has now published what will become its guidelines on the sound management of third-party risk regarding non-ICT services. The final guidelines confirm that ICT service contracts are removed from scope but a wider range of non-ICT third party arrangements are covered.

Key changes

The EBA has added new exclusions since the consultation. Most notably, there is a new exclusion for regulated financial services that are legally required to be performed by another financial entity regulated under EU law. This sits alongside other exclusions for, for example, payment network infrastructure, clearing and settlement arrangements and correspondent banking.

The EBA has also changed specific aspects of its guidelines. For example, financial entities should require their service providers to notify them about new subcontracting arrangements, as well as any planned material changes to such arrangements. Firms are also told to record in their registers which subcontractors “effectively underpin” services supporting critical or important functions and focus their monitoring on these subcontractors.

Firms are also encouraged to combine their non-ICT register with the DORA register of information. ICT subcontractors that effectively underpin a non-ICT service supporting a critical or important function now need to be captured in the register as well.

Other drafting changes result from the EBA seeking to make the guidelines more proportionate. This includes limiting certain requirements to arrangements supporting firms’ critical or important functions. For example, the mandatory policy on the use of third party services now focuses on services that support critical or important functions. Firms may choose to merge this policy with the equivalent policy required under DORA.

The structure of the guidelines is relatively unchanged. They lay out how firms should manage third party arrangements across their lifecycle. Topics covered include pre-contractual analysis, contractual terms including subcontracting and audit rights, ongoing monitoring of third party service providers and exit strategies for arrangements supporting critical or important functions.

Application

In line with the consultation, a wider range of firms will need to apply the revised guidelines. Credit institutions, payment and e-money institutions, and certain investment firms were subject to the EBA outsourcing guidelines. The list now also includes more investment firms (Class 1-minus and Class 2 firms), MiCAR-authorised issuers of asset-referenced tokens and non-bank creditors under the Mortgage Credit Directive.

Timetable

The guidelines are final but awaiting translation into the EU’s official languages. The EBA has not yet specified a date of application.

When the guidelines do start to apply, they will be subject to transitional provisions. These give firms two years to uplift non-ICT contracts supporting critical or important functions. Firms should notify their regulators where contracts are not updated in time. There is more flexibility for non-critical arrangements which can be reviewed at their next renewal cycle.

Anticipating another repapering exercise, firms should start by determining how the guidelines will apply to their inventory of contracts and templates, how to identify which contracts support critical or important functions, and how work already done on DORA implementation can be usefully leveraged.

Webinar

We are hosting a webinar on the EBA guidelines at 11am UK time / midday CET on Wednesday 7 October 2026. Linklaters clients can get in touch with us to register.

Tags

outsourcing, third party risk, tprm, eba, eu, operational resilience