EBA Issues New Guidelines on Critical Third-Party Functions for Banks
The European Banking Authority (EBA) has issued final guidelines establishing a new framework for the management of third-party risks associated with services supporting critical or important functions at financial institutions.

Published on 18 September 2026, the Guidelines on the sound management of third-party risk related to non-ICT services are intended to replace the EBA’s 2019 Guidelines on outsourcing arrangements and create a broader framework covering third-party relationships beyond traditional outsourcing.
The new framework focuses on third-party arrangements supporting critical or important functions, defined as functions where disruption could materially impair the performance of a financial entity. The EBA said the risk-based approach is intended to allow institutions and supervisors to concentrate resources on arrangements presenting greater risks while reducing unnecessary requirements for less material relationships.
The guidelines cover both ICT and non-ICT third-party arrangements from an overall risk-management perspective. However, ICT services falling within the definition of ICT services under the Digital Operational Resilience Act (DORA) remain subject to the specific requirements of DORA. The new EBA guidelines primarily address non-ICT third-party services, creating a complementary framework alongside the existing EU operational-resilience regime.
The new approach broadens the regulatory concept from “outsourcing” to “third-party arrangements”. Outsourcing remains a category within the wider framework, meaning that institutions will need to consider a broader range of relationships with external service providers rather than limiting their assessment to arrangements that meet the traditional definition of outsourcing.
The guidelines cover the full lifecycle of a third-party arrangement. This includes initial risk assessment and due diligence, contractual arrangements, subcontracting, ongoing monitoring, documentation and the development of exit strategies.
Risk assessment is therefore required before an institution enters into a relevant third-party arrangement. Financial institutions need to determine the nature and level of risk associated with the service, the importance of the function being supported and the potential consequences of a disruption or failure by the external provider.
Due diligence forms another central component of the framework. Institutions are expected to assess third-party service providers before entering into arrangements and maintain appropriate oversight throughout the relationship. The assessment is intended to take account of the nature, scale and complexity of the relevant services and the risks created by reliance on an external provider.
Contractual arrangements will also need to address the institution’s ability to manage and monitor third-party risks. The framework covers matters including responsibilities, access to information, monitoring arrangements, subcontracting and provisions required to support the institution's ability to terminate or exit an arrangement where necessary.
Subcontracting is specifically included within the lifecycle requirements. Institutions therefore need to understand not only the direct service provider with which they contract, but also relevant dependencies created where the provider relies on other organisations to perform services.
Ongoing monitoring is required after a third-party relationship has been established. This reflects the fact that the risk profile of an arrangement can change over time as services, providers, subcontractors, technology, business models or operational dependencies develop.
Exit strategies are also incorporated into the framework. Financial institutions are expected to consider how they would terminate or transition a third-party arrangement without creating unacceptable disruption to critical or important functions. Exit planning is particularly relevant where an institution becomes heavily dependent on a single external provider.
The EBA has incorporated proportionality into the framework. The level of assessment, documentation and oversight should take account of the materiality and risk associated with the third-party arrangement rather than imposing identical requirements on every external service relationship.
The new guidelines also seek to create greater consistency between third-party risk management for ICT and non-ICT services. The EBA's objective is to allow financial institutions to adopt a more integrated approach rather than maintaining completely separate risk-management structures for different categories of external providers.
This approach is particularly relevant following the introduction of DORA, which established an EU framework for ICT third-party risk and direct oversight of designated critical ICT third-party providers. Under DORA, the European Supervisory Authorities can designate ICT providers as critical and conduct supervisory activities over them.
The new EBA guidelines address the remaining area of non-ICT third-party risk. The distinction between the two frameworks is therefore important: DORA governs the management and oversight of ICT third-party risks, while the EBA guidelines provide the principal framework for third-party arrangements involving non-ICT services within their scope.
The EBA's decision to replace its 2019 outsourcing guidelines follows significant changes in the EU financial regulatory framework. The earlier guidelines were developed before DORA and several subsequent legislative changes affecting credit institutions, investment firms, payment institutions and crypto-asset service providers.
The new framework has been developed under several EU legislative provisions, including the Capital Requirements Directive, the Payment Services Directive, the Investment Firms Directive, MiCA and the EBA Regulation.
A two-year transitional period has been established to allow financial institutions to implement the new requirements. During this period, institutions will need to review their existing third-party arrangements and make the necessary adjustments to their governance, risk-management processes, documentation and contractual arrangements.
The EBA's final guidelines are currently marked as final but not yet applicable pending translation into the official EU languages. The EBA's regulatory page states that the existing outsourcing guidelines will be repealed once the new framework becomes applicable.
For banks and other financial institutions, implementation will require an assessment of existing third-party relationships to determine which arrangements fall within the new framework and which support critical or important functions. Institutions will also need to ensure that their internal governance structures clearly allocate responsibility for third-party risk.
The framework extends beyond the initial decision to outsource or contract a service. Institutions will need to maintain oversight throughout the contractual lifecycle, including monitoring performance, assessing changes in risk, reviewing subcontracting arrangements and maintaining appropriate records.
The requirements also affect the relationship between financial institutions and their external service providers. Contracts supporting relevant functions may need to provide institutions with sufficient rights to obtain information, monitor performance, manage subcontracting and implement appropriate exit arrangements.
The introduction of the guidelines is part of the broader EU effort to establish a more consistent approach to operational and third-party risk across the financial sector. The EBA said the final framework incorporates feedback received during its public consultation and targeted outreach, as well as international standards including the Basel Committee on Banking Supervision's principles for the sound management of third-party risk.
The framework therefore establishes a broader regulatory approach in which financial institutions are expected to assess not only whether a service has technically been outsourced, but also the risks created by reliance on external parties for functions that are important to the institution's operations.
The two-year transition period provides institutions with time to identify relevant arrangements, assess their criticality, update governance and risk-management processes, review contracts and establish appropriate monitoring and exit arrangements before the new framework becomes fully applicable.
By fLEXI tEAM





Comments