From Outsourcing to Third-Party Risk: The EBA’s New Guidelines and What They Mean in Practice
What the EBA Guidelines Are About
On 18 September 2026, the EBA published its Final Report on the Guidelines on Third-Party Risk Management (EBA/GL/2026/09). The Guidelines replace the EBA's 2019 Guidelines on outsourcing arrangements, which are repealed with effect from the (still to be confirmed) date of application.
The rationale is explicit in the Final Report: the 2019 outsourcing Guidelines were drafted for a narrower population of addressees (credit institutions, large investment firms subject to CRD, payment and e-money institutions) and pre-date a wave of legislative change – the recast CRD6/CRR3 package, the Investment Firms Directive, MiCAR and, above all, DORA. DORA harmonised third-party risk management for ICT services but left the management of non-ICT third-party relationships governed by the older, narrower outsourcing framework, creating an uneven playing field and scope for regulatory arbitrage.
Conceptually, the Guidelines move from a narrow “outsourcing” lens to the broader concept of “third-party arrangements,” of which outsourcing is now expressly only a subset. The stated aim is to enable institutions to manage third-party risk holistically – covering both ICT (under: DORA) and non-ICT (these Guidelines) service relationships – rather than through two disconnected regimes.
Scope
Personal scope
The new Guidelines apply to a materially wider population than the 2019 outsourcing Guidelines. Addressees now include: institutions under CRD (and their third-country branches), investment firms other than small and non-interconnected firms under IFR, payment institutions (other than registered account information service providers), electronic money institutions, issuers of asset-referenced tokens under MiCAR, creditors under the Mortgage Credit Directive (MCD) that qualify as financial institutions, and financial or mixed financial holding companies approved under CRD. Application is required at individual, sub-consolidated and consolidated level for CRD institutions, at individual level for payment and e-money institutions, and at individual and (where applicable) group-wide level for ART issuers.
Scope of service providers – and the deliberate carve-out from DORA
Substantively, the Guidelines cover "internal governance arrangements, including sound risk management," for reliance on third-party service providers (TPSPs) to provide non-ICT services supporting functions, with particular focus on critical or important functions. ICT services as defined in Article 3(21) DORA are expressly excluded from scope. The Final Report frames this as a conscious allocation of territory: DORA governs third-party ICT risk; these Guidelines govern everything else, with the two regimes designed for consistency so that institutions can run a genuinely holistic third-party risk framework.
Because many arrangements will combine ICT and non-ICT elements, the Guidelines put the classification burden on the institution itself: where a non-ICT arrangement also involves the use of ICT services, it is for the financial entity to determine whether “the ICT element is material enough” to trigger DORA. The EBA points practitioners to the ESAs' DORA Q&As (DORA030 on the definition of ICT services, and DORA095 on mixed arrangements and subcontracted ICT elements) as interpretive guidance for this boundary. Firms should expect this demarcation exercise – and its documentation – to be an early and recurring practical challenge.
The list of services carved out entirely from the "third-party arrangement" concept largely mirrors the 2019 exclusions (statutory audit, market information services, payment network infrastructures, clearing and settlement, global financial messaging, correspondent banking, and a range of non-financial ancillary services and utilities), but is updated to reflect current market infrastructure (e.g., explicit reference to various credit card and payment schemes) and adds a new express exclusion for financial-services transactions between financial institutions, such as interbank lending and central bank facilities.
Temporal scope
The Guidelines will apply to all third-party arrangements entered into, reviewed or amended on or after the application date, and existing arrangements must be reviewed and brought into compliance. Review and documentation of arrangements supporting critical or important functions must be finalised within two years of the application date; if not, the institution must inform its competent authority, including of the remedial measures planned or a possible exit strategy. For non-critical arrangements, review and documentation may be left until the arrangement's next renewal – a more flexible approach than under the 2019 regime, and one the EBA says was adjusted in response to consultation feedback. The 2019 outsourcing Guidelines are repealed with effect from the same application date.
Summary of Content
The Guidelines are structured around five titles that will be familiar in shape to anyone who has worked with the 2019 outsourcing Guidelines, but are more elaborate throughout.
Title I – Proportionality and group application. A dedicated proportionality principle ties the intensity of compliance to the institution's risk profile, business model, scale and complexity, and a much more developed set of provisions than under the old regime governs centralised group/IPS arrangements – covering centrally-provided governance, centralised registers, centralised pre-contractual analysis and centralised exit plans, each subject to conditions ensuring the individual entity retains effective oversight and receives the relevant summaries.
Title II – Classification. Institutions must assess, for every arrangement, whether the services are non-ICT, whether the TPSP acts on a recurrent or ongoing basis, and whether the function is critical or important. A function is always critical or important if its disruption would materially impair authorisation compliance, financial performance, or the soundness/continuity of services. The definition of critical or important functions is identical to the concept used under DORA, as the Guidelines confirm. Outsourced internal control function tasks are presumed critical or important unless the institution proves otherwise; and institutions subject to BRRD must expressly cross-reference the critical functions/core business lines concepts under BRRD Article 2(1).
Title III – Governance framework. The management body must approve a strategy and policy on third-party risk management, remains fully responsible and accountable, and must expressly approve and periodically review the business continuity policy and internal audit plan for third-party arrangements. Institutions must avoid becoming an "empty shell", maintain conflict of interest, business continuity and internal audit frameworks, and keep a register of all third-party arrangements. The register content is substantially aligned with DORA's Article 28(3) register (including new fields such as contractual arrangement type – standalone/overarching/subsequent – recovery time/point objectives, and existence of an exit plan) so that firms are encouraged, where feasible, to run a single combined register.
Title IV – The third-party arrangement lifecycle. Pre-contractual analysis (criticality assessment, supervisory conditions, risk assessment, due diligence, conflicts check), contractual requirements (including mandatory clauses for critical/important functions on service levels, audit and access rights, insurance, business continuity, and exit), a considerably more prescriptive subcontracting regime with formal notification, objection and termination triggers, access/audit rights (including pooled audits and third-party certifications), termination rights, ongoing monitoring, and documented exit strategies for critical/important functions.
Title V – Supervisory guidelines direct competent authorities to assess third-party risk through SREP, monitor concentration risk (including at sector level, taking into account shared TPSPs across institutions), guard against "empty shell" structures, and escalate to restricting the scope of an arrangement or requiring exit where governance is inadequate. The Guidelines remain a key tool for assessing whether a firm’s heavy reliance on back-to-back transactions or intragroup transactions to transfer part of the market risk and credit risk could result in an „empty shell.”
Differences to the EBA Guidelines on Outsourcing
The most significant structural change is the shift from a single binary concept ("outsourcing") to a layered taxonomy.
Old regime – a single, counterfactual test. Under the 2019 Guidelines, only "outsourcing" arrangements were captured: "an arrangement of any form … by which that service provider performs a process, a service or an activity that would otherwise be undertaken by the institution … itself". Sub-outsourcing was likewise defined narrowly as onward transfer by the service provider under an outsourcing arrangement.
New regime – a broader "third-party arrangement" umbrella, with outsourcing as a subset. The new Guidelines define "third-party arrangement" as any arrangement “of any form … for the support of one or more functions … on a recurrent or an ongoing basis,” expressly stating that "this includes outsourcing arrangements as a subset". The narrower outsourcing definition survives essentially unchanged (function that would otherwise be performed in-house), but it is no longer the gateway test for the Guidelines to apply or relevant for whether certain obligations under the Guidelines apply. The new gateway is simply recurrent or ongoing third-party support of a function, while still excluding genuinely one-off engagements. “Subcontracting” replaces “sub-outsourcing” and is defined more broadly as any further transfer of a function, as a whole, or in part, by a TPSP to another provider.
The DORA carve-out reshapes the in-scope services. The single biggest scope difference is that the new Guidelines simply do not cover ICT services – these now sit exclusively within DORA. The 2019 Guidelines, by contrast, had detailed provisions specifically addressing cloud outsourcing – definitions of cloud computing and of public/private/community/hybrid deployment models, and IT security requirements woven into the contractual and security sections. All of that content is effectively excised from the successor Guidelines and now lives in DORA.
Classification of critical or important functions is materially unchanged in substance, but the drafting is tightened for consistency with DORA and BRRD. The core three-limb test (impairment of authorisation conditions, financial performance, or soundness/continuity of services) is essentially the same test carried over from the 2019 Guidelines, and the presumption that outsourced internal control function tasks are critical or important unless proven otherwise is also retained almost verbatim. What changes is: (i) the Final Report notes the definition is now made "fully consistent" with DORA's own critical/important function definition, so that classification of a given function should, in principle, be the same whether analysed under DORA or under these Guidelines; and (ii) a more explicit cross-reference to BRRD's "critical functions" and "core business lines" concepts is built into the classification section for resolution-relevant entities, which was only implicit (via the resolution authority contractual clauses) in the 2019 text.
Other notable content differences flowing from this reclassification: the subcontracting regime is considerably more prescriptive, with formal notice-and-objection procedures and specific contractual termination triggers where a TPSP subcontracts without approval, compared with the more principle-based sub-outsourcing provisions in the 2019 text; the register is redesigned for DORA alignment (contractual arrangement typology, RTO/RPO fields, exit-plan flag) versus the 2019 register fields; and due diligence factors now explicitly extend to operational/technical track record, geographic dependency management and supply-chain risk, areas not separately itemised in 2019.
What is next?
For legal and compliance teams of financial institutions, the practical consequences are significant, even though the underlying philosophy of proportionate, risk-based third-party governance is not new.
Wider population, wider remediation exercise. Investment firms, ART issuers, third-country branches, MCD creditors and (mixed) financial holding companies that were never within scope of the 2019 outsourcing Guidelines will need to build a third-party risk framework, register and policy essentially from scratch, on the same timeline as existing addressees carry out their re-classification exercise, or build upon the framework that they are already subject to.
A new inventory and demarcation exercise. Every institution already compliant with the 2019 Guidelines will need to re-inventory its third-party book against the new, broader “third-party arrangement” concept – capturing recurrent/ongoing arrangements that were not "outsourcing". They may revert to the prior exercise for DORA compliance and focus on those arrangements that they have not been considered as ICT-service. Given that this determination is left to the institution, subject to supervisory challenge, firms should expect this to be an area of supervisory scrutiny and potential divergence in approach across the market, at least initially.
Governance uplift. The explicit requirement for management body approval of the business continuity policy and internal audit plan specifically for third-party arrangements, together with the more developed group/IPS centralisation rules, will require institutions relying on group-level outsourcing/TPRM functions to document more carefully how local entities retain effective oversight and receive the required summaries and risk analyses.
Subcontracting chains under closer control. The formalised notice-and-objection mechanism, with an express contractual right (and obligation) to terminate the TPSP-subcontractor relationship in specified circumstances, will need to be reflected in template contracts and vendor management playbooks — a meaningfully more prescriptive standard than the 2019 sub-outsourcing provisions, and likely to generate renegotiation of existing master service agreements with providers.
Two-year transition, but front-loaded work for critical functions. The two-year window to complete review and documentation of arrangements supporting critical or important functions gives institutions a defined runway, but the requirement to notify the competent authority (with a remediation or exit plan) if that deadline is missed creates a strong incentive to prioritise the classification and remediation of the highest-risk book first, rather than treating the two years as slack.
Regulatory convergence, less arbitrage – at a cost of complexity. The EBA’s stated aim of closing the gap between ICT and non-ICT third-party risk management, and reducing scope for arbitrage via third-country providers, should over time produce a more coherent supervisory landscape. In the near term, however, institutions face the burden of running, interpreting and reconciling two closely related but formally separate regimes (DORA and these Guidelines) governing what business teams will often experience as a single vendor relationship — making the ICT/non-ICT boundary assessment, and its documentation, one of the more consequential new compliance tasks introduced by this Final Report.
