EBA’s New Non-ICT Third-Party Risk Guidelines: What Firms Should Know

On 18 September 2026, the European Banking Authority (EBA) published its final Guidelines on the sound management of third-party risk regarding non-ICT services (EBA/GL/2026/09).
The Guidelines broaden the existing outsourcing framework to cover a wider range of relationships with third-party service providers. For affected firms, this means reviewing whether their current governance arrangements, policies, registers and contracts adequately capture their reliance on external providers.
They will replace the EBA’s 2019 Guidelines on outsourcing arrangements once applicable. Their application date remains to be confirmed. EBA Final Report.
The main change is the broader scope of third-party risk management.
The new framework covers arrangements under which a third party provides non-ICT services supporting a firm’s functions on a recurring or ongoing basis. Outsourcing forms part of this broader category.
A service may therefore fall within scope even where the firm has not previously classified it as outsourcing. Firms will need to examine the service provided, the function it supports and the consequences of disruption.
The framework also covers relevant arrangements with group companies and providers located outside the EU. Intragroup arrangements remain subject to appropriate risk assessment and oversight.
Specified exclusions apply, including statutory audit and services without a material impact on the firm’s risk exposure or operational resilience. Firms should document their classification decisions and continue to manage the risks associated with excluded relationships.
Applicability depends on the firm’s regulatory status.
The Guidelines cover, among others:
Credit institutions.
Class 1 minus and Class 2 investment firms.
Payment institutions and electronic money institutions.
Issuers of asset-referenced tokens.
They also address relevant EU branches of third-country credit institutions, approved financial holding companies and mixed financial holding companies, and certain mortgage creditors that qualify as financial institutions.
Small and non-interconnected Class 3 investment firms and providers offering only account information services are excluded from the direct scope.
For Cyprus Investment Firms, prudential classification is therefore an essential starting point. Existing outsourcing requirements under MiFID II and Commission Delegated Regulation (EU) 2017/565 continue to apply.
The Guidelines are final, but they are not yet applicable.
As at 19 September 2026, the EBA identifies the Guidelines as final and awaiting translation into the EU official languages. The published report retains placeholders for the application and repeal dates. EBA publication status.
The implementation provisions distinguish between the following arrangements:
Arrangements | Implementation approach |
Arrangements entered into, reviewed or amended on or after the application date | The new Guidelines apply from that date. |
Existing arrangements supporting critical or important functions | A two-year transition from the application date applies to their review and documentation. If this work remains incomplete, firms should inform their competent authority, including the planned completion measures or possible exit strategy. |
Other existing arrangements within scope | Review and documentation may take place upon renewal. |
The two-year transition runs from the application date. The published report does not establish publication of the translations as the starting point for that period.
Once applicable, the new Guidelines will repeal the EBA Guidelines on outsourcing arrangements of 25 February 2019 (EBA/GL/2019/02). Firms should monitor the EBA’s publication of the definitive dates when planning implementation.
Several areas will require particular attention.
The register must capture the broader scope.Firms should maintain a register covering all non-ICT third-party arrangements within scope, distinguishing those supporting critical or important functions. An existing outsourcing register may therefore need to be expanded. Additional information is required for arrangements supporting critical or important functions, including relevant subcontractors, substitutability, recovery objectives and the existence of an exit plan.
Classification drives the level of oversight.More demanding requirements apply where a service supports a critical or important function. The assessment considers whether disruption or failure would materially impair financial performance, service continuity or compliance with authorisation requirements and applicable financial services law.
Governance and accountability remain with the firm.The management body should approve and regularly review the third-party risk strategy. The policy covering non-ICT services supporting critical or important functions should be reviewed at least annually. Responsibilities, reporting lines and internal resources should support effective oversight throughout the relationship.
Contracts require a differentiated review.Baseline contractual provisions apply to all arrangements within scope. These address matters such as service descriptions, service and data locations, data protection and recovery, service levels, cooperation with authorities and termination. Additional safeguards for critical or important functions include measurable performance targets, access and audit rights, business continuity requirements and adequate transition arrangements.
Subcontracting requires visibility and control.For services supporting critical or important functions, firms should understand the relevant subcontracting chain and the dependencies it creates. Contracts should address whether subcontracting is permitted, notification of proposed changes, approval or objection rights, and the safeguards necessary to maintain effective oversight.
Continuity and exit arrangements must work in practice.Firms should assess their ability to respond to provider failure, severe disruption or service deterioration. Exit plans for arrangements supporting critical or important functions should be documented, realistic and sufficiently tested where appropriate, taking account of alternative providers, internal capabilities and transition requirements.
Many of these controls already featured in the 2019 outsourcing framework. The preparation exercise should identify where existing controls need to be extended or refined to meet the new scope and requirements.
DORA remains relevant where an arrangement also involves ICT services.
These Guidelines address non-ICT services. ICT services fall under the DORA framework.
Where providing a non-ICT service also involves ICT services, paragraph 32 requires the financial entity to assess whether that ICT component is material to the service provision and triggers DORA requirements.
For mixed arrangements, firms should therefore document which requirements apply to the respective services. The Guidelines allow coordinated policies and registers across the two frameworks, provided the relevant requirements are met.
Firms can begin with a focused applicability and gap assessment.
We recommend:
Mapping non-ICT third-party arrangements, including those currently outside the outsourcing register.
Confirming which arrangements fall within scope and whether they support critical or important functions.
Where an arrangement combines non-ICT and ICT services, assessing whether the ICT elements trigger requirements under DORA.
Reviewing policies, registers, contracts and subcontracting controls against the revised requirements.
Prioritising arrangements supporting critical or important functions, including continuity and exit planning, with clear responsibilities and a realistic remediation timetable.
Early preparation will help firms identify the extent of the work required, engage providers where contractual changes are necessary, and plan implementation once the definitive application date is published.
ENAH Services Ltd can assist with applicability and gap assessments, reviews of third-party registers and contracts, and the development of proportionate governance, continuity and exit arrangements.
