Skip to content
Digital, Innovation, Payments

EBA third-party risk rules move towards a more proportionate framework

Published on 23 September 2026

Banks increasingly rely on external providers for services that can be important to their operations. The EBA’s final Guidelines on third-party risk for non-ICT services seek to strengthen the management of these dependencies, with requirements focused more clearly on arrangements supporting critical or important functions. Several points advocated by the ABBL during the consultation have been reflected in the final framework.

Summary

    The European Banking Authority has published its final Guidelines on the sound management of third-party risk related to non-ICT services (EBA/GL/2026/09).

    Once applicable, the Guidelines will replace the 2019 EBA Guidelines on outsourcing arrangements. They are currently awaiting translation into the EU’s official languages and are not yet applicable.

    The final EBA Guidelines apply to a broad range of financial entities, including credit institutions and other institutions within the scope of CRD/CRR, branches of third-country credit institutions, investment firms except small and non-interconnected firms, payment institutions, electronic money institutions, issuers of asset-referenced tokens (ARTs) under MiCA, and certain other financial institutions.

    The new framework covers the full lifecycle of third-party arrangements, from initial risk assessment and due diligence to contractual requirements, subcontracting, ongoing monitoring, documentation and exit strategies.

    The EBA has also confirmed a two-year transitional period for implementation.

    Why this matters

    Third-party risk is no longer limited to traditional outsourcing or technology providers.

    Banks increasingly depend on external firms for a wide range of specialised services. Some of these relationships can become important to the continuity of banking activities, particularly where they support critical or important functions (CIFs).

    The challenge is therefore to ensure that these dependencies are properly managed without subjecting every third-party relationship to the same level of regulatory requirements.

    The final Guidelines move in this direction by introducing a more proportionate approach, with greater focus on non-ICT arrangements that support CIFs and closer alignment with the framework already established under DORA.

    For banks and other financial institutions, this should help reduce unnecessary duplication while keeping attention on the relationships that matter most from an operational resilience perspective.

    A number of ABBL recommendations reflected in the final text

    During the EBA consultation in 2025, the ABBL advocated for a more proportionate framework and greater consistency with existing requirements.

    Several of these points have been reflected in the final Guidelines.

    Stronger alignment with DORA

    The final framework places greater emphasis on consistency with DORA and focuses requirements more clearly on arrangements supporting critical or important functions.

    This is important because institutions should not have to manage closely related operational risks through unnecessarily different regulatory frameworks.

    One register rather than parallel processes

    The EBA confirms that institutions may combine their non-ICT third-party register with the register maintained under DORA.

    This can help avoid duplicate processes and support a more coherent view of third-party dependencies across an institution.

    A more targeted approach to subcontracting

    The final Guidelines focus more closely on subcontractors that “effectively underpin” services supporting critical or important functions.

    This helps direct risk-management efforts towards subcontracting chains that can genuinely affect the continuity or resilience of a critical service.

    More proportionate documentation requirements

    The proposed five-year retention period for terminated third-party arrangements has been removed.

    Exit strategies are also limited to arrangements supporting CIFs, rather than applying across all third-party relationships.

    Together, these changes help concentrate regulatory requirements where the underlying operational risk is greatest.

    From regulatory requirements to operational resilience

    For the ABBL, effective third-party risk management remains essential.

    But resilience is strengthened not simply by adding more requirements. It also depends on ensuring that regulatory obligations are coherent, risk-based and operationally workable.

    The final Guidelines represent progress in this direction by focusing more clearly on critical dependencies and aligning parts of the framework with DORA.

    This should allow institutions to devote more attention and resources to the third-party relationships that could have the greatest impact on their operations.

    The ABBL will continue analysing the final Guidelines and their implementation implications and will keep members informed of further developments.

    The EBA’s final report and press release are available on the EBA website.

    Andrey Martovoy

    Andrey Martovoy

    Senior Adviser - Innovation & Digital, ABBL

    Published on 23 September 2026