On 18 September 2026 the European Banking Authority (EBA) published its Final Report containing the Guidelines on the sound management of third-party risk regarding non-ICT services (EBA/GL/2026/09) (the Guidelines) which will replace its 2019 Guidelines on outsourcing arrangements (the 2019 Guidelines).
The Guidelines are not a light-touch update. The EBA has broadened the framework beyond "outsourcing" to the wider concept of third-party risk management, with the stated aim of establishing one common framework for the management of third-party risk which enables financial institutions to manage third-party risk through two aligned regimes: non-ICT services under the Guidelines and ICT services under the Digital Operational Resilience Act (DORA).
For most institutions, this means more existing vendor relationships will fall in scope, some entities are newly caught altogether, and pre-contractual due diligence processes, contracts, registers and governance arrangements will need a health check to ensure they comply with the new requirements.
Which entities are newly in scope?
The Guidelines expand the list of addressees to include: creditors as defined in point (2) of Article 4 of Directive 2014/17/EU (MCD) which are financial institutions, and issuers of asset-referenced tokens (ARTs) under the Markets in Crypto-Assets Regulation (MiCAR). This is in addition to the credit institutions, investment firms, payment institutions and electronic money institutions already caught by the 2019 Guidelines, which will continue to be covered by the Guidelines.
The Guidelines also expressly address EU branches of third-country credit institutions (which are subject to a proportionate application of the framework) and approved financial holding companies and mixed financial holding companies.
Entities falling within one of these newly addressed categories will need to comply with the requirements from a lower starting point than those who are already complying with the 2019 Guidelines, and the compliance burden is not insignificant: third-party risk policies, registers, due diligence processes and contractual frameworks for non-ICT third-party arrangements may all need to be built rather than adjusted to meet the requirements.
Even where an entity was already in-scope, the population of arrangements requiring management is wider than before and will require a significant exercise to identify and remediate new in-scope arrangements as well as address the new governance and pre-contractual requirements.
What services do the Guidelines cover?
Third-party arrangements
Whereas the 2019 Guidelines applied to outsourcing arrangements, the Guidelines introduce the broader concept of "third-party arrangement" covering any arrangement with a third-party service provider (TPSP), including intragroup arrangements, for the support of one or more functions on a recurrent or ongoing basis. "Outsourcing arrangement" survives only as a narrower subset of this.
Practically, this means many non-ICT vendor relationships that were previously out of scope under the 2019 Guidelines, because the function was never categorised as an outsourcing, are now caught. Firms should expect to undertake an exercise to re-map their existing outsourcing compliance against this wider concept and identify which non-ICT arrangements fall within the definition of third-party arrangement.
Non-ICT Services
The Guidelines specifically apply to non-ICT services provided by a TPSP and expressly carve out any services which are within the scope of DORA.
In practice, institutions will now be running two coordinated but distinct EU third-party risk frameworks side by side: DORA for ICT third-party service providers, and these Guidelines for non-ICT providers, with the EBA urging a holistic approach bridging the two.
Excluded services
Some non-ICT services are expressly excluded from the scope of the Guidelines (a refined and, in places, extended list to the excluded arrangements under the 2019 Guidelines). Excluded services not in scope of the Guidelines are set out below.
Excluded services
Excluded services (reflective of existing exclusions under 2019 Guidelines):
- A service that is legally required to be performed by a TPSP (e.g. statutory audit)
- Clearing and settlement arrangements between clearing houses, central counterparties and settlement institutions and their members
- Market information services
- Payment network infrastructures (e.g. Visa, MasterCard, European payment initiatives, WERO, GIE CB)
- Global financial messaging infrastructures that are subject to oversight by relevant authorities (e.g. SWIFT)
- Correspondent banking services
- The acquisition of utilities (e.g. electricity, gas, water, telephone services).
- The acquisition of goods (e.g. plastic cards, card readers, office supplies, personal computers, furniture).
- The acquisition of services that do not have material impact on the financial entities’ risk exposures or on their operational resilience (e.g. advice from an architect, printing services, providing legal opinion including on tax, and representation in front of the court and administrative bodies, public relations consulting, cleaning, gardening and maintenance of the institution’s or payment institution’s premises, medical services, servicing of company cars, catering, canteen, cafeteria, vending machine services, clerical services, travel services, post-room services, receptionists, secretaries and switchboard operators).
Excluded services (introduced under the Guidelines):
- Financial transactions between financial institutions (e.g. inter-bank lending) or with central banks (e.g. deposit and lending facilities)
- A regulated financial service that is legally required to be performed by another financial entity regulated under EU law (e.g. custody and safekeeping, or trading venue services)
Key differences from the 2019 Outsourcing Guidelines
In addition to the fundamental change to the scope of the Guidelines to now cover the much broader concept of third-party arrangements rather than just outsourcing arrangements, the most significant shifts can be categorised into the areas summarised below. Across these topics, the Guidelines apply the principle of proportionality and a risk-based approach, with enhanced provisions for arrangements supporting critical or important functions.
Key topic
Contractual requirements
Summary of key new requirement:
The Guidelines impose contractual requirements for all arrangements. Under the 2019 regime, the detailed mandatory contract terms applied only to outsourcing of critical or important functions. This is a significant expansion. The Guidelines set a general baseline (service description, location and location-change notification, governing law, data provisions, service levels, cooperation with authorities, termination rights) for the whole population of third-party arrangements. Under the Guidelines there are also enhanced requirements for agreements in relation to critical or important functions which reflect the substantive elements of the requirements in the 2019 Guidelines e.g. precise quantitative and qualitative performance targets, reporting / notification obligations, business continuity testing requirements, unrestricted audit rights and exit strategy provisions. The Guidelines have a granular breakdown of the audit-related requirements.
Practical implications:
Baseline clauses for all arrangements. Conduct a full contract review across all third-party arrangements (not just outsourcing of critical or important functions) to assess compliance with the new general contractual baseline, including service descriptions, data provisions, location requirements, governing law and termination rights.
Enhanced clauses for critical or important functions. Contracts supporting critical or important functions should be separately assessed against the enhanced requirements, including quantitative and qualitative performance targets, audit rights (noting the new granular audit provisions), business continuity testing and exit strategy obligations.
Templates. Contract templates and playbooks will need to be updated to reflect the new two-tier structure.
Exit planning. Review existing exit plans and assess whether arrangements supporting critical or important functions can be transferred, reintegrated or terminated without undue disruption.
Remediation. A remediation programme should be established to uplift existing agreements within the transitional period.
Subcontracting
Summary of key new requirement:
The Guidelines introduce a more detailed and formal subcontracting regime. The previous consent-based model is replaced by a structured workflow with mandatory notice period, an explicit right to object and request modifications before the change is implemented, an express prohibition on the TPSP proceeding until approval or non-objection, and three termination grounds. Some of the requirements only apply to subcontractors supporting critical or important functions or material parts thereof. The Guidelines also introduce a requirement to identify subcontractors that "effectively underpin" a critical or important function and record this in the register and to focus ongoing oversight on such subcontractors.
Practical implications:
Identification and classification. Develop a methodology to identify and classify subcontractors that "effectively underpin" a critical or important function (as distinct from those that merely support it) and ensure these are recorded in the register. This mirrors DORA's ICT subcontracting concept and will require new analytical criteria and documentation.
Workflow. Establish a formal subcontracting change-management workflow, including defined notice periods, an explicit right-to-object mechanism, a documented approval or non-objection process, and contractual termination triggers for non-compliance. This replaces any informal consent-based practices currently in place.
Contract updates. Review existing contractual subcontracting clauses and update them to reflect the new mandatory approval, objection and termination provisions (this should form part of the contractual requirements workflow above).
Policy & Governance
Summary of key new requirement:
Under the Guidelines, the management body must have a written policy specifically on the use of non-ICT services supporting critical or important functions (under the 2019 Guidelines, an outsourcing policy was required).
Financial entities may merge the policy with their existing DORA Article 28(10) ICT policy provided it differentiates ICT vs non-ICT services, TPSPs authorised by competent authorities vs unauthorised, intragroup vs external arrangements, and EU vs third-country TPSPs.
Financial entities should have in place business continuity plans and conduct business impact analysis of their exposures to severe business disruptions.
The Guidelines set out a number of responsibilities on the management body including explicit requirements to approve a strategy on the sound management of third-party risks (including the policy on third-party risk management), as well as approve the business continuity plan and the internal audit plans regarding third-party arrangements, audits and modifications to them.
The management body remains fully responsible for the financial entity's activities and compliance at all times. Use of TPSPs must not result in the financial entity becoming an "empty shell" or lacking the substance, resources and expertise necessary to remain authorised and oversee its third-party arrangements effectively.
Practical implications:
Policy. Review the management body's written policy on third-party arrangements to ensure it specifically addresses non-ICT services supporting critical or important functions. Where a DORA Article 28(10) ICT third-party policy already exists, consider integrating the non-ICT policy into it, provided it clearly differentiates between: ICT and non-ICT services; TPSPs authorised by competent authorities and those that are not; intragroup and external arrangements; and EU and third-country TPSPs.
Governance. Governance frameworks should also be reviewed to ensure that third-party risk oversight responsibilities at management body level are clearly assigned and documented. The person chosen to manage third-party risk may be the same person who manages risk under the DORA framework.
Monitoring. Review existing monitoring and escalation processes to ensure appropriate oversight of third-party arrangements throughout their lifecycle, including ongoing assessment of TPSP performance and risk.
Register
Summary of key new requirement:
The register and reporting requirements now more closely align with the requirements under DORA. The register must now capture a DORA-style contractual hierarchy and LEI/EUID identifiers. For arrangements supporting critical or important functions, the register must contain additional information including the governing law of the contract, the dates of the most recent audits, outcome of the last substitutability assessment, the existence of an exit plan and the estimated annual budget cost for the third-party arrangement. The register should, to the extent possible, be consistent with the DORA register, and financial entities should avoid discrepancies between the two registers. Financial entities may combine both registers into a single register. The enhanced register is intended, among other things, to support competent authorities in identifying concentration risks and potential threats to financial stability.
Practical implications:
Design. Conduct a gap analysis of the existing third-party register against the new data requirements, including DORA-style contractual hierarchy fields, LEI/EUID identifiers, and (for critical or important function arrangements) governing law, audit dates, substitutability assessments, exit plan status and estimated annual budget costs.
Alignment. Assess whether to build one consolidated third-party register covering both ICT (under DORA Article 28(3)) and non-ICT arrangements, or to maintain separate registers with aligned data structures and reporting formats. Where a DORA register is already in place, consider reusing its format and taxonomy to reduce duplication.
Pre-contractual risk assessment and due diligence
Summary of key new requirement:
Under the Guidelines the scope of the pre-contractual risk assessment has been broadened to require assessment of the potential impact on operational risk, reputational risk, legal risk and concentration risk at an entity level. The due diligence factors to be considered retain the factors in the 2019 Guidelines and for critical or important functions requires consideration of additional factors including ensuring that the TPSP has business continuity/disaster recovery/contingency plans and ensuring that it has proper arrangements that ensure it is ‘effectively possible’ to conduct audits (including onsite).
These assessments are to be carried out on a risk‑based and proportionate basis, with more detailed analysis for higher‑risk arrangements and those supporting critical or important functions.
Practical implications:
Templates. Update pre-contractual risk-assessment templates to formally capture reputational, legal and concentration risk analysis alongside operational risk for all third-party arrangements, applied on a risk-based and proportionate basis, not just those supporting critical or important functions.
Enhanced due diligence. For critical or important function arrangements, enhance due diligence procedures to verify that TPSPs have adequate business continuity, disaster recovery and contingency plans, and that effective on-site audit arrangements are practically achievable.
Supervisory expectations
Summary of key new requirement:
The Guidelines strengthen the role of competent authorities in assessing third-party risk. Competent authorities are expected to assess third-party arrangements as part of the supervisory review and evaluation process (SREP) and equivalent supervisory processes, including whether third-party arrangements may constitute a material change to the conditions of a financial entity's authorisation. Competent authorities should also assess concentration risk and, where supervisory concerns arise, may require remedial action or restrictions in relation to third-party arrangements supporting critical or important functions.
Practical implications:
Supervisory readiness. Firms should ensure that third-party risk assessments, registers, governance documentation and contractual arrangements are complete, current and readily available for supervisory review.
Authorisation considerations. Firms should consider, as part of their governance processes, whether significant third-party arrangements could have implications for the conditions of their authorisation and engage with supervisors where appropriate.
Transitional timing
Timelines for compliance with the Guidelines are two-tiered:
third party arrangements that support critical or important functions: review and documentation to ensure compliance must be completed within two years from the date of application; and
third party arrangements that do not support critical or important functions: review and documentation to be carried out on renewal of the arrangement.
In respect of the first bullet, where the review and documentation of arrangements supporting critical or important functions have not been finalised within the two-year transitional period, firms should notify their competent authority and set out the measures planned to complete the review or their possible exit strategy.
The date of application of the Guidelines and other relevant dates were left as placeholders in the Final Report and are expected to be confirmed once the Guidelines are formally published. On that application date, the 2019 Guidelines will be repealed and superseded, and financial entities should treat the new Guidelines as the governing framework for non‑ICT third‑party risk.
Key Takeaways
The Guidelines represent a step change in third-party risk management for financial entities. By moving beyond the narrower outsourcing lens of the 2019 Guidelines to encompass all third-party arrangements for non-ICT services, and by aligning the framework more closely with DORA, the EBA has signalled an expectation of a joined-up, enterprise-wide approach to third-party oversight.
For financial entities in scope of these new Guidelines, the practical workload is significant: contracts, registers, governance policies, risk-assessment templates and subcontracting workflows all require review and, in many cases, material uplift. Newly in-scope entities face the additional challenge of building these frameworks from the ground up. Although the Guidelines explicitly follow a proportional, risk based approach, firms will need to be able to evidence robust governance, documentation and oversight across all non-ICT third-party arrangements, with stricter provisions for those supporting critical or important functions. Given the two-year transitional period for critical or important function arrangements, and based on our DORA remediation experience, firms should begin their gap analysis and remediation planning early.
We recommend that firms begin with a structured gap analysis across their existing third-party risk frameworks, prioritising newly in-scope entities and arrangements, critical or important function contracts, and alignment decisions with their existing DORA compliance programmes.
If you would like to discuss how the Guidelines may affect your business, please get in touch with your usual Simmons & Simmons contact.






_11zon.jpg?crop=300,495&format=webply&auto=webp)






_11zon.jpg?crop=300,495&format=webply&auto=webp)



.jpg?crop=300,495&format=webply&auto=webp)

