The EBA published its final Guidelines on the sound management of third-party risk regarding non-ICT services on 18 September 2026. The Guidelines replace the EBA’s 2019 Outsourcing Guidelines with the effective date of the new Guidelines still to be confirmed. In this briefing, we set out key features of the Guidelines and the practical steps financial entities should now be considering.
Background
The EBA indicated that a primary driver for the Guidelines, and the replacement of the EBA’s 2019 Outsourcing Guidelines, was the current disparity between the application of regulatory rules to non-ICT services and ICT services. At present, DORA provides a harmonised regulatory framework for ICT services, but this was not replicated in respect of non-ICT services. The new Guidelines seek to address this by moving away from the narrower concept of “outsourcing” and focusing on “third-party arrangements”, with the result of a more harmonised regulatory approach towards non-ICT services. The EBA also stated that this new approach will help ensure a level playing field and foster supervisory convergence across ICT and non-ICT services.
Key features of Guidelines
Application to broader scope of arrangements
The most significant change introduced by the Guidelines is that in-scope financial entities will need to apply the requirements of the Guidelines to a broader scope of arrangements as compared to the EBA’s 2019 Outsourcing Guidelines. The Guidelines do this by prescribing that their requirements must be met in respect of “third-party arrangements”. In essence, the concept of third-party arrangements is designed to capture arrangements for non-ICT services delivered on an ongoing basis with outsourcing arrangements expressly captured as a subset of third-party arrangements. Along with expanding the scope of arrangements falling under the Guidelines, the Guidelines are clear on what type of arrangements are not in-scope. ICT services arrangements are expressly excluded from the Guidelines and will instead continue to be subject to DORA. The Guidelines also expressly exclude certain categories of services from their scope such as services legally required to be performed by a third-party service provider (e.g. statutory audit), regulated financial services that must be performed by another regulated financial entity, payment network infrastructure and certain clearing, settlement and correspondent banking arrangements.
Application to a broader scope of regulated entities
The EBA’s 2019 Outsourcing Guidelines applied to credit institutions, certain investment firms, electronic money institutions and payment institutions. The new Guidelines will apply to these entities as well as a range of other regulated entities including third-country branches carrying out banking activities in the EU, issuers of asset-referenced tokens under MiCAR, relevant financial institution creditors under the Mortgage Credit Directive and approved financial holding companies and mixed financial holding companies.
Focus on critical or important functions
While the Guidelines apply to a wider scope of arrangements and a broader range of financial entities, it is notable that the Guidelines are particularly focused on third-party arrangements supporting critical or important functions. The EBA states that this approach is intended to reduce unnecessary operational and supervisory burdens for less material arrangements while maintaining sound risk management. This approach also aligns with the Guidelines’ proportionality principle and is generally consistent with the approach in the EBA’s 2019 Outsourcing Guidelines.
Greater alignment with DORA
The Guidelines require financial entities to maintain a register of all third-party arrangements. The substance of this register is closely aligned with the DORA Register of Information, and the Guidelines expressly permit a single integrated register covering both DORA and the Guidelines (albeit financial entities can elect to maintain separate registers). The Guidelines also recognise that financial entities can develop either integrated or separate strategies for ICT and non-ICT third-party risk management, including that financial entities may put in place a single policy governing the use of ICT and non-ICT service providers where they elect to deploy a single strategy. The concept of critical or important function has also been updated in the final version of the Guidelines to closely align with the definition of this concept under DORA.
Governance and monitoring
The Guidelines include an uplift of the governance requirements as against the EBA’s 2019 Outsourcing Guidelines. For example, financial entities must establish a role tasked with monitoring all third-party arrangements or must designate a member of senior management who is directly accountable to the management body and responsible for overseeing the third-party risks. The Guidelines also require approval by the management body of business continuity and internal audit plans for third-party arrangements.
Contracts
The Guidelines prescribe certain contractual provisions that must be included in all third-party arrangements and certain additional contractual provisions that must be included in third-party arrangements that support critical or important functions. This is different from the approach in the EBA’s 2019 Outsourcing Guidelines, which mandated only contractual provisions for inclusion in outsourcing arrangements supporting critical or important functions. It is, however, aligned with the approach set out in DORA which prescribes certain contractual provisions for inclusion in all ICT services agreements and certain additional contractual provisions that must be included in ICT services agreements supporting critical or important functions. Helpfully, the nature of the contractual provisions prescribed by the Guidelines is very similar to that set out in DORA and the EBA’s 2019 Outsourcing Guidelines.
Timings and practical steps towards compliance
The date from which the Guidelines will apply has not yet been confirmed by the EBA but the Guidelines do make clear that financial entities will have a two-year period from the Guidelines’ application date to ensure that third-party arrangements supporting critical or important functions are reviewed and documented in line with the requirements of the Guidelines. For third-party arrangements supporting non-critical or important functions, they may be reviewed and documented for alignment with the Guidelines as part of the renewal process for such arrangements.
While the Guidelines afford financial entities some time to align third-party arrangements with the Guidelines’ relevant requirements, the compliance effort required of some financial entities could be reasonably significant (particularly where they expect to have a significant number of third-party arrangements that are subject to the Guidelines that were not previously subject to the EBA’s 2019 Outsourcing Guidelines), so commencing these compliance efforts in the coming months would be prudent.
Areas that financial entities may particularly wish to focus on as part of these compliance efforts include:
- Identification: Identify non-ICT third-party arrangements that now fall within scope but were not previously classified as outsourcing arrangements.
- Prioritisation: The Guidelines place particular focus on third-party arrangements that support critical or important functions and recognise that the Guidelines’ requirements are to be applied proportionately by financial entities. Therefore, appropriately prioritise compliance efforts in respect of the Guidelines once you identify all of your in-scope third-party arrangements.
- Contracts: Review the contracts in place for third-party arrangements against the contractual requirements of the Guidelines and identify gaps. Financial entities that previously undertook a contractual remediation exercise for DORA should be able to leverage the process and some of the collateral developed for that exercise.
- Governance: Review relevant governance and oversight structures and ensure that they are appropriately applied to third-party arrangements and uplifted, where required for alignment with the requirements of the Guidelines.
- Documentation: Develop your register of information for third-party arrangements and ensure that relevant policy documentation is either uplifted or developed (e.g. business continuity plan, third-party risk management policy, etc.).
Irish position
The CBI Outsourcing Guidance closely reflects the EBA’s 2019 Outsourcing Guidelines, so it is expected that the CBI will update this Guidance to reflect the EBA’s new Guidelines in due course. Therefore, Irish regulated firms that are not subject to the EBA’s new Guidelines but are subject to the CBI Outsourcing Guidance may wish to plan on the basis that the CBI Outsourcing Guidance will be updated in light of the EBA’s new Guidelines.
The authors would like to thank Vivienne O’Keeffe for her contribution to this briefing.


