Home › Academy › Library › Final report on Guidelines on the sound…
Synthesis note · Guide

Final report on Guidelines on the sound management of third-party risk related to non-ICT services

European Banking Authority (EBA) · 2026 · Guide · 98 pages · Intermediate

This final report presents guidelines for the management of risks related to non-ICT third-party service providers in the financial sector. It emphasizes the importance of strong governance and operational resilience in light of the growing reliance of financial entities on these providers. The guidelines aim to strengthen compliance requirements and establish effective internal control mechanisms to minimize…

General Information

This document is the final report of the guidelines (EBA/GL/2026/09) issued by the European Banking Authority (EBA) in September 2026. It concerns the sound management of risks related to non-information and communication technology (non-ICT) third-party service providers in the European financial sector. The scope covers financial institutions subject to the CRD, IFD, PSD 2, MiFID II, MiCAR directives, as well as credit institutions, investment firms, payment institutions, issuers of asset-backed tokens (ARTs), and financial mortgage lenders. The document is based on approximately the first 34 pages provided, out of a total of 98 pages, and excludes ICT services which fall under the DORA regulation. It targets the post-2026 period and is intended for risk managers, data scientists, and master's students specializing in finance and risk management.

Executive Summary

The report addresses the management of risks related to the increasing use by financial entities of non-ICT third-party service providers, who offer specialized expertise and improve efficiency but also increase operational risks. These guidelines aim to strengthen governance and operational resilience of financial entities facing these risks, complementing the DORA framework which covers ICT services. They rely on the legal mandates of the CRD, IFD, PSD 2, MiFID II, and MiCAR directives, and incorporate supervisory requirements from competent authorities. The document clearly defines the concepts of third parties, third-party arrangements, critical or important functions, and concentration risks. It emphasizes the ongoing responsibility of financial entities' management bodies, who cannot delegate their obligations, especially in case of outsourcing critical functions. Entities must have sufficient resources to oversee these relationships, ensure continuity of critical functions, manage conflicts of interest, and plan exit strategies. Authorities must monitor systemic risks related to concentration of third-party providers, particularly those located outside the EU, and ensure a harmonized framework with DORA to avoid regulatory arbitrage. Key recommendations include adopting a written policy on contractual relationships with TPSPs, conducting rigorous pre-contractual analyses, fully documenting arrangements, implementing continuity and audit plans, and considering ESG risks. These measures must be proportionate to the size, complexity, and risk profile of entities. The report finally stresses the need for a holistic approach integrating ICT and non-ICT risks for effective third-party risk management.

Context and Objectives

Trust in the reliability of the financial system is essential to its proper functioning and role in the economy. Financial entities have increased their use of non-ICT third-party service providers to reduce costs, improve flexibility and efficiency, but this generates major operational risks. The European regulatory framework, notably the CRD, IFD, PSD 2, MiFID II, MiCAR directives, as well as the DORA regulation for ICT services, imposes governance and risk management requirements. However, the management of risks related to non-ICT services provided by third parties was not harmonized. These guidelines aim to fill this gap by establishing a common framework for sound management of non-ICT third-party risks, particularly for critical or important functions. They target financial entities and competent authorities, taking into account structural diversity, including groups, members of institutional protection schemes, and third-country entities. The objectives are to ensure continuity of critical functions, avoid creation of "empty shell" entities, prevent systemic risks linked to provider concentration, and guarantee effective and consistent supervision within the European Union.

Summary of Key Points by Theme

Key definitions:

- Third-party arrangements: contractual relationships between a financial entity and a third-party provider, including intragroup arrangements, for the provision of functions on a recurring or ongoing basis (p.19).

- Critical or important functions: functions whose failure or disruption would significantly affect the entity's financial performance, service continuity, or regulatory compliance (p.20).

- Concentration risk: excessive dependence on one or more third-party providers that could threaten continuity of critical functions or financial stability (p.20).

Governance and responsibilities:

- The board of directors (management body) retains full and entire responsibility for managing third-party risks, with no delegation possible (p.28).

- Adoption of an annual written policy on the use of critical non-ICT services, covering all phases of the contract lifecycle (p.30-31).

- Appointment of a senior officer to oversee third-party risks, with adequate resources (p.28-29).

- Obligation to maintain sufficient substance to avoid "empty shell" entities (p.29).

Risk assessment and management:

- Systematic identification of critical or important functions supported by TPSPs (p.26).

- Exclusion of ICT services, which fall under the DORA framework (p.16-17).

- Thorough pre-contractual analysis including due diligence, risk assessment, conflicts of interest, and business continuity (p.31).

- Continuous monitoring of TPSP performance and changes, with audit rights and access for entities and authorities (p.28, p.32).

- Management of conflicts of interest, notably in intragroup arrangements or within institutional protection schemes (p.32-33).

Business continuity and exit plans:

- Development and periodic testing of business continuity plans involving TPSPs (p.33).

- Preparation of documented exit plans for critical functions, enabling migration, reintegration, or cessation of activity (p.31).

Supervision and systemic risks:

- Obligation for competent authorities to have a comprehensive view of third-party arrangements, especially for critical functions (p.12-13).

- Monitoring of concentration risks and excessive dependence, notably regarding TPSPs located outside the EU (p.5-6).

- Harmonization of requirements with DORA to avoid regulatory arbitrage (p.7-9).

Proportionality:

- Application of proportionality principles according to the size, complexity, and risk profile of entities (p.22-23).

- Adaptation of requirements for less complex entities or non-critical functions (p.23).

Contractual relationships:

- Necessity of written contracts detailing access rights, audit, subcontracting conditions, and termination clauses (p.28, p.31).

- Prohibition of delegation of management responsibilities, even in case of subcontracting (p.29).

Regulatory compliance:

- Compliance with European legislation, notably GDPR for personal data protection (p.29).

- Consideration of environmental, social, and governance (ESG) risks, particularly for third-country TPSPs (p.24).

Application and implementation:

- Effective date to be defined, with a two-year transitional period for compliance of existing arrangements (p.21).

- Mandatory notification by competent authorities to the EBA on compliance with the guidelines (p.15).

- Repeal of the 2019 EBA outsourcing guidelines (p.21).

Main Findings and Lessons Learned

Findings:

- The increased use of non-ICT TPSPs by financial entities is a major trend generating significant operational risks (p.4-6).

- Critical or important functions are precisely defined and their management is essential for continuity and compliance of entities (p.19-20).

- The management body's responsibility is inalienable, even in case of outsourcing (p.28).

- Competent authorities must monitor concentration risks and third-party arrangements, notably those involving third-country TPSPs (p.5-6, p.12-13).

Assumptions:

- A harmonized approach between the DORA (ICT) framework and these guidelines (non-ICT) will enable holistic third-party risk management (p.7-9).

- Application of the proportionality principle ensures adaptation of requirements to entities' specificities (p.22-23).

Interpretations:

- Intragroup arrangements are not less risky than external third parties and must be subject to the same requirements (p.10-11).

- Excessive concentration on a limited number of TPSPs can generate systemic risks (p.12-13).

- Conflict of interest management is crucial, notably within groups and institutional protection schemes (p.32-33).

Uncertainties:

- The precise effective date of the guidelines remains to be defined (p.21).

- The concrete impact of requirements on current practices of entities, especially smaller ones, remains to be observed (p.23).

Conclusions and Recommendations

The EBA recommends that financial entities establish robust governance and non-ICT third-party risk management frameworks, including:

- An annual written policy on relationships with TPSPs, covering all phases of the contract lifecycle.

- Systematic identification and assessment of critical or important functions supported by TPSPs.

- Implementation of rigorous due diligence procedures before contracting.

- Continuous monitoring of TPSPs, including audit and access rights for entities and authorities.

- Proactive management of conflicts of interest, particularly in intragroup arrangements.

- Development and periodic testing of continuity plans and documented exit plans.

- Application of the proportionality principle to adapt requirements according to size and complexity.

- Ensuring entities do not become "empty shells" and maintain sufficient substance.

- Close cooperation with competent authorities, notably for notification of critical arrangements and systemic risk management.

Competent authorities must integrate these guidelines into their supervisory practices, ensure effective monitoring of third-party risks, and prevent systemic risks related to TPSP concentration, particularly those located outside the EU. The framework must be aligned with DORA to ensure a coherent approach to ICT and non-ICT risks. The application date will be set later, with a two-year transitional period for compliance of existing arrangements.

Key takeaways

References

Year
2026
Type
Guide
Level
Intermediate
Licence
Attribution required
Original document
https://www.eba.europa.eu/sites/default/files/2026-09/dc9ccbb3-79b9-4…
Read the original document ← Back to the library

Synthesis note written from the full document by DataSAI Academy. This note comes from the scientific library of the DataSAI Academy, open to all.