From outsourcing to third-party arrangements: new EBA Guidelines on non-ICT third-party risk
- Articles and memoranda
- Posted 30.09.2026
On 18 September 2026, the European Banking Authority (“EBA”) published its final report on Guidelines on the sound management of third-party risk related to non-ICT services (EBA/GL/2026/09, the “2026 Guidelines”)1. They will repeal the EBA Guidelines on outsourcing arrangements (EBA/GL/2019/02, the “2019 Guidelines”)2, implemented in Luxembourg through Circular CSSF 22/806 on outsourcing arrangements, as amended (“Circular 22/806”)3.
From outsourcing to third-party arrangements
The main concept is no longer outsourcing, but third-party arrangements. A third-party arrangement is any arrangement under which a provider supports one or more of the institution’s functions on a recurrent or ongoing basis; outsourcing is a subset of that concept (paragraph 17). Whether the institution would otherwise have performed the function itself no longer determines whether the framework applies.
The 2019 Guidelines already required institutions to manage the risks from all third-party arrangements, whether or not they qualified as outsourcing (paragraph 33 of the 2019 Guidelines). What changes is that documentation and contractual requirements now follow the wider perimeter.
Most exclusions in paragraph 33 of the 2026 Guidelines are familiar: statutory audit, market information services, clearing and settlement and correspondent banking were already outside the scope of the 2019 Guidelines. There are also new exclusions, including regulated services that must by law be performed by another EU-regulated entity, such as custody and trading venues, as well as transactions between financial institutions acting as counterparties and transactions with central banks. The ancillary services exclusion now turns on the absence of material impact.
Contracts, audit rights and registers
Under the 2019 Guidelines the detailed list of mandatory clauses applied only to the outsourcing of critical or important functions (“CIFs”) (paragraph 75). Other types of outsourcing were not unregulated: a written agreement was required in all cases, as were internal audit review rights and a reference to supervisory and resolution powers, regardless of criticality (paragraphs 74, 85 and 86 of the 2019 Guidelines). The 2026 Guidelines replace that dispersed baseline with an explicit minimum content for every in-scope arrangement, plus additional content for CIF arrangements (paragraphs 84 and 85 of the 2026 Guidelines).
Supervisory access is largely unchanged: for CRD institutions, the obligation to refer to the powers of competent and resolution authorities still applies regardless of criticality (paragraph 97). For non-CIF arrangements, however, institutions should consider including access and audit rights on a risk-based approach (paragraph 99), where the 2019 Guidelines required them to ensure those rights (paragraph 88).
In Luxembourg, the impact may be more limited, because point 77 of Circular 22/806 already prescribes minimum content for all outsourcing agreements. The incremental drafting effort is therefore likely to focus on arrangements that fall within scope but do not qualify as outsourcing.
The register must cover all in-scope arrangements and, subject to proportionality, be consistent to the extent possible with the DORA register of information; the two may be combined (paragraphs 58 to 61). Additional CIF fields include the rank of subcontractors in the chain, recovery objectives, substitutability and whether an exit plan exists (paragraph 62). Unlike the DORA register, it is produced only on request to the competent authority (paragraph 63).
Subcontracting
This is likely the area with the heaviest drafting burden. Contracts for services supporting CIFs must specify whether subcontracting is permitted and on what conditions. They must now also address subcontractor and parent-company location risks, reporting down the chain, continuity if a subcontractor fails, and access and audit rights for competent and resolution authorities (paragraphs 87 to 89).
Governance: largely a reuse exercise
The management body must approve a strategy on third-party risk, which may be integrated with or kept separate from the corresponding ICT strategy (paragraph 38). The policy is limited to non-ICT services supporting CIFs, must be reviewed at least annually, and may be integrated with the policy that DORA requires for ICT services (paragraphs 47 to 49). The CIF definition is aligned with DORA and the prescriptive list of assessment factors has been removed (paragraphs 34 to 37).
Notification perimeter is narrower. Planned CIF arrangements and functions that become critical or important remain notifiable, but material changes and severe events are reportable only for CIF arrangements (paragraphs 65 and 66). Luxembourg’s three-month advance notification would seem to be unaffected for now.
Timing
The 2026 Guidelines are not yet applicable. Their application date will be set once the guidelines have been translated into all EU official languages. They will apply to arrangements entered into, reviewed or amended on or after the application date, and existing arrangements must then be reviewed and amended accordingly (paragraphs 18 and 19). If the review and documentation of CIF arrangements is incomplete by the end of two-year period following the date of application , the institution must inform the competent authority and set out the measures planned to complete the exercise or its exit strategy (paragraph 20). Other arrangements may be reviewed upon renewal (paragraph 21).
Next steps
Institutions may wish to start by identifying recurrent non-ICT arrangements outside their outsourcing inventory, and recording the basis for any exclusion relied on. Mapping the register fields against the DORA register will show whether maintaining a single, integrated register is realistic. Contract templates should be tested against paragraphs 84, 85 and 89 of the 2026 Guidelines, with subcontracting likely requiring the most extensive updates.
| 1 | EBA, Final Report - Guidelines on the sound management of third-party risk related to non-ICT services, EBA/GL/2026/09, 18 September 2026. | |||
| 2 | EBA, Guidelines on outsourcing arrangements, EBA/GL/2019/02, 25 February 2019. | |||
| 3 | Circular CSSF 22/806 on outsourcing arrangements, as amended by Circulars CSSF 25/883 and CSSF 26/915. | |||