The European Banking Authority has finalized Guidelines establishing a broader, more proportionate framework for managing third-party risk involving non-ICT services. Updating the 2019 outsourcing Guidelines, the framework covers third-party arrangements beyond outsourcing but concentrates stricter requirements on services supporting critical or important functions. It complements the Digital Operational Resilience Act, which governs third-party risk involving ICT services, and applies to financial entities including credit institutions, certain investment firms, payment and electronic money institutions, issuers of asset-referenced tokens and specified mortgage creditors. Financial entities must manage arrangements across their full lifecycle, including risk assessment, due diligence, contracting, subcontracting, monitoring and exit planning. Management bodies remain accountable and firms must retain sufficient resources and substance to oversee providers. Requirements include registers of third-party arrangements, contractual audit and access rights for critical or important functions, controls over subcontracting, business continuity arrangements and feasible exit strategies. Competent authorities should assess entity and sector concentration risks and may restrict services or require firms to exit arrangements where effective supervision or regulatory compliance cannot otherwise be ensured. A two-year transitional period applies to the review and documentation of existing arrangements supporting critical or important functions. If this work is not completed within that period, financial entities must inform their competent authority of the planned completion measures or possible exit strategy, while other arrangements may be reviewed when renewed.
2026-09-18European Banking Authority
European Banking Authority finalizes DORA-aligned non-ICT third-party risk Guidelines with two-year transition
The European Banking Authority has finalized DORA-aligned Guidelines for managing third-party risk involving non-ICT services, replacing its narrower 2019 outsourcing framework. Stricter governance, contracting, monitoring and exit requirements focus on arrangements supporting critical or important functions. Financial entities have a two-year transitional period to review and document those existing arrangements.