Skip to main content

New EBA Guidelines on Third-Party Risk Management

The new framework creates further implementation needs for affected financial entities

The European Banking Authority (“EBA”) has published its final Guidelines on the management of third-party risk related to non-ICT services. The Guidelines will replace the existing EBA Guidelines on outsourcing arrangements, align the requirements with the provisions under DORA for ICT services and extend the regulatory focus from outsourcing arrangements to a broader range of recurrent or ongoing third-party arrangements. For affected financial entities, this requires an assessment of their third-party risk management framework, including, in particular, a review of their service provider classification, registers, contracts and internal governance processes.

1. Background and timeline

Following its 2025 consultation, the EBA published the final Guidelines on 18 September 2026. Unlike the previous EBA Guidelines on outsourcing arrangements, the new Guidelines generally cover any non-ICT arrangement under which a third-party service provider supports a function of a financial entity on a recurrent or ongoing basis. Outsourcing arrangements are now only a subset of these third-party arrangements. In addition to CRD institutions, payment institutions and electronic money institutions, the scope now includes issuers of asset-referenced tokens as well as certain investment firms and third-country branches.

ICT services within the meaning of DORA are excluded from the Guidelines. Since DORA became applicable, overlaps between the concepts of outsourcing and ICT services created a risk of dual regulation. With the 9th MaRisk Amendment, Bafin already excluded ICT services from the scope of AT 9 MaRisk. The EBA has now followed suit, while aligning the requirements with DORA and pursuing a “holistic approach”. The classification of hybrid arrangements remains challenging: where non-ICT services include ICT components, financial entities should assess whether the use of those components is material to the provision of the services and therefore triggers the application of DORA.

2. Key changes for affected financial entities

The Guidelines follow the basic structure of the previous Guidelines on outsourcing arrangements. However, the broader concept of third-party arrangements means that financial entities must also capture contractual arrangements that were previously not classified as outsourcing. The outsourcing register must therefore be extended to include all in-scope third-party arrangements. Processes previously designed for outsourcing arrangements, such as risk assessments, due diligence and monitoring, must also be extended to the now broader population of contractual arrangements.

The alignment with DORA is particularly evident in the contractual requirements. While the previous Guidelines specified minimum contractual provisions only for the outsourcing of critical or important functions, the new Guidelines adopt the two-tier system established by Article 30 DORA: paragraphs 83 et seq. require minimum contractual provisions for all in-scope third-party arrangements and additional provisions for arrangements supporting critical or important functions. Financial entities should therefore reassess existing outsourcing arrangements and contractual templates.

3. Outlook

It remains to be seen when and how Bafin will implement the Guidelines. Section 25b of the German Banking Act, which is specified (among others) by the MaRisk, only regulates outsourcing arrangements and not the broader concept of third-party arrangements.

Despite the differentiated transitional arrangements, affected financial entities should promptly assess their third-party arrangements against the new requirements and determine the need for adjustments.

Did you find this useful?

Thanks for your feedback

Insights and Further Information