EBA Publishes Updated Guidelines on Third-Party Risk Management: What it Means for Financial Services Firms and Their Critical Third-Party Suppliers
On 18 September 2026, the European Banking Authority (EBA) published its final Guidelines on the sound management of third-party risk (EBA/GL/2026/09) (the “Guidelines”) to replace the existing 2019 Guidelines on outsourcing arrangements. This follows a public consultation in 2025.
The Guidelines establish a risk management framework for financial institutions using third-party service providers (TPSPs) for non-Information and Communication Technology (“non-ICT”) services, with a particular focus on services supporting critical or important functions.
Background
The financial services sector has become increasingly reliant on a concentrated number of third-party service providers, including those offering critical services to financial services firms.
Against this backdrop of increased risks associated with overreliance on a limited number of TPSPs, the regulatory landscape for managing third-party risk in the EU has evolved significantly. The Digital Operational Resilience Act (DORA) introduced a harmonised framework for ICT third-party risk management, and the EBA’s existing guidelines addressed related but narrower ground, focusing only on outsourcing arrangements, rather than wider third-party service provision.
The Guidelines have been updated with the aim of establishing a more harmonised framework regarding the sound management of third-party risk, creating clearer requirements for ICT third-party services (under DORA) and non-ICT third-party services (under the Guidelines). The old outsourcing guidelines, which covered both ICT and non-ICT third-party outsourced services, will be repealed upon the new Guidelines coming into effect.
Scope of Application
The Guidelines apply to a broader range of financial entities than under the outsourcing guidelines, including credit institutions, relevant third-country branches, Class 1-minus and Class 2 investment firms, payment institutions, and electronic money institutions.
The EBA has drawn a clear line between the Guidelines and DORA. ICT services within DORA’s scope are excluded and remain governed by DORA’s ICT third-party risk management framework. However, entities are expected to adopt a holistic approach covering both ICT and non-ICT third-party risk, in particular where non-ICT third-party services include an element of ICT services.
The Guidelines apply to all non-ICT third-party arrangements, representing a notable expansion beyond the traditional narrow outsourcing regulation framework.
A number of arrangements are excluded from scope of the Guidelines, including legally required services (e.g. statutory audit), market information services, global payment network infrastructures, and immaterial services.
Substance of Guidelines
The Guidelines follow a broadly similar structure to their predecessor. They set out expectations for how firms should manage third-party arrangements throughout their life cycle, addressing areas such as robust internal governance arrangements, pre-contractual due diligence, key contractual provisions (including in relation to subcontracting and audit rights), ongoing oversight of third-party service providers and detailed exit planning for arrangements underpinning critical or important functions.
The Guidelines require firms to maintain an updated register on all TPSP arrangements, including both the non-ICT third-party arrangements and those required under DORA. Where TPSPs use ICT subcontractors effectively underpinning such non-ICT services supporting critical or important functions under DORA, those subcontractors should now be documented in the register as well.
Although there are similarities between the Guidelines and their predecessor, the widened scope of the Guidelines means that firms may now have much broader regulatory obligations in respect of their supply chain.
Firms may also face challenges as to the scope of applicable regulations where the services provided by TPSPs combine both ICT and non-ICT services, which is becoming more common. Firms will need to assess whether the ICT service element is enough to fall within the scope of DORA, in addition to the application of the Guidelines.
Timeline
The effective date of the Guidelines has not yet been specified. A two-year transitional period is contemplated for bringing existing arrangements supporting critical or important functions into line with the Guidelines. Firms should use this period to map their non-ICT third-party arrangements, conduct gap analyses, and update governance frameworks and contracts.
Contract remediation processes used by firms to achieve DORA compliance may be a helpful starting point when assessing contract remediation for compliance with the Guidelines.
Next Steps
Financial services firms should begin assessing the practical implications now, as the Guidelines will apply to arrangements entered into, reviewed, or amended from the application date.
Service providers of critical or important functions to regulated firms should expect to receive requests for information and contract amendments from their regulated customers. Such providers may want to consider a pro-active approach to assist their regulated customers with their compliance process, and to streamline their own processes where they have an extensive regulated customer base.
How We Can Help
Morrison Foerster regularly advises financial services firms and their suppliers on complex regulatory requirements, including EBA guidelines and DORA, and has a deep understanding of how to balance regulatory compliance with commercial and operational considerations. Please contact the authors to discuss how MoFo can help.


