European Banking Authority (EBA)Guidelines EBA/GL/2026/09

EBA/GL/2026/09: EBA third-party risk guidelines to replace 2019 outsourcing guidelines

European Banking Authority (EBA)Guidelines EBA/GL/2026/09Issued

By the ExamPass CY editorial teamPublished

Short answer

On 18 September 2026 the EBA published final Guidelines on the sound management of third-party risk related to non-ICT services (EBA/GL/2026/09). They are addressed to credit institutions, investment firms that are not small and non-interconnected, payment and e-money institutions and issuers of asset-referenced tokens, and will repeal the EBA's 2019 Guidelines on outsourcing. ICT services stay under DORA. The guidelines are not yet applicable: the date of application has not been set, and a two-year transition applies to reviewing existing arrangements that support critical or important functions.

At a glance

What changes
One EBA framework for non-ICT third-party arrangements, focused on those supporting critical or important functions, will replace the 2019 Guidelines on outsourcing.
Who is affected
Credit institutions, investment firms other than small and non-interconnected ones, payment and e-money institutions and issuers of asset-referenced tokens. Crypto-asset service providers, UCITS management companies and AIFMs are not addressees.
  • Investment firms that are not small and non-interconnected (Class 2 and Class 1 minus)
  • Credit institutions
  • Payment institutions and electronic money institutions
  • Issuers of asset-referenced tokens
  • Compliance, risk and internal audit staff who oversee outsourcing and other third-party arrangements
What to do
Map non-ICT third-party arrangements, flag those that support critical or important functions, and plan the register, the policy, reviews and exit strategies.
By when
Not yet applicable — date of application still to be set

What has the EBA published?

On 18 September 2026 the European Banking Authority published its final report on Guidelines on the sound management of third-party risk related to non-ICT services, reference EBA/GL/2026/09. The guidelines cover third-party arrangements across their life cycle, from risk assessment and due diligence to contracting, subcontracting, monitoring, documentation and exit. Outsourcing arrangements are treated as a subset of third-party arrangements.

ICT services are excluded because they fall within the Digital Operational Resilience Act (DORA); the guidelines apply to non-ICT services, but firms should take a holistic approach to both. The EBA Guidelines on outsourcing of 25 February 2019 are repealed with effect from the date of application. Competent authorities and financial institutions must make every effort to comply, and national supervisors must tell the EBA whether they comply or intend to comply.

Who is in scope?

The guidelines are addressed to competent authorities and to credit institutions, third-country branches, investment firms other than small and non-interconnected investment firms, payment institutions, electronic money institutions, issuers of asset-referenced tokens and certain mortgage creditors, as well as approved financial holding companies and mixed financial holding companies. Class 1 minus and Class 2 investment firms apply them without prejudice to the outsourcing requirements of MiFID II and Delegated Regulation (EU) 2017/565 and to relevant ESMA guidance.

Crypto-asset service providers are not addressees; the EBA notes that Article 73 of MiCA regulates their outsourcing. UCITS management companies and AIFMs are not addressees either, although the guidelines apply on a consolidated and sub-consolidated basis, which can include them where they are part of a banking or investment-firm group's prudential scope of consolidation.

What will firms be expected to do?

A function is critical or important where its disruption would materially impair the firm's continuing compliance with its authorisation or other obligations, its financial performance, or the soundness or continuity of its services and activities. Operational tasks of internal control functions should always be considered critical or important unless the firm's assessment shows otherwise. Some services are excluded, such as services legally required to be performed by a third party (for example the statutory audit), market information services and the purchase of goods or utilities.

The management body should approve a written policy on non-ICT services supporting critical or important functions and review it at least once a year, and the firm should assign a role or a member of senior management to oversee third-party risk. Relying on third parties takes no responsibility away from the management body, and firms should not become 'empty shells'. Firms should keep a register of all third-party arrangements, consistent as far as possible with the DORA register of information and possibly combined with it, inform their competent authority in a timely manner of planned arrangements for critical or important functions, and be able, within an appropriate time, to move such a function to another provider, bring it back in-house or discontinue the business activities that depend on it. See our study note on outsourcing critical functions.

When will the guidelines apply?

Not yet. The EBA lists the guidelines as final and awaiting translation into the official EU languages and as not yet applicable, and the final report leaves the date of application blank. From that date they apply to all third-party arrangements entered into, reviewed or amended, and firms should review and amend existing arrangements to bring them into line.

Where the review and documentation of existing arrangements supporting critical or important functions is not finalised within two years of the date of application, firms should inform their competent authority, including the measures planned to complete the review or the possible exit strategy. Arrangements supporting other functions may be reviewed and documented when they are renewed.

In the official wording

“The use of TPSPs for the provision of services to support functions cannot result in the delegation of the management body’s responsibilities.”

EBA, Final report: Guidelines on the sound management of third-party risk related to non-ICT services (EBA/GL/2026/09), para. 41

When does it apply?

Applies now

  • Nothing new yet: EBA/GL/2026/09 is final but not yet applicable.
  • The EBA Guidelines on outsourcing of 25 February 2019 remain in place until they are repealed with effect from the date of application of the new guidelines.

Applies later

No later dates announced.

What to do

  1. List all non-ICT third-party arrangements and mark those that support critical or important functions.No fixed deadline
  2. Compare your outsourcing policy and outsourcing register with the guidelines and with your DORA register of information.No fixed deadline
  3. Check whether your competent authority confirms that it will apply the guidelines, and note the date of application once the EBA sets it.No fixed deadline

In the exam

Outsourcing of critical or important functions by investment firms is part of the organisational requirements in the CySEC Advanced and Basic exam material.

Related study notes

Preparing for an exam?

Practise the topics behind this update

Exam-style questions with a hint before you answer and a full explanation after, chapter by chapter.

Sources

  1. Final report: Guidelines on the sound management of third-party risk related to non-ICT services (EBA/GL/2026/09) (opens in a new tab)

    EBAOfficial text

  2. The EBA publishes its final Guidelines on the management of third-party risk, delivering a more proportionate and consistent framework aligned with DORA (opens in a new tab)

    EBAOfficial text

  3. Guidelines on third party risk management (status page) (opens in a new tab)

    EBAOfficial text

Summary prepared by the ExamPass CY editorial team; it is not the official text. Quotations are reproduced from the source for the purpose of reporting and review.

Get the weekly Regulatory Brief

New CySEC, ESMA, AMLA and EU publications in plain English: what changes, who is affected and what to do by when.

How often?

More updates

All updates →