Non-ICT third-party risk rules set tighter oversight for EU banks
On September 18, 2026, the European Banking Authority (EBA) issued final guidelines on managing third-party risk for non-ICT service providers. The framework repeals the 2019 outsourcing rules and extends governance standards to investment firms, payment entities, and crypto issuers.
Stricter duties for critical operations
Under the final guidelines (EBA/GL/2026/09), financial entities must systematically manage risks from non-ICT third-party service providers (TPSPs).
The framework complements the Digital Operational Resilience Act (DORA), covering credit institutions, investment firms under IFD, payment institutions, and asset-referenced token issuers under MiCAR.
Institutions must apply stricter safeguards to arrangements supporting critical or important functions, including mandatory due diligence, explicit termination clauses, and comprehensive audit rights.
Additionally, firms must maintain an updated register of all third-party contracts and ensure they do not become “empty shells” lacking operational substance.
A two-year window to comply
The guidelines repeal the 2019 outsourcing framework following a three-month consultation that drew 72 industry responses.
Financial entities receive a two-year transitional period from the date of application to review and document arrangements supporting critical or important functions.
Non-critical contracts need only be updated upon contract renewal.
The framework explicitly excludes statutory audits, payment network infrastructures, clearing arrangements, and routine services like utilities or maintenance.
Harmonisation at the cost of complexity
Running parallel rules for ICT and non-ICT vendors imposes a heavy load on mid-sized institutions.
The two-year transition softens the blow, but renegotiating legacy contracts will strain internal resources.
Supervisors must apply proportionality pragmatically to prevent a slide into formalistic compliance.