EBA/GL/2026/09: Third-Party Risk for Non-ICT Services

Legal status as of: 5 October 2026 – this article is based on the European Banking Authority (EBA) Final Report published on 18 September 2026. The application date of the Guidelines has not yet been announced – we will update this post once it is confirmed.

On 18 September 2026, the EBA published its Final Report on the Guidelines on the sound management of third-party risk related to non-ICT services (EBA/GL/2026/09). The new Guidelines will replace the 2019 EBA Guidelines on outsourcing arrangements (EBA/GL/2019/02) and extend to non-ICT service providers the same lifecycle approach that DORA introduced for ICT third-party providers.

For banks, investment firms and payment institutions, this means one thing: vendor risk management will no longer be split into “DORA” and “everything else”. Both parts will need to follow consistent rules.

In this article, we explain what the new Guidelines change, who they apply to, how they relate to DORA, and where to start preparing before the transition period begins.

What are the EBA/GL/2026/09 Guidelines?

The Guidelines are issued under Article 74 of Directive 2013/36/EU (CRD) and set out the internal governance and risk management arrangements that financial entities should have in place when they rely on third-party service providers for non-ICT services. They cover the full lifecycle of a third-party arrangement: risk assessment, due diligence, contracting, subcontracting, monitoring, documentation and exit strategies.

Particular focus is placed on arrangements supporting critical or important functions (CIFs) – functions whose disruption would materially impair the performance of the entity. These arrangements are subject to the full set of requirements.

What changes compared with the 2019 Guidelines?

Much of the substance carries over from the outsourcing Guidelines, but the starting point and scope change:

Area EBA/GL/2019/02 EBA/GL/2026/09
Starting point Outsourcing arrangement Any third-party arrangement – outsourcing is only a subset
Services covered Outsourcing of ICT and non-ICT services Non-ICT services – ICT services within the scope of Chapter V of DORA are excluded
Entities in scope Institutions, payment institutions and electronic money institutions Wider – including issuers of asset-referenced tokens and mortgage creditors that are financial institutions
Register Register of outsourcing arrangements Register of third-party arrangements – may be combined with the DORA register of information
Relationship with DORA Issued before DORA Designed to complement DORA, with consistent logic and the same CIF definition

The most important practical change: classifying a contract as “not outsourcing” no longer takes it out of scope.

Who do the new Guidelines apply to?

The Guidelines are addressed to national competent authorities and, through them, to supervised entities that use non-ICT services provided by third parties:

  • institutions within the meaning of CRD/CRR, including banks,
  • investment firms – except small and non-interconnected investment firms under Article 12(1) IFR,
  • payment institutions,
  • electronic money institutions,
  • issuers of asset-referenced tokens (ARTs),
  • creditors as defined in the Mortgage Credit Directive that are financial institutions.

Third-party risk is assessed not only at the level of the individual entity but also in the context of the group.

How do the EBA/GL/2026/09 Guidelines relate to DORA?

They complement each other. DORA governs risks related to ICT third-party service providers, while the new Guidelines cover non-ICT service providers. Together they form a complete third-party risk management (TPRM) framework, and the EBA explicitly expects institutions to take a holistic approach across both areas.

The boundary between the two regimes is drawn by the type of service, not the provider – the same counterparty may deliver an ICT service (DORA) and a non-ICT service (the Guidelines). For mixed services, the institution should take and document a decision on the applicable regime, together with a justification of how material the ICT component is.

Key principles of the new Guidelines

  • Proportionality – the full regime applies to arrangements supporting critical or important functions; less material arrangements carry a lighter burden. This approach is familiar from DORA.
  • End-to-end lifecycle – risk assessment, due diligence, contracting, subcontracting, monitoring, documentation and exit strategy, consistent with DORA.
  • Concentration risk – renewed emphasis on dependency on single providers, including outside the ICT domain.
  • Management body accountability – the third-party risk management strategy and policy are approved by the management body.

When do the new Guidelines apply?

The application date has not yet been confirmed – the Guidelines are awaiting publication of translations into all official EU languages. Until then, the 2019 outsourcing Guidelines remain in force.

From the application date, the new rules will apply to third-party arrangements entered into, reviewed or amended, and a two-year transition period is foreseen for bringing existing arrangements into line.

What do in-scope institutions need to do?

  1. Reclassify contracts – review the entire non-ICT supplier base: which contracts are third-party arrangements, which support critical or important functions, and where a mixed service requires a DORA vs Guidelines decision.
  2. Update policies – replace the outsourcing policy with a third-party risk management policy aligned with the DORA framework.
  3. Amend contracts – requirements on SLAs, audit rights, business continuity plans and exit strategies, now also for relationships outside the ICT domain.
  4. Extend the register – a register of non-ICT arrangements, which the EBA allows to be kept together with the DORA register of information.
  5. Monitoring and concentration – ongoing oversight of non-ICT providers, their subcontractors and the risk of dependency on single providers.

BCMLogic expert comment: the main cost of compliance will not be the new requirements themselves, but the scale of the non-ICT contract review. That is why we recommend starting the inventory now, without waiting for the application date. Institutions that have implemented DORA have a head start – their CIF classifications, process maps, supplier data and exit strategies are a ready-made starting point.

Common mistakes in preparation

  • Waiting for the application date – a two-year transition period is shorter than it seems when hundreds of contracts need to be reviewed and amendments negotiated.
  • Relying on the old “not outsourcing” classification – with the new starting point, such contracts may still fall within the Guidelines.
  • Building a separate non-ICT register – two independent registers mean double data maintenance and a risk of inconsistency, even though the EBA allows a single combined one.
  • No documented decisions for mixed services – choosing DORA or the Guidelines without a justification will be hard to defend in an audit or supervisory review.
  • Overlooking subcontractors and the group perspective – concentration risk often only becomes visible at the level of the supply chain or the group.

How we are preparing BCMLogic Next

We are analysing an extension of the platform’s current scope (DORA) to cover non-ICT arrangements. Mapping the requirements of the Guidelines to the functions used for DORA today looks as follows:

Requirement of the Guidelines BCMLogic Next function used for DORA today
Register of supplier arrangements Register of Information – to be extended to non-ICT arrangements
Classification of critical or important functions CIF classification linked to the BIA and process map
Due diligence and supplier risk assessment Supplier assessments (Vendor module) – new non-ICT templates
Monitoring, concentration, subcontractors Supply chain and concentration risk analysis
Business continuity plans and exit strategies Continuity module – BCM plans and exit plans linked to contracts

The model under analysis assumes one register for two regimes: each contract is classified as ICT / non-ICT / mixed, and validation rules check data completeness against the applicable regime. Reclassification of the existing contract base would follow four steps:

  1. Inventory – import of the non-ICT contract base from spreadsheets, procurement systems or the contract repository.
  2. Initial AI classification – the GRC AI Expert, grounded in the text of the Guidelines and DORA, proposes a classification for each contract with references to specific provisions.
  3. Human decision – every proposal is approved or corrected by the business owner. AI recommends; the user decides.
  4. Contract gap plan – for CIF arrangements, the system identifies gaps (SLA, audit, continuity, exit) and builds an amendment schedule.

Classification decisions, assessments and contract gaps are to be versioned, with a full audit trail. We expect the analysis to run until Q1 2027 and plan to release the extension in 2027 within existing instances. We will share detailed timelines once the application date of the Guidelines is confirmed.

FAQ

Do the EBA/GL/2026/09 Guidelines replace the 2019 Guidelines on outsourcing arrangements?

Yes. The EBA/GL/2019/02 Guidelines will be repealed on the date the new Guidelines start to apply. Until then, the existing outsourcing regime remains in force.

When do the new EBA Guidelines apply?

The application date has not yet been confirmed – the Guidelines are awaiting translation into the official EU languages. From that date, they will apply to arrangements entered into, reviewed or amended, with a two-year transition period for existing arrangements.

What is the difference between a third-party arrangement and outsourcing?

A third-party arrangement is the broader concept – outsourcing is only a subset of it. Classifying a contract as not being outsourcing no longer takes it out of scope. The full set of requirements applies primarily to arrangements supporting critical or important functions.

Do the new Guidelines cover ICT services?

No. ICT services within the scope of Chapter V of DORA are excluded from the Guidelines and remain subject to DORA. For mixed services, the institution should document its decision on which regime applies.

Can ICT and non-ICT arrangements be kept in a single register?

Yes. The EBA allows the register of non-ICT arrangements to be combined with the register of information required under DORA.

Where should institutions start preparing?

With an inventory of non-ICT supplier contracts. The next steps are contract reclassification, a policy update, a contract amendment plan and extending the register.

Summary

The EBA/GL/2026/09 Guidelines close the third-party risk management framework that DORA left open on the non-ICT side. The logic is familiar – proportionality, critical or important functions, the arrangement lifecycle – but the scope is much wider than traditional outsourcing. The application date is not yet known, but now is a good time to inventory the non-ICT contract base and plan a single, shared process for all suppliers – instead of building a second, parallel system alongside DORA.

See how this could work in your organisation

If your organisation manages suppliers in line with DORA and is preparing for the new EBA Guidelines, see how the register of information, supplier assessments and exit plans work together on a single GRC platform. BCMLogic Solutions supports financial and technology companies in operational risk management, business continuity and regulatory compliance – in line with ISO 22301, ISO 27001 and requirements such as DORA and NIS2.

Book a demo →