6 Oct 2026
EBA 2026 Third-Party Risk Guidelines: What Suppliers to EU Financial Institutions Should Prepare For
The EBA's final 2026 guidelines on the sound management of third-party risk extend DORA-like principles to non-ICT services. Current status, scope, transitional timeline, and what suppliers should prepare.

EBA 2026 Third-Party Risk Guidelines: What Suppliers to EU Financial Institutions Should Prepare For
Last reviewed: 6 October 2026. This article summarizes a regulatory development that was finalized very recently and whose official application date had not yet been published in all EU languages at the time of writing. It is for general informational purposes only, is not legal advice, and should be verified against the EBA's own published guidelines before you rely on it for a compliance decision.
Disclaimer: This is a time-sensitive regulatory topic. The information below reflects the European Banking Authority's own public statements as of early October 2026. Guideline text, application dates, and transitional arrangements can be updated or clarified after publication. Always confirm current status directly on the EBA's website or with qualified counsel before making a compliance decision.
Quick answer
On 18 September 2026, the European Banking Authority (EBA) published its final Guidelines on the sound management of third-party risk, which will replace the EBA's 2019 Outsourcing Guidelines. As of this review, the guidelines are final but still awaiting formal translation into all EU official languages — they are not yet in force, and a two-year transitional period is intended to support a "smooth and proportionate" implementation once they do apply. The guidelines extend DORA-style third-party risk management principles to non-ICT services — professional services, consulting, legal, marketing, and other third-party arrangements that DORA (which covers ICT services only) does not reach. If your company supplies non-ICT services to an EU bank, payment institution, investment firm, or similar regulated entity, this is the framework that will eventually shape how that customer assesses, contracts with, monitors, and plans to exit its relationship with you.
What the regulation says vs. what your customer may ask you for: the legal obligation sits with the financial entity, not with you as a supplier. Everything in this article that describes what a vendor should "expect" or "prepare" is an operational inference about what financial entities commonly need from suppliers to meet their own obligations — not a direct legal requirement on your company.
Contents
- Current legal status (check this first)
- What changed: from "outsourcing" to "third-party risk"
- How this relates to DORA
- Who is covered
- Critical or important functions: why this concept matters
- What financial-entity customers may need from suppliers
- The transitional timeline
- What this can mean operationally for your business
- FAQ
- Official sources
Current legal status (check this first)
This is the single most important section of this article, because the master brief behind it exists specifically to avoid overstating where this regulation stands.
As of early October 2026, based on the EBA's own published statement:
- The guidelines are final — the EBA has completed its consultation (which ran from 8 July 2025 to 8 October 2025) and published its final report and guidelines on 18 September 2026.
- They are "final and awaiting translation into the EU official languages" — meaning the guidelines are not yet formally in force across the EU in the way a fully published, translated EBA guideline is.
- A two-year transitional period is intended to support implementation once the guidelines do take effect, to give financial entities time to update contracts, registers, and internal processes.
- We could not independently verify an exact calendar application date (the specific date the two-year clock starts) from public sources at the time of this review. Do not assume the guidelines are already fully applicable, and do not assume a specific start date without checking the EBA's guidelines page directly — EBA guidelines typically confirm their application date once official-language translations are published.
Because this regulation was finalized only days before this article's last-reviewed date, treat any specific application date you see elsewhere (including in earlier drafts of commentary written before 18 September 2026) with caution. Confirm current status on the EBA's own site before making a business decision.
What changed: from "outsourcing" to "third-party risk"
The EBA's previous framework, the 2019 Guidelines on outsourcing arrangements, focused specifically on outsourcing relationships. The new guidelines are broader in two ways:
- Broader scope of relationship. Rather than being limited to "outsourcing" as a specific legal/functional concept, the new guidelines apply to third-party arrangements more generally — including, according to legal commentary on the final text, professional services, consulting, legal services, marketing, and similar arrangements with external providers, not just classic outsourcing.
- A more unified, risk-based approach. The guidelines are explicitly designed to be proportionate: they concentrate the more detailed requirements on third-party arrangements that support a financial entity's critical or important functions, while reducing operational and supervisory burden for less material arrangements — rather than applying one uniform standard to every supplier relationship regardless of risk.
What this typically means for a supplier: if your service is genuinely peripheral to your financial-institution customer's operations, you may see comparatively light-touch treatment. If your service supports something the customer considers critical or important, expect a more structured, DORA-like process.
How this relates to DORA
It's easy to conflate this with DORA, but they are distinct, complementary frameworks:
| DORA (Regulation (EU) 2022/2554) | EBA third-party risk guidelines (2026) | |
|---|---|---|
| Legal form | Directly applicable EU regulation | EBA guidelines (a "comply or explain" supervisory instrument, not a directly binding regulation in the same sense) |
| Scope | ICT services and digital operational resilience | Third-party arrangements generally, explicitly including non-ICT services |
| Status as of Oct 2026 | In force and applicable since 17 January 2025 | Final, awaiting translation; not yet applicable; two-year transition period to follow |
| Who it binds directly | In-scope EU financial entities (see our DORA guide for the list) | The same broad population of EU financial institutions the EBA regulates, for their non-ICT third-party relationships |
| Vendor's relationship to it | Indirect, via contract/due diligence flow-down (unless designated a "critical" ICT provider) | Indirect, via contract/due diligence flow-down |
For ICT services, DORA is the primary reference. For everything else your financial-institution customer buys from external providers — consulting, legal, facilities, marketing, recruitment, and other non-ICT services — these EBA guidelines are intended to be the aligned, non-ICT counterpart, using similar underlying principles (risk assessment, contracting, subcontracting, monitoring, exit planning, documentation) so the two frameworks work together rather than creating a gap.
Who is covered
Based on EBA and legal-commentary sources, the guidelines are expected to apply broadly to institutions within the EBA's remit, including credit institutions, investment firms, payment institutions and electronic money institutions, and other entities subject to the EBA's governance expectations (for example, referencing obligations under Directive 2013/36/EU, PSD2, and related EU banking/payments legislation), with some categories — such as certain credit intermediaries and specific PSD2-registered account information service providers — reportedly excluded or treated differently. Confirm your specific customer's regulatory status and whether they fall within scope directly with them — this article cannot make that determination for your business.
Critical or important functions: why this concept matters
Like DORA, these guidelines organize their requirements around whether a third-party arrangement supports a "critical or important function" — broadly, a function whose disruption would materially impair the financial entity's performance, ongoing compliance, financial condition, or continuity of services. This concept, not the type of service you provide, is what appears to drive how much scrutiny a given supplier relationship receives.
Practical implication: two suppliers offering superficially similar services to the same bank can face very different levels of due diligence and contractual requirement, depending on how the bank classifies the function each one supports — a classification decision that sits with the customer, not the vendor.
What financial-entity customers may need from suppliers
Based on the lifecycle the guidelines are reported to cover, financial-entity customers are likely to look for the following from non-ICT suppliers, particularly where a critical or important function is involved:
| Lifecycle stage | What the guideline addresses | What a supplier may be asked for |
|---|---|---|
| Risk assessment & due diligence | Pre-contractual assessment of the third party and the arrangement's criticality | Company information, financial stability indicators, relevant policies, references, and risk-relevant disclosures |
| Contracting | Minimum contractual content, more detailed for critical/important functions | Willingness to accept audit/access rights, performance terms, data and confidentiality provisions, defined service levels |
| Subcontracting | Disclosure and management of the supplier's own subcontractors | A maintained list of your subcontractors/sub-suppliers and, where relevant, terms flowing down to them |
| Monitoring | Ongoing oversight of the relationship, proportionate to risk | Periodic status updates, notice of material changes, cooperation with review requests |
| Documentation | A register of third-party arrangements, aligned with DORA's register concept for a unified view | Accurate, current information to keep your customer's register correct |
| Exit strategy | A defined, and for higher-risk arrangements tested, exit plan | Cooperation on transition assistance and data return/deletion at contract end |
The transitional timeline
Here is what's publicly confirmed as of this review, and what remains open:
- 8 July 2025 – 8 October 2025: Public consultation on the draft guidelines.
- 18 September 2026: EBA final report and final guidelines published.
- Currently: Final text awaiting translation into EU official languages before formal application.
- After application begins: A two-year transitional period is intended to give financial entities time to update contracts and registers.
- Not yet confirmed in the sources available for this review: the exact date the transitional period begins, and therefore the exact date by which financial entities (and, by extension, their suppliers) need full compliance.
Practical takeaway: you do not need to treat this as an immediate compliance deadline today. You do need to expect that, over the next one to three years, EU financial-institution customers will increasingly reference this framework in due diligence, contract renewals, and register-of-information requests — and building the underlying readiness now (accurate subcontractor lists, current policies, a documented exit-cooperation stance) avoids a scramble later.
What this can mean operationally for your business
If you supply non-ICT services (consulting, legal, marketing, recruitment, facilities, or similar) to an EU bank, payment institution, investment firm, or similar regulated entity:
- Expect due-diligence and contract-renewal conversations to reference "third-party risk" more explicitly, not just "outsourcing," even for relationships that wouldn't previously have been labeled outsourcing
- Be ready to describe whether your service could plausibly be classified as supporting a "critical or important function" for that customer, and don't be surprised if two similar customers classify you differently
- Maintain a current list of your own subcontractors/sub-suppliers relevant to the service you provide
- Expect contract terms addressing audit/access rights, data handling, and exit cooperation to become more standard, particularly on renewal
- Keep your own documentation (policies, insurance, relevant certifications) current so you can respond quickly when a customer updates their register of information
- Don't assume this applies only to "tech" suppliers — this framework is explicitly about non-ICT services, so professional-services and consulting firms should expect to see it too
This is the same underlying discipline covered in our guides to vendor due diligence and third-party risk management from the vendor side — this EBA framework is the specific EU regulatory backdrop behind why EU financial-institution customers ask for that information.
FAQ
Are the EBA's 2026 third-party risk guidelines already in force?
Not as of this review. They are final but were, as of the EBA's own most recent public statement, awaiting translation into EU official languages, with a two-year transitional period to follow before full implementation is expected. Confirm current status on the EBA's site before treating this as an active compliance deadline.
Do these guidelines apply to ICT services?
No — DORA is the primary framework for ICT services. These EBA guidelines are designed to extend similar, aligned principles to non-ICT third-party arrangements, and the two are intended to work together rather than overlap.
Does this replace the 2019 EBA Outsourcing Guidelines?
Yes, based on the EBA's own description, the new guidelines are intended to replace the 2019 Outsourcing Guidelines once they take effect.
My company provides consulting/marketing/legal services, not IT — does this affect us?
Potentially yes. Unlike DORA, this framework is not limited to ICT services — legal commentary on the final guidelines describes coverage extending to professional services, consulting, legal, marketing, and similar third-party arrangements.
What should we do right now, given the guidelines aren't fully in force yet?
There's no need to treat this as an urgent deadline today. It's reasonable to start keeping subcontractor lists, policies, and relevant documentation current, since EU financial-institution customers are likely to reference this framework increasingly in due diligence and contract renewals over the transitional period.
Where can I check the current official status myself?
The EBA publishes guideline text and status updates on its own site under "Guidelines on the sound management of third-party risk" — check there directly, since dates and translated text can be published or clarified after this article was last reviewed.
Related reading
- DORA for ICT Vendors: What Financial Institutions Need From Their Technology Providers
- Third-Party Risk Management From the Vendor Side
- Vendor Due Diligence Checklist: What Suppliers Should Prepare
Keep your evidence current while this framework takes effect
You don't need to solve this today, but the underlying readiness — current subcontractor lists, up-to-date policies, a clear record of what each financial-services customer has asked for — is the same evidence a security questionnaire or due-diligence review asks for. MatchAudit's Vendor Assurance workspace helps you keep that evidence organized and reusable across every regulated customer relationship you manage, with a per-customer view of what's current and what needs attention.
- Start free: see your readiness across customers
- Talk to us about a financial-services customer relationship: contact us
- Compare plans: pricing
Official sources
- European Banking Authority, press release: "The EBA publishes its final Guidelines on the management of third-party risk, delivering a more proportionate and consistent framework aligned with DORA" (18 September 2026): eba.europa.eu
- European Banking Authority, Guidelines on outsourcing arrangements (2019, being replaced): eba.europa.eu
- EUR-Lex, Regulation (EU) 2022/2554 (DORA), for comparison on ICT-specific scope: eur-lex.europa.eu
