If a key service provider became unavailable tomorrow, could your organisation maintain its critical operations?
On 18 September 2026, the European Banking Authority (EBA) published its final guidelines on the sound management of third-party risk regarding non-ICT services. The guidelines complement the Digital Operational Resilience Act (DORA), which addresses ICT third-party risk, and place particular emphasis on arrangements supporting critical or important functions. They establish proportionate expectations throughout the third-party relationship, from initial assessment and due diligence through to monitoring and exit.
Assessing the Scope of Third-Party Arrangements
The framework extends beyond traditional outsourcing to recurring or ongoing non-ICT third-party arrangements, including intragroup services. Financial entities within scope should assess their arrangements against the Guidelines’ definitions and exclusions, identifying the functions each provider supports and the potential impact of disruption on financial performance, service continuity and regulatory compliance. For each in-scope arrangement, firms should document whether the service supports a critical or important function and the rationale for that classification.Existing outsourcing registers provide a useful starting point but may not capture the full extent of an organisation’s dependencies. Moreover, contract value alone is a poor indicator of operational importance, as even a modestly priced service may support a function that would be difficult to transfer to another provider at short notice.
Firms should look across their third-party arrangements to identify whether different providers rely on the same subcontractor or operating location. Such shared dependencies can create concentrations of risk that may be overlooked when arrangements are assessed individually.
Governance and Operational Resilience
Management bodies remain accountable for activities performed through third parties and should define, approve, and regularly review the organisation’s third-party risk management strategy. The policy covering non-ICT services supporting critical or important functions should also be approved by the management body and reviewed at least annually. Effective oversight requires clearly assigned responsibilities, proportionate risk assessments and due diligence, appropriate contractual safeguards, and ongoing monitoring. Reporting should give management a clear view of significant dependencies, deteriorating service performance, and matters requiring action.For arrangements supporting critical or important functions, contracts should secure access and audit rights, controls over subcontracting, and termination and transition provisions.
Continuity and exit plans for these arrangements should reflect the practical constraints of transferring a service. These include the availability of alternative providers, realistic transition periods, access to records, and the internal resources needed to maintain operations. Testing these assumptions can reveal where an exit plan may be difficult to execute.
Firms should also maintain an up-to-date register of in-scope arrangements, which may be combined with DORA’s register of information. Timely supervisory notifications should cover planned arrangements supporting critical or important functions, functions newly classified as critical or important, and material changes or severe events affecting such arrangements that could materially disrupt business activities.
Implementation and Transitional Arrangements
The Guidelines are final and awaiting translation, with the application date still to be confirmed. From the application date, the Guidelines will replace the EBA’s 2019 Guidelines on outsourcing arrangements. The Guidelines will apply to arrangements entered into, reviewed or amended on or after the application date.Existing arrangements supporting critical or important functions should be reviewed, amended where necessary, and documented within two years of that date. Where this work remains incomplete, firms should notify their competent authority, setting out the measures planned or a possible exit strategy. For other existing arrangements, review and documentation may take place at renewal.
Why Early Preparation Matters
The final requirements give firms a clear basis for assessing their readiness now. Mapping dependencies, resolving contractual gaps, and establishing credible alternatives can require considerable time and coordination across business, risk, compliance, and procurement teams. An early gap assessment can therefore help management prioritise the arrangements requiring the most attention, assign responsibility for remediation, and establish realistic completion dates. Integrating this work into scheduled contract reviews also creates an opportunity to agree necessary changes with providers before implementation pressures increase.How BDO Malta Can Help
BDO Malta’s Risk Advisory team can support your organisation’s preparation for the EBA’s Guidelines on non-ICT third-party risk management. Our support includes gap assessments, reviews of governance and risk management processes, and enhancements to monitoring, business continuity and exit arrangements. We help translate the findings into a practical implementation roadmap, with defined actions, responsibilities and realistic completion dates.Contact our team to discuss your organisation’s readiness for the Guidelines and how we can support your next steps.
.png)
