Skip to main content
Category: Regulatory Frameworks

EBA Guidelines on Sound Management of Third-Party Risk

Also known as: EBA Draft Guidelines on the sound management of third-party risk, EBA Guidelines on third-party risk management (non-ICT services)
Simply put

The EBA Guidelines on Sound Management of Third-Party Risk are draft guidance issued by the European Banking Authority to help financial institutions and certain investment firms manage the risks that arise when they rely on outside providers for services. As of the July 2025 consultation, the draft focuses specifically on non-ICT (non-technology) related services provided by third parties. Because the draft was published for consultation and public hearing rather than as a finalized standard, its provisions may change before adoption.

Formal definition

A draft set of Guidelines developed by the European Banking Authority (EBA), released for consultation on 8 July 2025, that specifies internal governance arrangements, including sound risk management practices, for institutions and investment firms in relation to third-party arrangements covering non-ICT related services provided by third-party service providers. The Guidelines are intended to establish a more comprehensive approach to managing third-party risks and, according to consultation responses, to align closely with the Digital Operational Resilience Act (DORA), which addresses ICT-related third-party risk. Scope note: as evidenced, the draft is expressly limited to non-ICT related services and therefore does not itself govern ICT third-party arrangements, which fall under DORA; practitioners should also treat this as consultation-stage guidance rather than a finalized or binding standard, and its final content, applicability, and effective date were not established in the evidence provided. The framework applies within the EU financial-sector supervisory context and should not be assumed to apply across other jurisdictions or sectors.

Why it matters

For EU financial institutions, third-party arrangements covering non-ICT services, ranging from outsourced operational functions to professional and support services, have historically been governed by a patchwork of guidance, most notably the EBA's earlier work on outsourcing arrangements. The draft EBA Guidelines on Sound Management of Third-Party Risk, released for consultation on 8 July 2025, signal the regulator's intent to establish a more comprehensive and consistent approach to how institutions and certain investment firms govern and manage these relationships. For risk, compliance, and procurement professionals, this matters because it shapes supervisory expectations around internal governance and risk management practices for a category of third-party dependency that sits outside the technology-focused regime.

Who it's relevant to

Financial institutions and in-scope investment firms in the EU
The draft Guidelines are directed at institutions and certain investment firms subject to EBA supervision. Governance, risk, and compliance teams within these organizations should review the consultation draft to anticipate how supervisory expectations for non-ICT third-party arrangements may evolve, while recognizing that provisions may change before adoption.
Third-party risk and procurement teams
Professionals responsible for onboarding, governing, and monitoring outside providers of non-ICT services should track how the Guidelines may shape internal governance and risk management practices. The draft's non-ICT scope means it complements, rather than replaces, the ICT-focused requirements addressed by DORA.
DORA and operational resilience program owners
Because the Guidelines are intended to align closely with DORA, teams managing ICT third-party risk under DORA benefit from understanding where the non-ICT Guidelines apply. This helps maintain a coherent, comprehensive approach across both technology and non-technology third-party arrangements without conflating the two regimes.
Regulatory affairs and policy specialists
Given the consultation and public hearing process launched on 8 July 2025, policy and regulatory affairs professionals have an opportunity to engage with the EBA's proposals and monitor changes. They should treat the draft as consultation-stage guidance whose final content, applicability, and effective date were not established in the available evidence.

Inside EBA Guidelines on Sound Management of Third-Party Risk

Scope of Outsourcing and Third-Party Arrangements
The Guidelines typically delineate which arrangements fall within scope, often distinguishing outsourcing (where a provider performs a function that would otherwise be undertaken by the institution itself) from broader third-party arrangements. Not every purchase of goods or services is treated as outsourcing, and the classification affects which governance and documentation requirements apply.
Governance and Oversight Responsibilities
Expectations that the management body retains ultimate accountability for outsourced and third-party functions and cannot delegate that responsibility to the provider. This generally covers internal governance arrangements, allocation of roles, and the principle that outsourcing does not diminish the institution's regulatory obligations.
Criticality and Materiality Assessment
A structured process for determining whether a function is critical or important, which drives the depth of due diligence, contractual protections, and ongoing monitoring. This assessment is risk-tiered rather than uniform; less material arrangements typically attract lighter requirements.
Pre-Contract Due Diligence and Risk Assessment
Requirements to assess a prospective provider's ability to perform the function, including operational capacity, financial soundness, and risk exposure, before entering an arrangement. This covers onboarding assessment but is distinct from, and does not substitute for, ongoing monitoring over the life of the relationship.
Contractual Provisions
Expectations that written agreements address matters such as access and audit rights, information security, sub-outsourcing, data location, service levels, and termination and exit rights. These provisions establish contractual entitlements but do not by themselves verify a provider's actual performance or controls.
Sub-Outsourcing and Chain Oversight
Provisions addressing arrangements where a provider further delegates functions to its own subcontractors, extending the institution's concern beyond the direct third party. Visibility and control typically weaken beyond the first tier, and the Guidelines generally expect institutions to consider this Nth-party exposure rather than assume it is covered by the direct contract.
Ongoing Monitoring and Performance Management
Continuous oversight of the arrangement against agreed service levels and risk indicators, recognizing that a point-in-time due diligence conclusion can become stale as circumstances change.
Documentation and Registers
Expectations to maintain a register or inventory of arrangements, typically with additional detail for those classified as critical or important, supporting oversight and supervisory review.
Exit Strategies and Business Continuity Considerations
Requirements to plan for orderly termination or substitution of a provider, including for critical functions. This addresses continuity of the function and is distinct from a provider's own disaster recovery arrangements, though the two may interrelate.
Concentration Considerations
Attention to reliance on individual providers and to broader concentration, such as multiple institutions depending on the same provider, which can create systemic exposure beyond any single relationship.

Common questions

Answers to the questions practitioners most commonly ask about EBA Guidelines on Sound Management of Third-Party Risk.

Are the EBA guidelines the same as the DORA regulation, and can I use one interchangeably with the other?
No. The EBA guidelines and DORA are distinct instruments with different legal forms and scopes, and they should not be treated as interchangeable. Guidelines issued by the EBA are supervisory expectations that competent authorities and financial institutions are expected to apply under a 'comply or explain' mechanism, whereas a regulation carries directly binding legal force. They also differ in focus: EBA third-party risk guidance addresses outsourcing and third-party arrangements broadly, while DORA concentrates specifically on digital operational resilience and information and communication technology risk. An institution typically needs to understand how the two interact rather than assume compliance with one satisfies the other, and where their requirements overlap or diverge should be assessed case by case.
Does following the EBA guidelines mean an arrangement is 'compliant' and the associated third-party risk is resolved?
No. The guidelines set out expectations for how institutions should govern and manage third-party arrangements; they do not confer a compliance certification, nor do they eliminate the underlying risk. Applying the guidance is intended to support sound governance, due diligence, and ongoing oversight, but residual risk remains after controls are applied, and supervisory expectations are ultimately interpreted and enforced by the relevant competent authority. Adherence to the guidelines is best understood as a component of a risk management program rather than a guarantee of a particular outcome or an assurance that the third party performs as expected.
Which arrangements fall within scope, and how do I tell what the guidelines actually cover?
Scope determination typically starts with identifying whether an arrangement qualifies as outsourcing or a broader third-party arrangement, since the depth of expected governance and due diligence often depends on that classification and on the criticality or importance assigned to the function. In many programs institutions maintain a register of arrangements and apply a materiality or criticality assessment to decide the level of oversight. Because the guidelines emphasize direct contractual arrangements, visibility into subcontractors and further tiers may be more limited unless specifically addressed through contract terms and monitoring, so mapping what is in scope versus what falls outside it is an early implementation step.
How should due diligence under the guidelines be structured across the arrangement lifecycle?
Due diligence is generally treated as a lifecycle activity rather than a one-time onboarding exercise. Pre-contract assessment typically covers the provider's capability, financial condition, operational resilience, and risk profile relative to the criticality of the function, while contracting establishes rights such as audit, access, and information provisions. Ongoing monitoring then tracks performance and changes in the provider's risk over the life of the arrangement, since a point-in-time assessment can become stale as circumstances change. Programs commonly calibrate the intensity of each stage to the risk tier or criticality of the arrangement rather than applying uniform depth everywhere.
What contractual provisions are commonly expected for critical or important arrangements?
For arrangements assessed as critical or important, institutions typically seek contractual terms that preserve their ability to oversee, control, and if necessary exit the arrangement. These often include audit and access rights, information and reporting obligations, provisions addressing subcontracting, security and data handling requirements, and defined exit or termination arrangements. The precise terms and how far they extend to subcontractors depend on the arrangement's criticality and the institution's risk appetite, and the ability to actually exercise such rights in practice can vary, particularly where visibility beyond the direct provider is limited.
How do exit strategies fit into the expectations, and why do they matter?
Exit strategies are generally expected for critical or important arrangements so that an institution can discontinue or transfer a function without unacceptable disruption to its operations. This typically involves identifying alternatives, understanding dependencies and potential concentration, and planning for orderly transition. Exit planning addresses the risk of being unable to move away from a provider and should be distinguished from ordinary business continuity or disaster recovery measures, which deal with maintaining or restoring service rather than replacing the provider. The rigor of exit planning is usually proportionate to the criticality of the function and the difficulty of substitution.

Common misconceptions

The Guidelines apply only to outsourcing, so non-outsourcing supplier relationships are out of scope entirely.
While outsourcing is a central focus, the framing addresses third-party risk more broadly. The classification of an arrangement affects which specific requirements apply, but treating every non-outsourcing supplier as unregulated misreads how the scope and criticality assessments operate.
Completing pre-contract due diligence satisfies the ongoing obligation to manage the arrangement.
Due diligence at onboarding is a point-in-time assessment and does not discharge the expectation of continuous monitoring. Provider risk profiles can change, so onboarding assessment and ongoing oversight are treated as distinct requirements.
Outsourcing a critical function transfers the associated regulatory responsibility to the provider.
The management body typically retains ultimate accountability. Contractual arrangements allocate obligations between the parties but do not diminish the institution's own regulatory responsibility for the function.

Best practices

Apply a risk-tiered assessment to classify each arrangement by criticality or materiality, and scale due diligence, contractual controls, and monitoring to that classification rather than applying a uniform standard.
Maintain a current register of third-party and outsourcing arrangements, capturing additional detail for those identified as critical or important to support internal oversight and supervisory review.
Secure and actively use contractual rights such as audit and access, sub-outsourcing controls, and termination provisions, while recognizing that contractual entitlements do not substitute for independent verification of a provider's controls.
Establish ongoing monitoring against agreed service levels and risk indicators so that point-in-time onboarding conclusions are periodically revalidated as circumstances change.
Extend oversight beyond the direct provider to material sub-outsourcing, acknowledging that visibility typically diminishes beyond the first tier and planning accordingly.
Develop and periodically test documented exit strategies for critical functions, keeping these distinct from, but coordinated with, the provider's own continuity and recovery arrangements.
Assess concentration exposure, including single-source dependencies and reliance on providers that may also be widely used across the sector.
Application Security Isn’t Optional Anymore.