.png)
The EBA has published new guidelines for managing third-party risk in non-ICT services. They are not yet applicable, but they give regulated fintechs and the businesses supplying them a reason to review their arrangements now.
On 18 September 2026, the European Banking Authority (EBA) published its final guidelines on third-party risk management. Once applicable, these guidelines will replace the EBA’s 2019 Outsourcing Guidelines and sit alongside the EU’s Digital Operational Resilience Act (DORA), which governs ICT third-party risk. The EBA has not yet set an application date.
The short version? This is a time to prepare, rather than a new deadline to meet today.
The guidelines are relevant to a range of EU-regulated financial businesses, including banks, payment institutions, e-money institutions, certain investment firms and issuers of asset-referenced tokens. They focus particularly on third-party services that support a critical or important function: one whose disruption could materially affect the regulated business. The EBA’s announcement explains this focus in more detail.
You may also need to pay attention if your business is not regulated. If you supply services to an EU-regulated fintech, your customer may need more information about your business, stronger contractual protections and a clearer plan for what happens if the arrangement ends or your service is disrupted. The precise requests will depend on the service you provide and how important it is to that customer.
Under the 2019 framework, firms concentrated on identifying and managing outsourcing arrangements. The new EBA third-party risk guidelines take a broader view of third-party arrangements. That means firms may need to revisit supplier relationships they previously treated as falling outside their outsourcing programme.
This does not mean every supplier will need the same level of scrutiny. The EBA’s approach concentrates the more demanding requirements on arrangements supporting critical or important functions.
DORA governs ICT third-party risk; the new EBA guidelines address non-ICT services. For a supplier providing both, the practical task is to understand which parts of the relationship fall under which framework and record the reasoning.
Regulated firms need a reliable picture of the third parties they depend on: what each supplier does, which functions it supports and what risks a disruption could create. For suppliers, this may translate into more detailed fintech supplier due diligence questions and requests for information throughout the relationship.
Using a third party does not transfer responsibility for managing the resulting risk. Firms should be ready to show how they assess, approve, monitor and, where necessary, exit important arrangements. For suppliers, that may mean more discussion of audit rights, ongoing reporting and exit support during fintech outsourcing agreement negotiations.
There is no need to treat the publication of the final report as an immediate compliance deadline. The EBA’s guidelines page lists them as not yet applicable, with no application date currently shown. The 2019 Outsourcing Guidelines remain the relevant EBA framework until the new guidelines apply.
There is, however, useful groundwork to do:
The next step is to watch for the confirmed application date and assess the transition provisions against your existing arrangements.
The EBA’s message is that third-party risk management should reflect the services a financial business actually relies on, not just the contracts it has historically labelled “outsourcing”. For regulated fintechs, that starts with understanding the supplier base. For suppliers, it starts with understanding how important their service is to each regulated customer.
We’ll follow this update with a closer look at the practical implications for contracts and supplier negotiations. In the meantime, you can explore our Outsourcing Explained series for more on negotiating these arrangements.
Need legal support with your fintech outsourcing agreements or third-party arrangements? Founders Law helps payment institutions, e-money institutions and fintech suppliers review outsourcing agreements, assess third-party arrangements and negotiate contracts with regulated customers. Get in touch