What EU fintechs need to know about the new EBA third-party risk guidelines
September 22, 2026
-
Blog

What EU fintechs need to know about the new EBA third-party risk guidelines

By 
Dimitrios Karakolis - Legal Director & Head of Fintech

New EBA third-party risk guidelines: what EU fintechs and their suppliers need to know

The EBA has published new guidelines for managing third-party risk in non-ICT services. They are not yet applicable, but they give regulated fintechs and the businesses supplying them a reason to review their arrangements now.

On 18 September 2026, the European Banking Authority (EBA) published its final guidelines on third-party risk management. Once applicable, these guidelines will replace the EBA’s 2019 Outsourcing Guidelines and sit alongside the EU’s Digital Operational Resilience Act (DORA), which governs ICT third-party risk. The EBA has not yet set an application date.

The short version? This is a time to prepare, rather than a new deadline to meet today.

What do the EBA guidelines mean for payment and e-money institutions?

The guidelines are relevant to a range of EU-regulated financial businesses, including banks, payment institutions, e-money institutions, certain investment firms and issuers of asset-referenced tokens. They focus particularly on third-party services that support a critical or important function: one whose disruption could materially affect the regulated business. The EBA’s announcement explains this focus in more detail.

You may also need to pay attention if your business is not regulated. If you supply services to an EU-regulated fintech, your customer may need more information about your business, stronger contractual protections and a clearer plan for what happens if the arrangement ends or your service is disrupted. The precise requests will depend on the service you provide and how important it is to that customer.

What is changing for third-party risk management in fintech?

1. The focus is wider than traditional outsourcing

Under the 2019 framework, firms concentrated on identifying and managing outsourcing arrangements. The new EBA third-party risk guidelines take a broader view of third-party arrangements. That means firms may need to revisit supplier relationships they previously treated as falling outside their outsourcing programme.

This does not mean every supplier will need the same level of scrutiny. The EBA’s approach concentrates the more demanding requirements on arrangements supporting critical or important functions.

2. Firms will need to distinguish between ICT and non-ICT services

DORA governs ICT third-party risk; the new EBA guidelines address non-ICT services. For a supplier providing both, the practical task is to understand which parts of the relationship fall under which framework and record the reasoning.

3. Supplier information will matter more

Regulated firms need a reliable picture of the third parties they depend on: what each supplier does, which functions it supports and what risks a disruption could create. For suppliers, this may translate into more detailed fintech supplier due diligence questions and requests for information throughout the relationship.

4. Responsibility stays with the regulated firm

Using a third party does not transfer responsibility for managing the resulting risk. Firms should be ready to show how they assess, approve, monitor and, where necessary, exit important arrangements. For suppliers, that may mean more discussion of audit rights, ongoing reporting and exit support during fintech outsourcing agreement negotiations.

What should regulated fintechs and their suppliers do now?

There is no need to treat the publication of the final report as an immediate compliance deadline. The EBA’s guidelines page lists them as not yet applicable, with no application date currently shown. The 2019 Outsourcing Guidelines remain the relevant EBA framework until the new guidelines apply.

There is, however, useful groundwork to do:

  • Regulated fintechs: map your non-ICT suppliers, identify the services that may support critical or important functions, and check whether your contracts and supplier records give you the information and rights you may need.
  • Fintech suppliers: consider how your regulated customers use your service. If it supports an important part of their operations, prepare for more detailed questions about your controls, subcontractors, continuity arrangements and contract terms.

The next step is to watch for the confirmed application date and assess the transition provisions against your existing arrangements.

The takeaway

The EBA’s message is that third-party risk management should reflect the services a financial business actually relies on, not just the contracts it has historically labelled “outsourcing”. For regulated fintechs, that starts with understanding the supplier base. For suppliers, it starts with understanding how important their service is to each regulated customer.

We’ll follow this update with a closer look at the practical implications for contracts and supplier negotiations. In the meantime, you can explore our Outsourcing Explained series for more on negotiating these arrangements.

Need legal support with your fintech outsourcing agreements or third-party arrangements? Founders Law helps payment institutions, e-money institutions and fintech suppliers review outsourcing agreements, assess third-party arrangements and negotiate contracts with regulated customers. Get in touch

Fintech
Next
Previous