Article

The EU’s new regime for third-party providers of non-ICT services: contractual requirements

The EU’s new regime for third-party providers of non-ICT services: contractual requirements

On September 18, 2026, the European Banking Authority (EBA) published its final guidelines on the sound management of third-party risk relating to non-ICT services, replacing the EBA's 2019 Guidelines on outsourcing arrangements. Among the most notable changes is a more prescriptive list of clauses that must be included in third-party arrangements, including outsourcing agreements, with more detailed guidance on how those must address various risks. The new requirements will apply to all new third-party arrangements, with a requirement on firms to bring existing third-party arrangements, including outsourcings, for critical or important functions agreements into line within two years. For other arrangements, amendments are needed at the point of renewal or amendment.

Our bulletin below considers the new contractual requirements in detail and proposes key action points for financial services entities in-scope of the guidelines.

Related capabilities