On 18 September 2026, the European Banking Authority (EBA) published its final Guidelines on the sound management of third-party risk regarding non-ICT services (EBA/GL/2026/09). The Guidelines set out how banks, payment institutions and investment firms ("institutions") must manage risk arising from work with outside vendors and service providers. They cover what has traditionally been called "outsourcing," but now reach further. The Guidelines follow a public consultation that closed on 8 October 2025, and institutions should now turn to implementation.
The Guidelines replace the EBA's 2019 outsourcing guidelines, which are repealed from the date the new Guidelines apply. They build a single, more consistent framework for vendor risk across the EU and account for the EU's digital and IT resilience law (DORA), which entered into force after the 2019 rules were written.
Institutions rely on outside providers to cut costs, access specialist expertise, and focus on core activities. That reliance carries risk: if a vendor fails, customers and the wider financial system can be affected. The final rules are broader in scope and more prescriptive on governance, contracts and documentation than their 2019 predecessor.
The Key Changes, Now Finalized
The rules cover more than just "outsourcing"
Institutions must now apply strict obligations not only to arrangements meeting the technical definition of "outsourcing," but to the broader concept of a "third-party arrangement": any arrangement with an outside provider, including group companies , for the support of a function on a recurrent or ongoing basis. Outsourcing remains one type of this wider category, not the whole of it.
In practice, some vendor relationships that fell outside "outsourcing" before , because they were one-off engagements, or covered functions the institution would not otherwise perform in-house, are now caught, subject to a lighter baseline rather than the fuller obligations for outsourcing or for critical/important functions. The final Guidelines also confirm a list of excluded services (including statutory audits, market information services, payment network infrastructures, and low-impact ancillary services such as cleaning, catering or office supplies). Institutions should not assume their existing outsourcing register already covers everything, and will need to map their full vendor population against the final scope.
IT service providers: only some fall under DORA
The Guidelines apply only to non-ICT services from third-party providers, that is, services falling outside Chapter V of DORA. ICT services have their own dedicated regime under DORA, separate from these EBA Guidelines, and DORA defines "ICT services" narrowly (software, data hosting, technical support delivered on an ongoing basis, and similar). Not everything commonly called an "IT service" meets that definition; some remain governed by these EBA Guidelines instead.
Institutions can no longer treat 'IT vendor' as a single category. Two questions typically arise, addressed below.
Either way, institutions need a documented internal methodology for making that assessment.
Two presumptions narrow the scope for non-critical classification
Institutions have always had to classify a vendor arrangement as 'critical or important' where disruption, defect or failure could materially impair regulatory compliance, financial performance, or the soundness or continuity of the institution's services. That test is unchanged, but two presumptions now substantially narrow when an arrangement can be treated as non-critical, addressed below.
First, if a bank relies on an outside provider for the operational tasks of internal control functions, such as compliance, risk management or internal audit, the arrangement must always be treated as critical or important by default. A bank may depart from this presumption only where its assessment establishes that a failure to provide, or an inappropriate provision of, those tasks would not have an adverse impact on the effectiveness of the internal control functions.
Second, if a bank uses an outside provider for the provision of functions of banking activities, payment services, or the issuance of asset-referenced tokens, to an extent that would require authorisation or registration by a competent authority, that arrangement must automatically be treated as critical or important. This classification is automatic and admits no exception.
Together, these two presumptions significantly narrow the scope for treating vendor arrangements as non-critical, particularly those touching internal control functions or regulated activities. Institutions should assess their existing vendor arrangements against both presumptions and should expect to reclassify certain arrangements as critical or important as a result. Where a bank seeks to rebut the presumption in respect of an internal-control arrangement, it should document the basis for that assessment, as supervisors are likely to request it.
Due diligence requirements are finalized and broadened
Institutions must already conduct due diligence before entering into any third-party arrangement, and the level of detail should be proportionate to the function's criticality.
For critical or important functions, the final rules largely preserve the 2019 expectations, but add assessment of the provider's business reputation, internal controls and risk management processes, geographic dependencies, business continuity arrangements, required regulatory authorisations, and auditability. Crucially, due to the broader 'third-party arrangement' concept, baseline due diligence applies to the much wider population of arrangements the Guidelines cover, not just outsourcing arrangements.
This raises the bar for pre-contractual due diligence significantly. Institutions should update due diligence checklists and templates now, so new vendor assessments already meet the standard, and plan any retrospective review of existing arrangements against the transition deadline.
Every vendor contract needs certain minimum protections, not just the critical ones
Previously, only critical or important outsourcing contracts needed a detailed list of minimum protections; basic contracts just needed clear, written allocation of rights and obligations.
Under the final Guidelines, every vendor contract must clearly allocate rights and obligations in writing and include a baseline set of minimum protections: a description of the services, the locations where they will be performed, governing law, data protection and data location provisions, service level descriptions, termination rights, and the provider's obligation to cooperate with competent and resolution authorities. Critical or important arrangements need additional protections on top: detailed service level targets, audit and access rights, business contingency testing requirements, and mandatory exit strategies with a transition period.
In effect, several protections that used to be reserved for the most important contracts now apply to all vendor contracts as standard.
Institutions must update existing contracts accordingly. The Guidelines apply to all third-party arrangements entered into, reviewed or amended on or after the (as yet unconfirmed) application date. For arrangements supporting critical or important functions, institutions that have not completed their review and documentation within two years of that date must notify their competent authority, including planned remediation measures or a possible exit strategy. Non-critical arrangements may instead be reviewed at their next renewal. Institutions should start reviewing contracts and identifying gaps now, particularly for large or complex vendors, where renegotiation lead times are typically longer.
The Bottom Line
Vendor risk management has been substantially overhauled, though the proportionality principle still gives smaller or simpler institutions some flexibility relative to large, complex ones. Every institution faces the same core to-do list: re-check which vendors count as critical, update governance policies, and renegotiate contracts that fall short, and confirm continued alignment with the domestic outsourcing regime alongside the new EU baseline.
This publication also comes alongside new EBA rules on internal governance, expected around the third quarter of 2026, meaning bank governance will remain a major focus well into 2027.
Given the scope of these changes, institutions are well advised to begin implementation now: mapping the existing vendor population against the final requirements represents a practical first step toward compliance ahead of the transitional deadlines.
What This Means for Institutions Operating in Sweden
The EBA Guidelines are not directly binding law in Sweden; they sit alongside the existing domestic outsourcing regime, requiring institutions to, among other things, notify Finansinspektionen of outsourcing arrangements and maintain adequate control over outsourced activities, which Swedish institutions must continue to satisfy in parallel.
The applicable statutory basis depends on the institution type: outsourcing by credit institutions is governed by the Banking and Financing Business Act (lag (2004:297) om bank- och finansieringsrörelse); investment services outsourcing falls under the Securities Market Act (lag (2007:528) om värdepappersmarknaden); and payment institution outsourcing is governed by the Payment Services Act (lag (2010:751) om betaltjänster).
Finansinspektionen's implementing regulations add a common core of detailed requirements set out in FFFS 2014:1 for credit institutions and investment firms and in FFFS 2010:3 for payment institutions. ICT-related arrangements fall outside this framework and are instead governed directly by DORA.
Whatever stage your institution has reached in implementing these guidelines, Deloitte brings proven expertise in financial regulation, implementation strategy, and governance frameworks. Contact us today to explore how we can support your compliance journey.
Paulina Malmberg
Director | Legal | Head of Financial Regulatory
pmalmberg@deloitte.se
+46 70 080 28 86
Carl-Johan Roth
Manager | Legal | Financial Regulatory
caroth@deloitte.se
+46 70 080 36 42