EBA widens bank vendor rules beyond outsourcing: Deloitte

- The EBA published final third-party risk guidelines on Sept. 18, 2026.
- The Guidelines replace the EBA’s 2019 outsourcing guidelines.
- The EBA rules cover any recurring arrangement with an outside provider.
- Every EBA-covered vendor contract now needs minimum protections.
PARIS, FRANCE — European banks, payment institutions and investment firms face stricter rules on how they manage outside vendors, after the region’s banking regulator replaced its 2019 outsourcing guidelines with a broader third-party risk framework.
The new rules reach beyond classic outsourcing to cover almost any recurring service an institution buys from an outside provider, including group companies.
New rules reach past classic outsourcing
The European Banking Authority (EBA) published its final Guidelines on the sound management of third-party risk regarding non-ICT services on Sept. 18, 2026, according to an analysis by Deloitte.
The Guidelines apply to any “third-party arrangement,” meaning any arrangement with an outside provider for the support of a function on a recurrent or ongoing basis, with outsourcing now one type within that wider category.
Some vendor relationships that fell outside “outsourcing” before are now caught, subject to a lighter baseline, while services such as statutory audits, market information services, cleaning and catering are excluded.
The rules cover only non-ICT services, since information and communication technology (ICT) services have their own regime under the EU’s Digital Operational Resilience Act (DORA).
Where one contract bundles separate ICT and non-ICT services, institutions must split the arrangement and apply each regime to its part, Deloitte said.
Stricter contracts and critical-function tests
Arrangements covering the operational tasks of internal control functions, such as compliance, risk management or internal audit, must be treated as critical or important by default.
Every vendor contract must now include minimum protections, including a description of the services, where they will be performed, governing law, data location provisions, service levels and termination rights.
Critical or important arrangements need more, including audit and access rights, business contingency testing and mandatory exit strategies with a transition period.
Institutions that have not reviewed critical arrangements within two years of the application date, which is not yet confirmed, must notify their competent authority.
“Institutions should not assume their existing outsourcing register already covers everything,” Deloitte said, adding that they will need to map their full vendor population against the final scope.
For providers selling business process outsourcing (BPO) work to European banks, the rules bring tougher due diligence, fuller contracts and more exit planning into even smaller engagements.
Vendors that can document service locations, data handling and continuity plans will be better placed as banks reclassify arrangements, a checklist buyers can build using OA’s ultimate guide to outsourcing and its entry on outsourcing models.
Related news
- Concentrix acquires GRC firm CastleHill · 16 Sep
- Insurance investment outsourcing hits record $5.5Tn, APAC surges · 3 Jul
- European insurers rethink BPO for the AI era: ISG · 1 Jul
Disclosure: Outsource Accelerator uses AI tools in the backend of its editorial workflow. Every article is reviewed and verified by a human editor before publication.
Stay ahead of the outsourcing industry. Join thousands of business leaders who rely on Outsource Accelerator for the news, trends, and expert insights that matter. Subscribe to our free newsletter and never miss an update.

Independent




