← Back to News
Regulation

EBA extends DORA-style third-party rules to non-IT providers

The EBA's final guidelines, published September 18, bring the vendors behind card production, collections, and customer support under a DORA-aligned framework. Payment and e-money institutions are named. A two-year transition applies, but the start date is not yet set.

Networks mentionedCB

The European Banking Authority (EBA) published final guidelines on September 18, 2026, on how financial firms should manage the risk of outsourcing services that fall outside information technology. The Guidelines on the sound management of third-party risk regarding non-ICT services complement DORA, the EU's Digital Operational Resilience Act, which already covers IT providers. Payment institutions and electronic money institutions are named among the firms that must comply.

🔑
Critical or important functions carry the heaviest duties
The toughest obligations do not apply to every contract, only to those that support a critical or important function. The guidelines use the same definition as DORA, so firms do not have to keep two inventories depending on the type of provider.

One approach for IT and non-IT providers

Until now, a payment institution applied DORA to its IT providers and the EBA's 2019 outsourcing guidelines to everyone else. The new guidelines bring both under one approach, with the same vocabulary, the same register logic, and the same requirement for an exit strategy. That holds whether the provider supplies hosting, collections, customer service, or card logistics. The guidelines apply to:

  • credit institutions under the Capital Requirements Directive (CRD)
  • payment institutions as defined by the second Payment Services Directive (PSD2)
  • electronic money institutions
  • investment firms, except small and non-interconnected ones, and nonbank mortgage lenders under the Mortgage Credit Directive
  • issuers of asset-referenced tokens under the Markets in Crypto-Assets Regulation (MiCAR)

Firms get a two-year transitional period. If a firm has not finished reviewing and documenting its contracts that support critical or important functions by the end of it, it must tell its supervisor and set out the measures it plans to take or its exit strategy. Providers of account information services only are outside the scope.

Desk covered with documents and a pen
Supervisors are looking at the contract again: what can be audited, terminated, and replaced.

The work starts with finding the contracts

For a midsize firm, the first step is a paperwork exercise, not a legal one. Compliance teams need to locate the contracts, identify those that support a critical or important function, and check what each one says about audit rights, subcontracting chains, and how the service would be moved in-house or to another provider. Most of the gaps supervisors find come from old contracts that renewed automatically and whose signed copy no one can find.

The second step is the exit. A credible exit strategy means knowing how long it would take to switch providers, in what format the data would come back, and what the move would cost. All three are negotiated when the contract is signed. They are hard to get once the firm depends on the provider.

The application date is still blank

The EBA has not set a date of application. The final report leaves it in square brackets, and the EBA says the text is awaiting translation into the EU's official languages. The new framework replaces the 2019 outsourcing guidelines, but their repeal date is also left blank.

Sept. 18, 2026
final guidelines published
EBA
2 years
transitional period
EBA
72
responses to the consultation that closed in October 2025
EBA, final report
2019
year of the outsourcing guidelines being replaced
Save Consulting Group

Card production, statements, and collections are in scope

Payment institutions rarely work alone. They hand card personalization, statement production, collections, part of customer support, and sometimes compliance paperwork to third parties. None of these services counts as IT under DORA, but an outage at any of them stops the business as surely as a server failure.

⚠️
Supervisors will ask for the register and the exit plan
Writing a policy is the easy part. The hard part is keeping the register current and proving that an exit is possible. A contract with no audit clause, no exit terms, and no documented replacement plan stands out immediately in an inspection.

The guidelines exclude payment network infrastructures (the final report cites Visa, Mastercard, Wero, and GIE CB), clearing and settlement arrangements, global financial messaging infrastructures such as SWIFT, and services that a third party is legally required to perform, such as statutory audits. A firm's dependence on a card network or a messaging system therefore falls outside this framework.

For French firms, the clock effectively starts when the translated versions are published. The work can begin sooner: building the inventory of contracts that support critical or important functions is the one step that does not depend on any application date.

Provenance

Published September 18, 2026

4 sources, 3 distinct domains

↗ EBA, The EBA publishes its final Guidelines on the management of third-party risk, delivering a more proportionate and consistent framework aligned with DORA · eba.europa.eu↗ EBA, Final report on the Guidelines on third-party risk management (PDF) · eba.europa.eu↗ Save Consulting Group, The EBA publishes its final Guidelines on the management of third-party risk · savecg.com↗ PayTechLaw, New EBA guidelines on third-party risk management · paytechlaw.com
← All news