The European Banking Authority (EBA) published final guidelines on September 18, 2026, on how financial firms should manage the risk of outsourcing services that fall outside information technology. The Guidelines on the sound management of third-party risk regarding non-ICT services complement DORA, the EU's Digital Operational Resilience Act, which already covers IT providers. Payment institutions and electronic money institutions are named among the firms that must comply.
One approach for IT and non-IT providers
Until now, a payment institution applied DORA to its IT providers and the EBA's 2019 outsourcing guidelines to everyone else. The new guidelines bring both under one approach, with the same vocabulary, the same register logic, and the same requirement for an exit strategy. That holds whether the provider supplies hosting, collections, customer service, or card logistics. The guidelines apply to:
- credit institutions under the Capital Requirements Directive (CRD)
- payment institutions as defined by the second Payment Services Directive (PSD2)
- electronic money institutions
- investment firms, except small and non-interconnected ones, and nonbank mortgage lenders under the Mortgage Credit Directive
- issuers of asset-referenced tokens under the Markets in Crypto-Assets Regulation (MiCAR)
Firms get a two-year transitional period. If a firm has not finished reviewing and documenting its contracts that support critical or important functions by the end of it, it must tell its supervisor and set out the measures it plans to take or its exit strategy. Providers of account information services only are outside the scope.
The work starts with finding the contracts
For a midsize firm, the first step is a paperwork exercise, not a legal one. Compliance teams need to locate the contracts, identify those that support a critical or important function, and check what each one says about audit rights, subcontracting chains, and how the service would be moved in-house or to another provider. Most of the gaps supervisors find come from old contracts that renewed automatically and whose signed copy no one can find.
The second step is the exit. A credible exit strategy means knowing how long it would take to switch providers, in what format the data would come back, and what the move would cost. All three are negotiated when the contract is signed. They are hard to get once the firm depends on the provider.
The application date is still blank
The EBA has not set a date of application. The final report leaves it in square brackets, and the EBA says the text is awaiting translation into the EU's official languages. The new framework replaces the 2019 outsourcing guidelines, but their repeal date is also left blank.
Card production, statements, and collections are in scope
Payment institutions rarely work alone. They hand card personalization, statement production, collections, part of customer support, and sometimes compliance paperwork to third parties. None of these services counts as IT under DORA, but an outage at any of them stops the business as surely as a server failure.
The guidelines exclude payment network infrastructures (the final report cites Visa, Mastercard, Wero, and GIE CB), clearing and settlement arrangements, global financial messaging infrastructures such as SWIFT, and services that a third party is legally required to perform, such as statutory audits. A firm's dependence on a card network or a messaging system therefore falls outside this framework.
For French firms, the clock effectively starts when the translated versions are published. The work can begin sooner: building the inventory of contracts that support critical or important functions is the one step that does not depend on any application date.