The EBA Is Retiring "Outsourcing". Delegation Didn't Get Simpler.
Fredrik Gröndahl6 min readThought Leadership

On 18 September 2026 the EBA published final guidelines on non-ICT third-party risk (EBA/GL/2026/09), which will replace its 2019 outsourcing guidelines and let banks keep one register for ICT and non-ICT providers. Fund administrators, management companies and TCSPs are not addressed, but they will meet the standard through the due diligence their bank and depositary counterparties run on delegates.
For years, a fund administrator delegating transfer agency and a bank relying on a data centre were described in different vocabularies. One was outsourcing. The other, since DORA applied in January 2025, has been ICT third-party risk. The legal split survives: ICT services stay under DORA, everything else falls under the new guidelines. What the EBA removed is the reason to keep two separate registers.
That matters more than a terminology change usually does, because the register you keep, the due diligence you run, and the exit strategy you can produce on demand were all built around that old split.
What the EBA third-party risk guidelines change: one register instead of two
The EBA published its final report on the sound management of third-party risk regarding non-ICT services (EBA/GL/2026/09), which will replace the Authority's 2019 Guidelines on Outsourcing Arrangements once the new text applies. The headline finding is procedural: the guidelines ask that the non-ICT register be consistent with the DORA register of information, and allow firms to combine both in a single register.
The finding underneath is more consequential. The guidelines narrow the scope of what gets full-strength scrutiny (subcontractors that "effectively underpin" a critical function, not the whole subcontracting chain) and replace the proposed five-year record retention period for ended arrangements with "an appropriate period." That looks like simplification. It is, for the arrangements the EBA now considers immaterial. For the arrangements it considers material, the bar has not moved: documented risk assessment, a live register entry, and an exit strategy that can be tested, not just written.
The guidelines apply directly to credit institutions, investment firms other than small and non-interconnected ones, payment institutions and e-money institutions, issuers of asset-referenced tokens under MiCAR, and certain financial creditors under the Mortgage Credit Directive. They do not, on their face, reach AIFMs, UCITS management companies, fund administrators or TCSPs. The application date is not fixed yet, because the text is still awaiting translation into the EU's official languages. Once the guidelines apply, firms have two years to finish reviewing arrangements that support critical or important functions, or to explain the delay to their supervisor.
Why the direct scope is the wrong thing to watch
Reading the applicability list and concluding this is a bank problem misses how delegation actually works in fund services. A Luxembourg ManCo delegating portfolio management, a fund administrator delegating parts of its transfer agency function, a TCSP delegating identity verification: none of these firms are EBA-regulated credit institutions or investment firms in most cases, but nearly all of them sit somewhere in a chain that includes one. The depositary bank holding the fund's assets is often an EBA-scoped credit institution. That bank now has a single register it may combine with its DORA register, one proportionality test to apply, and, in our expectation, a refreshed due diligence questionnaire to send downstream to every delegate it relies on, including the fund administrator or TCSP that thought this guideline did not apply to them.
The practical effect is that the standard travels even where the legal obligation does not. A depositary or custodian bank rebuilding its third-party register around EBA/GL/2026/09 will ask its delegates for the same things the guideline now asks of it: a documented criticality assessment, evidence of ongoing monitoring of the arrangement, and, for anything classified as critical, a tested exit plan. Firms that cannot produce that on request will find themselves flagged in somebody else's register as the unclassified risk.
The guidelines bind the bank, not you. But each requirement below becomes a question in the questionnaire your counterparty sends. Paragraph numbers refer to EBA/GL/2026/09. The third column is our guidance, not text from the guidelines.
| What the guidelines require of the bank | Where | What to have ready as a delegate |
|---|---|---|
| A register of all third-party arrangements that separates those supporting critical or important functions | Para. 58 | Your own view of whether the service you provide supports a critical or important function, and why |
| Subcontractors that effectively underpin a critical non-ICT service are documented in the register | Para. 58 | A list of the subcontractors behind your service and what each one does |
| The non-ICT register should be consistent with the DORA register of information and may be combined with it | Para. 61 | One set of identifiers and service descriptions, so your answers match what you already gave for ICT |
| Ended arrangements stay in the register for an appropriate period | Para. 59 | Records of terminated arrangements you can still produce |
| Exit plans for critical arrangements that are realistic, documented and, where appropriate, sufficiently tested | Para. 115 | A clear account of how data and work would be handed back or moved to another provider |
| Two years from the date of application to finish reviewing critical arrangements, or explain the delay to the supervisor | Para. 20 | Expect the questions inside that window, not after it |
The convergence with DORA is the actual story
DORA's register of information already forced ICT-heavy firms to build a structured, queryable inventory of who they depend on and why. What EBA/GL/2026/09 does is take that same architecture, the same logic of criticality tiers, subcontractor mapping and exit-readiness, and extend it to every other non-ICT service a bank relies on, which for a depositary includes fund-related services.
This is not two compliance programmes converging by coincidence. It is the EBA acknowledging that a firm's operational resilience does not care whether the dependency runs on a server or a service agreement. A transfer agent that cannot deliver NAV data on time is as disruptive to a fund as a cloud outage. The guideline formalises what any operationally minded compliance officer already knew: the register is the control, not the category label attached to it.
For firms that already built a DORA-aligned register with an eye toward proportionality and reusability, this is confirmation, not new work. For firms that treated DORA as an IT project bolted onto compliance rather than a data decision, it is a second bill coming due on the same debt.
What this means for management companies, TCSPs and fund administrators
Three things to do now, ahead of formal application.
First, inventory delegation arrangements against a single criteria set, not two. If your firm still has a "vendor register" for IT and a separate "delegate register" for portfolio management, transfer agency or fund accounting, that split is the thing the new guidelines let banks and other regulated firms remove. Building one register now, organised by criticality rather than by category, means you are ready to answer the due diligence questionnaire before it arrives, rather than reconstructing the answer under deadline.
Second, expect upstream due diligence to tighten even though the guideline does not name you. Depositary banks, custodians and any EBA-regulated counterparty in your delegation chain will be rebuilding their own registers around this framework once it applies. The firms that can hand over a documented criticality assessment and an exit strategy without a scramble will keep the relationship on easier terms than the firms that cannot.
Third, treat the softer retention wording and the narrower subcontracting scope as licence to prioritise, not to relax. The EBA reduced the paperwork burden for arrangements it now considers non-material. It did not reduce the evidentiary bar for the arrangements that matter. Knowing which is which, and being able to show your reasoning, is the actual compliance task.
The position
Regulators keep dissolving the boundary between "IT risk" and "operational risk" because the boundary was never real. It was a historical artifact of which department wrote which policy. A fund administrator's dependency on a transfer agent and a bank's dependency on a cloud provider are the same kind of fact: a function the firm does not perform itself, that it needs functioning anyway, and that it has to be able to prove it assessed, monitors and could replace.
Firms that keep building separate registers for separate regulatory instruments are optimising for the audit that already happened, not the one coming. The ones that treat every third-party dependency, IT or otherwise, as entries in one evidentiary system will spend the coming period updating a register. The ones that don't will spend it building one from scratch, under a supervisor's clock instead of their own.
If a bank or depositary counterparty is about to send you its new due diligence questionnaire, talk to our team about answering it from one documented record.
Frequently asked questions
Do the EBA third-party risk guidelines apply to fund administrators, ManCos or TCSPs?
Not directly. The guidelines are addressed to credit institutions, investment firms other than small and non-interconnected ones, payment and e-money institutions, issuers of asset-referenced tokens under MiCAR and certain mortgage creditors. A fund administrator, management company or TCSP meets them as a service provider to one of those firms, through the documentation and due diligence that firm now has to keep.
When do the new guidelines start to apply?
The date is not fixed yet. The EBA published the final report on 18 September 2026 and lists the guidelines as final and awaiting translation into the EU official languages. The 2019 outsourcing guidelines are repealed once the new text applies, and firms then have two years to finish reviewing arrangements that support critical or important functions, or tell their supervisor why not.
Do banks now have to keep one register instead of two?
They may, but they do not have to. The guidelines ask that the non-ICT register be consistent with the DORA register of information and allow firms to combine both in a single register. Our view: a delegate should prepare as if the counterparty will choose one register, because that is where the questions will come from.
What does an exit plan need to show?
For arrangements supporting critical or important functions, the guidelines expect exit plans that are realistic, feasible, documented and, where appropriate, sufficiently tested, for example by analysing the cost, resources and timing of moving a service to another provider. A delegate that can explain how its work and data would be handed over makes that plan easier for its client to write.
Sources
- EBA, Final report: Guidelines on the sound management of third-party risk regarding non-ICT services (EBA/GL/2026/09), 18 September 2026
- EBA, Guidelines on third-party risk management (status page)
- EBA press release: The EBA publishes its final Guidelines on the management of third-party risk, 18 September 2026
- ESMA, Digital Operational Resilience Act (DORA)
- Regulation (EU) 2022/2554 (DORA), EUR-Lex


