Financial Services Regulation
DETAIL

EBA Guidelines on Outsourcing Arrangements (EBA/GL/2019/02), Being Replaced by EBA/GL/2026/09

SmartSuite provides the system for managing controls, evidence, mappings, assessments, and reporting.
Framework text may require a separate license unless explicitly provided.

Overview

The EBA Guidelines on outsourcing arrangements (EBA/GL/2019/02) are the European Banking Authority's harmonized framework for how financial institutions govern, assess, contract, monitor, and exit outsourcing arrangements. They set criteria for deciding whether an outsourced function is critical or important, require a register of all outsourcing arrangements, and specify the pre-outsourcing analysis, due diligence, contractual terms, sub-outsourcing conditions, access and audit rights, and exit strategies institutions must have in place.

The EBA published the guidelines on 25 February 2019; they applied from 30 September 2019 to credit institutions and investment firms subject to the Capital Requirements Directive and to payment and electronic money institutions, replacing the 2006 CEBS guidelines on outsourcing and the EBA's 2017 recommendations on outsourcing to cloud service providers. On 18 September 2026 the EBA published its final Guidelines on the sound management of third-party risk related to non-ICT services (EBA/GL/2026/09), which, once applicable, will repeal the 2019 guidelines; the new guidelines are awaiting translation into the EU official languages, are not yet applicable, and provide a two-year transitional period for reviewing and documenting existing arrangements that support critical or important functions.

Institutions implement the guidelines by adopting an outsourcing policy approved by the management body, assessing each proposed arrangement for criticality and risk, performing due diligence on the provider, agreeing contracts that secure the required rights, recording the arrangement in the register, monitoring performance and concentration risk, and maintaining documented exit strategies. Because ICT third-party risk is now governed by the EU Digital Operational Resilience Act, the 2026 guidelines refocus the EBA framework on non-ICT services supporting critical or important functions and align its register and life cycle with DORA.

Why it Matters

Outsourcing lets financial institutions use specialist providers and cloud services, but supervisors expect that it never leaves an institution as an empty shell unable to control its critical functions. The EBA guidelines are the reference European supervisors use for that expectation, and their replacement by EBA/GL/2026/09 means institutions must plan for both the current requirements and the transition to the new third-party risk framework.

Key benefits include:

  • One EU-wide framework

Harmonized requirements across credit institutions, investment firms, and payment and e-money institutions replaced fragmented national and sectoral expectations.

  • Criticality drives proportionality

Arrangements supporting critical or important functions attract the full requirements, while less material arrangements receive lighter treatment.

  • A register supervisors can rely on

The register of outsourcing arrangements gives institutions and competent authorities a single record of what is outsourced, to whom, and with what risk.

  • Contracts that secure control

Required contractual terms cover access, information and audit rights, sub-outsourcing, data location, business continuity, and termination.

  • Continuity with DORA

The 2026 guidelines align the non-ICT third-party framework with DORA's ICT provisions so institutions can run one third-party risk program.

How it Works

EBA/GL/2019/02 is organized around governance and the outsourcing life cycle. The governance provisions require sound arrangements, an outsourcing policy, management of conflicts of interest, business continuity plans, and an internal audit function that covers outsourcing, with proportionate application to groups and institutional protection schemes. The assessment provisions define outsourcing and critical or important functions and require the register and its documentation. The life cycle provisions cover pre-outsourcing analysis including supervisory conditions, risk assessment, and due diligence; the contractual phase including sub-outsourcing, access, information and audit rights, and termination rights; ongoing monitoring; and exit strategies for arrangements supporting critical or important functions. Competent authorities supervise these arrangements with particular attention to concentration risk.

The 2026 successor, EBA/GL/2026/09, keeps the same life cycle but narrows the scope to non-ICT services, since ICT services are within DORA's scope, and focuses its stricter provisions on third-party arrangements supporting critical or important functions. It requires a register for non-ICT arrangements that is consistent with the DORA register of information and may be combined with it, extends addressees to issuers of asset-referenced tokens and creditors under the Mortgage Credit Directive, and applies to arrangements entered into, reviewed, or amended on or after its application date, with existing critical or important arrangements to be reviewed and documented within two years of that date and non-critical arrangements at renewal. The 2019 guidelines are repealed with effect from the application date.

Within SmartSuite, institutions keep the outsourcing register and the DORA register of information as one connected data set: each arrangement carries its criticality assessment, risk assessment, due diligence evidence, contractual rights, sub-outsourcing chain, monitoring results, and exit strategy, so the transition from EBA/GL/2019/02 to EBA/GL/2026/09 is a change of requirement set rather than a new system.

Key Elements

  • Outsourcing policy and governance

The management body approves an outsourcing policy and remains responsible for outsourced functions, with conflicts of interest, business continuity, and internal audit coverage addressed.

  • Critical or important functions

Criteria determine which outsourced functions are critical or important, triggering the full requirements including exit strategies and supervisory notification.

  • Register of outsourcing arrangements

Institutions maintain a register of all outsourcing arrangements with prescribed data, available to competent authorities.

  • Pre-outsourcing analysis and due diligence

Before contracting, institutions assess supervisory conditions, risks, and the provider's suitability, including sub-outsourcing and data location.

  • Contractual requirements

Written agreements secure service levels, access, information and audit rights, data protection, sub-outsourcing conditions, business continuity, and termination rights.

  • Monitoring and concentration risk

Institutions monitor performance and risk on an ongoing basis, and competent authorities assess concentration at individual and system level.

  • Exit strategies

Documented, tested exit plans exist for arrangements supporting critical or important functions.

Framework Scope

EBA/GL/2019/02 applies to credit institutions and investment firms subject to the Capital Requirements Directive and to payment institutions and electronic money institutions, on an individual, sub-consolidated, and consolidated basis, and is addressed to their competent authorities. EBA/GL/2026/09 is addressed to institutions under the CRR, third-country branches, investment firms other than small and non-interconnected firms, payment and e-money institutions, issuers of asset-referenced tokens under MiCAR, and creditors under the Mortgage Credit Directive, and covers non-ICT services provided by third-party service providers, with its stricter provisions applying to arrangements supporting critical or important functions. ICT services fall under DORA.

Framework Objectives

The guidelines exist so that reliance on third parties never weakens an institution's control over its critical functions or a supervisor's ability to oversee them.

Harmonize outsourcing and third-party risk management across EU financial institutions.

Keep the management body responsible for outsourced and third-party-supported functions.

Identify arrangements supporting critical or important functions and apply stricter requirements to them.

Secure access, information, audit, and termination rights through contracts.

Maintain a register that gives institutions and supervisors a complete view of arrangements and concentration risk.

Align non-ICT third-party risk management with the DORA framework for ICT services.

Framework in Context

The EBA outsourcing guidelines are part of the EBA's internal governance rulebook alongside EBA/GL/2019/04 on ICT and security risk management, and they draw on the Basel Committee's principles for the sound management of third-party risk and for operational resilience. Since January 2025 the EU Digital Operational Resilience Act has governed ICT third-party risk, which is why EBA/GL/2026/09 confines the EBA framework to non-ICT services. The guidelines are the EU counterpart of the U.S. Interagency Guidance on Third-Party Relationships and of the UK PRA's outsourcing expectations, and institutions commonly satisfy their due diligence and monitoring requirements with ISO/IEC 27001 certification, SOC 2 reports, and ISO/IEC 27036 supplier security practices.

Common Framework Mappings

The guidelines are commonly mapped to the EU rules and international principles they operate with and to the assurance and supplier security standards used to meet their due diligence requirements.

Mapped frameworks include:

EU DORA

EBA GL/2019/04

PSD2

BCBS Operational Resilience Principles

PRA SS1/21

Interagency TPRM Guidance (2023)

ISO/IEC 27036

ISO 27001:2022

SOC 2

NIST SP 800-161 Rev.1

At a Glance
EBA Guidelines on Outsourcing Arrangements (EBA/GL/2019/02), Being Replaced by EBA/GL/2026/09
  • Classification
    Category
    Financial Services Regulation
    Domain
    Financial Services Regulation
    Framework Family
    Other
  • Regulatory Context
    Type
    Guidance
    Legal Instrument
    Guideline
    Sector
    Financial Sector
    Industry
    Financial Services
  • Region / Publisher
    Region
    European Union
    Region Detail
    European Union
    Publisher
    European Banking Authority (EBA)
  • Versioning
    Version
    EBA/GL/2019/02 (applicable); EBA/GL/2026/09 final report of 18 September 2026 (not yet applicable)
    Effective Date
    September 30, 2019 (EBA/GL/2019/02); EBA/GL/2026/09 application date to be set after translation, with a two-year transitional period
    Issue Date
    February 25, 2019 (EBA/GL/2019/02); September 18, 2026 (EBA/GL/2026/09)
  • Adoption
    Adoption Model
    Regulatory Compliance
    Implementation Complexity
    High
  • Official Reference
License Information

License included / downloadable: Yes

Both sets of guidelines are published free of charge by the European Banking Authority, and their register and life cycle structure is included with the platform.

Framework text is licensed by its publisher and is included only where stated above.

Official Resources
EBA Guidelines on third-party risk management page
The EBA rulebook page carrying the 2026 guidelines, their status, the final report, and the 2019 version of the outsourcing guidelines.
EBA/GL/2019/02 Guidelines on outsourcing arrangements (PDF)
The consolidated text of the 2019 outsourcing guidelines as published by the EBA.
Final report on EBA/GL/2026/09 (PDF)
The final report on the Guidelines on the sound management of third-party risk related to non-ICT services, with the guidelines text, application, transitional, and repeal provisions.
EBA press release of 18 September 2026
The EBA's announcement of the final third-party risk guidelines, their focus on critical or important functions, and the two-year transitional period.
SMARTSUITE

How SmartSuite Supports EBA Outsourcing Guidelines

SmartSuite provides the system for managing controls, evidence, mappings, assessments, and reporting.

For the EBA outsourcing guidelines, SmartSuite maintains the register of arrangements with criticality and risk assessments, due diligence evidence, contractual rights, sub-outsourcing chains, monitoring results, and exit strategies, and carries the same records into the EBA/GL/2026/09 and DORA registers.

Outsourcing Register

Hold every arrangement with its reference, provider, function, criticality assessment, data location, and sub-outsourcing chain in a register aligned with the DORA register of information.

Ownership, Cadence, and Accountability

Assign business and risk owners, schedule reviews by criticality, and route management body approvals and supervisory notifications through workflows.

Evidence Collection and Audit Trail

Attach due diligence reports, contracts, audit rights, and certifications to each arrangement with timestamps and reviewers.

Pre-Outsourcing Analysis and Monitoring

Run risk assessments and due diligence before contracting and monitor performance, incidents, and changes throughout the arrangement.

Concentration and Exit Planning

Track provider concentration across functions and entities and maintain tested exit strategies for critical or important functions.

Supervisory Reporting

Produce register extracts, critical-function summaries, and transition status for competent authorities and the management body.

Related frameworks

EU DORA

DORA is an EU regulation requiring financial firms to manage ICT risks, report incidents, test security, and oversee third-party providers.

EBA GL/2019/04

EBA Guidelines set ICT and security risk management requirements to strengthen operational resilience and protect EU financial institutions' information systems.

PSD2

PSD2 is an EU directive that strengthens security, transparency, and consumer protection for electronic payments and third-party providers.

BCBS Operational Resilience Principles

The Basel Committee's seven Principles for Operational Resilience set the international baseline for how banks deliver critical operations through disruption.

PRA SS1/21

PRA SS1/21 sets the Prudential Regulation Authority's expectations for how UK banks and insurers identify important business services, set impact tolerances, and stay within them.

FCA SYSC 15A (PS21/3)

FCA PS21/3 and SYSC 15A require UK-regulated firms to identify important business services, set impact tolerances, map and test their resilience, and self-assess against them.

ISO 27001:2022

ISO/IEC 27001:2022 is an international ISMS standard that helps organizations manage information security risks and protect data.

SOC 2

SOC 2 assesses and reports on a service organization's controls for security, availability, processing integrity, confidentiality, and privacy.

ONBOARDING FAQS

Frequently Asked Questions For EBA Outsourcing Guidelines

What are the EBA Guidelines on outsourcing arrangements?

EBA/GL/2019/02 is the European Banking Authority's harmonized framework for governing, assessing, contracting, monitoring, and exiting outsourcing arrangements. Published on 25 February 2019 and applicable from 30 September 2019, it replaced the 2006 CEBS outsourcing guidelines and the EBA's 2017 cloud outsourcing recommendations.

Who do the 2019 guidelines apply to?

Credit institutions and investment firms subject to the Capital Requirements Directive, and payment institutions and electronic money institutions, on an individual, sub-consolidated, and consolidated basis. They are also addressed to their competent authorities.

What is EBA/GL/2026/09?

It is the EBA's final Guidelines on the sound management of third-party risk related to non-ICT services, published on 18 September 2026. Once applicable it will repeal the 2019 outsourcing guidelines, focusing the framework on third-party arrangements supporting critical or important functions and aligning it with DORA.

When do the new guidelines apply?

The final report of 18 September 2026 is awaiting translation into the EU official languages, and the application date will be set once that is complete. The guidelines apply to arrangements entered into, reviewed, or amended on or after that date, with a two-year transitional period to review and document existing arrangements supporting critical or important functions.

How do the guidelines relate to DORA?

ICT services provided by third-party providers are within the scope of the EU Digital Operational Resilience Act, so EBA/GL/2026/09 covers non-ICT services only. Its register should be consistent with the DORA register of information, and institutions may combine the two.

What must the register contain?

The 2019 guidelines require a register of all outsourcing arrangements with prescribed information, including the provider, the function, whether it is critical or important, data location, and sub-outsourcing. The 2026 guidelines require a register for non-ICT arrangements that may be combined with the DORA register.

How does SmartSuite support the EBA guidelines?

SmartSuite holds the register with criticality assessments, due diligence evidence, contractual rights, monitoring results, and exit strategies for each arrangement, and lets institutions carry the same records into the EBA/GL/2026/09 and DORA registers during the transition.

Operationalize EBA GL/2019/02 with Connected Workflows

Manage controls, risks, evidence, and audits in one platform designed for modern governance, risk, and compliance.