THIRD PARTYCURRENT
Regulatory Watch · Official European supervisory-guidance analysis

EBA final non-ICT guidelines await an application date

The European Banking Authority published final third-party-risk guidelines for non-ICT services on September 18, 2026, but its authority page still marks them not yet applicable. EU financial firms can map affected critical or important arrangements now while retaining the applicable 2019 outsourcing baseline until the replacement takes effect.

Third Party Current editorial graphic. Source material: EBA Guidelines on third party risk management; analysis and presentation by Third Party Current.

Keep publication, applicability, and replacement as three dates

The immediate answer is a status decision, not a wholesale control replacement. The EBA press release is dated September 18, 2026 and the final-report page now says final and awaiting translation into EU official languages. The final report is expressly marked not yet applicable, with no populated application date or compliance deadline on the official page as reviewed September 21. The same page retains the 2019 outsourcing guidelines as its applicable previous version. A policy register should therefore hold the final non-ICT package as a forthcoming framework and the 2019 version as the operative reference where that earlier guidance applies.

The old registered EBA URL for outsourcing arrangements now resolves to the new third-party-risk page. That redirect is a discovery and citation change, not evidence that the old guidance stopped applying on the redirect date. Preserve the original URL, the final destination, the September 18 announcement, the old applicable status, and the new not-yet-applicable status as separate fields. Monitor the EBA page for translation, an application date, any compliance deadline, and a consolidated text before changing control effective dates.

Scope the affected arrangement before mapping a control

The EBA describes the final package as guidance for non-ICT third-party services supporting critical or important functions, with a broader holistic approach across ICT and non-ICT relationships. Its press release names due diligence, contracting, subcontracting, monitoring, documentation, and exit strategies across the arrangement lifecycle. That public description supports a review of affected relationship inventories; it does not establish that every vendor, service, affiliate, or subcontractor has identical treatment or that DORA ICT obligations have been replaced.

For each potentially affected arrangement, a useful comparison record identifies the regulated entity, service and function, criticality determination, legal and contractual entity, ICT or non-ICT character, subcontracted chain, governing instrument, current control owner, and the source of any DORA overlap. Map the 2019 outsourcing obligation and the final non-ICT guidance separately. Where a relationship spans both domains, document which authority and arrangement feature supports each control instead of attaching a single “EBA-compliant” label to the supplier.

Make transition work auditable without claiming early effect

A change plan can compare the existing outsourcing register, due-diligence file, contract terms, monitoring schedule, subcontractor notices, concentration analysis, and exit evidence against the final text. Record gaps as planned work with an accountable owner, dependency, consultation or translation question, and decision date. The EBA press release mentions a two-year transitional period, but a project deadline cannot be calculated safely from that phrase while the official application-date field is blank. Counsel and the competent authority should resolve entity-specific interpretation and timing.

The practical buyer test is whether a third-party-risk platform can preserve two simultaneous authority baselines, versioned control mappings, affected-relationship scope, human approval, and transition receipts. A vendor demonstration should include a critical non-ICT outsourced service, a mixed ICT service, and a less material relationship, then show what the system marks current, planned, inapplicable, and unresolved. A populated task list is not evidence that a final guideline is already effective or that the financial entity has met its supervisory duties.

Evidence boundary and next update

This account relies on the EBA status page and its linked September 18 press release. It does not interpret the full final PDF clause by clause, establish country-specific implementation, assert a date absent from the status page, or assess a financial entity’s compliance. The 2019 and 2026 records need explicit version labels in dashboards, audits, and public summaries so a reader cannot mistake a final-but-pending report for an in-force replacement.

The next material trigger is an EBA application date, compliance deadline, translated or consolidated text, or competent-authority implementation notice. Those future records should update the timeline and affected control map while retaining the September 18 publication event and the previous status. Until then, the defensible public conclusion is narrower: final guidance exists, the previous version remains shown as applicable, and the transition date remains unknown on the reviewed official page.

What we will watch next

Third Party Current will watch for later primary-source evidence that changes the maintained company, capability, or standards record. The next useful evidence may include implementation documentation, release details, regulator findings, corrected methods, product packaging, customer-observable workflow, or a subsequent company statement. Until then, the dated source and its stated boundary remain attached to this analysis.

Primary source: EBA Guidelines on third party risk management · Official European Banking Authority guideline-status page.

Source boundary: Independent analysis of the EBA guideline-status page and September 18, 2026 press release, reviewed September 21, 2026. The EBA did not review or sponsor this article. The exact future application date and compliance deadline were not populated on the reviewed page; no financial institution, vendor implementation, or legal outcome was tested. This is not legal or supervisory advice.

Editorial record: Published September 21, 2026; last reviewed September 21, 2026. Corrections policy.