EBA/GL/2019/02
Applicable EBA guidance defining outsourcing, identifying critical or important functions, and setting expectations for governance, records, pre-outsourcing analysis, due diligence, contracting, access and audit rights, security, subcontracting, monitoring, concentration, exit strategies, and supervisory cooperation. The EBA has been updating the framework to align non-ICT third-party risk with DORA.
What the authority establishes
Applicable EBA guidance defining outsourcing, identifying critical or important functions, and setting expectations for governance, records, pre-outsourcing analysis, due diligence, contracting, access and audit rights, security, subcontracting, monitoring, concentration, exit strategies, and supervisory cooperation. The EBA has been updating the framework to align non-ICT third-party risk with DORA.
It provides a detailed operating blueprint for outsourcing governance beyond purely cyber controls. Buyers need to distinguish outsourcing from other third-party arrangements, document criticality, maintain registers, preserve audit and access rights, monitor subcontracting and concentration, and maintain credible exit plans. Coverage should explicitly disclose the ongoing EBA revision rather than presenting the 2019 text as static.
The record is written for operational interpretation, not legal advice. Applicability depends on entity type, jurisdiction, relationship, service, data, criticality, contractual commitments, and later authority guidance.
Who should read it
The primary audiences named in this review are EU banking and financial-institution outsourcing teams, operational-risk and resilience leaders, procurement, legal, compliance, and internal-audit teams, payment and electronic-money institutions, service providers supporting critical or important functions. Those roles may divide responsibility differently, but the operating record should still show scope, accountable ownership, evidence, review, exceptions, and the final decision.
Third-party lifecycle implications
Governance
Teams should determine what this authority expects at the governance stage, which function owns the judgment, what evidence must be retained, and what later change would reopen the record.
Pre-Outsourcing Analysis
Teams should determine what this authority expects at the pre-outsourcing analysis stage, which function owns the judgment, what evidence must be retained, and what later change would reopen the record.
Due Diligence
Teams should determine what this authority expects at the due diligence stage, which function owns the judgment, what evidence must be retained, and what later change would reopen the record.
Contracting
Teams should determine what this authority expects at the contracting stage, which function owns the judgment, what evidence must be retained, and what later change would reopen the record.
Register Maintenance
Teams should determine what this authority expects at the register maintenance stage, which function owns the judgment, what evidence must be retained, and what later change would reopen the record.
Ongoing Monitoring
Teams should determine what this authority expects at the ongoing monitoring stage, which function owns the judgment, what evidence must be retained, and what later change would reopen the record.
Subcontractor Oversight
Teams should determine what this authority expects at the subcontractor oversight stage, which function owns the judgment, what evidence must be retained, and what later change would reopen the record.
Exit Strategy
Teams should determine what this authority expects at the exit strategy stage, which function owns the judgment, what evidence must be retained, and what later change would reopen the record.
Capabilities that may support the work
These links identify relevant operating capabilities; they do not state that any product creates compliance.
Intake And Inventory
establishing an accountable record of relationships, products, owners, and critical services. Buyers should test the workflow against their own scope and evidence requirements.
Inherent Risk Tiering
using relationship context to determine proportional diligence and review. Buyers should test the workflow against their own scope and evidence requirements.
Due Diligence And Assessments
collecting and reviewing evidence before and during a relationship. Buyers should test the workflow against their own scope and evidence requirements.
Evidence Collection
preserving source material, responses, and reviewer context. Buyers should test the workflow against their own scope and evidence requirements.
Continuous Monitoring
bringing material external and internal change into an owned response workflow. Buyers should test the workflow against their own scope and evidence requirements.
Issue Remediation
assigning findings, deadlines, exceptions, and closure evidence. Buyers should test the workflow against their own scope and evidence requirements.
Fourth-Party Visibility
identifying and explaining important downstream dependencies. Buyers should test the workflow against their own scope and evidence requirements.
Regulatory Mapping
connecting program records to obligations and examination needs. Buyers should test the workflow against their own scope and evidence requirements.
Reporting
turning program activity into operator, executive, and board-ready information. Buyers should test the workflow against their own scope and evidence requirements.
Offboarding
closing access, data, evidence, and residual obligations when a relationship ends. Buyers should test the workflow against their own scope and evidence requirements.
What software cannot decide
Software can structure records, route work, preserve evidence, surface change, and support reporting. It cannot determine legal applicability, set risk appetite, negotiate accountable contract terms, validate every external claim, accept residual risk, or make management responsible for an outcome. Those remain organizational decisions.