New EBA Guidelines on third-party arrangements clarify the relationship with DORA
The European Banking Authority (the EBA) has published new Guidelines on the sound management of third-party risk regarding non-ICT services (the Guidelines), which will replace the 2019 Guidelines on outsourcing arrangements and clarify the boundary with Regulation (EU) 2022/2554 (DORA).
The date of application is not yet set and will most likely be fixed alongside the publication of the official translations. The transitional period will run for two years from the date of application, during which existing arrangements must be reviewed and reassessed.
Where the review of existing agreements on critical or important functions is not finalised within the two years, institutions will have to inform their supervisory authority, setting out the measures planned to complete the review or possible exit strategies.
Agreements relating to functions that are not critical or important may be reviewed and reassessed upon their regular renewal.
The key elements are as follows:
Relationship with DORA
- ICT services governed by DORA fall outside the scope – the Guidelines cover only non-ICT services (e.g. functions supporting operational tasks of internal control functions, prudential and regulatory reporting).
- The framework policy on non-ICT third-party arrangements may be merged with its DORA equivalent, provided ICT and non-ICT services remain clearly distinguished. A combined register of information is also allowed.
- Where a service combines ICT and non-ICT elements, if the ICT element is material for the provision of the service, DORA should be applied instead. In such cases, the institution should, however, perform a formal assessment (e.g. during initial or periodic due diligence of the provider) and ensure a sufficient audit trail for supervisors. This rule should also be applied in the context of the European Supervisory Authorities’ position regarding financial services entailing ICT components.
Expanded scope of application
- All “third-party arrangements”, including any non-ICT service supporting a function on a recurring or ongoing basis, are covered, with outsourcing as a subset. Rather than first asking whether the agreement concerns a function provided on a recurring or ongoing basis that the institution would normally perform itself (i.e. outsourcing), the Guidelines require a broader assessment of whether:
- The services are not ICT services.
- The services support (not necessarily replace) an institution’s function on an ongoing or recurring basis.
- The function in question is critical or important.
- Compared with the 2019 Guidelines, which apply to credit institutions, investment firms, payment institutions and electronic money institutions, the regime will also capture EU branches of non-EU banks, mortgage credit providers, issuers of ARTs under Regulation (EU) 2023/1114 (MiCAR) and approved financial and mixed financial holding companies under Directive 2013/36/EU (CRD).
Lifecycle management
- The full lifecycle of a third-party arrangement is covered, from pre-contractual due diligence through mandatory contractual clauses and ongoing monitoring to exit planning. Most of the process remains broadly the same as under the current outsourcing regime but is more closely aligned with DORA (some elements, such as the contents of the registers of information, are borrowed from it).
- The Guidelines also include guidance for supervisors. The approach is risk-based, with particular attention to audit rights, exit strategies, and ensuring that reliance on providers does not reduce the financial entity to an empty shell.
Practical implications
- In Lithuania, the Bank of Lithuania had intended to amend Resolution No 03-166 of 10 November 2020 on the Approval of the Rules on the Outsourcing of Operational Functions of Financial Market Participants once DORA became applicable, but those amendments have still not been introduced. These new Guidelines may give the Bank of Lithuania the clarity it needs to finalise the amendments and publish the long-awaited revamp.
- Once the date of application of the Guidelines is set, arrangements in place at that time that support critical or important functions will have to be aligned within two years. Other agreements will need to be updated only upon renewal.
- If institutions do not complete their reviews of agreements supporting critical or important functions in time, they will have to notify their supervisory authority of the measures planned or of any exit strategies.
- The risk management lifecycle will remain largely unchanged where an institution’s framework already meets current regulatory expectations and good practice. The challenge will lie in reassessing every existing third-party arrangement. The current framework asks only whether the provider performs something the institution would otherwise do itself (i.e. “is it outsourcing?”), whereas the new framework will also capture arrangements that merely support, but do not replace, the institution’s functions on a recurring or ongoing basis.
- In light of the above, institutions should begin reviewing their current outsourcing policies and reassessing their agreements as soon as possible.
Have more questions? Contact Marius Matiukas.