EBA Outsourcing Guidelines
Definition
EBA Outsourcing Guidelines
EBA outsourcing guidelines are the European Banking Authority’s rules on how banks and payment firms govern their outside suppliers. Critical or important functions attract the strictest rules, and classifying one is a call the institution must be able to defend.
The guidelines replaced earlier recommendations and brought cloud arrangements into the same framework as everything else.
They are not a regulation, but supervisors apply them through the comply-or-explain mechanism, which makes the distinction academic in practice.
Their relationship with newer law is the live question — a technology-focused regulation now covers much of the same ground for the same institutions.
Key takeaways
- The guidelines have applied since 30 September 2019 across banks, investment firms and payment institutions.
- The critical or important classification determines which obligations attach.
- Institutions must maintain a register of all outsourcing arrangements.
- A newer European regulation now governs technology arrangements alongside these guidelines.
How it works
Scope and timing are settled. The guidelines applied from 30/09/2019 and cover credit institutions and investment firms under the Capital Requirements Directive, along with payment and electronic money institutions.
Classification is the pivot. The guidelines specify the criteria for assessing whether an outsourced activity, service, process or function is critical or important, and that assessment drives everything else.
The criteria are not a checklist you can pass. They ask what happens to the institution’s operations, its regulatory obligations and its soundness if the function stops working.
The register is the artefact supervisors ask for first — institutions maintain a documented inventory of arrangements, which is what turns a scattered supplier estate into something a regulator can examine.
| Classification | Typical consequence |
|---|---|
| Critical or important | Full due diligence, board involvement, exit plan, audit rights |
| Not critical or important | Proportionate governance under the general framework |
| Any outsourcing | Entry in the register regardless of classification |
| Intra-group | Assessed on substance, not on ownership |
| Sub-outsourcing | Chain transparency and conditions passed down |
Getting the classification wrong is the common failure — institutions under-classify to reduce workload, then discover during an inspection that the supervisor reads the same arrangement differently.
Then came the overlap. A dedicated regulation entered into application on 17 Jan 2025 and now governs technology arrangements for financial entities, sitting alongside these guidelines rather than repealing them.
Examples
European institutions have had these guidelines long enough for their weak spots to be well mapped. Each arrangement below cost somebody real money before anyone read the governing text.
A mid-sized bank classifies its card processing as not critical. The supervisor disagrees during an inspection, and the classification decision becomes the finding rather than the processing itself.
A payment institution keeps its register in three spreadsheets across two countries. The arrangements are all governed, but the institution cannot produce a single view on request.
An investment firm outsources reconciliation to a provider that subcontracts overnight work. Sub-outsourcing transparency is required, and the firm did not know the second tier existed.
A bank treats an intra-group technology arrangement as internal. Assessment is on substance, so the arrangement carries the same obligations as an external one. The register entry, the exit plan and the audit rights all have to exist.
Related terms
European financial outsourcing rules now come from several instruments that a single contract may engage. The definitions here keep adjacent regimes apart when a contract cites several at once.
- Digital Operational Resilience Act (DORA): the technology regulation now layered over these guidelines.
- Regulated outsourcing: supervised sector outsourcing across industries.
- Banking outsourcing: the sector practice these guidelines were written for.
- Vendor management outsourcing: the programme that maintains the register.
- Business continuity plan (BCP): the resilience element every critical function needs.
- Compliance outsourcing: contracting the compliance function rather than an operational one.
- Risk outsourcing: moving risk activity out without moving the obligation.
FAQ
Are the guidelines binding?
They operate on a comply-or-explain basis with national supervisors. In practice institutions treat them as binding because supervisors do.
Who do they apply to?
Credit institutions and investment firms under the Capital Requirements Directive, plus payment and electronic money institutions.
What makes a function critical or important?
The guidelines set criteria centred on the consequences of failure for the institution’s obligations, operations and soundness. The assessment is the institution’s own.
Does everything go in the register?
Yes. All outsourcing arrangements are recorded, with the classification determining what further obligations attach.
Has the newer technology regulation replaced them?
No. It applies alongside them from January 2025, covering technology arrangements while the guidelines continue to cover outsourcing more broadly.
Is intra-group outsourcing exempt?
No. Arrangements are assessed on substance rather than ownership, so a group service company is treated like any other provider.
Review verified partners in the Outsource Accelerator directory and favour firms whose critical function analysis already exists.







Independent




