EBA Guidelines on outsourcing arrangements (EBA/GL/2019/02), outsourcing a function to a service provider
EBA Guidelines on outsourcing arrangements (EBA/GL/2019/02)
Guidance, not a law: the European Banking Authority's reading of Capital Requirements Directive, Robust Governance Arrangements of Institutions (Article 74(1)). It binds nobody by itself; the law it reads does.
Guidance on an AI sector rules rule, addressed to public and private bodies.
- Private right of action
- No
- Instrument type
- guidance published by a regulator
- Obligation class
- Governance
- Audit expectation
- periodic
- Who audits it
- Internal independent
As of .
What the regulator expects
- These guidelines are addressed to competent authorities and, among financial institutions, to institutions as defined in point 3 of Article 4(1) of Regulation (EU) No 575/2013, payment institutions and electronic money institutions (paragraph 7). They apply from to all outsourcing arrangements entered into, reviewed or amended on or after that date (paragraph 13).
- Institutions, payment institutions and electronic money institutions should establish whether an arrangement with a third party falls under the definition of outsourcing, an arrangement of any form by which a service provider performs a process, a service or an activity that would otherwise be undertaken by the institution itself (paragraphs 12 and 26).
- Institutions and payment institutions should always consider a function as critical or important where a defect or failure in its performance would materially impair their continuing compliance with the conditions of their authorization, their financial performance, or the soundness or continuity of their banking and payment services and activities; or when operational tasks of internal control functions are outsourced, unless the assessment establishes that a failure to provide the outsourced function or its inappropriate provision would not have an adverse impact on the effectiveness of the internal control function; or when they intend to outsource functions of banking activities or payment services to an extent that would require authorization by a competent authority (paragraph 29).
- The management body should approve, regularly review and update a written outsourcing policy and ensure its implementation, and the policy should include the main phases of the life cycle of outsourcing arrangements and define the principles, responsibilities and processes in relation to outsourcing (paragraphs 41 and 42).
- Before entering into any outsourcing arrangement, institutions and payment institutions should assess whether it concerns a critical or important function, assess whether the supervisory conditions for outsourcing are met, identify and assess all relevant risks, undertake appropriate due diligence on the prospective service provider, and identify and assess conflicts of interest (paragraph 61).
- Institutions and payment institutions should ensure in their selection and assessment process that the service provider is suitable and, for critical or important functions, that it has the business reputation, abilities, expertise, capacity, resources, organizational structure and required authorizations or registrations to perform the function in a reliable and professional manner (paragraphs 69 and 70).
- The rights and obligations of the institution or payment institution and the service provider should be clearly allocated and set out in a written agreement, and the agreement for a critical or important function should set out at least the matters in paragraph 75, including the description of the function, the dates and notice periods, the governing law, the conditions for sub-outsourcing, the locations where the function is provided and data are kept and processed, the right to monitor performance, the agreed service levels, the service provider's reporting obligations and the requirements to implement and test business contingency plans (paragraphs 74 and 75).
- Institutions and payment institutions should maintain an updated register of information on all outsourcing arrangements, distinguishing the outsourcing of critical or important functions from other outsourcing arrangements, with at least a reference number, the dates and notice periods, and a brief description of the outsourced function including the data outsourced and whether personal data are transferred or processed by the service provider (paragraphs 52 and 54).
- The internal audit function's activities should cover, following a risk-based approach, the independent review of outsourced activities, and the audit plan and program should include the outsourcing arrangements of critical or important functions (paragraph 50).
Who enforces it
Enforcement body
The competent authorities of the Member States, which should comply with the guidelines by incorporating them into their practices as appropriate, and which notify the European Banking Authority whether they comply or intend to comply; the guidelines carry no enforcement action of their own.
What this law does
The European Banking Authority issued the guidelines pursuant to Article 16 of Regulation (EU) No 1093/2010, and its final report says that, in accordance with Article 16(3), competent authorities and financial institutions must make every effort to comply with the guidelines.
Paragraph 2 says that guidelines set out the European Banking Authority's view of appropriate supervisory practices within the European System of Financial Supervision or of how Union law should be applied in a particular area.
Paragraph 5 says that the guidelines specify the internal governance arrangements, including sound risk management, that institutions, payment institutions and electronic money institutions should implement when they outsource functions, in particular with regard to the outsourcing of critical or important functions.
The final report says that, in accordance with Article 74 of Directive 2013/36/EU, institutions should have robust internal governance arrangements that include a clear organizational structure, and that outsourcing arrangements are one aspect of that structure. The final report also says that Article 74(3) of Directive 2013/36/EU gives the European Banking Authority the mandate to develop guidelines on institutions' governance arrangements.
Paragraph 7 says that the guidelines are addressed to institutions as defined in point 3 of Article 4(1) of Regulation (EU) No 575/2013, to payment institutions as defined in Article 4(4) of Directive (EU) 2015/2366 and to electronic money institutions within the meaning of Article 2(1) of Directive 2009/110/EC.
Paragraph 12 defines outsourcing as an arrangement of any form between an institution, a payment institution or an electronic money institution and a service provider by which that service provider performs a process, a service or an activity that would otherwise be undertaken by the institution, the payment institution or the electronic money institution itself. Paragraph 12 defines a function as any processes, services or activities.
Paragraph 13 says that, with the exception of paragraph 63(b), the guidelines apply from to all outsourcing arrangements entered into, reviewed or amended on or after that date, and that paragraph 63(b) applies from .
Paragraph 15 says that, where the review of outsourcing arrangements of critical or important functions is not finalized by , institutions and payment institutions should inform their competent authority of that fact, including the measures planned to complete the review or the possible exit strategy.
Paragraph 16 says that institutions and payment institutions should complete the documentation of all existing outsourcing arrangements, other than for outsourcing arrangements to cloud service providers, following the first renewal date of each arrangement, but by no later than . The European Banking Authority's page for the guidelines gave the status applicable and the application date 30/09/2019.
Paragraph 26 says that institutions and payment institutions should establish whether an arrangement with a third party falls under the definition of outsourcing. Paragraph 29 says that institutions and payment institutions should always consider a function as critical or important where a defect or failure in its performance would materially impair the matters it lists.
Those matters include their financial performance and the soundness or continuity of their banking and payment services and activities. Paragraph 29 also says that they should consider a function as critical or important when operational tasks of internal control functions are outsourced, unless the assessment establishes that a failure to provide the outsourced function or the inappropriate provision of it would not have an adverse impact on the effectiveness of the internal control function.
Paragraph 41 says that the management body should approve, regularly review and update a written outsourcing policy and ensure its implementation. Paragraph 42 says that the policy should include the main phases of the life cycle of outsourcing arrangements and define the principles, responsibilities and processes in relation to outsourcing.
Paragraph 50 says that the internal audit function's activities should cover, following a risk-based approach, the independent review of outsourced activities, and that the audit plan and program should include, in particular, the outsourcing arrangements of critical or important functions.
Paragraph 52 says that institutions and payment institutions should maintain an updated register of information on all outsourcing arrangements, distinguishing between the outsourcing of critical or important functions and other outsourcing arrangements.
Paragraph 54 says that the register should include at least a reference number for each outsourcing arrangement, the start date and the next contract renewal, end date or notice periods, and a brief description of the outsourced function, including the data that are outsourced and whether personal data have been transferred or their processing is outsourced.
Paragraph 61 says that, before entering into any outsourcing arrangement, institutions and payment institutions should assess if it concerns a critical or important function, assess if the supervisory conditions for outsourcing are met, identify and assess all relevant risks, undertake appropriate due diligence on the prospective service provider, and identify and assess conflicts of interest.
Paragraph 69 says that, before entering into an outsourcing arrangement, institutions and payment institutions should ensure in their selection and assessment process that the service provider is suitable.
Paragraph 70 says that, for critical and important functions, they should ensure that the service provider has the business reputation, appropriate and sufficient abilities, the expertise, the capacity, the resources, the organizational structure and, if applicable, the required regulatory authorizations or registrations to perform the function in a reliable and professional manner.
Paragraph 74 says that the rights and obligations of the institution, the payment institution and the service provider should be clearly allocated and set out in a written agreement.
Paragraph 75 says that the outsourcing agreement for critical or important functions should set out at least a clear description of the outsourced function, the start and end dates and notice periods, the governing law, the conditions for sub-outsourcing, the locations where the function is provided and where relevant data are kept and processed, the right to monitor the service provider's performance, the agreed service levels, the service provider's reporting obligations, and the requirements to implement and test business contingency plans.
Paragraph 17 repealed the Committee of European Banking Supervisors guidelines on outsourcing of and the EBA recommendations on outsourcing to cloud service providers with effect from .
Regulation (EU) 2022/2554, the Digital Operational Resilience Act, applies from under Article 64. Chapter V of Regulation (EU) 2022/2554, headed managing of ICT third-party risk, begins with Article 28, which requires financial entities to manage ICT third-party risk as an integral component of ICT risk within their ICT risk management framework.
The European Banking Authority's page for the guidelines says that its Guidelines on the sound management of third-party risk related to non-ICT services, once applicable, will repeal the Guidelines on outsourcing arrangements. The final report of on those replacement guidelines (EBA/GL/2026/09) provides that the EBA Guidelines on outsourcing of are repealed with effect from a date that the final report does not yet state.
The same final report says that DORA sets out the framework on the management of third-party risks with regard to ICT services, while the replacement guidelines apply to the management of third-party risks with regard to non-ICT services. The same final report excludes from the replacement guidelines the management of ICT risk and the use of third-party service providers to provide ICT services as defined in Article 3(21) of Regulation (EU) 2022/2554, because they fall within the scope of DORA.