Managing Non ICT Third Party Risk as a Prudential Imperative

Managing Non ICT Third Party Risk as a Prudential Imperative

In recent years, financial institutions have increasingly relied on third‑party providers for key operational and support functions. The EBA’s draft Guidelines on non‑ICT third‑party risk management clarify that these arrangements pose material prudential and governance risks and introduce a harmonized supervisory framework which, for Luxembourg institutions, aligns as far as possible with DORA while limiting additional supervisory burden. 

From outsourcing to structural dependency

Third party service provision has evolved from a tactical outsourcing decision into a structural feature of financial institutions’ operating models. Administrative services, fund operations, internal control activities, customer servicing, accounting, treasury or group provided functions are increasingly delivered by external or intra group entities. The draft EBA Guidelines (or “Guidelines”) on the Sound Management of Third Party Risk reflect a clear supervisory conclusion: risk arises not from the contractual label applied to an arrangement, but from the degree of dependency it creates.

The Guidelines deliberately move beyond the traditional concept of outsourcing. Any arrangement whereby a third party service provider performs or supports a function on a recurrent basis may fall within scope, regardless of whether it is labeled outsourcing, delegation or service provision. This broader approach is particularly relevant in Luxembourg, where cross border group structures and shared service centers are common. From a regulatory perspective, such arrangements can materially affect the institution’s risk profile, governance and ability to remain compliant with authorization conditions.

Management body accountability cannot be delegated

A central pillar of the Guidelines is the reaffirmation of management body accountability. The Guidelines make explicit that responsibility for all activities of the institution can never be delegated to third party service providers. Even where functions are performed externally, the management body remains fully accountable for oversight, decision making and risk management.

This principle aligns closely with the CSSF’s long standing supervisory focus on substance, effective management and local oversight. In practice, Luxembourg based institutions, today, are expected to demonstrate that senior management and boards retain sufficient understanding of outsourced or externally supported functions to effectively challenge performance, risk assessments and incidents. Reliance on contractual assurances or group level reporting alone is no longer sufficient.

Non ICT third party risk as a governance risk

Non ICT third party risk is therefore first and foremost a governance risk. Excessive reliance on third parties for operational or control functions can weaken internal governance arrangements, dilute accountability and impair the effectiveness of internal control functions.

In Luxembourg, where institutions often rely on group entities or specialized service providers located abroad, supervisors will increasingly expect clear evidence that local management retains sufficient authority, decision making power and resources. This includes the ability to intervene, request changes, activate exit strategies and, where necessary, reintegrate functions without undue disruption.

Preventing “Empty Shell” and Letter Box institutions

The EBA Guidelines introduce an explicit prudential concern: the risk of “empty shell” or “letter box” institutions. Where critical activities, control functions or decision making processes are predominantly performed by third parties, an institution may no longer demonstrate the substance required to support its license.

This risk is particularly relevant in Luxembourg’s internationally oriented financial center, where business models often rely on delegation and group servicing. For CSSF supervised entities, third party arrangements are no longer assessed solely through an operational lens, but as a factor directly linked to authorization sustainability, resolvability and supervisory confidence.

Concentration risk beyond technology

Another key dimension addressed by the Guidelines is concentration risk. While digital concentration is covered by the Digital Operational Resilience Act (DORA), the EBA highlights that non ICT concentration can be equally disruptive. Dependence on a limited number of service providers for critical operational or governance functions may create vulnerabilities at both entity and sector level.

In Luxembourg’s ecosystem, where multiple institutions may rely on the same administrators, depositaries or group service providers, such risks can have broader financial stability implications. The Guidelines therefore require institutions to identify, assess and actively manage concentration risks, including substitutability and exit feasibility.

Documentation as a supervisory control mechanism

To address these concerns, the Guidelines impose robust documentation and transparency requirements. Institutions must maintain comprehensive registers of all third party arrangements, including assessments of criticality, subcontracting chains, substitutability and exit strategies.

For CSSF supervisors, this documentation is not a formal exercise: it is a core supervisory tool, enabling informed dialogue, targeted interventions and a clear understanding of group wide dependencies. Weak documentation increasingly signals weak governance.

A necessary complement to DORA

Importantly, the EBA framework complements, rather than duplicates, the Digital Operational Resilience Act. While DORA focuses on ICT services and digital resilience, the EBA Guidelines ensure that non ICT dependencies are governed with equal rigor.

Together, these frameworks reflect a holistic supervisory view of operational resilience, extending well beyond technology to organizational design, governance and strategic control. For instance, the Guidelines ensure consistency with the DORA register by allowing financial institutions to store consistent information for both ICT and non-ICT services, including the possibility of using one single register. Taking into account the application of proportionality, the level of information to be documented has been limited to reduce the burden on both firm and regulators.

Bringing this together operationally, when you have ICT and non-ICT service providers

Based on experience supporting banks and asset managers operating under both frameworks, we believe that an integrated approach that builds on synergies between the DORA’s requirements for third parties and the requirements of these Guidelines represents the most effective path forward. A streamlined approach is even more important given the breadth of non-ICT service providers that firms have a govern, including administrative services, cash management services, customer services, depositary tasks and administration for UCI, finance, treasury, accounting and reporting, internal control functions, investment services, lending, payment services and securities services. 

In practice, this approach is applied across both ICT and non ICT third party service providers through a single, integrated third party risk management framework, while applying DORA and the EBA non ICT Guidelines in parallel and where each is relevant. The approach starts by building a common foundation covering criticality assessments, multi vendor strategies, concentration risk, exit feasibility and overarching third party governance. On this basis, suppliers are then differentiated according to the nature of the services provided. ICT third party service providers are assessed against DORA specific requirements, including ICT risk controls, operational resilience measures, register of information updates, resilience testing expectations and, where applicable, CSSF notification obligations for critical or important ICT outsourcing. Non ICT third party service providers are governed under the EBA Guidelines through enhanced due diligence, governance arrangements, contractual safeguards, ongoing monitoring and structured exit planning, addressing risks that fall outside DORA’s scope but remain prudentially material. By leveraging shared framework components such as criticality checklists, due diligence questionnaires, contractual clause reviews, risk assessments, exit plans, service level monitoring and harmonized registers, institutions can avoid duplication while ensuring full regulatory coverage.

This allows DORA and the EBA Guidelines to be operationalized consistently rather than in silos, providing supervisors with a coherent view of third party dependencies across the entire operating model. Applied to a selected and risk based set of suppliers, the model supports a continuous “Plan, Remediate and Comply” cycle, enabling institutions to demonstrate effective governance, resilience and control over both ICT and non ICT third party risks within a single, sustainable operating framework.

Conclusion: A strategic and prudential imperative

For Luxembourg’s financial institutions, once these Guidelines come into effect, managing non ICT third party risk will no longer be a compliance exercise delegated to procurement or operations. It will become a strategic and prudential imperative, directly linked to governance quality and supervisory trust.

Institutions that fail to address the Guidelines will not only remain exposed to non ICT third party risks that fall outside DORA’s scope but will also face weakened governance, increased exposure to non‑traditional third‑party dependencies, and an erosion of supervisory confidence.

Summary

In recent years, financial institutions have increasingly relied on third‑party providers for key operational and support functions. The EBA’s draft Guidelines on non‑ICT third‑party risk management clarify that these arrangements pose material prudential and governance risks and introduce a harmonized supervisory framework which, for Luxembourg institutions, aligns as far as possible with DORA while limiting additional supervisory burden.

About this article

Authors