Third-party risk management for Indian BFSI
Why questionnaire-based vendor assessment fails in Indian banking, financial services and insurance, and how to build a tiered, continuously monitored TPRM programme instead.
Every bank, insurer and NBFC in India runs a vendor risk programme. Most of them are questionnaire programmes: a spreadsheet goes out, answers come back, someone files them, and the vendor is considered assessed for another year. The programme is real. The assurance is largely notional.
Why questionnaire-based assessment fails
Four structural problems, none of which are fixed by a better questionnaire.
- Self-reported. The party being assessed writes the answers, is not independently verified, and has an obvious incentive. Nobody describes their own patching discipline as poor.
- Point-in-time. An answer given in June describes June. Vendor environments change continuously; the assessment does not.
- Unfalsifiable at scale.Verifying one vendor's claims properly takes days. With four hundred vendors, verification does not happen, so the questionnaire becomes a record that a question was asked.
- Blind past the first tier.Your vendor's vendors are where a surprising share of real incidents originate, and the questionnaire almost never reaches them.
The consequence is a programme that produces documentation rather than warning. When a supplier is compromised, the organisation usually learns about it from the supplier, from a customer, or from the news — not from its own oversight.
The regulatory anchor: liability does not transfer
The RBI Master Direction on Outsourcing of Information Technology Services was issued on 10 April 2023 and came into effect on 1 October 2023. It applies to scheduled commercial banks other than regional rural banks, local and small finance banks, payments banks, primary urban co-operative banks above Tier 2, credit information companies, NBFCs other than base layer, and the all-India financial institutions.
Its central principle is short and consequential: a regulated entity's liability towards its customers is not diminished by an outsourcing arrangement, nor may such an arrangement impede supervision by the RBI. Responsibility stays with you regardless of who operates the system.
The transition window has now closed. Agreements due for renewal before 1 October 2023 had twelve months from issuance; those renewing later had until the renewal date or 36 months from issuance, whichever came first — a backstop that expired in April 2026. Existing arrangements are expected to be compliant now, not on their next convenient renewal.
Summarised from public sources as at July 2026. Applicability depends on entity classification — confirm your own position with counsel. Not legal advice.
Start by tiering, not by assessing
The most common programme design error is treating all vendors alike. The stationery supplier and the core banking hosting provider do not warrant the same scrutiny, and pretending otherwise guarantees that the scrutiny is shallow everywhere.
Tier on impact, not on spend. The question is not what you pay a vendor but what happens if they are unavailable, breached, or found to have exfiltrated data.
| Tier | Definition | Oversight |
|---|---|---|
| A — Critical | Processes customer data at scale, or outage halts a regulated activity | Continuous monitoring, contractual minimum rating, quarterly review, exit plan tested |
| B — Important | Material operational dependency, limited customer data | Continuous monitoring, alerting on degradation, annual review |
| C — Standard | Business services, no sensitive data, replaceable | Monitoring with exception-based escalation |
| D — Minimal | No systems access, no data, trivially replaceable | Onboarding check only |
Axis Max Life Insurance operates a tiered framework of exactly this shape, in which critical vendors are contractually required to hold a minimum rating — moving the requirement out of the assessment and into the agreement, where it has consequences.
Replace attestation with continuous evidence
Once vendors are tiered, the second change is what oversight actually consists of. External monitoring observes a vendor's internet-facing posture continuously and independently — no cooperation required, and no incentive to flatter.
What that adds over a questionnaire:
- Evidence rather than assertion. An expired certificate or an exposed service is observed, not claimed.
- Change detection. The useful signal is usually degradation — a vendor whose posture slips sharply over six weeks is telling you something a questionnaire never will.
- Coverage at scale. Monitoring four hundred vendors costs roughly what monitoring forty does. Verifying four hundred questionnaires does not.
- Fourth-party visibility.Mapping your vendors' dependencies surfaces the concentration risk that first-tier assessment structurally cannot see.
A rollout sequence that works
- Build the actual vendor list. Procurement records, accounts payable and the CMDB will disagree. Reconciling them typically surfaces 20–40% more third parties than any single system knows about, and this step alone often justifies the programme.
- Tier ruthlessly. Expect roughly 5% Tier A and 15% Tier B. If a third of your vendors are critical, the tiering is wrong.
- Baseline Tier A and B externally before telling vendors anything. You want an unmanaged picture first.
- Set contractual thresholds at renewal. A minimum rating, a remediation window, and a right to monitor. This is the step most programmes skip and most need.
- Route alerts to an owner. An alert with no named owner and no SLA is noise that trains people to ignore the console.
- Report the portfolio, not the incidents.Boards need distribution and trend across tiers, not a list of last month's findings.
What is different in India
Domestic vendor coverage varies more than you expect
Global platforms have excellent coverage of multinationals and uneven coverage of smaller Indian suppliers with a thin external footprint. Test this during evaluation with fifteen of your own real vendors — deliberately including your smallest regional ones — rather than a vendor-supplied sample.
Concentration risk is genuinely concentrated
A relatively small number of domestic providers sit behind a large share of BFSI operations in areas such as payment processing, core banking and KYC. Fourth-party mapping frequently reveals that nominally diversified vendor sets converge on the same two or three dependencies.
Remediation is a relationship, not a ticket
Detecting that a vendor has a problem is the easy part. Getting a mid-sized Indian supplier to fix it requires someone who can have the conversation in the right language, in the right timezone, with the right technical specificity. Programmes run entirely from a global console with US-hours support tend to detect well and remediate slowly.
Metrics worth reporting
- Percentage of Tier A and B vendors under continuous monitoring — target 100%
- Distribution of vendor ratings by tier, quarter on quarter
- Number of vendors below the contractual threshold, and days outstanding
- Median time from alert to vendor acknowledgement
- Fourth-party concentration: dependencies shared by more than five Tier A vendors
Note what is absent: the count of questionnaires issued. It measures activity, not risk, and reporting it upward quietly reinforces the wrong programme.