Third-party risk management for Indian BFSI
Why questionnaire-based vendor assessment fails in Indian BFSI, and how to build a tiered, continuously monitored TPRM programme under the RBI outsourcing Directions, 2025.
Every bank, insurer and NBFC in India runs a vendor risk programme. Most of them are questionnaire programmes: a spreadsheet goes out, answers come back, someone files them, and the vendor is considered assessed for another year. The programme is real. The assurance is largely notional.
Why questionnaire-based assessment fails
Four structural problems, none of which are fixed by a better questionnaire.
- Self-reported. The party being assessed writes the answers, is not independently verified, and has an obvious incentive. Nobody describes their own patching discipline as poor.
- Point-in-time. An answer given in June describes June. Vendor environments change continuously; the assessment does not.
- Unfalsifiable at scale. Verifying one vendor's claims properly takes days. With four hundred vendors, verification does not happen, so the questionnaire becomes a record that a question was asked.
- Blind past the first tier. Your vendor's vendors are where a surprising share of real incidents originate, and the questionnaire almost never reaches them.
The consequence is a programme that produces documentation rather than warning. When a supplier is compromised, the organisation usually learns about it from the supplier, from a customer, or from the news — not from its own oversight.
The regulatory anchor: liability does not transfer
For commercial banks the instrument is now the Reserve Bank of India (Commercial Banks – Managing Risks in Outsourcing) Directions, 2025 — RBI/DOR/2025-26/171, issued 28 November 2025 with immediate effect. They consolidate financial and IT outsourcing into a single framework and repeal the prior outsourcing guidance for the banks they cover, including the 2023 Master Direction on Outsourcing of Information Technology Services. They apply to scheduled commercial banks other than regional rural banks, small finance banks, local area banks and payments banks; foreign banks operating through branches get a comply-or-explain approach on the IT outsourcing provisions. NBFCs have their own parallel instrument issued the same day.
The central principle survives every rewrite, because it is the point: a regulated entity's liability towards its customers is not diminished by an outsourcing arrangement, nor may such an arrangement impede supervision by the RBI. Responsibility stays with you regardless of who operates the system.
The transition window has closed. New agreements had to comply from inception; existing IT outsourcing agreements had until 10 April 2026, at renewal or earlier. Existing arrangements are expected to be compliant now, not on their next convenient renewal.
What the 2025 Directions actually demand of a vendor programme is worth stating plainly, because it is more than a questionnaire can carry. Due diligence covering financial soundness, reputation, compliance history, internal controls and security practices. A materiality determination driven by business criticality and concentration rather than contract value. A standing management structure to monitor outsourced activity — not an annual review. Audit rights reaching the service provider and its subcontractors, with RBI inspection rights doing the same. Documented exit plans with transition timelines and data destruction. And for IT specifically: data localisation where applicable, identity and access management, regular security assessments, cloud governance, and incident reporting within six hours of detection. Certain functions cannot be outsourced at all — internal audit, compliance, and decision-making such as KYC determination, loan approval and investment portfolio management.
Summarised from public sources as at August 2026, including the RBI outsourcing Directions of 28 November 2025 and the cybersecurity Directions of 31 July 2026, both linked above. Applicability depends on entity classification — confirm your own position with counsel. Not legal advice.
Start by tiering, not by assessing
The most common programme design error is treating all vendors alike. The stationery supplier and the core banking hosting provider do not warrant the same scrutiny, and pretending otherwise guarantees that the scrutiny is shallow everywhere.
Tier on impact, not on spend. The question is not what you pay a vendor but what happens if they are unavailable, breached, or found to have exfiltrated data.
| Tier | Definition | Oversight |
|---|---|---|
| A — Critical | Processes customer data at scale, or outage halts a regulated activity | Continuous monitoring, contractual minimum rating, quarterly review, exit plan tested |
| B — Important | Material operational dependency, limited customer data | Continuous monitoring, alerting on degradation, annual review |
| C — Standard | Business services, no sensitive data, replaceable | Monitoring with exception-based escalation |
| D — Minimal | No systems access, no data, trivially replaceable | Onboarding check only |
Axis Max Life Insurance operates a tiered framework of exactly this shape, in which critical vendors are contractually required to hold a minimum rating — moving the requirement out of the assessment and into the agreement, where it has consequences.
Replace attestation with continuous evidence
Once vendors are tiered, the second change is what oversight actually consists of. External monitoring observes a vendor's internet-facing posture continuously and independently — no cooperation required, and no incentive to flatter.
What that adds over a questionnaire:
- Evidence rather than assertion. An expired certificate or an exposed service is observed, not claimed.
- Change detection. The useful signal is usually degradation — a vendor whose posture slips sharply over six weeks is telling you something a questionnaire never will.
- Coverage at scale. Monitoring four hundred vendors costs roughly what monitoring forty does. Verifying four hundred questionnaires does not.
- Fourth-party visibility. Mapping your vendors' dependencies surfaces the concentration risk that first-tier assessment structurally cannot see.
A rollout sequence that works
- Build the actual vendor list. Procurement records, accounts payable and the CMDB will disagree. Reconciling them typically surfaces 20–40% more third parties than any single system knows about, and this step alone often justifies the programme.
- Tier ruthlessly. Expect roughly 5% Tier A and 15% Tier B. If a third of your vendors are critical, the tiering is wrong.
- Baseline Tier A and B externally before telling vendors anything. You want an unmanaged picture first.
- Set contractual thresholds at renewal. A minimum rating, a remediation window, and a right to monitor. This is the step most programmes skip and most need.
- Route alerts to an owner. An alert with no named owner and no SLA is noise that trains people to ignore the console.
- Report the portfolio, not the incidents. Boards need distribution and trend across tiers, not a list of last month's findings.
What is different in India
Domestic vendor coverage varies more than you expect
Global platforms have excellent coverage of multinationals and uneven coverage of smaller Indian suppliers with a thin external footprint. Test this during evaluation with fifteen of your own real vendors — deliberately including your smallest regional ones — rather than a vendor-supplied sample.
Concentration risk is genuinely concentrated
A relatively small number of domestic providers sit behind a large share of BFSI operations in areas such as payment processing, core banking and KYC. Fourth-party mapping frequently reveals that nominally diversified vendor sets converge on the same two or three dependencies.
Remediation is a relationship, not a ticket
Detecting that a vendor has a problem is the easy part. Getting a mid-sized Indian supplier to fix it requires someone who can have the conversation in the right language, in the right timezone, with the right technical specificity. Programmes run entirely from a global console with US-hours support tend to detect well and remediate slowly.
Metrics worth reporting
- Percentage of Tier A and B vendors under continuous monitoring — target 100%
- Distribution of vendor ratings by tier, quarter on quarter
- Number of vendors below the contractual threshold, and days outstanding
- Median time from alert to vendor acknowledgement
- Fourth-party concentration: dependencies shared by more than five Tier A vendors
Note what is absent: the count of questionnaires issued. It measures activity, not risk, and reporting it upward quietly reinforces the wrong programme.