Third-Party Risk Management for enterprises
Continuous, evidence-based monitoring of your vendor ecosystem across 325 million+ companies — with real-time alerts, dark web intelligence and fourth-party visibility.
- /01Continuous monitoring across 325 million+ companies
- /02Real-time alerts on vendor posture changes
- /03Dark Web Intelligence — 1,000+ underground forums
- /04Fourth-party visibility (your vendors' vendors)
- /05AI-powered: pre-filled profiles, questionnaire analysis
Nearly half of all breaches now involve a third party — 48% in Verizon's 2026 DBIR, up from 30% a year earlier. Most enterprises have no continuous visibility into supplier security at all: they have a folder of completed questionnaires, a spreadsheet of criticality ratings, and an honest belief that both were accurate on the day they were written. A vendor's defences can collapse in a week. The question is whether you find out from a monitoring alert or from the vendor's breach notification.
Third-Party Risk Management in 45 seconds: why a questionnaire can't keep pace with a vendor, and what continuous monitoring shows instead.
Why questionnaires fail
Not because vendors lie. Because the instrument has three structural defects that no amount of diligence corrects:
- It is self-reported. The vendor assesses itself, and the assessment is rarely verified against anything observable.
- It is point-in-time. It records a belief held on the day the form was completed, and nothing updates it afterwards.
- It is rarely re-read. Completed questionnaires are filed as evidence of process, not consulted as sources of risk information.
Continuous external monitoring inverts all three: independently observed, recalculated daily, and pushed to you as an alert instead of waiting to be looked up. Our guide on third-party risk management for banks and insurers works through what a tiered programme looks like in practice.
What TPRM does, job by job
Onboard a vendor without waiting for a questionnaire
Continuous monitoring covers 325 million+ companies, so most of your vendor portfolio is already rated on the day you start. A rating answers the first diligence question before a questionnaire is sent; where a contract still requires one, AI-assisted assessment pre-fills the vendor profile and analyses the answers, and the questionnaire can concentrate on the controls a rating cannot see.
Monitor continuously, and hear about movement
The signal that matters is not a vendor's absolute score but its movement — a supplier sliding forty points in a month is telling you something a static rating never will. Alerts arrive when posture changes, alongside dark and deep web intelligence across 1,000+ underground forums for credentials and data associated with your suppliers. The same question, pointed at your own estate, is what the credential exposure check works through.
Re-tier vendors on evidence
A vendor's tier should move when its risk does. Ratings give the tiering model below a measured input that changes daily, rather than a criticality score set at onboarding and never revisited.
See fourth parties
Your vendors' vendors, and the concentration risk you inherited without contracting for it.
Report the portfolio to the board
One view a board can read: how many critical vendors sit below their tier's threshold, which moved this quarter, and what was done about each. It is dated and independently calculated, which makes it evidence rather than assertion.
Tiering: the part that determines whether it works
Monitoring two hundred vendors equally produces two hundred alerts and no action. Programmes that work tier the portfolio first, set a different threshold and a different response per tier, and assign a named owner to each. Axis Max Life Insurance — whose Bitsight rating of 810 is among the highest in Indian financial services — adopted an ABCD tiered framework in which critical vendors must hold a B or better, and replaced 100% of manual vendor questionnaires with continuous monitoring.
| Tier | Typical criteria | Response on deterioration |
|---|---|---|
| Critical | Holds regulated data, or an outage stops the business | Named owner, contractual minimum rating, escalation within days |
| Important | Material operational dependency, limited data access | Reviewed at the monthly vendor forum |
| Standard | Replaceable, no sensitive data | Monitored; acted on only at threshold breach |
What regulators expect
Regulators have moved decisively — the SEC and NYDFS in the US, DORA in the EU, and India's RBI, SEBI and IRDAI — toward requiring boards to evidence oversight of outsourcing and supply-chain risk rather than assert it. In India, every current instrument carries a third-party chapter — the RBI Directions of 31 July 2026 and the separate outsourcing Directions they preserve, SEBI's CSCRF, and IRDAI's 2026 Guidelines, which require third parties to be classified and overseen by risk tier. Which instrument binds you sets out the full picture.
India: the RBI outsourcing Directions, one per entity class
The RBI rewrote outsourcing as nine Directions, all dated 28 November 2025, one for each regulated class. For commercial banks they repeal the 2023 Master Direction on Outsourcing of IT Services, so a bank's vendor programme still mapped to the 2023 text is mapped to a repealed instrument. Regional Rural Banks are the only RBI class with no member of this family.
| Instrument | Reference | Who it binds |
|---|---|---|
| RBI outsourcing Directions, 2025 | RBI/DOR/2025-26/171 | Scheduled commercial banks — banking companies other than Small Finance Banks, Local Area Banks, Payments Banks and Regional Rural Banks — with the corresponding new banks and SBI. Immediate effect, with existing IT outsourcing agreements to comply by 10 April 2026. Repeals the 2023 Master Direction on Outsourcing of IT Services for the banks covered. |
| RBI NBFC outsourcing Directions, 2025 | RBI/DOR/2025-26/363 | NBFCs across the scale-based layers, together with HFCs, Core Investment Companies, standalone primary dealers and the account aggregator and P2P categories; NOFHCs excluded. Base Layer takes the general provisions only. Existing IT outsourcing agreements to comply by 10 April 2026. |
| RBI SFB outsourcing Directions, 2025 | RBI/DOR/2025-26/202 | Small Finance Banks. Covers outsourcing of financial services and of IT services. Immediate effect, with existing IT outsourcing agreements to comply at renewal or by 10 April 2026, whichever is earlier. |
| RBI Payments Bank outsourcing Directions, 2025 | RBI/DOR/2025-26/220 | Payments Banks. Covers outsourcing of financial services and of IT services. Immediate effect, with existing IT outsourcing agreements to comply at renewal or by 10 April 2026, whichever is earlier. |
| RBI LAB outsourcing Directions, 2025 | RBI/DOR/2025-26/245 | Local Area Banks, for material outsourcing of IT services only — the instrument has no financial-services chapter. Immediate effect, with existing IT outsourcing agreements to comply at renewal or by 10 April 2026, whichever is earlier. |
| RBI UCB outsourcing Directions, 2025 | RBI/DOR/2025-26/293 | All Urban Co-operative Banks for outsourcing of financial services; the IT outsourcing chapter and the IT-specific board provisions apply only to Tier 3 and Tier 4 UCBs. Immediate effect, with existing IT outsourcing agreements to comply at renewal or by 10 April 2026, whichever is earlier. |
| RBI RCB outsourcing Directions, 2025 | RBI/DOR/2025-26/318 | Rural Co-operative Banks — State and Central Co-operative Banks as defined in the NABARD Act, 1981 — for outsourcing of financial services only. No IT outsourcing chapter and no transition proviso: in force with immediate effect. |
| RBI AIFI outsourcing Directions, 2025 | RBI/DOR/2025-26/337 | EXIM Bank, NABARD, NaBFID, NHB and SIDBI, for material outsourcing of IT services only. Immediate effect, with existing IT outsourcing agreements to comply at renewal or by 10 April 2026, whichever is earlier. |
| RBI Credit Information Company outsourcing Directions, 2025 | RBI/DoR/2025-26/379 | Credit Information Companies under section 2(e) of the Credit Information Companies (Regulation) Act, 2005, for material outsourcing of IT services only. Not the Core Investment Companies the NBFC instrument calls CICs. Existing IT outsourcing agreements to comply at renewal or by 10 April 2026, whichever is earlier. |
Continuous monitoring produces that evidence as a by-product of operating: a dated, independently calculated record of each critical vendor's security performance over time, a documented tiering model, and an auditable alert-and-response trail. That is a materially stronger position at examination than a folder of self-assessments.
Ratings, questionnaires or VAPT?
Each answers a different question, and a vendor programme usually needs more than one. The difference is who produces the evidence, when, and whether the vendor has to agree to it.
| Security rating | Questionnaire | VAPT report | |
|---|---|---|---|
| Who produces it | An independent rating provider | The vendor, about itself | A tester the vendor engages |
| How current | Recalculated daily | The day it was completed | The test window |
| Vendor consent needed | No — externally observable signals only | Yes | Yes, and usually a scope agreement |
| What it sees | The internet-facing estate | Whatever the vendor chooses to describe | The systems in scope, inside and out |
| Best used for | Screening every vendor and watching for change | Controls a rating cannot see | Depth on the few critical vendors |
The longer argument is in security questionnaires vs security ratings.
Packages and vendor bands
TPRM comes in two packages, each banded by the number of vendors monitored (1–50 vendors, 51–100 vendors, 101–500 vendors, unlimited).
Continuous Monitoring
Continuous, evidence-based visibility across your vendor portfolio.
- Continuous visibility with real-time scoring
- Correlated risk vectors
- Unified attack surface management
- Vendor communication
- Dark and deep web intelligence
- Predictive vulnerability detection
- Framework intelligence
- Nth and fourth-party visibility
- Board reporting
- Workflow integrations and REST API
- Rule-based alerts
Continuous Monitoring + Vendor Risk Management — most commonly chosen
Adds the workflow layer — intake, assessment and remediation — on top of monitoring.
- Vendor intake workflows
- Risk assessment
- Vendor network access
- Portfolio-level management
- Vendor lifecycle management
- Vendor collaboration
- Remediation tracking
- Governance reporting
The practical difference is whether you need the workflow layer. Continuous Monitoring gives you visibility and alerts; adding Vendor Risk Management gives you intake, assessment, remediation tracking and governance reporting — the machinery that turns an alert into a closed action. Pricing is quoted in INR against scope; see the pricing page for what moves a quote.
Where to start
Point the instrument at yourself first. The complimentary Cyber Risk Rating Report shows you exactly what your vendors will see when you start rating them — which is both a useful calibration and, in our experience, a considerably more persuasive internal business case than a slide about supply-chain risk. If your own estate is the priority, Security Posture Management applies the same continuous measurement inward. Both run on the same Bitsight platform and the same rating.
Questions people actually ask about TPRM.
/01What is Third-Party Risk Management?
Third-Party Risk Management is the practice of identifying, assessing and continuously monitoring the security risk that vendors, suppliers and service providers introduce into an organisation. In its evidence-based form it measures each third party's externally observable security performance daily, rather than asking the vendor to describe its own controls once a year.
/02Why do vendor security questionnaires fail?
A questionnaire is self-reported, point-in-time and unverified. It records what a vendor believed about itself on the day someone filled the form in, it is rarely re-read after filing, and it cannot detect the posture collapse that happens three months later. Continuous external monitoring inverts all three properties: it is independently observed, updated daily, and it raises an alert at the moment a vendor's posture changes.
/03Do our vendors need to agree to be monitored?
No. Ratings are calculated entirely from external, attacker-visible signals, so a vendor can be monitored without its participation, its cooperation, or any contractual change. In practice most organisations tell their critical vendors anyway, because the conversation is more productive when both sides can see the same evidence.
/04What is fourth-party risk, and why does it matter?
Fourth parties are your vendors' vendors — the concentration you inherit without contracting for it. When a single cloud host, payment processor or managed service provider sits behind thirty of your suppliers, an incident there is a correlated failure across your portfolio rather than an isolated vendor problem. Fourth-party visibility surfaces that concentration before it becomes an outage.
/05How does TPRM help with RBI, SEBI, IRDAI and IFSCA expectations?
Indian regulators now expect boards to evidence oversight of outsourcing and supply-chain risk rather than assert it. Every one of the current instruments carries a third-party chapter — the RBI Directions of 31 July 2026, the separate RBI outsourcing Directions of 2025, SEBI's CSCRF, and IRDAI's 2026 Guidelines, which require third parties to be classified and overseen by risk tier. For a GIFT City entity the IFSCA Guidelines go further still, setting an express six-monthly review of third parties supporting core operations — the clearest cadence obligation in the Indian set. Continuous monitoring produces exactly that evidence: a dated, independently calculated record of each critical vendor's security performance over time, plus a documented tiering model and an auditable alert-and-response trail.
Start with the number, not the contract.
Your organisation already has a rating, calculated from signals anyone can see. Request the complimentary Cyber Risk Rating Report and find out what it says — as little as 45 minutes for publicly listed entities, up to 48 hours for all others. No agent, no system access, no questionnaire.
- PracticeThird-party risk management for Indian BFSIWhy questionnaires fail for vendor risk in BFSI, and how to build a tiered programme with continuous evidence instead.
- RegulationCyber security regulations in India: which one applies to youThe whole regulatory picture in one table, then a route from your entity type to the instrument that actually governs you.
- RegulationThe RBI Directions of 31 July 2026: which of the seven applies to youNot one instrument but seven, issued the same day. The applicability test first, then the obligations, the timings, and the outsourcing track they deliberately left alone.