The short answer: the RBI 2025 Outsourcing Directions require you to continuously monitor your vendors, not assess them once a year and file the result. This episode is the shift from point in time to always on, including the concentration risk your diversified vendor list is hiding.
See every vendor monitored continuously, ranked by exposure →
The questionnaire describes a vendor who no longer exists
A vendor completes your annual security questionnaire in January. It goes in the folder. By November its picture has changed through restructuring, new subcontractors, a new exposed interface, an undeclared incident and wobbling finances. You learn none of this until the next January form.
This is the structural failure of point in time vendor risk. Episode 3 established that a filed certificate is not verification. Episode 4 established that a contractual audit right you never exercise is not a control. This episode is where both problems get solved, because the regulation no longer accepts the annual snapshot.
What RBI now actually requires
Oversight is ongoing, not once and done. A regulated entity must continuously monitor outsourced activities, maintain a central register of material outsourcing, conduct regular audits, and review the service provider's financial and operational condition at least once a year, with a risk based approach to everything else.
Continuously monitor
Not review annually. The annual review still exists as a floor. It is no longer the whole programme.
Highlight deterioration
Reviews must surface breach in performance, confidentiality, security and operational resilience preparedness. Forward looking, not a confirmation that last year looked fine.
Outsourcing failures will increasingly be viewed as governance failures, with accountability attaching to senior management and the Board. A firm falls foul when its monitoring framework was never capable of seeing the failure coming.
Why the annual questionnaire cannot do this job
The annual questionnaire is not merely insufficient. It is the wrong instrument for the task, for three structural reasons.
Self reported
The vendor describes itself, with every incentive to present well. That is attested evidence. An adversary attacks the observed reality, not the questionnaire.
A quarterly questionnaire is still a snapshot, still self reported, still backward looking. Continuous monitoring exists because the questionnaire's failures are not fixable by making it longer or more frequent.
What continuous monitoring actually watches
Done properly, it watches the signals that move between annual reviews and that a self report would never surface. For a material BFSI vendor, keep a live eye on at least the following.
Systems and services exposed to the internet, and any change in them. A new interface, a lapsed certificate, MFA that stopped enforcing, each is a risk change the day it happens.
Disclosed and discoverable, so a breach at the vendor becomes a signal you act on rather than something you learn months later or never.
See deterioration, the exact thing the Directions require your reviews to highlight, rather than a single pass or fail at one moment.
A vendor sliding toward distress is exit risk in slow motion. Catch deterioration in operational resilience preparedness.
A change in subcontractors, which under the 2025 Directions needs your approval anyway, does not slip past you.
The distinction that matters is attested versus observed. Continuous monitoring watches the observed reality of a vendor, continuously, and weights it above what the vendor tells you once a year.
The events that must trigger a fresh look
Certain events must trigger a full reassessment immediately, regardless of the annual cycle, because any one of them can invalidate everything your last review concluded.
The vendor you approved is not the vendor you now have.
New owners, new incentives, often new risk.
Fourth parties shift under you without a calendar invite.
Reassess now. The annual cycle is irrelevant.
A firm that reviews every vendor on schedule but has no mechanism to react to a mid year acquisition or breach is monitoring the calendar rather than the risk. The trigger is the event, not the date.
Concentration risk, the exposure a per vendor view can never show
Concentration risk emerges not from any single vendor, but from how your vendors relate to each other and to what sits beneath them. Only a portfolio view reveals it. RBI requires you to assess risks arising from undue concentration of outsourcing.
One provider running so many critical functions that its failure would cripple you. Visible the moment you sort inventory by function or owner. Obvious, and manageable.
Diversified vendors that all run on the same hyperscaler or region. Invisible in a per vendor view. This is where the real damage lives.
The cloud concentration problem
You diversify fraud, KYC, analytics and communications vendors deliberately. Then you look one layer down, at the fourth party dependencies from Episode 2, and discover all four run on the same hyperscaler, often in the same region. Your diversified list has a single point of failure underneath it.
Regulators treat this as systemic stability, not just firm risk. The UK has designated major cloud providers as critical third parties. India takes a different path: RBI supervises your management of the cloud relationship, not the provider directly. Under that model, seeing and managing your own concentration is not optional.
Require material vendors to disclose which hyperscaler and which region they run on, so the shared foundation becomes visible.
What happens to your operations across all vendors sitting on that foundation at once.
Substitutability is not an infrastructure preference. It is a resilience and increasingly a regulatory expectation.
You cannot manage a concentration you cannot see, and the whole point of cloud concentration is that it is invisible until you deliberately look underneath your vendors.
From monitoring to breach likelihood
Compliance status is point in time and backward looking. Breach likelihood is forward looking and continuous. A vendor can be fully compliant on paper and carrying rising live exposure at the same time.
Green ticks in a folder
Whether controls were described as present at a moment that has already passed.
Exposure ranked live
How exposed a vendor is right now, and whether that exposure is rising, before the incident rather than after it.
The point of watching vendors continuously is not to keep the compliance folder current. It is to know which vendor in your portfolio is most likely to get you breached.
Why this is a Bugmetrics problem
Continuous monitoring across a full vendor portfolio, with concentration made visible and exposure scored in real time, is not something a small compliance team can do by hand with questionnaires and a spreadsheet.
Deterioration in a vendor's posture surfaces when it happens, which is what the Directions require your reviews to highlight.
At any moment know which vendor is most likely to cause a loss, rather than discovering it in next year's questionnaire.
Shared cloud foundations and single provider dependencies a per vendor view hides become something you can manage.
A vendor incident or material change triggers a fresh look rather than waiting for the annual cycle.
The Episode 2 inventory kept current, mapped across RBI, SEBI CSCRF, DPDP, ISO 27001 and SOC 2.
Compliance tells you the questionnaire came back green. Bugmetrics tells you which vendor is about to get you breached.
If you are the vendor, not the bank
The era of the annual questionnaire being the whole relationship is ending. Your BFSI customers are expected to monitor you continuously, react to incidents and changes as they happen, and understand the fourth party dependencies underneath you, including which cloud and region you run on.
Vendors who do well under continuous monitoring have nothing that deteriorates quietly between reviews, and can disclose hyperscaler dependencies and critical vendors without hesitation. Transparency about your own fourth parties is becoming part of being a trustworthy BFSI vendor.
Frequently asked
Does RBI require continuous vendor monitoring?+
Yes. The 2025 Outsourcing Directions require regulated entities to continuously monitor outsourced activities, maintain a central register of material outsourcing, conduct regular audits, and review vendors' financial and operational condition at least annually, with reviews that highlight deterioration in performance, security and operational resilience. Continuous monitoring is the standard, and the annual review is a floor.
Why is an annual vendor questionnaire not enough?+
Because it is self reported, it captures only a single moment in a year during which the vendor changes continuously, and it measures whether controls were described as present rather than whether the vendor's live exposure is rising. Risk accumulates in the gaps between annual captures.
What is concentration risk in outsourcing?+
It is the risk arising from depending too heavily on a single provider or a limited number of providers, or from many of your vendors sharing the same underlying dependency such as one cloud provider. RBI requires you to assess undue concentration as part of vendor due diligence.
What is cloud concentration risk?+
It is the systemic risk that arises when many firms, and many of their vendors, rely on the same small set of cloud providers. A single provider or region outage can then disrupt large parts of the financial sector at once. It is often hidden because individually diversified vendors turn out to share the same cloud foundation.
How does India regulate cloud concentration?+
Indirectly. RBI supervises the regulated entity's management of its cloud relationship rather than the cloud provider directly, so the responsibility to assess and manage cloud concentration sits with the regulated entity itself.
What events should trigger a vendor reassessment outside the annual cycle?+
A material change in the vendor's services or architecture, a change in ownership, a change in subcontracting arrangements, or a significant security incident at the vendor. Any of these should trigger a fresh assessment immediately.
How Bugmetrics helps
Vendor risk that updates once a year is a folder, not a control. Bugmetrics makes it continuous.
Deterioration in a vendor's posture surfaces when it happens, which is what the Directions require your reviews to highlight.
At any moment know which vendor is most likely to cause a loss, rather than discovering it in next year's questionnaire.
Shared cloud foundations and single provider dependencies a per vendor view hides become something you can manage.
A vendor incident or material change triggers a fresh look rather than waiting for the annual cycle.
Compliance tells you the boxes were checked. Bugmetrics tells you which vendor is about to get you breached.
See your vendors monitored live, ranked by exposure →
Next in the series, Episode 6, the finale: Exit, Resilience and When a Vendor Fails. Continuous monitoring tells you a vendor is failing. This is what you do about it. The enforceable exit strategy, the substitutability test, and the vendor breach runbook everyone documents and nobody rehearses. Read Episode 6 →
Sources, verified against primary text: the RBI (Non-Banking Financial Companies, Managing Risks in Outsourcing) Directions, 2025, including the due diligence factors on undue concentration and the monitoring, central register and periodic review requirements, with equivalent provisions in the parallel Commercial Banks, Small Finance Banks, Payments Banks and AIFI Directions; the RBI (Outsourcing of Information Technology Services) Directions, 2023; and SEBI CSCRF (August 2024, as amended). Cloud concentration discussion reflects publicly reported developments including UK critical third party designations, FSB work on third party dependencies, and RBI's reported work with IFTAS on a community cloud. Applicability varies by entity class. General information only, not legal advice.