All articles
ComplianceEpisode 6 of 6 · Finale· 23 min read
Third Party Risk Management for Fintech, BFSI & NBFC

TPRM for BFSI, Episode 6: Exit, Resilience and When a Vendor Fails (The Test Everyone Skips)

You must be able to leave any vendor and keep running. The mandated exit strategy, tested continuity, step in rights, and the vendor breach runbook nobody rehearses. The series finale.

AS
Ankita Sharma
Talk to an expert
Exit
Must stay reversible
Leave and keep running
Test
Not just document
BCP and DR exercised
Step in
Vendor insolvency
Retain control to operate
6 of 6
Series finale
TPRM for Fintech, BFSI & NBFC

The short answer: the RBI 2025 Outsourcing Directions require you to be able to exit any vendor and keep operating. Most firms have exit and continuity on paper and have never tested them, which is the same as not having them. This finale is the test everyone documents and nobody rehearses.

See which vendor failure you are least prepared for →

The plan in the drawer

Somewhere in your compliance repository is an exit plan. It names an alternative provider, describes in general terms how you would move, was written to satisfy a requirement, and never opened again.

Then the day comes. Catastrophic outage, insolvency, or a breach so severe you cut them off. You open the plan under real pressure and discover it names a provider you never onboarded, assumes data formats you never tested, and depends on a migration nobody rehearsed. The plan describes an exit. It does not enable one.

Across five episodes we established that your vendors are your liability, that you must know and classify them, verify rather than trust them, bind them contractually, and monitor them continuously. This finale is the moment all of that is tested at once.

Reversibility, the principle RBI built into the Directions

RBI expects a regulated entity to retain the ability to unwind an outsourcing arrangement, switch to another provider, or bring the function back in house. Outsourcing must never become a one way door.

A function outsourced so completely that you could never take it back is not a managed arrangement. It is a dependency you have lost control of. Exit strategies, continuity testing and step in rights exist to guarantee one thing: that your outsourcing decisions remain yours to reverse.

The exit strategy the Directions mandate

The requirement is explicit. Drawn from the NBFC Directions and mirrored across bank and AIFI versions, the exit obligations are four.

Clear exit strategy

Your IT outsourcing policy must contain a strategy for business continuity during and after exit, not a clause that merely acknowledges exit is possible.

Plans for different scenarios

Planned migration at contract end is not the same as emergency cut off after a breach. Cover both, with a stipulated minimum period to execute them.

Identified alternatives

A different service provider or bringing the service back in house. This is substitutability, and it is where most exit plans fail.

Safe data on exit

Agreements must cover safe removal or destruction of data, hardware and all records. A vendor that cannot cleanly return or destroy your data is one you can never fully leave.

Substitutability, the requirement most exit plans fail

Naming an alternative is easy. Being able to move to one is not. RBI requires you to assess availability of alternatives or in house delivery, including cost, time and resources.

The alternative that does not exist

The plan names a competitor you never onboarded, never tested a migration with, and have no contract with. In an emergency the alternative is months away, not days.

The bring it in house option is the ultimate backstop. Could you actually run this function yourself at short notice if every external option failed. For some functions the honest answer is no, and knowing that changes how much redundancy you build elsewhere. See also Episode 5 on concentration.

Business continuity and disaster recovery, and the testing that makes them real

You must require your service provider to develop, maintain and, critically, test a robust framework for business continuity and recovery. Joint testing with the provider is invited, and the plans must be commensurate with the nature and scope of the service.

A business continuity plan that has never been tested is an assumption, not a capability. A joint recovery exercise is the only way to discover, in advance, that your vendor's recovery time is longer than your tolerance, or that failover depends on a system you also depend on.

This is where the testing rights from Episode 4 become operational reality. A right you never exercise tells you nothing. A joint test once a year tells you exactly where the plan breaks while you still have time to fix it.

Step in rights, drafting for the vendor's worst day

Not a planned migration and not a recoverable outage, but the vendor failing underneath you. Insolvency. Liquidation. Sudden termination. The Directions require you to retain enough control to intervene and continue operations.

If the vendor goes into liquidation, can you still reach your data, records and enough of the operating environment to keep serving customers or execute an orderly transition. Planning for the failure of a vendor you trust is not a lack of faith. It is the requirement.

When a vendor is breached, the runbook

A vendor breach triggers the four clock reporting problem, on a clock that started when the vendor detected the incident, not when you found out.

Step 1
Clock starts at the vendor

CERT-In within six hours from the vendor's detection. That is why Episode 4 insisted on a one hour notification SLA.

Step 2
Fan out to the same regulators

CERT-In, RBI or SEBI, the Data Protection Board without delay and again at seventy two hours, and affected individuals. A vendor breach does not reduce your obligations.

Step 3
Contain by cutting the vendor off

Revoke access, credentials and API keys. Isolate the integration without destroying evidence for the seventy two hour report.

Step 4
Scope from your inventory

The Episode 2 register lets you say what data the vendor held in minutes, not days. Without it you cannot file a defensible report.

Step 5
Decide whether this is also an exit

A breach severe enough to cut a vendor off may force the exit strategy under the worst conditions. This is when you learn if the plan was ever real.

The test everyone skips

Documented is not the same as rehearsed. An exit plan never executed, a BCP never tested, a step in right never exercised, a breach runbook never drilled, are assumptions dressed as capabilities.

Run the tabletop. Take your most critical vendor, assume it fails at the worst possible moment, and walk the organisation through exit, continuity, step in and breach reporting. Finding broken assumptions in a conference room is the entire point.

This was never a documentation exercise

Outsourcing does not dilute your liability. So you have to know your vendors, verify them, bind them in contract, monitor them continuously, and survive when one fails. Vendor failure is inevitable somewhere in a portfolio. Governance failure is a choice.

If you are the vendor, not the bank

Your BFSI customers must be able to exit you cleanly, recover if you fail, step in if you collapse, and get their data back or destroyed on the way out. Transition assistance, jointly tested continuity, proven data export and deletion, and a one hour breach notification can feel like they are planning to leave before the relationship begins.

Reframe it. A vendor that is easy to leave is easier to choose. In a regulated market that demands reversibility, being genuinely exitable is a selling point.

The series, in one line each

Episode 1

Outsourcing does not dilute your liability. You can delegate the activity, never the accountability.

Episode 2

You cannot govern what you have not listed. Build the inventory, classify by materiality, and see the fourth parties behind your vendors.

Episode 3

A filed certificate is not verification. Assess capability on an ongoing basis, and weight observed evidence over attested claims.

Episode 4

The contract is the control. It cannot transfer your liability, but it is the only thing that makes your requirements enforceable.

Episode 5

The annual questionnaire describes a vendor who no longer exists. Monitor continuously, and see the concentration a per vendor view hides.

Episode 6

You must be able to leave any vendor and keep running. Test the exit, the continuity and the breach response before you need them.

Frequently asked

What does RBI require in a vendor exit strategy?+

The 2025 Outsourcing Directions require a clear exit strategy that ensures business continuity during and after exit, plans for different exit and termination scenarios with a minimum execution period, identified alternative arrangements including a different provider or bringing the service in house, and contractual clauses for safe return or destruction of data, hardware and records.

What is substitutability in outsourcing?+

It is whether you can actually replace a vendor, not just name an alternative. RBI requires you to assess the availability of alternative providers or in house delivery, including the cost, time and resources involved. Concentration undermines substitutability when the alternatives all share the same underlying dependency, such as one cloud provider.

Does RBI require vendor business continuity plans to be tested?+

Yes. The Directions require the service provider to periodically test its business continuity and recovery plan, and allow the regulated entity to conduct joint testing and recovery exercises with the vendor. A plan that is never tested is treated as an assumption, not a capability.

What are step in rights?+

They are the regulated entity's retained control and right to intervene to continue operations if a vendor unexpectedly terminates, becomes insolvent or is liquidated. The Directions require firms to retain enough control to keep operating through a vendor's failure.

What happens when a vendor is breached?+

The regulated entity's reporting obligations apply, on clocks that start when the vendor detects the incident. That means CERT-In within six hours, the sectoral report to RBI or SEBI, and the Data Protection Board and affected individuals under DPDP, alongside containment by cutting off vendor access and scoping the breach from your vendor register.

Why test an exit plan if it is already documented?+

Because a documented plan that has never been executed reliably contains broken assumptions that only surface under real conditions. Testing, through a tabletop or joint exercise, reveals them while they are cheap to fix rather than during an actual failure.

How Bugmetrics helps

Exit and resilience fail when they live in a binder nobody has opened. Bugmetrics keeps the readiness real.

Exit and continuity readiness tracked

See which critical vendors have a tested exit path and which have a plan on paper only.

Concentration made visible

Know when named alternatives share the same foundation and substitutability is an illusion.

Scored by exposure and ranked

Know which vendor failure you are least prepared for before it happens.

A living vendor register

When a vendor is breached, scope in minutes what data it could reach under a six hour clock.

Compliance tells you the exit plan is written. Bugmetrics tells you whether it would actually work, and which vendor is about to test it for you.

See your vendor failure readiness, vendor by vendor →

This completes the series, Third Party Risk Management for Fintech, BFSI and NBFC. Six episodes, one argument. Your vendors are your liability, and the work is making sure that when one fails, it stays the vendor's failure and not yours.

Start with your vendor exposure, ranked by real risk →

Sources, verified against primary text: the RBI (Non-Banking Financial Companies, Managing Risks in Outsourcing) Directions, 2025, including the exit strategy, business continuity and disaster recovery, and step in rights provisions, with equivalent provisions in the parallel Commercial Banks, Small Finance Banks, Payments Banks and AIFI Directions; the RBI (Outsourcing of Information Technology Services) Directions, 2023; SEBI CSCRF (August 2024, as amended); and the DPDP Act, 2023 and DPDP Rules, 2025. Applicability varies by entity class. General information only, not legal advice.

See your vendor failure readiness

Exit paths, continuity, and which vendor you are least prepared to lose, before the crisis opens the binder.

Book a demo

Or explore Bugmetrics for Fintech & BFSI

Keep reading

TPRM · Episode 5 · 22 min

Continuous Monitoring and Concentration Risk

TPRM · Episode 4 · 23 min

The Contract Is the Control

TPRM · Episode 1 · 22 min

Why Your Vendors Are Now Your Liability