All articles
ComplianceEpisode 4 of 6· 23 min read
Third Party Risk Management for Fintech, BFSI & NBFC

TPRM for BFSI, Episode 4: The Contract Is the Control (The Clauses That Survive an RBI Inspection)

A standard MSA does not make a vendor relationship compliant. The clauses the RBI 2025 Directions say your agreement shall include, plus the DPDP processing terms most contracts miss.

AS
Ankita Sharma
Talk to an expert
Shall
Include language
Mandatory, not illustrative
≤1h
Incident flowdown
So you keep the 6h clock
DPA
On top of MSA
Rule 6 equivalent safeguards
4 of 6
This series
TPRM for Fintech, BFSI & NBFC

The short answer: for a regulated financial entity, the outsourcing contract is not paperwork that follows the deal. It is the control itself. The RBI 2025 Directions mandate the exact clauses your agreement must carry, and DPDP layers a data processing agreement on top.

See whether your vendor contracts actually hold up →

The agreement that governs nothing

A vendor is onboarded. An MSA is signed for commercials, pricing and SLAs. Data starts flowing. Eighteen months later something goes wrong, and the contract says nothing useful about audit access, incident timing, subcontractors or exit.

Due diligence, from Episode 3, tells you whether to trust a vendor. The contract is how you make that trust enforceable when trust runs out. A standard MSA is written to close a deal. A compliant outsourcing agreement is written for the day the relationship goes wrong.

What the contract can and cannot do

You cannot outsource your liability, and you cannot contract it away either. Under DPDP and RBI, statutory accountability stays with you. When the regulator or the customer comes, they come to you.

Bind the vendor

Create the standards, access and behaviour you need for your own obligations: the six hour clock, audit rights, RBI inspection, exit. None exist unless the contract creates them.

Recover when it fails

You still bear the statutory penalty, but indemnity and hold harmless let you pursue the vendor for losses its failure caused. Without that, you absorb everything alone.

The contract does not transfer your liability. It transfers your ability to demand, to inspect, to exit, and to recover. That is why the regulator treats specific clauses as mandatory, and why an inspection reads your contracts as evidence of control.

The clauses the Directions say your agreement shall include

The 2025 Outsourcing Directions do not suggest terms. They mandate them. Shall include leaves no room for interpretation. An agreement missing these is non compliant on its face.

Clause area
What the agreement must contain
Service standards
Defined service levels and performance standards the vendor must meet.
Confidentiality
Confidentiality of customer information, expressly surviving expiry or termination.
Your audit rights
Right to audit through internal or external auditors or agents, and to obtain related audit reports.
RBI access
RBI's right to access documents, transaction records and other information stored or processed by the vendor within a reasonable time.
RBI inspection
RBI's right to cause an inspection of the vendor, and its books and accounts.
Business continuity
Contingency and BCP provisions, and for IT, the right to require and test them.
Subcontracting control
No material subcontracting without prior approval, with flowdown and primary vendor liability for the chain.
Access to data and systems
Your access to all data, systems, documents and records held by the vendor for the service.
Termination
A termination clause and a minimum period for executing termination.
Data on exit
Safe return or destruction of data, hardware and records, digital and physical, on exit.

For AIFIs the Directions go further: audit and inspection rights extend to subcontractors, you get a contractual right to seek supply chain information, and RBI's access reaches down the chain too. Read that as the direction of travel for the whole sector.

The clauses that fail inspection most often

The list above is the baseline. In practice, four areas are where contracts are weakest and where an inspection or an incident exposes them.

Audit and inspection rights that actually work

Rights must be unconditional. Access conditioned on vendor consent, confidentiality policies, annual-only windows, or extra fees hands the vendor a veto over your regulator. If RBI cannot inspect the vendor, the vendor cannot be used.

The offshore clauses, where cross border adds a layer

If any part of the arrangement sits outside India, the Directions add specific contractual requirements. Start with parties in jurisdictions that generally uphold confidentiality. Then ensure four things.

Monitor country risk continuously

Track political, social, economic and legal conditions in the vendor's jurisdiction, with contingency and exit strategies ready.

Specify governing law clearly

The agreement must state which law governs the arrangement, with no ambiguity.

Records survive insolvency

Availability of records to you and RBI must hold even if the vendor goes into liquidation in a foreign system.

Audit rights reach offshore

You and RBI must be able to direct and conduct audit or inspection of the foreign-based vendor.

The DPDP layer, the data processing agreement your MSA is missing

Under the DPDP Act, a Data Fiduciary may engage a Data Processor only under a valid contract. A standard MSA does not satisfy this. Rule 6 requires equivalent security safeguards. Without a DPA, a vendor breach leaves you carrying full penalty exposure with no contractual recourse.

DPA clause
What it does
Purpose limitation
Process only on your instructions and only for the defined purpose, so the vendor does not drift into Fiduciary status.
Security safeguards
Maintain safeguards equivalent to yours, as Rule 6 requires.
Breach notification
Notify you of any personal data breach fast enough to meet your reporting clocks.
Data principal rights support
Cooperate with access, correction, erasure and grievance requests.
Retention and deletion
Delete or return personal data on instruction, purpose fulfilment or termination, and prove it.
Sub processing control
No onward transfer without permission and without flowdown of the same terms.
Cross border transfer
Document destination country and address consequences if the government later restricts it.
Indemnity
Allocate financial liability so you can recover losses caused by the processor's breach.

The deletion clause connects to DPDP Episode 3 on retention. Your erasure obligation cascades to processors. A vendor that cannot delete on demand and certify it makes your own erasure impossible to prove.

Data localisation and residency clauses

DPDP itself does not mandate blanket localisation, but sectoral regulators do for specific categories. RBI payment data localisation requires the entire payment data set stored only in India, with foreign-leg data repatriated within a defined window.

Where those rules apply, the contract must fix storage location, prohibit non compliant transfers, and require the residency behaviour the regulator demands. A generic cross border clause that lets the vendor store data wherever convenient is a localisation breach waiting to be signed.

Legacy contracts are the live exposure

These clauses are not a future requirement. As Episode 1 established, the transition windows have already closed. A legacy vendor contract that has never been updated is present non compliance.

Do not wait for the natural renewal cycle. Remediate now through RBI compliant addenda. Standardise regulator aligned master clauses for every new vendor. Align legal review to regulatory enforceability, not just commercial risk. The contracts you signed before the rules changed are exactly the ones an inspection will look at first.

A contract is only as strong as your ability to use it

Perfect audit rights never exercised. A one hour incident SLA with no way to know whether it is honoured. Inspection once at onboarding and never again. The contract gives you the power. Using it is a separate discipline.

This is where the contract meets continuous monitoring, and where Bugmetrics fits. Live evidence turns a contractual audit right into an ongoing view. Ranking by exposure tells you which contract to enforce this quarter. One control library maps across RBI, SEBI CSCRF, DPDP, ISO 27001 and SOC 2.

A clause you never exercise is a comfort, not a control. Episode 5 is about turning the contractual right into continuous oversight.

If you are the vendor, not the bank

Your BFSI customers are required to put these clauses in front of you. Unconditional audit and RBI inspection rights. One hour incident notification. Prior approval before material subcontracting. Confidentiality that survives termination. Clean data exit. A DPDP DPA with equivalent safeguards and indemnity. These are not aggressive demands you can negotiate away.

The vendors who close BFSI deals fast are the ones who can accept these terms without a three month legal battle, because they already operate in a way that makes the terms true.

Frequently asked

What clauses must an RBI outsourcing agreement include?+

The 2025 Outsourcing Directions mandate, among others, defined service standards, confidentiality surviving termination, your audit rights, RBI's rights to access records and to inspect the vendor, business continuity provisions, subcontracting controls with prior approval and flowdown, your access to all data and systems, a termination clause with a minimum notice period, and safe return or destruction of data on exit. The language is shall include, so these are mandatory.

Can a contract transfer my liability to the vendor?+

No. Under both the RBI framework and the DPDP Act, your regulatory liability cannot be disclaimed by contract. What the contract can do is bind the vendor to the standards you need and give you a route to recover your losses through indemnity.

How fast must a vendor notify me of a security incident?+

Fast enough for you to report to RBI within six hours of the vendor's detection. In practice this means a contractual notification SLA of about an hour or less, not a general commitment to inform you.

What is a DPDP data processing agreement and do I need one with every vendor?+

A DPA is the valid contract the DPDP Act requires before a processor can handle personal data on your behalf. Every vendor that processes personal data for you needs one. It must impose equivalent security safeguards, breach notification, deletion on instruction, sub processing controls and indemnity. A standard MSA does not meet this.

Do offshore vendors need special clauses?+

Yes. The agreement must specify governing law, ensure records remain available to you and RBI even if the vendor is liquidated, secure audit and inspection rights over the foreign vendor, and support continuous monitoring of the country risk in the vendor's jurisdiction.

Do I need to fix contracts signed before the rules changed?+

Yes, and the deadline has passed. Legacy contracts should be remediated now through compliant addenda rather than waiting for renewal, because an unremediated legacy contract is a present non compliance.

How Bugmetrics helps

A contract is only a control if you can exercise it. Bugmetrics turns contractual rights into continuous oversight.

Audit rights, actually used

Vendor posture assessed from live evidence rather than exercised once at onboarding.

Scored by exposure and ranked

Know which contract most needs enforcing this quarter.

Incident and control signals current

Verify a one hour notification SLA and safeguards clause, not just hold the paper.

Clause status tracked per vendor

Gaps in agreements surface before an inspection finds them.

Compliance tells you the contract was signed. Bugmetrics tells you whether the vendor behind it is about to get you breached.

See your vendor contracts turned into live oversight →

Next in the series, Episode 5: Continuous Monitoring and Concentration Risk. A contract gives you the right to watch a vendor. This is how you actually do it, beyond the annual questionnaire, and how you find the single provider dependency that can take you down before it does. Read Episode 5 →

Sources, verified against primary text: the RBI (Non-Banking Financial Companies, Managing Risks in Outsourcing) Directions, 2025, including the outsourcing agreement clauses, the subcontracting approval and liability provisions, the exit strategy provisions, and the offshore outsourcing requirements, with equivalent and in the AIFI Directions broader provisions; the RBI (Outsourcing of Information Technology Services) Directions, 2023 (RBI/2023-24/102); the DPDP Act, 2023 and DPDP Rules, 2025; and RBI's payment data localisation requirement. This is not a substitute for legal drafting. General information only, not legal advice.

See vendor contracts turned into live oversight

Audit rights, incident SLAs and clause gaps, exercised continuously rather than filed once.

Book a demo

Or explore Bugmetrics for Fintech & BFSI

Keep reading

TPRM · Episode 5 · 22 min

Continuous Monitoring and Concentration Risk

TPRM · Episode 3 · 21 min

Due Diligence That Is Not Theatre

TPRM · Episode 2 · 21 min

Building the Vendor Inventory