All articles
ComplianceEpisode 3 of 6· 21 min read
Third Party Risk Management for Fintech, BFSI & NBFC

TPRM for BFSI, Episode 3: Due Diligence That Is Not Theatre (Why a Filed Certificate Is Not Verification)

Collecting a vendor's SOC 2 and filing it is not due diligence. The RBI factors, the certificate gaps nobody reads, and why real assessment is continuous.

AS
Ankita Sharma
Talk to an expert
6+
RBI factors
Beyond the certificate slice
Past
SOC 2 window
History, not live posture
Carve-out
Cloud layer
Often outside the report
3 of 6
This series
TPRM for Fintech, BFSI & NBFC

The short answer:collecting a vendor's SOC 2 report and filing it in a folder is not due diligence. It is the appearance of due diligence. RBI requires ongoing assessment of whether a service provider can meet its obligations, across factors that go well beyond a certificate.

See vendor risk verified from live evidence, not filed PDFs →

The folder full of confidence

Every mature vendor management programme has the folder. One sub folder per vendor, each with a SOC 2, an ISO certificate, a signed questionnaire, maybe a penetration test summary. When an auditor asks whether you performed due diligence, you open the folder. It looks complete.

It is, for the most part, theatre. Not because the documents are fake. They are usually real. It is theatre because collecting a document that describes a vendor is not the same as verifying the vendor. A certificate tells you a vendor met a defined set of controls, over a defined past period, within a scope the vendor chose. It does not tell you the vendor is secure today, that the systems holding your data were even in scope, or that nothing has changed since the auditor left.

In Episode 2 we built the inventory. This episode is about the next question, the one the folder pretends to answer but does not. Can this vendor actually be trusted with what you are about to give it, and can you prove that on the day something goes wrong.

What RBI actually asks you to do

Start with the regulation, because it is more specific than most firms realise.

The 2025 Outsourcing Directions require a regulated entity to perform due diligence while considering or renewing an outsourcing arrangement. In the NBFC Directions it reads:

An NBFC shall perform appropriate due diligence while considering or renewing an outsourcing arrangement, to assess the capability of the service provider to comply with obligations in the outsourcing agreement on an ongoing basis.

Two words do enormous work there. Ongoing basis. The regulation is not asking whether the vendor was capable when a certificate was issued. It is asking whether the vendor can keep meeting its obligations across the life of the relationship. A filed SOC 2 from fourteen months ago answers a different, narrower, mostly historical question.

The Directions then require evaluation of qualitative, quantitative, financial, operational, legal and reputational factors, concentration risk, past experience and competence, and financial soundness under adverse conditions, alongside conflict of interest, business continuity, audit coverage, internal controls, security monitoring and data protection.

A SOC 2 report touches, at best, a slice of the operational and security factors. The regulation describes a multi dimensional assessment. The folder holds a one dimensional document. That gap is the subject of this episode.

The RBI due diligence factors, translated for BFSI

Here is the regulator's list, turned into questions a BFSI risk team can act on. Each row is a dimension the folder usually misses.

Factor
The question it forces
Qualitative and quantitative
Does the vendor have the people, processes and scale to deliver reliably, and what do uptime, incidents and SLAs actually show?
Financial soundness
Could this vendor still be operating, and honouring commitments, two years from now, including under stress?
Operational
Can it deliver to the contract standard day after day, not just on the day it was assessed?
Legal
What legal and regulatory environment does it operate in, especially if any part sits offshore?
Reputational
Would associating with this vendor, or inheriting its failures, damage your standing with customers or the regulator?
Concentration
How much do you already depend on this provider, or on the provider underneath it, and what happens if it fails?
Competence and experience
Has it demonstrably done this before, at your scale, across the full contract term?
Conflict of interest
Does it have relationships or incentives that could work against your interests?
Business continuity
Can it keep running, or recover fast, when something breaks, and has that ever been tested?
Security and data protection
Are the controls protecting your specific data real, current, and covering the systems that actually hold it?

The last row is where most programmes concentrate their effort, and where the certificate does the most damage, because it creates the illusion that the row is fully handled. It is not.

Why a certificate is not verification

A SOC 2 or ISO 27001 certificate is a useful input. A vendor that has none is a genuine red flag. The problem is treating the certificate as the answer. It has four structural limits the folder hides.

It describes the past, not the present

A SOC 2 Type 2 covers a fixed historical window that has already ended. Between that window and today the vendor could have changed architecture, lost security staff, onboarded a risky subcontractor, or suffered an incident. The certificate cannot know.

This is the Bugmetrics thesis applied to your vendors. You can collect a perfect certificate from a vendor that is about to get you breached. The certificate measures whether boxes were checked over a past window within a chosen scope. It does not measure the live exposure that determines whether your customer data walks out the door.

What real security due diligence looks like

If the certificate is an input rather than an answer, what fills the gap. Verify the things the paper cannot, against the vendor as it is now.

External attack surface

The systems and services exposed to the internet that an attacker would see today.

Incident and breach history

Disclosed and discoverable history, not only what the questionnaire admits.

Scope of assurance

Whether the product and data environment you will use is inside the report, or carved out.

Fourth party governance

Whether the vendor's own subcontractor and supply chain controls hold up.

Still true this quarter

Whether any of this is current, or only true on the day the last form was completed.

Attested

What the vendor tells you

Questionnaires and certificates. Useful, but self reported and often lagging.

Observed

What its systems show

An adversary attacks observed reality, not the questionnaire. Weight observed over attested.

SEBI's CSCRF points the same way. A regulated entity remains responsible for its vendors' compliance, and audit rights extend to material subcontractors, precisely because a vendor's attestation about its supply chain is not sufficient.

The axis everyone skips, financial and operational health

Security due diligence gets the attention. Financial and operational due diligence gets skipped, and RBI names both explicitly for a reason.

A vendor can be impeccably secure and still be a serious risk if it is quietly running out of money. If a provider holding your critical function fails financially, the security of its controls is irrelevant. You face an unplanned exit, data trapped in a failing company, and a scramble for continuity. The Directions require assessment of financial soundness under adverse conditions, and review of the financial and operational condition of material vendors at least annually.

Concentration belongs here too. A vendor that is individually sound can still represent unacceptable risk if you depend on it too heavily, or if it sits on the same underlying provider as several of your other critical vendors.

Due diligence is not a gate you pass once

The most persistent error is treating due diligence as an onboarding event. Assess, tick, sign, move on. The regulation does not permit this reading, and the word ongoing is why.

Material vendors need at least annual review, with a risk based cadence for the rest. Beyond the calendar, certain events must trigger a fresh assessment regardless of when the last one happened.

Service or architecture change

A material change in what the vendor runs or how it runs it.

Ownership change

New owners, new incentives, and often a new risk profile overnight.

Subcontracting change

Under the 2025 Directions, material subcontracting needs your approval anyway.

Significant security incident

Any serious incident can invalidate everything your last assessment concluded.

If your only signal about a vendor arrives once a year in a form the vendor fills in about itself, then for the eleven months in between you are relying on a snapshot reality has already moved past. The regulator is describing continuous oversight. A once a year PDF is not that.

Why this is a Bugmetrics problem

Continuous, evidence based due diligence is not something a small compliance team can do by hand across a full vendor portfolio. It has to be systematised.

Instead of a folder of static certificates, vendor risk is assessed from live, observed evidence and kept current. Every vendor is scored on real exposure and ranked. Certificates still have their place as inputs, but they sit alongside observed reality rather than substituting for it. One control library maps across RBI, SEBI CSCRF, DPDP, ISO 27001 and SOC 2.

Compliance tells you the vendor's boxes were checked. Bugmetrics tells you whether the vendor is about to get you breached. For a regulator that now demands ongoing capability assessment, that difference is the whole obligation.

If you are the vendor, not the bank

If you sell into banks, NBFCs or brokers, this episode is a preview of the scrutiny coming at you, and a guide to passing it faster.

Your BFSI customers are being told, in writing, that collecting your certificate is not enough. The old motion of emailing a SOC 2 and a bridge letter and considering the review closed is ending. What replaces it is a demand for current, verifiable evidence. An evidenced posture is becoming the fastest path through BFSI procurement, not a nice to have.

Frequently asked

Is collecting a SOC 2 report enough for vendor due diligence?+

No. A SOC 2 report is a useful input but not verification. It covers a past window, often carves out the vendor's own critical providers such as its cloud host, and does not by itself confirm the vendor is secure today or that the systems holding your data were in scope. RBI requires ongoing assessment of a vendor's capability across financial, operational, legal, reputational and other factors, which a certificate does not provide.

What does RBI require in vendor due diligence?+

The 2025 Outsourcing Directions require an evaluation of the service provider across qualitative, quantitative, financial, operational, legal and reputational factors, concentration risk, past experience and competence, and financial soundness under adverse conditions, performed to assess the vendor's ability to meet its obligations on an ongoing basis.

What is a SOC 2 scope carve out and why does it matter?+

It is when the auditor's scope excludes the vendor's own underlying providers. If your vendor runs on a major cloud platform and that platform is carved out, the report does not cover the infrastructure layer at all, which is often the layer where the most significant risk concentrates.

Is a bridge letter reliable assurance?+

Only to a limited degree. A bridge letter is a management representation from the vendor, not an audited document, and no auditor signs or stands behind it. It can reasonably cover a short gap, but it is not equivalent to current, independent assurance.

How often should vendor due diligence be repeated?+

Material vendors should be reviewed at least annually, with a risk based cadence for others, and reassessment should be triggered by material changes in the vendor's services, ownership or subcontracting, or by a significant security incident.

Why assess a vendor's financial health if it is secure?+

Because a financially failing vendor is an operational risk regardless of its security. If a provider running a critical function collapses, you face an unplanned exit and potential loss of access to data and service, which the security of its controls does nothing to prevent.

How Bugmetrics helps

Due diligence fails when it is a folder of documents rather than a live assessment. Bugmetrics makes it continuous.

Observed evidence, not just PDFs

Vendor risk assessed from live posture so what you know reflects the vendor as it is now.

Scored by exposure and ranked

The vendor most likely to cause a breach surfaces at the top instead of looking compliant in a folder.

Certificates as one input

Attestations sit alongside observed reality rather than substituting for it.

Continuous reassessment

The ongoing capability RBI requires is a live state, not an annual scramble.

Compliance tells you the boxes were checked. Bugmetrics tells you which vendor is about to get you breached.

See vendor due diligence run on live evidence →

Next in the series, Episode 4: The Contract Is the Control. Due diligence tells you whether to trust a vendor. The contract is how you make that trust enforceable. The clauses that survive an RBI inspection, from audit rights to incident flowdown to DPDP processor terms. Read Episode 4 →

Sources, verified against primary text: the RBI (Non-Banking Financial Companies, Managing Risks in Outsourcing) Directions, 2025, including the due diligence provisions at paragraphs 29 and 30 and the periodic review requirement, with equivalent provisions in the parallel Commercial Banks, Small Finance Banks, Payments Banks and AIFI Directions; the RBI (Outsourcing of Information Technology Services) Directions, 2023 (RBI/2023-24/102); SEBI CSCRF (August 2024, as amended) on third party accountability and material subcontractor audit rights; and the DPDP Act, 2023 and DPDP Rules, 2025 on Data Processor obligations. Descriptions of SOC 2 report structure, scope carve outs and bridge letters reflect the AICPA reporting standards and established assurance practice. Applicability varies by entity class. General information only, not legal advice.

See vendor due diligence on live evidence

Ranked exposure from observed posture, not a folder of stale certificates.

Book a demo

Or explore Bugmetrics for Fintech & BFSI

Keep reading

TPRM · Episode 4 · 23 min

The Contract Is the Control

TPRM · Episode 2 · 21 min

Building the Vendor Inventory

TPRM · Episode 1 · 22 min

Why Your Vendors Are Now Your Liability