The short answer: you cannot govern a vendor you have not listed, and Indian regulators now require the list. Building it means classifying every arrangement as material or non material against the actual regulatory test, tracing fourth parties including software components, and measuring how much of your operation depends on a single provider you never chose deliberately.
See every vendor and its exposure in one live inventory →
The vendor nobody remembered
An RBI inspection team asks a simple question. Show us your complete list of IT service providers, classified by materiality, with the supply chains behind them.
The compliance lead pulls up a spreadsheet. It has the obvious names. The cloud provider, the core banking vendor, the KYC platform. It does not have the quiet ones.
Analytics tool a product manager bought on a company card. Read access to transaction data. Never on the register.
Document verification inside the KYC platform. Three steps from any contract you signed.
Email delivery carrying one time passwords. Customer authentication data, absent from the spreadsheet.
Agents paste account numbers into chat. A customer data store that never made the list.
Every one of those is a place customer data lives. Not one of them is on the list. This is the quiet failure at the base of most third party risk programmes. Everything downstream depends on a complete and correctly classified inventory. In Episode 1 we established that your vendors are now your liability. This episode is about knowing who they actually are.
The inventory is no longer optional, it is a written mandate
For years the vendor list was an internal convenience. It is now a regulatory requirement, in explicit language.
The RBI (Managing Risks in Outsourcing) Directions, 2025, in the versions issued for NBFCs, commercial banks, small finance banks and AIFIs, all carry the same instruction. In the NBFC Directions it appears at paragraph 82:
An NBFC shall create an inventory of IT services outsourced to service providers, including key entities involved in their supply chains. Further, the NBFC shall map its dependency on third parties and periodically evaluate it.
Read the two things that sentence demands, because they are more than they first appear.
Include the supply chains
Not just the vendors you contracted with, but the key entities behind them. This is the fourth party requirement, written into law. An inventory that stops at your direct vendors is incomplete by the plain text of the Direction.
Map and periodically evaluate dependency
The inventory is not a static register you file once. It is a living map of how much you rely on each third party, reviewed on a risk based cadence. A spreadsheet last updated in 2023 does not satisfy this.
Material versus non material, and why the test surprises people
Not every vendor carries the same weight. Material arrangements attract the full weight of the Directions. The definition is precise, and the word that catches teams out is or.
Material outsourcing of IT services means any service which, if disrupted or compromised, has the potential to either:
Significantly impact the regulated entity's business operations if disrupted or compromised.
Typical examples: Core banking, payments switch, primary cloud region.
Most people classify by operational criticality. Would we go down if this failed? That is limb (a). A vendor can fail that test and still be material under limb (b), purely because it touches customer data.
Looks replaceable in a day. Still material under limb (b) because it carries contact data and authentication codes.
Operationally minor. A compromise is a customer data event, so the arrangement is material.
Agents paste account numbers. Customer data exposure makes it material even when uptime risk is low.
Holds the customer database. Easy to swap vendors. Still material under the data limb.
The rule of thumb: classify on operational impact and on data sensitivity, separately. If a vendor touches customer personal or financial data in a way that a breach would harm your customers, treat it as material regardless of how easily you could replace it. The regulator is protecting the customer, not just your uptime.
Getting this wrong is expensive in both directions. Under classify and an inspection finds a light touch regime on a vendor that needed the full one. Over classify everything and a small team drowns, so the genuinely critical vendors get the same shallow attention as the trivial ones.
The Appendix III trap, where misclassification cuts the other way
Appendix III of the 2023 Master Direction sets out activities that are not considered outsourcing of IT services. Two traps live here.
Assuming something is outside when it is not
Outsourcing of IT services covers infrastructure, maintenance, network and security, data centres, application development and hosting, and technology services tied to the payment system ecosystem. If a vendor does any of that on a material basis, it is in scope, whatever procurement labelled it.
Falling outside IT is not a free pass
A service that is not IT outsourcing is often still financial services outsourcing, with its own RBI regime. Marking a vendor out of scope for IT and then doing nothing else is how firms end up non compliant under a regulation they never checked.
The safe posture is three buckets. Very few vendors belong in a fourth labelled nothing applies.
Full weight of the IT Outsourcing Directions. Due diligence, contracts, monitoring, exit, incident flowdown.
Still IT outsourcing, lighter regime, but not invisible. Keep it on the inventory and review on a risk cadence.
Outside IT outsourcing often means a different RBI regime applies. Not a free pass. Do not mark "nothing applies."
What the vendor register must actually carry
An inventory that lists vendor names and renewal dates is a contact list, not a risk register. Each entry needs enough to support classification, diligence, monitoring and exit.
Build the structure now, even if some columns start empty. The empty cells are themselves your risk map.
The fourth party problem, the risk you did not sign up for
You signed one contract. Your customer's Aadhaar linked identity data passes through four companies. Three of them you have never heard of.
Regulated entity. One contract signed.
Your direct vendor.
Subcontractor you may never have assessed.
Two more links. Aadhaar linked data still yours to protect.
These are your fourth parties. A breach three links down the chain is still a breach of your customer's data, still your filing, still your liability. The chain does not dilute responsibility. It hides it.
A service provider may not subcontract a material outsourced activity without your prior approval. Quiet fourth parties are no longer allowed.
Obligations must flow down the chain, and the primary service provider remains fully liable for acts and omissions of its subcontractors.
Require each provider to list subcontractors and functions, then assess materiality with them. Capture the material ones in your inventory.
The software fourth party, and why the SBOM exists
When a vendor ships you software, that software is built from components. Open source libraries, third party modules, dependencies pulled in by other dependencies. When a vulnerability lands, the question is simple. Are we running the affected component, and where?
That ingredients list is the software bill of materials, or SBOM. SEBI has made this a requirement under CSCRF for critical and core systems.
Obtain an SBOM for new critical and core software before you buy.
Generate SBOMs for critical systems within the CSCRF timeline. For many SEBI REs that window has already run.
Update the SBOM when a patch, upgrade or new dependency lands.
The international minimum elements for an SBOM, originally set out by the US NTIA and refreshed in 2026 by CISA with international partners, list supplier, component name and version, unique identifiers, dependency relationships, and author and timestamp. CERT-In is among the agencies associated with that guidance. The SBOM is becoming the standard way to see the software supply chain, and BFSI is early in the queue to need it.
A complete vendor inventory now has two layers. The companies in your supply chain, and the software components inside the products they give you. Both are fourth party risk. Both belong in the map.
Concentration risk, the dependency the inventory reveals
Build the inventory properly and it will show you something individual vendor assessments never could. How much of your operation rests on a single point. The 2025 Directions make concentration an explicit due diligence factor.
One provider running so many critical functions that its failure would cripple you. Sorting the inventory by owner or function surfaces it immediately.
Fraud, KYC and analytics look independent until all three run on the same cloud region. Only a supply chain aware inventory shows the shared failure point.
Why a spreadsheet inventory is already out of date
A vendor inventory in a spreadsheet is accurate on the day it is finished and decaying every day after. New vendors, quiet subcontractors, shadow SaaS, region changes. None of them show up in a static file until the week before an audit.
The 2025 Directions do not ask for a snapshot. They ask you to map your dependency and periodically evaluate it. That is a description of a live system, not a document.
This is the gap Bugmetrics is built to close. The vendor inventory is assembled from the tools you already run and kept current continuously. Every vendor is scored on exposure, ranked so your biggest risk surfaces first, and the supply chain and data access behind each one is part of the picture.
If you are the vendor, not the bank
If you sell into banks, NBFCs or brokers, the inventory obligation lands on you from the other side, and it is getting more demanding.
Your BFSI customers will ask for your subcontractors and what each one does, where data and infrastructure sit, and increasingly your SBOM. If they cannot get a clear answer, the safe regulatory choice is to treat opacity as risk, and the safest choice of all is not to use you. Knowing your own fourth parties is now part of being sellable.
Frequently asked
What is a vendor inventory in third party risk management?+
It is a complete, classified register of every third party that provides services to a regulated entity, including the supply chains behind those vendors. Under the RBI 2025 Outsourcing Directions it is a mandatory control, and it must map the entity's dependency on third parties and be evaluated periodically.
What is material outsourcing under RBI rules?+
Material outsourcing of IT services is any service which, if disrupted or compromised, would either significantly impact the regulated entity's business operations, or have a material impact on its customers through unauthorised access, loss or theft of customer information. Either limb is enough to make a vendor material.
Does a vendor that only handles data but is easy to replace count as material?+
Often yes. The materiality test has two independent limbs, and the second is about customer data impact, not operational criticality. A vendor you could replace in a day can still be material because a breach of the data it holds would harm your customers.
What is fourth party risk?+
Fourth party risk is the risk introduced by your vendors' subcontractors and suppliers, the parties behind the party you contracted with. The RBI 2025 Directions require your inventory to include these supply chain entities, and hold your primary vendor liable for them.
What is an SBOM and does BFSI need one?+
A software bill of materials is an ingredients list of every component inside a piece of software, including its dependencies. SEBI's CSCRF requires regulated entities to obtain and maintain SBOMs for critical and core systems, so they can locate a vulnerable component quickly when one is disclosed.
How often should the vendor inventory be updated?+
Continuously in practice. The Directions require periodic, risk based evaluation of dependency, and vendor relationships change often enough that a static annual snapshot is out of date long before the next review.
How Bugmetrics helps
A vendor inventory is only as good as how current it is. Bugmetrics keeps it live.
Assembled from the tools you already run, so new and changed vendors surface instead of waiting for a spreadsheet update.
Your single biggest risk is at the top of the list, not buried in a folder of PDFs.
The fourth party layer the 2025 Directions require is part of the picture, not a blind spot.
Shared underlying dependencies stop hiding behind a diversified looking vendor list.
Compliance tells you the list is complete. Bugmetrics tells you which vendor on it is about to get you breached.
See your vendor inventory, live and ranked by exposure →
Next in the series, Episode 3: Due Diligence That Is Not Theatre. A filed SOC 2 certificate is not verification. How to run risk based due diligence across the factors RBI actually names, and how to tell a real assessment from a folder of PDFs. Read Episode 3 →
Sources, verified against primary text: the RBI (Non-Banking Financial Companies, Managing Risks in Outsourcing) Directions, 2025, including the inventory mandate at paragraph 82 and the due diligence factors at paragraph 30, with the equivalent provisions in the parallel Commercial Banks, Small Finance Banks and AIFI Directions; the RBI (Outsourcing of Information Technology Services) Directions, 2023 (RBI/2023-24/102), including the definition of material outsourcing and Appendix III; SEBI CSCRF (August 2024, as amended) on the SBOM requirement; and the NTIA and CISA minimum elements for a software bill of materials. Applicability varies by entity class. General information only, not legal advice.