All articles
ComplianceEpisode 2 of 6· 21 min read
Third Party Risk Management for Fintech, BFSI & NBFC

TPRM for BFSI, Episode 2: Building the Vendor Inventory (Material vs Non-Material, and the Fourth Party Problem)

You cannot govern a vendor you have not listed. Material versus non material, the Appendix III trap, and the fourth parties hiding inside your vendors.

AS
Ankita Sharma
Talk to an expert
¶82
Inventory mandate
RBI 2025 NBFC Directions
2
Materiality limbs
Operations or customer data
4th
Party layer
Supply chains must be listed
2 of 6
This series
TPRM for Fintech, BFSI & NBFC

The short answer: you cannot govern a vendor you have not listed, and Indian regulators now require the list. Building it means classifying every arrangement as material or non material against the actual regulatory test, tracing fourth parties including software components, and measuring how much of your operation depends on a single provider you never chose deliberately.

See every vendor and its exposure in one live inventory →

The vendor nobody remembered

An RBI inspection team asks a simple question. Show us your complete list of IT service providers, classified by materiality, with the supply chains behind them.

The compliance lead pulls up a spreadsheet. It has the obvious names. The cloud provider, the core banking vendor, the KYC platform. It does not have the quiet ones.

Shadow SaaS

Analytics tool a product manager bought on a company card. Read access to transaction data. Never on the register.

Nested API

Document verification inside the KYC platform. Three steps from any contract you signed.

OTP rail

Email delivery carrying one time passwords. Customer authentication data, absent from the spreadsheet.

Support pasteboard

Agents paste account numbers into chat. A customer data store that never made the list.

Every one of those is a place customer data lives. Not one of them is on the list. This is the quiet failure at the base of most third party risk programmes. Everything downstream depends on a complete and correctly classified inventory. In Episode 1 we established that your vendors are now your liability. This episode is about knowing who they actually are.

The inventory is no longer optional, it is a written mandate

For years the vendor list was an internal convenience. It is now a regulatory requirement, in explicit language.

The RBI (Managing Risks in Outsourcing) Directions, 2025, in the versions issued for NBFCs, commercial banks, small finance banks and AIFIs, all carry the same instruction. In the NBFC Directions it appears at paragraph 82:

An NBFC shall create an inventory of IT services outsourced to service providers, including key entities involved in their supply chains. Further, the NBFC shall map its dependency on third parties and periodically evaluate it.

Read the two things that sentence demands, because they are more than they first appear.

First

Include the supply chains

Not just the vendors you contracted with, but the key entities behind them. This is the fourth party requirement, written into law. An inventory that stops at your direct vendors is incomplete by the plain text of the Direction.

Second

Map and periodically evaluate dependency

The inventory is not a static register you file once. It is a living map of how much you rely on each third party, reviewed on a risk based cadence. A spreadsheet last updated in 2023 does not satisfy this.

Material versus non material, and why the test surprises people

Not every vendor carries the same weight. Material arrangements attract the full weight of the Directions. The definition is precise, and the word that catches teams out is or.

Material outsourcing of IT services means any service which, if disrupted or compromised, has the potential to either:

Significantly impact the regulated entity's business operations if disrupted or compromised.

Typical examples: Core banking, payments switch, primary cloud region.

Most people classify by operational criticality. Would we go down if this failed? That is limb (a). A vendor can fail that test and still be material under limb (b), purely because it touches customer data.

OTP / statement email

Looks replaceable in a day. Still material under limb (b) because it carries contact data and authentication codes.

Analytics with transaction read

Operationally minor. A compromise is a customer data event, so the arrangement is material.

Support / chat tooling

Agents paste account numbers. Customer data exposure makes it material even when uptime risk is low.

Marketing CRM

Holds the customer database. Easy to swap vendors. Still material under the data limb.

The rule of thumb: classify on operational impact and on data sensitivity, separately. If a vendor touches customer personal or financial data in a way that a breach would harm your customers, treat it as material regardless of how easily you could replace it. The regulator is protecting the customer, not just your uptime.

Getting this wrong is expensive in both directions. Under classify and an inspection finds a light touch regime on a vendor that needed the full one. Over classify everything and a small team drowns, so the genuinely critical vendors get the same shallow attention as the trivial ones.

The Appendix III trap, where misclassification cuts the other way

Appendix III of the 2023 Master Direction sets out activities that are not considered outsourcing of IT services. Two traps live here.

Assuming something is outside when it is not

Outsourcing of IT services covers infrastructure, maintenance, network and security, data centres, application development and hosting, and technology services tied to the payment system ecosystem. If a vendor does any of that on a material basis, it is in scope, whatever procurement labelled it.

Falling outside IT is not a free pass

A service that is not IT outsourcing is often still financial services outsourcing, with its own RBI regime. Marking a vendor out of scope for IT and then doing nothing else is how firms end up non compliant under a regulation they never checked.

The safe posture is three buckets. Very few vendors belong in a fourth labelled nothing applies.

Material IT outsourcing

Full weight of the IT Outsourcing Directions. Due diligence, contracts, monitoring, exit, incident flowdown.

Non material IT outsourcing

Still IT outsourcing, lighter regime, but not invisible. Keep it on the inventory and review on a risk cadence.

Financial services outsourcing

Outside IT outsourcing often means a different RBI regime applies. Not a free pass. Do not mark "nothing applies."

What the vendor register must actually carry

An inventory that lists vendor names and renewal dates is a contact list, not a risk register. Each entry needs enough to support classification, diligence, monitoring and exit.

Field
Why it is there
Legal entity and internal owner
Accountability. Every vendor needs a named owner inside your organisation.
Service description
What they actually do, in plain terms, not the contract title.
Classification
Material IT outsourcing, non material, or financial services outsourcing.
Data accessed
Personal and financial categories the vendor can reach. Drives limb (b) and DPDP processor analysis.
Storage location
Onshore or offshore, and which cloud region. Feeds localisation and cross border checks.
Fiduciary or Processor under DPDP
Who is accountable for the personal data in this relationship.
Subcontractors and supply chain
The fourth parties. Required by the 2025 Directions.
Concentration flag
Heavy dependency, or a shared underlying provider across many of your vendors.
Contract status
Whether the agreement carries the required clauses. Covered in Episode 4.
Incident notification SLA
How fast this vendor must tell you about a breach. Governs your reporting clock.
Last diligence and next review
Proof the periodic evaluation is actually happening.
Exit readiness
Whether a tested exit path exists. Covered in Episode 6.

Build the structure now, even if some columns start empty. The empty cells are themselves your risk map.

The fourth party problem, the risk you did not sign up for

You signed one contract. Your customer's Aadhaar linked identity data passes through four companies. Three of them you have never heard of.

01
You

Regulated entity. One contract signed.

02
Lending platform

Your direct vendor.

03
KYC provider

Subcontractor you may never have assessed.

04
Doc verify + face match

Two more links. Aadhaar linked data still yours to protect.

These are your fourth parties. A breach three links down the chain is still a breach of your customer's data, still your filing, still your liability. The chain does not dilute responsibility. It hides it.

Prior approval for subcontracting

A service provider may not subcontract a material outsourced activity without your prior approval. Quiet fourth parties are no longer allowed.

Liability stays with the principal

Obligations must flow down the chain, and the primary service provider remains fully liable for acts and omissions of its subcontractors.

Identify the material links

Require each provider to list subcontractors and functions, then assess materiality with them. Capture the material ones in your inventory.

The software fourth party, and why the SBOM exists

When a vendor ships you software, that software is built from components. Open source libraries, third party modules, dependencies pulled in by other dependencies. When a vulnerability lands, the question is simple. Are we running the affected component, and where?

That ingredients list is the software bill of materials, or SBOM. SEBI has made this a requirement under CSCRF for critical and core systems.

At procurement

Obtain an SBOM for new critical and core software before you buy.

For existing systems

Generate SBOMs for critical systems within the CSCRF timeline. For many SEBI REs that window has already run.

On every change

Update the SBOM when a patch, upgrade or new dependency lands.

The international minimum elements for an SBOM, originally set out by the US NTIA and refreshed in 2026 by CISA with international partners, list supplier, component name and version, unique identifiers, dependency relationships, and author and timestamp. CERT-In is among the agencies associated with that guidance. The SBOM is becoming the standard way to see the software supply chain, and BFSI is early in the queue to need it.

A complete vendor inventory now has two layers. The companies in your supply chain, and the software components inside the products they give you. Both are fourth party risk. Both belong in the map.

Concentration risk, the dependency the inventory reveals

Build the inventory properly and it will show you something individual vendor assessments never could. How much of your operation rests on a single point. The 2025 Directions make concentration an explicit due diligence factor.

Single vendor concentration

One provider running so many critical functions that its failure would cripple you. Sorting the inventory by owner or function surfaces it immediately.

Systemic fourth party concentration

Fraud, KYC and analytics look independent until all three run on the same cloud region. Only a supply chain aware inventory shows the shared failure point.

Why a spreadsheet inventory is already out of date

A vendor inventory in a spreadsheet is accurate on the day it is finished and decaying every day after. New vendors, quiet subcontractors, shadow SaaS, region changes. None of them show up in a static file until the week before an audit.

The 2025 Directions do not ask for a snapshot. They ask you to map your dependency and periodically evaluate it. That is a description of a live system, not a document.

This is the gap Bugmetrics is built to close. The vendor inventory is assembled from the tools you already run and kept current continuously. Every vendor is scored on exposure, ranked so your biggest risk surfaces first, and the supply chain and data access behind each one is part of the picture.

If you are the vendor, not the bank

If you sell into banks, NBFCs or brokers, the inventory obligation lands on you from the other side, and it is getting more demanding.

Your BFSI customers will ask for your subcontractors and what each one does, where data and infrastructure sit, and increasingly your SBOM. If they cannot get a clear answer, the safe regulatory choice is to treat opacity as risk, and the safest choice of all is not to use you. Knowing your own fourth parties is now part of being sellable.

Frequently asked

What is a vendor inventory in third party risk management?+

It is a complete, classified register of every third party that provides services to a regulated entity, including the supply chains behind those vendors. Under the RBI 2025 Outsourcing Directions it is a mandatory control, and it must map the entity's dependency on third parties and be evaluated periodically.

What is material outsourcing under RBI rules?+

Material outsourcing of IT services is any service which, if disrupted or compromised, would either significantly impact the regulated entity's business operations, or have a material impact on its customers through unauthorised access, loss or theft of customer information. Either limb is enough to make a vendor material.

Does a vendor that only handles data but is easy to replace count as material?+

Often yes. The materiality test has two independent limbs, and the second is about customer data impact, not operational criticality. A vendor you could replace in a day can still be material because a breach of the data it holds would harm your customers.

What is fourth party risk?+

Fourth party risk is the risk introduced by your vendors' subcontractors and suppliers, the parties behind the party you contracted with. The RBI 2025 Directions require your inventory to include these supply chain entities, and hold your primary vendor liable for them.

What is an SBOM and does BFSI need one?+

A software bill of materials is an ingredients list of every component inside a piece of software, including its dependencies. SEBI's CSCRF requires regulated entities to obtain and maintain SBOMs for critical and core systems, so they can locate a vulnerable component quickly when one is disclosed.

How often should the vendor inventory be updated?+

Continuously in practice. The Directions require periodic, risk based evaluation of dependency, and vendor relationships change often enough that a static annual snapshot is out of date long before the next review.

How Bugmetrics helps

A vendor inventory is only as good as how current it is. Bugmetrics keeps it live.

A continuous vendor inventory

Assembled from the tools you already run, so new and changed vendors surface instead of waiting for a spreadsheet update.

Scored by exposure and ranked

Your single biggest risk is at the top of the list, not buried in a folder of PDFs.

Supply chain and data access

The fourth party layer the 2025 Directions require is part of the picture, not a blind spot.

Concentration made visible

Shared underlying dependencies stop hiding behind a diversified looking vendor list.

Compliance tells you the list is complete. Bugmetrics tells you which vendor on it is about to get you breached.

See your vendor inventory, live and ranked by exposure →

Next in the series, Episode 3: Due Diligence That Is Not Theatre. A filed SOC 2 certificate is not verification. How to run risk based due diligence across the factors RBI actually names, and how to tell a real assessment from a folder of PDFs. Read Episode 3 →

Sources, verified against primary text: the RBI (Non-Banking Financial Companies, Managing Risks in Outsourcing) Directions, 2025, including the inventory mandate at paragraph 82 and the due diligence factors at paragraph 30, with the equivalent provisions in the parallel Commercial Banks, Small Finance Banks and AIFI Directions; the RBI (Outsourcing of Information Technology Services) Directions, 2023 (RBI/2023-24/102), including the definition of material outsourcing and Appendix III; SEBI CSCRF (August 2024, as amended) on the SBOM requirement; and the NTIA and CISA minimum elements for a software bill of materials. Applicability varies by entity class. General information only, not legal advice.

See your vendor inventory, live and ranked

Materiality, fourth parties and concentration, kept current from the tools you already run.

Book a demo

Or explore Bugmetrics for Fintech & BFSI

Keep reading

TPRM · Episode 3 · 21 min

Due Diligence That Is Not Theatre

TPRM · Episode 1 · 22 min

Why Your Vendors Are Now Your Liability

Industry · Fintech & BFSI

Bugmetrics for Fintech & BFSI