The short answer: for an Indian bank, NBFC or broker, third party risk management is no longer a procurement formality. Four regulatory regimes now converge on a single principle. You can outsource the activity, but you cannot outsource the accountability.
See every vendor scored, ranked by real exposure →
The 3 a.m. call that is not your incident, and is entirely your problem
Your KYC vendor gets breached. Not you. Their systems, their misconfiguration, their compromised credential. Under every regulation that governs your business, the breach is now yours to report, yours to answer for, and yours to pay for.
The KYC vendor is breached. Their misconfiguration. Their credential. Their database.
PAN, Aadhaar linked identity, selfies collected on your behalf. Now on a forum.
You report it. You answer for it. You pay for it. Under every regime that binds you.
For years, outsourcing was treated as a way to move both work and risk off your books. That assumption is now explicitly, repeatedly, and expensively wrong.
The one sentence every regulator now agrees on
Read the RBI Master Directions, the 2025 Outsourcing Directions, SEBI's CSCRF and the DPDP framework side by side and a single sentence appears in all of them:
Outsourcing does not diminish the obligations of the regulated entity.
Fully responsible for CIA of customer data at service providers
Solely responsible for vendor compliance and tool output
Fiduciary accountable even when a Processor handles the data
Same idea, three times. The activity is delegable. The liability is not.
The regimes, in one frame
Click each instrument. You have to satisfy all of them at once, and they overlap heavily.
RBI (Outsourcing of IT Services) Master Direction, 2023
RBI/2023-24/102Scheduled Commercial Banks (ex RRBs), certain co-operative banks, CICs, NBFC-Middle Layer and above, AIFIs
Board approved outsourcing policy, risk based due diligence, material outsourcing classification, contractual audit rights, continuous monitoring, exit strategy, 6 hour incident reporting flowdown
If you are a mid sized NBFC with a broking arm, you sit inside several of these at once. They are one vendor risk programme viewed through multiple regulatory lenses.
The deadline you may have already missed
The RBI IT Outsourcing Master Direction set two separate legacy deadlines. Both are now behind us. DPDP 2027 is not a substitute runway.
New outsourcing agreements must comply from signing.
Agreements due for renewal before 1 Oct 2023 had to comply.
Managing Risks in Outsourcing Directions effective immediately.
Final transition for remaining legacy IT outsourcing contracts.
Processor contracts, erasure cascade, Fiduciary accountability fully live.
If an outsourcing contract has not been re-papered for audit rights, incident timelines, subcontracting controls, data ownership and enforceable exit, you are already non-compliant. A supervisory inspection can say so today.
What "your vendor is your liability" actually means
The sharpest operational trap: the six hour clock starts when your vendor detects, not when you do. Click each step.
The six hour clock starts here, not when you find out.
You own the data, wherever it sits
RBI is explicit that the regulated entity remains responsible for the confidentiality, integrity and availability of customer data even when that data is captured, processed or stored by a service provider. There is no version of "the vendor had it, so it was the vendor's problem." The moment a customer's data exists inside your vendor's systems, its protection is still your regulatory duty.
The 6 hour clock runs through your vendor
Under the RBI IT outsourcing rules, a cyber incident at your service provider must be reported by the service provider to you without undue delay, so that you can report it to RBI within six hours of the vendor detecting it. The six hour clock does not start when you find out. It starts when your vendor finds out. If your vendor sits on an incident for four hours before telling you, you have two hours left on a clock you did not know was running.
Your vendor's subcontractor is still your exposure
RBI requires that contractual liability for the performance and practices of a service provider's subcontractors rests with the primary service provider, and that your oversight extends down the supply chain. A subcontractor, for these purposes, is one providing material or significant IT services specific to your arrangement. The chain does not end at the company you signed with.
A vendor breach is your breach to notify
Across RBI, SEBI and DPDP, a security incident or data breach at a processor becomes the regulated entity's obligation to report, to the regulator and, under DPDP, to affected individuals. The vendor's incident becomes your filing, on your clock, in your name.
What you are not allowed to outsource at all
Some functions cannot be outsourced, no matter how good the vendor. The test is not who owns the software. It is who is actually exercising the judgement.
- Technology that supports a lending decision
- Tooling for compliance monitoring
- KYC capture and verification infrastructure
- Internal audit and compliance function
- Decision making / loan sanctioning
- KYC approval (the judgement itself)
The DPDP overlay almost nobody connects
Covered in depth in our DPDP series. Every vendor that touches personal data on your behalf is a Data Processor.
A processor can only be engaged under a valid contract
The lawful basis for a processor handling your customers' data is the contract between you and them. No contract, or a contract without the right data protection terms, and the processing itself is on shaky ground.
Fiduciary versus Processor must be defined
In a co-lending or LSP chain, a single borrower's data passes through several hands. DPDP does not automatically decide who is the accountable Data Fiduciary and who is merely a Processor. Your contracts have to allocate it.
Erasure has to cascade
When a customer withdraws consent or a retention period expires, your obligation to erase extends to data held by processors on your behalf. If your vendor cannot delete on instruction and produce evidence of it, you cannot prove erasure, and unprovable erasure is treated as no erasure.
Why a compliance checklist will not save you here
SOC 2 collected. Box ticked. Audit passed. Certificate describes a vendor in March, within a scope they defined.
Does not prove they are secure today. Does not prove your systems are in scope. An adversary does not care what the questionnaire said.
Compliance tells you the boxes are checked. It does not tell you which vendor is about to get you breached.
If you are the vendor, not the bank
Everything above is being applied to you. Due diligence, audit rights, one hour breach SLAs, SBOM requests, and enforceable exit terms are now a commercial gate.
The vendors who win BFSI deals answer that scrutiny with evidence in an afternoon. If you are a regulated fintech providing IT services to a bank, you sit on both sides at once.
What this series covers
Six episodes, each owning one layer of the problem.
The reckoning and the regulatory map. Outsourcing does not dilute liability.
Material versus non material outsourcing, and the fourth party problem hiding in your supply chain.
Risk based assessment across the factors RBI actually names, and why a filed certificate is not verification.
The clauses that survive an RBI inspection, from audit rights to the six hour flowdown to DPDP processor terms.
Moving beyond the annual questionnaire, and the single provider dependency that can take you down.
The enforceable exit strategy and the vendor breach runbook everyone documents and nobody rehearses.
Frequently asked
What is third party risk management in BFSI?+
It is the discipline of identifying, assessing and continuously monitoring the risk that vendors, service providers and their subcontractors introduce to a regulated financial entity. In India it is now mandated by RBI's outsourcing directions, SEBI's CSCRF and the DPDP framework, all of which hold the regulated entity accountable for its vendors.
Does outsourcing transfer liability to the vendor?+
No. This is the central principle of every applicable Indian regulation. Outsourcing does not diminish the regulated entity's obligations. You remain responsible for customer data, incident reporting and regulatory compliance even when a vendor performs the activity.
What is the RBI deadline for outsourcing compliance?+
New outsourcing agreements from 1 October 2023 had to comply from signing. Existing agreements had two deadlines: those due for renewal before 1 October 2023 by 9 April 2024, and those due for renewal after it by renewal or 10 April 2026, whichever was earlier. Both dates have passed, so legacy contracts not yet updated are already exposed.
Which vendors count as material outsourcing?+
Broadly, any vendor whose disruption or failure would significantly affect your operations, or materially affect your customers through unauthorised access, loss or theft of their information. Episode 2 covers classification in detail.
How fast must a vendor report a cyber incident?+
Fast enough for you to meet your own six hour reporting deadline to RBI, which starts when the vendor detects the incident. In practice this means contractually requiring notification within an hour or less.
Does DPDP apply to my vendors?+
Yes. Any vendor processing personal data on your behalf is a Data Processor under DPDP. You remain the accountable Data Fiduciary, must engage them under a valid contract, and must be able to cascade erasure and breach handling to them.
How Bugmetrics helps
Your single biggest vendor risk surfaces first instead of hiding in PDFs.
See what a vendor failure would cost and which fix reduces it most.
Mapped across RBI, SEBI CSCRF, DPDP, ISO 27001 and SOC 2.
No agents. Connected in minutes. Continuous, not annual.
Compliance tells you the boxes are checked. Bugmetrics tells you which vendor is about to get you breached.
See your vendor risk, ranked by real exposure →
Next: Episode 2, Building the Vendor Inventory. Material versus non material outsourcing, and the fourth party problem hiding in your supply chain.
Sources verified against primary RBI outsourcing directions (2023 and 2025), SEBI CSCRF, and the DPDP Act & Rules 2025. Applicability varies by entity class. General information only, not legal advice.