All articles
ComplianceEpisode 1 of 6· 22 min read
Third Party Risk Management for Fintech, BFSI & NBFC

TPRM for BFSI, Episode 1: Why Your Vendors Are Now Your Liability (RBI, SEBI & DPDP in One Frame)

You can outsource the activity, not the accountability. The vendor risk reckoning for Indian financial services, mapped.

AS
Ankita Sharma
Talk to an expert
5
Instruments
RBI IT · NBFC · AIFI · SEBI · DPDP
Apr '26
Outer deadline
Already passed for legacy IT contracts
6h
Incident clock
Starts when the vendor detects
1 of 6
This series
TPRM for Fintech, BFSI & NBFC

The short answer: for an Indian bank, NBFC or broker, third party risk management is no longer a procurement formality. Four regulatory regimes now converge on a single principle. You can outsource the activity, but you cannot outsource the accountability.

See every vendor scored, ranked by real exposure →

The 3 a.m. call that is not your incident, and is entirely your problem

Your KYC vendor gets breached. Not you. Their systems, their misconfiguration, their compromised credential. Under every regulation that governs your business, the breach is now yours to report, yours to answer for, and yours to pay for.

01
Not your systems

The KYC vendor is breached. Their misconfiguration. Their credential. Their database.

02
Your customers

PAN, Aadhaar linked identity, selfies collected on your behalf. Now on a forum.

03
Your problem

You report it. You answer for it. You pay for it. Under every regime that binds you.

For years, outsourcing was treated as a way to move both work and risk off your books. That assumption is now explicitly, repeatedly, and expensively wrong.

The one sentence every regulator now agrees on

Read the RBI Master Directions, the 2025 Outsourcing Directions, SEBI's CSCRF and the DPDP framework side by side and a single sentence appears in all of them:

Outsourcing does not diminish the obligations of the regulated entity.
RBI

Fully responsible for CIA of customer data at service providers

SEBI

Solely responsible for vendor compliance and tool output

DPDP

Fiduciary accountable even when a Processor handles the data

Same idea, three times. The activity is delegable. The liability is not.

The regimes, in one frame

Click each instrument. You have to satisfy all of them at once, and they overlap heavily.

RBI (Outsourcing of IT Services) Master Direction, 2023

RBI/2023-24/102
Who it binds

Scheduled Commercial Banks (ex RRBs), certain co-operative banks, CICs, NBFC-Middle Layer and above, AIFIs

Vendor demands

Board approved outsourcing policy, risk based due diligence, material outsourcing classification, contractual audit rights, continuous monitoring, exit strategy, 6 hour incident reporting flowdown

Status · In force since 1 Oct 2023. Both legacy transition dates (9 Apr 2024 and 10 Apr 2026) have now passed

If you are a mid sized NBFC with a broking arm, you sit inside several of these at once. They are one vendor risk programme viewed through multiple regulatory lenses.

The deadline you may have already missed

The RBI IT Outsourcing Master Direction set two separate legacy deadlines. Both are now behind us. DPDP 2027 is not a substitute runway.

1 Oct 2023
IT MD in force

New outsourcing agreements must comply from signing.

9 Apr 2024
Legacy window 1

Agreements due for renewal before 1 Oct 2023 had to comply.

28 Nov 2025
NBFC Directions

Managing Risks in Outsourcing Directions effective immediately.

10 Apr 2026
Outer deadline · PASSED

Final transition for remaining legacy IT outsourcing contracts.

13 May 2027
DPDP substantive

Processor contracts, erasure cascade, Fiduciary accountability fully live.

If an outsourcing contract has not been re-papered for audit rights, incident timelines, subcontracting controls, data ownership and enforceable exit, you are already non-compliant. A supervisory inspection can say so today.

What "your vendor is your liability" actually means

The sharpest operational trap: the six hour clock starts when your vendor detects, not when you do. Click each step.

Vendor detects

The six hour clock starts here, not when you find out.

01

You own the data, wherever it sits

RBI is explicit that the regulated entity remains responsible for the confidentiality, integrity and availability of customer data even when that data is captured, processed or stored by a service provider. There is no version of "the vendor had it, so it was the vendor's problem." The moment a customer's data exists inside your vendor's systems, its protection is still your regulatory duty.

02

The 6 hour clock runs through your vendor

Under the RBI IT outsourcing rules, a cyber incident at your service provider must be reported by the service provider to you without undue delay, so that you can report it to RBI within six hours of the vendor detecting it. The six hour clock does not start when you find out. It starts when your vendor finds out. If your vendor sits on an incident for four hours before telling you, you have two hours left on a clock you did not know was running.

03

Your vendor's subcontractor is still your exposure

RBI requires that contractual liability for the performance and practices of a service provider's subcontractors rests with the primary service provider, and that your oversight extends down the supply chain. A subcontractor, for these purposes, is one providing material or significant IT services specific to your arrangement. The chain does not end at the company you signed with.

04

A vendor breach is your breach to notify

Across RBI, SEBI and DPDP, a security incident or data breach at a processor becomes the regulated entity's obligation to report, to the regulator and, under DPDP, to affected individuals. The vendor's incident becomes your filing, on your clock, in your name.

Liability follows the data chain
Your NBFC
Regulated entity
Full liability
Lending platform
Primary vendor
Material outsourcing
KYC provider
Subcontractor
Still your exposure
Doc verify API
Fourth party
Data still travels

What you are not allowed to outsource at all

Some functions cannot be outsourced, no matter how good the vendor. The test is not who owns the software. It is who is actually exercising the judgement.

Allowed
  • Technology that supports a lending decision
  • Tooling for compliance monitoring
  • KYC capture and verification infrastructure
Prohibited
  • Internal audit and compliance function
  • Decision making / loan sanctioning
  • KYC approval (the judgement itself)

The DPDP overlay almost nobody connects

Covered in depth in our DPDP series. Every vendor that touches personal data on your behalf is a Data Processor.

1

A processor can only be engaged under a valid contract

The lawful basis for a processor handling your customers' data is the contract between you and them. No contract, or a contract without the right data protection terms, and the processing itself is on shaky ground.

2

Fiduciary versus Processor must be defined

In a co-lending or LSP chain, a single borrower's data passes through several hands. DPDP does not automatically decide who is the accountable Data Fiduciary and who is merely a Processor. Your contracts have to allocate it.

3

Erasure has to cascade

When a customer withdraws consent or a retention period expires, your obligation to erase extends to data held by processors on your behalf. If your vendor cannot delete on instruction and produce evidence of it, you cannot prove erasure, and unprovable erasure is treated as no erasure.

Why a compliance checklist will not save you here

Paperwork

SOC 2 collected. Box ticked. Audit passed. Certificate describes a vendor in March, within a scope they defined.

Exposure

Does not prove they are secure today. Does not prove your systems are in scope. An adversary does not care what the questionnaire said.

Compliance tells you the boxes are checked. It does not tell you which vendor is about to get you breached.

If you are the vendor, not the bank

Everything above is being applied to you. Due diligence, audit rights, one hour breach SLAs, SBOM requests, and enforceable exit terms are now a commercial gate.

The vendors who win BFSI deals answer that scrutiny with evidence in an afternoon. If you are a regulated fintech providing IT services to a bank, you sit on both sides at once.

What this series covers

Six episodes, each owning one layer of the problem.

1
This episodeYou are here

The reckoning and the regulatory map. Outsourcing does not dilute liability.

2
Building the vendor inventory

Material versus non material outsourcing, and the fourth party problem hiding in your supply chain.

3
Due diligence that is not theatre

Risk based assessment across the factors RBI actually names, and why a filed certificate is not verification.

4
The contract is the control

The clauses that survive an RBI inspection, from audit rights to the six hour flowdown to DPDP processor terms.

5
Continuous monitoring and concentration risk

Moving beyond the annual questionnaire, and the single provider dependency that can take you down.

6
Exit, resilience and when a vendor fails

The enforceable exit strategy and the vendor breach runbook everyone documents and nobody rehearses.

Frequently asked

What is third party risk management in BFSI?+

It is the discipline of identifying, assessing and continuously monitoring the risk that vendors, service providers and their subcontractors introduce to a regulated financial entity. In India it is now mandated by RBI's outsourcing directions, SEBI's CSCRF and the DPDP framework, all of which hold the regulated entity accountable for its vendors.

Does outsourcing transfer liability to the vendor?+

No. This is the central principle of every applicable Indian regulation. Outsourcing does not diminish the regulated entity's obligations. You remain responsible for customer data, incident reporting and regulatory compliance even when a vendor performs the activity.

What is the RBI deadline for outsourcing compliance?+

New outsourcing agreements from 1 October 2023 had to comply from signing. Existing agreements had two deadlines: those due for renewal before 1 October 2023 by 9 April 2024, and those due for renewal after it by renewal or 10 April 2026, whichever was earlier. Both dates have passed, so legacy contracts not yet updated are already exposed.

Which vendors count as material outsourcing?+

Broadly, any vendor whose disruption or failure would significantly affect your operations, or materially affect your customers through unauthorised access, loss or theft of their information. Episode 2 covers classification in detail.

How fast must a vendor report a cyber incident?+

Fast enough for you to meet your own six hour reporting deadline to RBI, which starts when the vendor detects the incident. In practice this means contractually requiring notification within an hour or less.

Does DPDP apply to my vendors?+

Yes. Any vendor processing personal data on your behalf is a Data Processor under DPDP. You remain the accountable Data Fiduciary, must engage them under a valid contract, and must be able to cascade erasure and breach handling to them.

How Bugmetrics helps

Scored & ranked by exposure

Your single biggest vendor risk surfaces first instead of hiding in PDFs.

Breach likelihood modelled

See what a vendor failure would cost and which fix reduces it most.

One control library

Mapped across RBI, SEBI CSCRF, DPDP, ISO 27001 and SOC 2.

Evidence from your tools

No agents. Connected in minutes. Continuous, not annual.

Compliance tells you the boxes are checked. Bugmetrics tells you which vendor is about to get you breached.

See your vendor risk, ranked by real exposure →

Next: Episode 2, Building the Vendor Inventory. Material versus non material outsourcing, and the fourth party problem hiding in your supply chain.

Sources verified against primary RBI outsourcing directions (2023 and 2025), SEBI CSCRF, and the DPDP Act & Rules 2025. Applicability varies by entity class. General information only, not legal advice.

See every vendor scored, ranked by real exposure

Continuous vendor scoring across RBI, SEBI CSCRF and DPDP, so your biggest exposure surfaces first, not last.

Book a demo

Or explore Bugmetrics for Fintech & BFSI

Keep reading

DPDP · Episode 1 · 12 min

DPDP Rules 2025: The Dual Compliance Playbook

DPDP · Episode 2 · 14 min

Continuous data governance for BFSI

DPDP · Episode 4 · 18 min

Breach readiness & the four-clock incident runbook