Skip to main content

Shieldrisk AI

RBI, SEBI, and IRDAI Are Raising the Bar - Is Your Vendor Risk Program Ready

RBI, SEBI, and IRDAI Are Raising the Bar: Is Your Vendor Risk Program Ready

For India’s regulated financial and insurance sectors, vendor risk has moved from a back-office concern to a board-level supervisory expectation. The Reserve Bank of India, the Securities and Exchange Board of India, and the Insurance Regulatory and Development Authority of India have each, within the space of two years, issued frameworks that sharpen what regulated entities must do about the third parties they depend on.

The message running through all three is consistent and pointed: you may outsource the work, but you cannot outsource the accountability. A vendor’s security gap is your compliance finding. For any institution still running vendor risk as a periodic, paperwork-driven exercise, the question is no longer whether the bar has risen—it is whether your program can clear it.

A Common Direction Across Three Regulators

Although each regulator governs a different sector, their expectations have converged. All three now require a structured governance framework for third-party arrangements, genuine due diligence proportionate to how critical a vendor is, contractual security obligations, and—most significantly—ongoing monitoring rather than a one-time assessment at onboarding.

This convergence matters because it signals where supervision is heading. The annual sign-off, long treated as sufficient, is being replaced by an expectation of continuous oversight that an institution must be able to evidence at any time, not reconstruct in the weeks before an audit.

RBI: Accountability Cannot Be Outsourced

The RBI’s Master Direction on Outsourcing of Information Technology Services, issued in April 2023 and effective from October 2023, applies to banks, NBFCs, and other regulated entities. It requires a comprehensive risk management framework covering the identification, measurement, mitigation, management, and reporting of risks arising from IT outsourcing arrangements.

Its governing principle is unambiguous: a regulated entity’s liability to its customers is not diminished by outsourcing, nor is the RBI’s ability to supervise impeded by it. In other words, when a service provider fails, the regulated entity answers for it. The Direction expects due diligence before engagement and continuous oversight throughout the relationship—not a single check at the start.

SEBI CSCRF: You Are Solely Responsible for Your Vendors

In August 2024, SEBI issued the Cybersecurity and Cyber Resilience Framework (CSCRF), consolidating its previous cybersecurity circulars into a single directive spanning market infrastructure institutions, brokers, depository participants, mutual funds, and other registered entities. On vendor management, the CSCRF is especially direct: regulated entities are solely responsible for ensuring their third-party vendors meet the framework’s requirements.

That word—solely—removes the comfortable ambiguity many programs relied on. A vendor’s compliance gap becomes the regulated entity’s audit finding, and the regulator will not distinguish between the two. The framework also sets concrete expectations, such as requiring any cloud service provider hosting critical systems or sensitive data to be ISO 27001 certified, and demanding that cybersecurity requirements be assessed, monitored, and enforced across vendors and outsourced services.

IRDAI: Extending Security Obligations to Every Intermediary

IRDAI’s Information and Cyber Security Guidelines, 2023, announced in April 2023, extend cybersecurity obligations across the insurance ecosystem—insurers, brokers, corporate agents, web aggregators, TPAs, and more. Insurers must ensure that their contracted intermediaries and vendors comply with the guidelines, supported by documented security assessments, contractual security requirements, and ongoing monitoring.

The guidelines also expect organizational accountability, including C-suite ownership of information and cybersecurity, regular security audits, and active control over third-party contractors. As with RBI and SEBI, the throughline is that the insurer remains answerable for the security posture of everyone it relies on.

What Audit-Ready Looks Like Now

Meeting these expectations consistently calls for a program with a few characteristics in common across all three regimes:
1. A complete, risk-tiered vendor inventory, so the depth of due diligence matches each vendor’s criticality.
2. Continuous monitoring of vendor security posture, not a single annual questionnaire, with alerts when a vendor’s exposure changes.
3. Mapped, retrievable evidence—assessments, contracts, monitoring records, and remediation trails—aligned to the specific clauses each regulator examines.
4. Clear governance and accountability, including documented ownership and reporting lines that satisfy supervisory scrutiny.

Built this way, audit readiness stops being a fire drill. The evidence a regulator asks for already exists, current and organized, because the program produces it continuously rather than assembling it under deadline.

Conclusion

RBI, SEBI, and IRDAI have, in close succession, redefined what adequate vendor risk management looks like for India’s financial and insurance institutions. The common demand is continuous oversight backed by retrievable evidence, anchored by the principle that accountability stays with the regulated entity no matter how much work is outsourced. Programs designed for an annual checkbox will struggle here. Programs designed to monitor, evidence, and govern continuously are the ones that will pass.

How ShieldRisk Can Help

Shieldbyte Infosec built ShieldRisk to close exactly this gap. ShieldRisk combines AI-driven vendor risk assessments, continuous external attack surface monitoring, and built-in mapping to RBI, SEBI CSCRF, IRDAI, ISO 27001, and DPDPA requirements—so your team moves from periodic, questionnaire-based checks to a living, evidence-backed view of every vendor. If you want to see where your third-party risk really sits today, we would be glad to walk you through it.