Blog

The third-party risk field guide

Practical writing on vendor risk, regulatory frameworks and assessment craft, from the team building Transilience.

FrameworksFeatured · June 24, 2026 · 12 min read

SEBI CSCRF, explained for vendor risk teams

The Cybersecurity and Cyber Resilience Framework changed what SEBI-regulated entities must prove about their third parties. A function-by-function reading (Govern, Identify, Protect, Detect, Respond, Recover) and exactly what your vendor questionnaire has to cover for each.

Read the article →
CSCRF GV.RR.3
Risk assessment of outsourced activities
Met · confidence 92%
Fundamentals10 min

What is third-party risk management? A 2026 primer

Inherent risk, control maturity, residual risk: the three numbers every TPRM program runs on, why the order matters, and how regulators expect you to compute them.

Read →
Frameworks11 min

RBI outsourcing directions: a vendor-by-vendor checklist

How to translate the RBI Master Directions on IT outsourcing into criticality ratings, questionnaire depth, contractual clauses and evidence requests, one vendor at a time.

Read →
Product9 min

Answer once, satisfy many: how control auto-mapping works

Inside the engine that maps one vendor answer to controls across 11 frameworks, why confidence matters more than coverage, and how evidence is reviewed against the exact control a vendor claims.

Read →
Assessment craft8 min

Why your vendors hate your questionnaire (and how to fix it)

A 1,764-question spreadsheet is a punishment, not a control. Tailoring by criticality, one question per control theme, and optional certification short-circuits cut it to 140, with a full audit trail for every choice.

Read →
Product9 min

Letting AI review the evidence, without breaking your audit

A document review engine maps each report to the control it evidences, checks currency and scope, and extracts real findings. Here is how it works, and the lines it will not cross.

Read →
Fundamentals9 min

Residual risk is a matrix, not a feeling

Criticality times maturity, with tier shifts you can defend to a regulator. The full scoring model behind every Transilience grade, including the two clamps that make it honest.

Read →

The quarterly risk brief

Framework changes, enforcement actions and assessment technique, four emails a year, nothing else.