Frameworks

RBI outsourcing directions: a vendor-by-vendor checklist

May 28, 2026 · 11 min read

How to translate the RBI Master Directions on IT outsourcing into criticality ratings, questionnaire depth, contractual clauses and evidence requests, one vendor at a time.


The RBI Master Directions on outsourcing of IT services rest on one principle that is not negotiable: outsourcing an activity never outsources the accountability for it. The Regulated Entity, and its board, remain responsible for the outsourced activity as if it were performed in-house. Everything else in the directions follows from that. Here is how to turn the principle into an operational, vendor-by-vendor checklist.

1. Classify every vendor by materiality

RBI expects you to distinguish material outsourcing from the rest, and to treat the two differently. In practice, materiality is a criticality rating built from a few dimensions: the operational impact if the vendor fails, the sensitivity and volume of data they touch, the regulatory exposure the relationship creates, and how hard the vendor would be to replace. Material vendors get the deepest assessments, the tightest contractual clauses and the most frequent review; non-material ones get a proportionate, lighter touch.

Write the rating and its rationale down. When an inspector asks why a given vendor was treated as material or not, the answer should already exist in the file, not be reconstructed after the fact.

2. Tie questionnaire depth to the tier

A material cloud or payments vendor should be probed for demonstrated effectiveness across access control, cryptography, data localisation, incident response and business continuity. A non-material advisory firm needs a far shorter set focused on governance and data handling. Sending everyone the same 1,900-question bank is not diligence; it is noise that buries the answers that actually matter and produces rushed, low-quality responses.

3. Get the contract clauses right

The directions expect specific rights to be written into the outsourcing agreement. A vendor questionnaire and evidence process should confirm each of these exists and is exercisable:

4. Request evidence from what the vendor claims

The efficient and defensible pattern is answer-driven evidence. A vendor that claims a control exists must substantiate it with a current, in-scope document. A 'No' is an admitted gap with nothing to prove. A certification the vendor already holds (SOC 2, ISO 27001) is requested as a report rather than re-interrogated control by control. That keeps the evidence locker focused on the controls that are genuinely in play for this specific relationship, and it keeps the vendor from drowning in irrelevant document requests.

5. Watch the fourth parties

Your vendor's vendors are your risk too. The directions expect you to understand material sub-contracting: which fourth parties the vendor relies on, what they do, and what assurance flows down to them. A questionnaire should ask for a sub-processor register and confirm that the vendor's own contracts flow down the security and audit obligations you rely on.

6. Keep the file inspection-ready

For each material vendor, an RBI inspector should be able to open one file and see the materiality rating and why, the completed assessment mapped to control references, the contractual rights in place, and current, in-scope evidence for each claimed control. If your TPRM tooling cannot produce that in a click, the directions will feel far heavier than they need to. If it can, an inspection becomes an export rather than a scramble.

See it in your own portfolio

Full question bank, both portals, and transparent launch pricing by vendor volume.

See launch pricing

Keep reading

Frameworks

SEBI CSCRF, explained for vendor risk teams

The Cybersecurity and Cyber Resilience Framework changed what SEBI-regulated entities must prove about their t

Fundamentals

What is third-party risk management? A 2026 primer

Inherent risk, control maturity, residual risk: the three numbers every TPRM program runs on, why the order ma

Product

Answer once, satisfy many: how control auto-mapping works

Inside the engine that maps one vendor answer to controls across 11 frameworks, why confidence matters more th