RBI outsourcing directions: a vendor-by-vendor checklist
How to translate the RBI Master Directions on IT outsourcing into criticality ratings, questionnaire depth, contractual clauses and evidence requests, one vendor at a time.
The RBI Master Directions on outsourcing of IT services rest on one principle that is not negotiable: outsourcing an activity never outsources the accountability for it. The Regulated Entity, and its board, remain responsible for the outsourced activity as if it were performed in-house. Everything else in the directions follows from that. Here is how to turn the principle into an operational, vendor-by-vendor checklist.
1. Classify every vendor by materiality
RBI expects you to distinguish material outsourcing from the rest, and to treat the two differently. In practice, materiality is a criticality rating built from a few dimensions: the operational impact if the vendor fails, the sensitivity and volume of data they touch, the regulatory exposure the relationship creates, and how hard the vendor would be to replace. Material vendors get the deepest assessments, the tightest contractual clauses and the most frequent review; non-material ones get a proportionate, lighter touch.
Write the rating and its rationale down. When an inspector asks why a given vendor was treated as material or not, the answer should already exist in the file, not be reconstructed after the fact.
2. Tie questionnaire depth to the tier
A material cloud or payments vendor should be probed for demonstrated effectiveness across access control, cryptography, data localisation, incident response and business continuity. A non-material advisory firm needs a far shorter set focused on governance and data handling. Sending everyone the same 1,900-question bank is not diligence; it is noise that buries the answers that actually matter and produces rushed, low-quality responses.
3. Get the contract clauses right
The directions expect specific rights to be written into the outsourcing agreement. A vendor questionnaire and evidence process should confirm each of these exists and is exercisable:
- Right to audit, for both the Regulated Entity and its appointed auditors, plus cooperation with pooled or shared audits where relevant.
- Regulator inspection and access rights, so RBI can access records and premises related to the outsourced activity.
- Data localisation and access, meeting the RBI storage requirements where they apply, with the ability to retrieve data on demand.
- Business continuity and a defined exit plan, covering what happens to your data and service if the vendor fails or the contract ends.
- Confidentiality, security and breach-notification obligations with defined timelines.
4. Request evidence from what the vendor claims
The efficient and defensible pattern is answer-driven evidence. A vendor that claims a control exists must substantiate it with a current, in-scope document. A 'No' is an admitted gap with nothing to prove. A certification the vendor already holds (SOC 2, ISO 27001) is requested as a report rather than re-interrogated control by control. That keeps the evidence locker focused on the controls that are genuinely in play for this specific relationship, and it keeps the vendor from drowning in irrelevant document requests.
5. Watch the fourth parties
Your vendor's vendors are your risk too. The directions expect you to understand material sub-contracting: which fourth parties the vendor relies on, what they do, and what assurance flows down to them. A questionnaire should ask for a sub-processor register and confirm that the vendor's own contracts flow down the security and audit obligations you rely on.
6. Keep the file inspection-ready
For each material vendor, an RBI inspector should be able to open one file and see the materiality rating and why, the completed assessment mapped to control references, the contractual rights in place, and current, in-scope evidence for each claimed control. If your TPRM tooling cannot produce that in a click, the directions will feel far heavier than they need to. If it can, an inspection becomes an export rather than a scramble.
See it in your own portfolio
Full question bank, both portals, and transparent launch pricing by vendor volume.
See launch pricing