Skip to content

Third-party risk

Third-party risk management for Indian banks and NBFCs: what RBI's outsourcing directions require

Aakash ChaudharyLast updated 9 October 20269 min read

Since 28 November 2025, RBI's outsourcing rules sit in entity-wise directions, such as the Commercial Banks and NBFC Managing Risks in Outsourcing Directions, 2025, replacing the 2023 IT outsourcing Master Direction. They require a Board-approved policy, due diligence, a materiality assessment, RBI inspection rights in the contract, tested business continuity, an exit strategy and a central record of material arrangements.

Which RBI directions govern outsourcing now?

Until late 2025, outsourcing rules were spread across several instruments. Banks followed the Guidelines on Managing Risks and Code of Conduct in Outsourcing of Financial Services, first issued in November 2006 and amended many times. IT outsourcing was governed by the Master Direction on Outsourcing of Information Technology Services of 10 April 2023, which applied from 1 October 2023 to banks, NBFCs in the Middle Layer and above, larger urban co-operative banks, credit information companies and the all-India financial institutions.

Many guides also cite a 2023 "Master Direction on Managing Risks and Code of Conduct in Outsourcing of Financial Services". That was a draft. RBI released it for comment on 26 October 2023, with comments due by 28 November 2023, and it was never issued as a final direction in that form.

On 28 November 2025 RBI issued 244 consolidated Master Directions and, by circular DOR.RRC.REC.302/33-01-010/2025-26, withdrew 9,445 older circulars. The withdrawal list includes both the 10 April 2023 IT outsourcing Master Direction and the 2006 bank outsourcing guidelines. Outsourcing is now covered by a separate direction for each category of regulated entity, for example the Reserve Bank of India (Commercial Banks – Managing Risks in Outsourcing) Directions, 2025 and the equivalent NBFC Directions, 2025. Each has one chapter on outsourcing of financial services and another on IT services. Actions taken under the withdrawn instruments remain governed by them.

Paragraph numbers in this article are from the Commercial Banks directions. The NBFC directions follow the same structure with different numbering, and other entity types, such as small finance banks or payments banks, should read the version issued for their own licence.

What counts as material outsourcing?

For financial services, paragraph 14 defines material outsourcing as arrangements which, if disrupted, have the potential to significantly impact the bank's business operations, reputation or profitability. Materiality is judged on five criteria: how important the activity is, the potential impact on earnings, solvency, liquidity, funding, capital and risk profile, the impact on reputation and strategy if the provider fails, the cost as a share of total operating costs, and the aggregate exposure to that provider where several functions go to it.

For IT services, paragraph 53(2) uses a two-limb test: disruption or compromise could significantly impact business operations, or unauthorised access, loss or theft of customer information could have a material impact on customers. Paragraph 53(3) then lists vendors that are not "service providers" for the IT chapter, including business correspondents, authorised payment system operators, telecom providers of leased lines, independent auditors and certain FinTech firms providing data retrieval, verification, digital document execution or call-centre services. Co-branding FinTech partnerships are dealt with under the financial-services chapter instead.

What can a bank or NBFC not outsource?

Paragraph 15 bars outsourcing of core management functions, including internal audit, the compliance function, and decision-making such as determining KYC compliance for opening deposit accounts, sanctioning loans (including retail loans) and managing the investment portfolio. The NBFC directions carry the same prohibition.

No prior RBI approval is needed to outsource financial services (paragraph 16), but outsourcing does not reduce the entity's obligations. Under paragraph 17 the bank is responsible for its service providers' actions, expressly including direct sales agents, direct marketing agents and recovery agents. Paragraph 18(vi) adds that a service provider that is not a subsidiary must not be owned or controlled by a director, officer or employee of the bank or their relatives. For IT services, paragraph 54 extends the bar to key managerial personnel and the approver of the arrangement, with an exception only by Board approval, followed by disclosure and monitoring.

What does the Board have to approve and review?

The Board, or a Board committee with delegated powers, approves the framework for evaluating risk and materiality, sets approval authorities, decides which material activities are outsourced, and reviews records of all material outsourcing every half-year (paragraph 12). It must also ensure an Annual Compliance Certificate is sent to RBI's Department of Supervision, covering the outsourcing contracts, the audit periodicity, major audit findings and action taken. NBFCs may delegate the half-yearly review only to the Risk Management Committee.

Two Board-approved policies are required. The outsourcing policy (paragraph 20) sets selection criteria, materiality parameters, delegation of authority and monitoring. The IT outsourcing policy (paragraph 57) adds roles of the Board, senior management and IT function, disaster recovery and business continuity, and termination and exit strategies. NBFCs in the Base Layer are outside the IT chapter and the IT-specific Board provisions; NBFCs in the Middle Layer and above are covered by all of it.

What must due diligence cover?

Paragraphs 29 and 30 require due diligence both when entering and when renewing an arrangement. It covers qualitative, quantitative, financial, operational, legal and reputational factors, concentration risk, past experience, financial soundness under adverse conditions, compliance, complaints and litigation, how the provider vets its own staff and sub-contractors, security and internal controls, business continuity, and the political and legal environment of the provider's jurisdiction. Paragraph 31 asks for independent reviews and market feedback where possible.

For IT services, paragraph 66 adds technology and infrastructure stability, data backup and disaster recovery, conflicts of interest, the ability to segregate the bank's data, cyber security risk assessment, and the ability to enforce the agreement. Paragraph 67 permits a risk-based approach. After onboarding, the provider's financial and operational condition is reviewed at least annually for financial services (paragraph 38), and at a risk-based periodicity for IT services (paragraph 75).

How should concentration risk be assessed?

Concentration appears three times. Paragraph 22(x) lists concentration and systemic risk among the risks to evaluate before outsourcing. Paragraph 30(ii) makes undue concentration part of due diligence. Paragraph 62 requires the bank to assess both multiple arrangements with the same provider and the outsourcing of critical or material functions to a limited number of providers.

That cannot be done from a list of contracts. Paragraph 77 requires an inventory of outsourced IT services that includes key entities in the providers' supply chains, and a map of the bank's dependency on third parties. In practice this means recording sub-contractors and hosting providers against each vendor, so that two apparently separate vendors running on the same cloud region show up as one dependency. Paragraph 72 allows pooled audits where several regulated entities use the same provider, and paragraph 74 allows reliance on recognised third-party certifications, without shifting responsibility away from the bank.

What must the outsourcing agreement contain?

Paragraph 34 lists the core terms for financial-services agreements, and paragraph 69 adds terms for IT services. Existing IT outsourcing agreements had to comply on renewal or by 10 April 2026, whichever was earlier; new ones must comply from signature (paragraph 2). The terms include:

  • Service and performance standards, and the bank's access to all books, records and information relevant to the outsourced activity.
  • The bank's prior approval for any sub-contractor (paragraphs 4(2) and 34(iv)), and for IT services, the provider's contractual liability for its sub-contractors' performance and risk practices (paragraph 69(xiii)).
  • The bank's right to audit the provider, by internal or external auditors, and to obtain audit reports (paragraph 34(vii)).
  • RBI's right to access the bank's records held by the provider and to inspect the provider (paragraphs 34(viii) and (ix)); for IT services, inspection extends to sub-contractors and to the bank's IT infrastructure, applications and data (paragraph 69(xii)).
  • Confidentiality controls, the provider's liability for breaches, and confidentiality that survives termination (paragraphs 34(v) and (xi)).
  • A termination clause with a minimum period for executing termination (paragraph 34(x)), and for IT services, the right to transfer the arrangement in an orderly way to another provider (paragraph 69(xv)).
  • For IT services: storage of data only in India where extant regulatory requirements so provide (paragraph 69(vi)), SLAs, reportable adverse events, and reporting of cyber incidents fast enough that the bank can report to RBI within six hours of the provider detecting them (paragraph 56).

What do business continuity and exit require?

Paragraph 40 requires the provider to document, maintain and test business continuity and recovery procedures, with the option of joint testing. Paragraph 41 asks the bank to plan for alternative providers or bringing the activity back in-house, including the cost and time involved. Paragraph 42 requires the provider to be able to isolate the bank's information and assets so that they can be removed, deleted or destroyed on termination.

For IT services, the policy must contain a clear exit strategy for business continuity during and after exit (paragraph 79), with plans for different exit scenarios and a minimum period to execute them (paragraph 80). Agreements must provide for safe removal or destruction of data, hardware and records, and must prohibit the provider from erasing or altering data during the transition unless the regulator or the bank says otherwise (paragraph 82). An exit plan that has never been walked through with the provider is a document, not a plan.

How should a vendor register be built to satisfy these directions?

The directions require a central record of material financial-services outsourcing, updated promptly and reviewed by the Board half-yearly (paragraph 36), and a central database of all IT outsourcing arrangements accessible to the Board, senior management, auditors and supervisors (paragraph 59(2)). A register that serves both needs one row per arrangement, not per vendor, with at least:

  • The activity, whether it is financial services or IT services, and the regulated entity in the group that contracted it.
  • The materiality assessment against the five paragraph 14 criteria or the paragraph 53(2) test, with its date, the approver and the next re-assessment date.
  • Due-diligence date and outcome, the next annual or risk-based review, and the latest audit or certification relied on.
  • Sub-contractors and key supply-chain entities, with the bank's consent recorded for each, and the hosting location of the bank's data.
  • A clause checklist against paragraphs 34 and 69, with any missing or qualified term flagged, such as an inspection right made subject to the provider's consent.
  • Business continuity test dates, the exit plan and its minimum execution period, and the conflict-of-interest declaration under paragraphs 18(vi) and 54.
  • Board review dates and the evidence used for the Annual Compliance Certificate.

Where does IntelloVendor fit?

IntelloVendor, IntelloSync's vendor management product, keeps this as a working record rather than a spreadsheet. It includes a materiality rubric that tiers suppliers, an RBI material-outsourcing assessment template that includes the inspection-rights test, and a clause playbook for RBI outsourcing terms that treats inspection language conditioned on the provider's consent as a failure rather than a pass. A sub-processor register feeds a concentration report showing providers shared across vendors, and lists material vendors with no sub-processor declaration separately, because an empty register is not evidence of no dependency.

The due-diligence report brings together materiality, clause coverage, sub-processors and the approval trail for each supplier, and access can be scoped by department so that one business unit does not see another's suppliers. It supports your compliance programme; the interpretation of the directions remains with your compliance and legal teams.

Read from rbi.org.in on 9 October 2026. We found no amendment to the 2025 outsourcing directions after their issue; RBI amends consolidated directions in place, so check the current text on rbi.org.in before relying on a paragraph number.

Aakash Chaudhary is the founder and CEO of IntelloSync, which builds IntelloVendor, a vendor management and supplier risk product used for outsourcing registers. This article summarises the directions as published by the Reserve Bank of India and is not legal advice. The views expressed are his own.

FAQ

Frequently asked questions

Is RBI's 2023 IT outsourcing Master Direction still in force?

No. The Master Direction on Outsourcing of Information Technology Services of 10 April 2023 was among the 9,445 circulars withdrawn by RBI on 28 November 2025. Its content now sits in entity-wise directions, such as the Commercial Banks and NBFC Managing Risks in Outsourcing Directions, 2025. Actions taken under the old direction remain governed by it.

Was the 2023 Master Direction on Managing Risks and Code of Conduct in Outsourcing of Financial Services finalised?

No. RBI released it as a draft on 26 October 2023 for comments until 28 November 2023. The operative rules for outsourcing of financial services are now in the entity-wise Managing Risks in Outsourcing Directions issued on 28 November 2025.

Does a bank or NBFC need RBI approval to outsource?

Not for outsourcing financial services: paragraph 16 of both the Commercial Banks and NBFC directions says prior RBI approval is not required. The arrangement remains subject to RBI supervision, and core management functions such as internal audit, compliance and loan sanction cannot be outsourced at all.

How often must the Board review material outsourcing?

Half-yearly. Paragraph 12 makes the Board, or a committee with delegated powers, responsible for reviewing records of all material outsourcing every half-year, and paragraph 36 requires the central record to be placed before it. NBFCs may delegate this review only to the Risk Management Committee.

Do the IT outsourcing provisions apply to every NBFC?

No. Under paragraph 3(2) of the NBFC directions, Base Layer NBFCs are outside Chapter IV on IT outsourcing and the IT-specific Board provisions, while the financial-services provisions still apply to them. NBFCs in the Middle Layer and above are covered by the directions in full.

Must an IT vendor store the bank's data in India?

The IT outsourcing agreement must provide for storage of data only in India "as applicable" under extant regulatory requirements (paragraph 69(vi) of the Commercial Banks directions). Whether a localisation rule applies depends on the data and the instruction that governs it, so record the basis for each arrangement.

See your contracts run themselves.

A 30-minute walkthrough with our team, on your use cases — then a 30-day free trial on every product.

View pricing