Ask a risk or compliance head at an Indian bank or NBFC how their vendor risk program actually works, and the honest answer, more often than not, still centers on a calendar: a questionnaire sent out, a certificate collected, a score assigned, and then set aside until the same time next year. For a modest, low-criticality vendor, that cadence may be defensible. For the vendors that actually matter — core banking platforms, cloud infrastructure, payment processors, AML and KYC screening providers — it is no longer defensible, and RBI's own outsourcing framework increasingly says so directly. The Reserve Bank of India's Master Direction on Outsourcing of Information Technology Services, 2023 does not treat vendor oversight as an annual event. It requires board-level accountability, contractual safeguards, ongoing due diligence, and continuous monitoring, with an annual review of a vendor's financial and operational condition set as a minimum floor, not a ceiling.
That distinction — floor versus ceiling — is where most Indian BFSI vendor risk programs still fall short. A single scheduled review each year captures whatever was true about a vendor on the day it was completed. It says nothing about what changes in the eleven months that follow: a security incident, a new subcontractor added to the delivery chain, a sanctions hit, a credit downgrade, a regulatory action filed in another jurisdiction. Globally, that gap has become the primary route through which incidents actually happen — Verizon's 2025 Data Breach Investigations Report found that third-party involvement in breaches has doubled to 30% year over year, and SecurityScorecard's 2025 Global Third-Party Breach Report puts the figure even higher, at 35.5% of breaches linked to third-party access. This article is written for CROs, heads of vendor risk, internal audit, and compliance leaders at Indian banks, NBFCs, and insurers evaluating whether their current review cycle can actually catch what RBI, and the market, now expect it to catch.
See how a unified, end-to-end governance model — spanning onboarding, screening, continuous monitoring, remediation, and audit-ready reporting — is designed to keep vendor risk current between review cycles, not just at renewal, in Crest.Digital's end-to-end governance framework.
See the Governance FrameworkWhy the Annual Vendor Review No Longer Meets the Bar
The annual review model was built for a slower risk environment, and it still has a role — as a formal checkpoint, a documented sign-off, a moment when a relationship manager and a risk analyst sit down and reconsider a vendor deliberately. What it was never built for is catching the risk that emerges between checkpoints, and for the vendors closest to core banking systems, customer data, and payment rails, that gap is exactly where exposure now lives.
A point-in-time snapshot ages the moment it's filed. A vendor's security posture, subcontractor chain, or financial condition can all shift within weeks of a review being signed off, and a program built entirely around annual cycles has no mechanism to notice until the next scheduled check-in — by which point the exposure may already have become an incident, a regulatory finding, or a customer-facing failure.
RBI's own framework treats continuous oversight as the baseline, not an enhancement. The Master Direction on Outsourcing of IT Services mandates board accountability, contractual safeguards, due diligence, continuous monitoring, and exit preparedness for regulated entities, with the annual financial and operational review of a service provider framed explicitly as a minimum requirement layered under that broader continuous-monitoring mandate — not a substitute for it. RBI examiners increasingly expect regulated entities to produce evidence of ongoing monitoring for material vendors — cloud, core banking, AML, KYC — not just a completed annual questionnaire on file.
The cost of catching an incident late is measurably higher. The average cost of a data breach in financial services reached $5.56 million in 2025, and breaches originating from a third-party system carry close to $4.8 million in remediation cost on top of the direct impact — figures that make the gap between an annual review and continuous oversight a financial exposure, not only a compliance one.
What Continuous Vendor Monitoring Actually Requires
Continuous vendor monitoring is not simply running the same annual questionnaire more often — it is a structurally different model built around ongoing signal collection, tiered attention, and automated triggers that force a reassessment before the next scheduled review date arrives. For Indian BFSI institutions, eight capabilities define what a genuinely continuous program looks like.
Continuous, Not Point-in-Time, Signal Monitoring
Ongoing tracking of cyber ratings, breach disclosures, and control status instead of a single annual snapshot.
Tiered Reassessment Cadence by Criticality
Tier 1 vendors — core banking, cloud, payment, AML/KYC — reassessed continuously; lower-tier vendors on a lighter but still active cycle.
Event-Triggered Reassessment
Automatic re-review triggered by a vendor breach, regulatory action, ownership change, or credit downgrade — not held until the next scheduled review.
Ongoing Sanctions & Adverse Media Screening
Continuous screening against sanctions lists and adverse media sources rather than a one-time check at onboarding.
Financial Health Monitoring
Ongoing tracking of vendor financial stability, so a service provider's ability to keep delivering isn't checked only once a year.
SLA & Contractual Compliance Tracking
Continuous verification that a vendor is meeting its security, uptime, and data-handling commitments, not just at contract renewal.
Remediation Workflow Tied to Real-Time Findings
Findings routed to a named owner with SLA-bound closure tracking, not logged in a review report and forgotten until the next cycle.
Audit-Ready, Always-Current Reporting
A live risk record that can be produced for RBI examiners, the board risk committee, or internal audit on demand, not reconstructed at review time.
Most of these capabilities are not new to TPRM in principle — the shift for Indian BFSI is that each one now has to run continuously, on the vendors RBI has flagged as material, rather than being reconstructed once a year at review time.
Crest.Digital combines vendor onboarding and authentication, sanctions and adverse media screening, financial health and litigation checks, AI-assisted questionnaires, continuous monitoring, remediation workflow, and audit-ready reporting — backed by former Big4 risk professionals — as one platform with managed services built in, so Indian banks and NBFCs can meet RBI's continuous-oversight expectations without adding headcount.
Building a Continuous Vendor Monitoring Program: A Step-by-Step Playbook
Most Indian BFSI institutions are not starting from zero — they already run an annual review process and a vendor registry of some kind. Continuous monitoring is best built as a layer on top of what exists, not a wholesale replacement, sequenced as follows.
Continuous Vendor Monitoring — Step by Step
- Move Vendor Risk Data Off Spreadsheets and Annual Questionnaires: Consolidate vendor records, assessments, and monitoring signals onto a single platform.
- Tier Vendors and Set a Differentiated Monitoring Cadence: Assign Tier 1 status to core banking, cloud, payment, and AML/KYC vendors for continuous monitoring.
- Define Event-Triggered Reassessment Rules: Build automated triggers for a breach, regulatory action, ownership change, or credit downgrade.
- Automate Sanctions and Adverse Media Screening: Run ongoing screening rather than a one-time onboarding check.
- Track Financial Health and SLA Compliance Continuously: Monitor vendor stability and contractual performance on an ongoing basis, not only at renewal.
- Build Always-Current, Audit-Ready Reporting: Maintain a live risk record producible for RBI examiners, the board, or internal audit on demand.
RBI's Master Direction is not the only signal pointing this direction. Guidance from the Securities and Exchange Board of India and the Insurance Regulatory and Development Authority of India has moved in a similar direction for the entities each regulates, consistently framing third-party oversight in terms of ongoing or continuous monitoring rather than periodic review. PwC's own analysis of RBI's third-party risk circulars notes that supervisory expectations have shifted from documentation-based compliance toward evidenced, ongoing oversight of vendor risk posture — a standard a static annual questionnaire cannot, on its own, satisfy. ISACA's guidance on AI-augmented assurance work adds a further test: automation is an acceptable substitute for manual review effort only as long as the institution can still evidence that a control operated as intended — precisely what a continuously monitored vendor record, timestamped, triggered, and auditable, is designed to demonstrate.
Where Agentic AI Fits in Continuous Vendor Monitoring
Continuous monitoring at BFSI scale — hundreds or thousands of vendors, each generating its own stream of sanctions updates, adverse media mentions, financial filings, and security-rating changes — is not a problem a manual team can keep pace with indefinitely. This is precisely the kind of structured, high-volume, judgment-adjacent work agentic AI is suited to.
AI-Assisted Due Diligence and Signal Triage
Conversational AI workflows can continuously scan sanctions lists, adverse media sources, regulatory enforcement databases, and vendor financial filings, flag only the changes that cross a defined risk threshold, and pre-assemble the supporting evidence — rather than generating a constant stream of low-value alerts that a risk analyst has to manually triage one by one.
AI-Driven Risk Orchestration Across the Vendor Portfolio
The more valuable capability is orchestration: a sanctions list update, a vendor breach disclosure, or a credit downgrade automatically triggering re-verification for every affected vendor relationship, with a pre-built risk summary and a recommended remediation owner already assigned by the time a human reviewer sees it. This is the core positioning behind Crest.Digital's agentic AI layer for vendor risk operations, and it is what allows a continuous monitoring program to actually stay continuous at the scale an Indian bank or NBFC's vendor portfolio requires.
Human-in-the-Loop Governance
None of this removes the need for a named human decision-maker on consequential calls — vendor risk acceptance, remediation escalation, offboarding — particularly for the vendors RBI has flagged as material to an institution's core operations. The right question for any AI-driven monitoring capability is not whether it can flag a change, but whether it preserves a defensible, auditable trail of who reviewed the flag and what they decided — the same trail an RBI examiner or the board risk committee will eventually ask to see, and the same standard that lets an institution demonstrate measurable impact from moving to a continuous model in the first place.
Frequently Asked Questions
Continuous vendor monitoring is the ongoing, near-real-time tracking of a third party's risk posture — security ratings, sanctions and adverse media status, financial health, contractual and SLA compliance — updated as new information becomes available, rather than reconstructed once a year at renewal. An annual vendor review, by contrast, is a point-in-time snapshot: a questionnaire completed, a certificate collected, a score assigned, and then set aside until the next cycle. The gap between reviews is exactly where risk changes — a vendor's security posture can shift, a subcontractor can be added, a regulatory action can be filed, or a sanctions hit can occur — and an annual model has no mechanism to catch any of it until the next scheduled check-in, by which point the exposure may already have materialized into an incident, a regulatory finding, or a customer-facing failure.
RBI's Master Direction on Outsourcing of Information Technology Services, 2023 explicitly requires regulated entities to maintain ongoing oversight of material IT service providers — including board-level accountability, continuous monitoring, and at minimum an annual review of a vendor's financial and operational condition — and RBI's broader supervisory expectations across banking, NBFC and cooperative bank circulars have moved firmly toward continuous, evidence-based oversight of critical vendors such as cloud, core banking, AML and KYC providers. An annual review still has a role as a formal checkpoint, but it is no longer treated as sufficient on its own; RBI examiners increasingly expect evidence that a regulated entity can demonstrate ongoing monitoring between review cycles, not just a completed questionnaire on file.
Start with vendors that map to RBI's definition of material outsourcing — core banking platforms, cloud infrastructure providers, payment processors, AML and KYC screening vendors, and any third party with direct access to customer data or systems critical to business continuity. These Tier 1 relationships carry the highest concentration of both regulatory scrutiny and actual operational exposure, and are where a breach, an outage, or a compliance lapse at the vendor translates most directly into a reportable incident for the institution. Lower-tier vendors without system access or customer data exposure can sit on a lighter monitoring cadence, but should not be excluded from the program entirely, since criticality can change as a vendor relationship expands.
A well-designed continuous monitoring program defines event-based triggers that force an out-of-cycle reassessment regardless of where a vendor sits in its scheduled review calendar: a confirmed data breach or security incident at the vendor, a regulatory action or enforcement order filed against it, a material change in ownership or corporate structure, a credit rating downgrade or signs of financial distress, a new subcontractor added to the service delivery chain, or negative adverse media coverage. Building these triggers into an automated monitoring system, rather than relying on a vendor to proactively disclose a material change, is what actually closes the gap that annual reviews leave open.
Agentic AI supports continuous vendor monitoring by continuously scanning sanctions lists, adverse media, financial filings, and security-rating feeds for every vendor in the portfolio, automatically flagging changes that meet a defined risk threshold, and routing only genuine exceptions to a human reviewer instead of generating a constant stream of low-value alerts. It can also assemble a pre-built risk summary the moment a trigger event fires — pulling together what changed, why it matters, and what the recommended next step is — so a risk analyst is reviewing a decision-ready packet rather than starting an investigation from scratch. Final decisions on vendor risk acceptance, remediation escalation, or offboarding still require a named human owner with an auditable sign-off trail.