★ TPRM Insights
RBI Outsourcing Guidelines: The TPRM Compliance Blueprint
6 min read · Regulatory Compliance · August 2026
India’s central bank has quietly rewritten the rules for how banks and NBFCs manage their vendors. The RBI third-party risk management guidelines — spanning the 2023 Master Direction on Outsourcing of Information Technology Services and the long-standing Guidelines on Managing Risks and Code of Conduct in Outsourcing of Financial Services — now hold regulated entities directly accountable for what their vendors do, not just what their contracts say. For risk, compliance, and audit teams, understanding these requirements is no longer optional groundwork; it is the baseline for surviving an RBI inspection.
★ Key Takeaways
RBI guidelines make regulated entities, not vendors, accountable for outsourced functions.
Materiality assessment drives the depth of due diligence, monitoring, and RBI reporting required.
A compliant outsourcing policy needs a tested exit strategy and explicit fourth-party coverage.
Continuous monitoring is replacing annual reviews as the RBI's practical expectation.
What Are the RBI's Third-Party Risk Management Guidelines?
The RBI’s third-party risk management guidelines are a set of binding directions — principally the Guidelines on Managing Risks and Code of Conduct in Outsourcing of Financial Services and the 2023 Master Direction on Outsourcing of Information Technology Services — that require every regulated entity, including banks, NBFCs, and payment system operators, to treat outsourced functions as if they were performed in-house for the purposes of risk, compliance, and customer accountability. The principle running through both documents is non-transfer of accountability: handing a function to a vendor never transfers the regulatory responsibility for that function. If a vendor mishandles customer data, breaches an SLA, or exposes the institution to fraud, the RBI holds the regulated entity liable, not the vendor.
The guidelines apply broadly. Core banking operations, IT infrastructure, cybersecurity monitoring, customer service, collections, and increasingly cloud and SaaS arrangements all fall within scope. Entities must maintain a board-approved outsourcing policy, conduct risk-based due diligence before onboarding any vendor, and report material outsourcing arrangements to the RBI on a defined cadence.
- Guidelines on Managing Risks and Code of Conduct in Outsourcing of Financial Services
- Master Direction on Outsourcing of Information Technology Services (2023)
- Sector-specific circulars covering cloud adoption, cybersecurity, and payment aggregator outsourcing
How Does the RBI Classify Outsourcing Risk?
The RBI classifies outsourcing arrangements primarily by materiality — whether disruption to the outsourced activity would significantly affect the entity’s business operations, reputation, profitability, or its ability to manage risk and meet regulatory obligations. A materiality assessment looks at the volume and value of transactions processed, the sensitivity of customer data involved, the availability of alternative providers, and how difficult the function would be to bring back in-house on short notice.
Material outsourcing arrangements attract heavier obligations: enhanced due diligence before signing, tighter service-level monitoring, more frequent risk reassessment, and mandatory reporting to the RBI. Group captives and related-party vendors do not get a pass either — the guidelines make clear that outsourcing to a group entity carries the same scrutiny as outsourcing to an external third party, because concentration and conflict-of-interest risk exist regardless of ownership structure.
In practice, most institutions end up with a two-tier vendor population: a small set of material vendors that receive board-level attention, and a much larger long tail of non-material vendors that are technically in scope but rarely reassessed. That long tail is where gaps tend to accumulate, because a vendor’s risk profile can shift — a data breach, a change of ownership, a credit downgrade — without triggering a reassessment until the next scheduled review, by which point the exposure has often already materialised.
What Must Banks and NBFCs Include in Their Outsourcing Policy?
An RBI-compliant outsourcing policy must be approved by the board and cover the full vendor lifecycle, not just contract signing. That means documented criteria for vendor selection and due diligence, defined service levels with measurable penalties for breach, ongoing performance and risk monitoring, and a tested business continuity and exit strategy for every material arrangement.
The exit strategy requirement is where many institutions fall short. RBI expects entities to be able to transition a material outsourced function to another provider or bring it in-house without material disruption to customers — which means contracts need explicit data return and deletion clauses, transition assistance periods, and contingency plans that are reviewed, not just filed away. Policies also need to address subcontracting: if a vendor further outsources part of the work, the regulated entity remains on the hook for that fourth-party exposure.
- Board-approved outsourcing policy reviewed at least annually
- Documented due diligence criteria applied before every vendor onboarding
- SLAs with measurable performance metrics and enforceable penalties
- Tested exit strategy and business continuity plan for material vendors
- Explicit contractual coverage of subcontracting and fourth-party risk
What Happens When a Regulated Entity Falls Short of RBI Outsourcing Requirements?
Falling short of RBI outsourcing requirements exposes a regulated entity to supervisory action ranging from formal corrective directions to monetary penalties and restrictions on specific business activities. Outsourcing and vendor governance gaps have become a recurring theme in RBI’s supervisory findings in recent years, particularly around IT outsourcing, data localisation, and inadequate board oversight of material vendor relationships.
Beyond the direct regulatory consequence, an outsourcing failure that leads to a customer data breach or service outage carries reputational cost that outlasts any penalty. Because the RBI’s non-transfer-of-accountability principle puts the regulated entity, not the vendor, in the public and regulatory spotlight, weak third-party oversight tends to surface at the worst possible moment — during an incident, not during a routine audit.
Supervisory reviews increasingly probe whether outsourcing decisions were actually risk-based, or whether they were driven by cost alone with due diligence added afterward as documentation. Entities that can show a consistent, evidenced process — risk scoring at onboarding, monitoring cadence tied to materiality, and clear escalation paths when a vendor’s risk profile changes — tend to fare far better in an inspection than entities that can only produce a signed contract and an annual questionnaire.
How Should Compliance Teams Operationalise RBI Third-Party Risk Requirements?
Compliance teams should move from point-in-time vendor audits to continuous monitoring that tracks a vendor’s risk posture between formal reviews, since RBI’s expectations increasingly assume real-time visibility rather than annual snapshots. That means monitoring financial health, security posture, adverse media, and regulatory actions on an ongoing basis, and escalating material changes to the board rather than waiting for the next scheduled reassessment cycle.
It also means mapping concentration and fourth-party risk explicitly. Many Indian banks and NBFCs now depend on a small number of cloud and IT service providers across multiple critical functions, which creates a single point of failure that a purely contract-by-contract view of outsourcing will miss. Building a consolidated register of material outsourcing arrangements, their subcontractors, and their interdependencies gives risk and audit teams the visibility the RBI guidelines assume they already have.
Conclusion
The RBI’s outsourcing framework is unambiguous about where accountability sits: with the regulated entity, always. Meeting that standard with spreadsheets and annual reviews is becoming harder as vendor ecosystems grow more complex and RBI’s supervisory expectations keep rising.
Crest helps risk, compliance, and audit teams move from static outsourcing registers to continuous, AI-powered third-party risk monitoring — covering materiality classification, financial health, cybersecurity posture, and fourth-party exposure in one place. If your outsourcing policy is due for a review, schedule a demo to see how Crest maps to RBI’s third-party risk expectations.
★ Frequently Asked Questions
Does the RBI outsourcing guideline apply to NBFCs, or only to banks?
The RBI’s outsourcing and third-party risk guidelines apply to all entities it regulates, including scheduled commercial banks, NBFCs, payment system operators, and cooperative banks, not just banks. Any RBI-regulated entity that outsources a financial or IT function to a third party falls within scope, regardless of its size or category.
What is "material outsourcing" under RBI guidelines?
Material outsourcing refers to an arrangement where disruption to the outsourced activity would significantly affect the regulated entity’s operations, reputation, profitability, or ability to manage risk and comply with regulation. Entities assess materiality using factors like transaction volume, data sensitivity, and how easily the function could be replaced or brought back in-house.
Can core banking functions be outsourced under RBI rules?
Certain core management and decision-making functions, such as credit sanctioning and overall risk management, are expected to remain with the regulated entity itself rather than being outsourced. Operational and support functions can generally be outsourced, but always subject to RBI’s due diligence, monitoring, and accountability requirements.
How often must vendor risk assessments be refreshed under RBI requirements?
RBI guidelines expect a risk-based approach, with material and high-risk vendors reassessed at least annually and more frequently if their risk profile changes. Increasingly, supervisory expectations favour continuous monitoring over static annual reviews, especially for vendors handling sensitive customer data or critical IT infrastructure.
What's the difference between the RBI's outsourcing guidelines and the 2023 Master Direction on IT outsourcing?
The original Guidelines on Managing Risks in Outsourcing of Financial Services cover outsourcing of financial and operational activities broadly, while the 2023 Master Direction on Outsourcing of Information Technology Services focuses specifically on IT and IT-enabled services, including cloud, cybersecurity, and data centre arrangements. Regulated entities generally need to comply with both, depending on the nature of each outsourcing arrangement.
Does outsourcing to a group company reduce RBI compliance obligations?
No. RBI guidelines explicitly state that outsourcing to a group or related-party entity carries the same due diligence, monitoring, and accountability requirements as outsourcing to an unrelated third party. Concentration and conflict-of-interest risks exist regardless of ownership, so group arrangements receive equal scrutiny.
★ See Crest in Action
Ready to Modernise Your TPRM?
Intelligence over information. Control over chaos. Insight over effort.
Published by the Crest Editorial Team · crest.digital