VRM Fundamentals · May 04, 2026 · 7 min read

Vendor Risk Management Framework: India vs Global (2026)

India's vendor risk regulations are mandatory, sector-specific, and increasingly enforceable. Global standards like ISO 27001 and NIST CSF set the best-practice ceiling. Here is how to build a framework that satisfies both.

If you manage vendor risk at an Indian enterprise or a global company with significant India operations, you are navigating two distinct worlds simultaneously. On one side sit voluntary, principle-based global frameworks — ISO 27001, NIST CSF, SOC 2 — that define what best practice looks like. On the other side sit India's sector regulators: the RBI, SEBI, IRDAI, and now the DPDPA 2023, each issuing prescriptive, mandatory guidelines that carry real enforcement teeth.

Most organisations in India pick one or the other. They either adopt a global framework and hope it covers local requirements, or they build entirely around regulatory checklists and miss the structural rigour that global standards provide. Neither approach is sufficient. This article lays out what each side demands, where they diverge, and how to architect a vendor risk management framework that satisfies both without doubling your workload.

Why VRM Frameworks Differ Across Geographies

The differences between Indian and global frameworks are not merely cosmetic — they reflect fundamentally different approaches to risk governance. Global frameworks like ISO 27001 or NIST CSF were designed to be universally applicable across industries, geographies, and organisation sizes. They define outcomes, not prescriptions: you should assess your third parties, you should have contracts with specific clauses, you should monitor on a risk-based basis. How you do it is largely your decision.

India's regulatory approach, by contrast, is sectoral and prescriptive. The Reserve Bank of India does not just say "manage your outsourcing risk" — it specifies the clauses your contracts must contain, the minimum due diligence steps you must take before engagement, and the scenarios in which you must notify the regulator. SEBI issues similar prescriptions for market intermediaries. This matters because it means Indian enterprises face a dual compliance burden: meet the mandatory floor set by regulators, and aspire toward the best-practice ceiling defined by global standards.

Regulatory Convergence Trend

India's DPDPA 2023, modelled partly on GDPR principles, signals a broader trend: Indian regulations are becoming more aligned with global standards over time. Organisations that build a unified framework today will face less rework as this convergence deepens.

Global VRM Frameworks at a Glance

Three global standards dominate how multinational organisations structure their third-party risk programmes.

ISO 27001 — Information Security Management

ISO 27001 addresses vendor risk through Annex A controls — specifically A.15 (Supplier Relationships), which requires organisations to identify security risks related to third parties, include information security requirements in contracts, monitor and review supplier services, and manage changes to supplier relationships. The standard is certification-based, meaning vendors themselves can hold ISO 27001 certification as evidence of their security posture. For organisations sourcing from global vendors, asking for ISO 27001 certification is a widely accepted minimum bar. The ISO 27001:2022 revision strengthened third-party controls further, adding cloud service provider requirements.

NIST Cybersecurity Framework

NIST CSF, developed by the US National Institute of Standards and Technology, organises cybersecurity activities into five functions: Identify, Protect, Detect, Respond, and Recover. Third-party risk management sits prominently in the Identify function. The NIST SP 800-161 publication is specifically dedicated to supply chain risk management and is widely used as a reference by large enterprises and public sector organisations globally. NIST does not offer certification but provides a detailed, actionable control catalogue.

SOC 2 and the Shared Responsibility Model

SOC 2 Type II reports, issued by service organisation auditors, give procurement teams audited evidence of a vendor's controls over security, availability, confidentiality, and privacy over a defined period. Requiring SOC 2 Type II from critical SaaS and technology vendors has become standard practice in North America and is increasingly demanded in India, particularly by BFSI organisations onboarding cloud-based services.

Crest's AI engine maps your vendor universe against 3,400+ data sources — across both Indian regulatory requirements and global risk signals — in a single unified view.

Explore Crest Intelligence →

India's Mandatory VRM Regulatory Landscape

India does not have a single, consolidated third-party risk law. Instead, obligations cascade from multiple sectoral regulators, each with jurisdiction over specific industries. Getting this right requires mapping your organisation's regulatory perimeter before building your framework.

RBI Outsourcing Guidelines (Banks, NBFCs, Payment Aggregators)

The Reserve Bank of India's Master Directions on outsourcing are the most detailed vendor risk rules in the Indian market. They apply to commercial banks, cooperative banks, NBFCs, and payment aggregators. Key obligations include: a board-approved outsourcing policy; risk-based due diligence before any outsourcing engagement; mandatory contract clauses covering data confidentiality, regulatory access rights, audit rights, business continuity, and sub-contracting restrictions; ongoing monitoring with annual reviews for material outsourcing; and specific incident reporting timelines. Critically, RBI guidance prohibits outsourcing activities that would amount to licensing, and requires regulated entities to retain ultimate accountability for outsourced functions.

SEBI TPRM Framework (Market Intermediaries)

SEBI's circulars on cyber security and cyber resilience framework for market intermediaries extend third-party risk obligations to stockbrokers, depositories, mutual funds, and investment advisers. These require a risk assessment before onboarding technology vendors, periodic vendor performance reviews, and an incident response process that covers third-party breaches. SEBI has taken a particularly hard line on cloud vendor due diligence, requiring specific assessments of data residency, encryption standards, and exit provisions.

Digital Personal Data Protection Act 2023

The DPDPA 2023 introduced a Data Fiduciary / Data Processor structure that fundamentally changes vendor contracts across all sectors — not just BFSI. Any vendor that processes personal data on your behalf is a Data Processor, and you as the Data Fiduciary remain legally accountable for that processing. This means vendor contracts must now include lawful processing bases, purpose limitations, security obligations, breach notification timelines, and data deletion/return clauses. VRM programmes that previously focused only on financial and operational risk must now incorporate a data protection risk layer for any vendor with access to personal data.

IRDAI (Insurers)

IRDAI's outsourcing and cyber security guidelines for insurers mirror the RBI approach — board-approved policies, due diligence, mandatory contract terms, and ongoing monitoring — with additional requirements specific to policyholder data protection and outsourcing to entities outside India.

India vs Global: Side-by-Side Comparison

DimensionGlobal Frameworks (ISO 27001 / NIST)India Regulations (RBI / SEBI / DPDPA)
NatureVoluntary, principle-based standardsMandatory, prescriptive regulations
EnforcementMarket-driven (certification, customer requirements)Regulatory penalties, licence action
ScopeCross-industry, geography-agnosticSector-specific (BFSI, insurance, data processors)
Due Diligence DepthRisk-based, organisational discretionPrescribed minimum steps, documented evidence required
Contract RequirementsRecommended clauses (Annex A.15)Mandatory clause lists with specific language guidance
Monitoring CadenceOngoing, risk-based frequencyAnnual minimum for material vendors; more frequent post-incident
Incident ReportingInternal escalation processesRegulatory reporting within defined timelines
Data ProtectionGDPR processor agreements (EU operations)DPDPA 2023 Data Processor contracts (all sectors)
Concentration RiskBest practice guidanceExplicitly managed and reportable (RBI)

Map Your Vendors Across Every Applicable Standard

Crest scores vendors across 9 risk domains and maps findings to RBI, SEBI, DPDPA, ISO 27001, and NIST requirements — automatically.

See the Platform →

Building a Unified Framework: Five Steps

Rather than running parallel compliance programmes, the most efficient approach is to build a single unified framework that explicitly maps Indian regulatory requirements to their global standard equivalents. Here is the architecture we recommend.

1

Map Your Regulatory Perimeter

Start by identifying every regulatory body with jurisdiction over your vendor relationships. An NBFC with a SaaS HR platform and a cloud data warehouse faces RBI outsourcing rules, DPDPA obligations, and potentially SEBI requirements if any market-facing services are involved. Document the mandatory requirements from each regulator before designing any controls.

2

Select a Global Framework as the Structural Backbone

ISO 27001 Annex A or NIST CSF Tier 3+ works well as the backbone for most Indian enterprises. Build your vendor risk taxonomy, control domains, and assessment questionnaires around the global standard, then overlay Indian regulatory requirements as mandatory addenda to each relevant control area. This avoids building two separate systems and makes dual reporting easier.

3

Classify and Tier Your Vendor Universe

Not all vendors carry equal risk. Tier them by criticality (what happens if this vendor fails?), data sensitivity (what data do they access?), and regulatory significance (is this an RBI-material outsourcing arrangement?). Apply enhanced due diligence to Tier 1 critical vendors, standard due diligence to Tier 2, and simplified checks to Tier 3. The tiering logic must align with both your internal risk appetite and the regulatory definition of "material outsourcing."

4

Design Controls for the Full Vendor Lifecycle

Onboarding, ongoing monitoring, incident response, and offboarding all need defined controls. For each lifecycle stage, document: what evidence is required, who is accountable, how often it must be refreshed, and which regulatory requirement it satisfies. The contract review stage is particularly important — ensure your standard vendor contract template includes both global best-practice clauses and India's mandatory requirements under the applicable sectoral guidelines and DPDPA 2023.

5

Automate Evidence Collection and Monitoring

A framework is only as good as its execution. Manual spreadsheet-based processes break down quickly as vendor populations grow. A TPRM platform like Crest enables continuous monitoring, automated risk scoring, and audit-ready evidence trails — all mapped to the specific regulatory and global standard requirements relevant to each vendor. This is particularly important for demonstrating compliance during RBI inspections or SEBI audits.

The Compliance Integration Dividend

One underappreciated benefit of building a unified framework is the compliance integration dividend it generates. When your VRM programme is structured around a mapped, documented control set, adding a new regulatory requirement becomes incremental rather than a ground-up rebuild. As India's DPDPA rules are finalised and as global regulations like GDPR or DORA (applicable if you operate in the EU) evolve, your framework absorbs them cleanly.

Organisations that have invested in this architecture also report significant benefits when responding to large enterprise RFPs. Global clients increasingly ask Indian vendors to demonstrate VRM capabilities during procurement — having an ISO 27001-aligned framework with documented India regulatory compliance is a competitive differentiator, not just a compliance cost.

For internal audit purposes, a unified framework also simplifies the audit plan. Rather than running separate vendor risk audits against RBI requirements, SEBI requirements, and ISO controls, a single audit cycle can cover all three if the framework mapping is clean and the evidence is centralised. See how internal audit teams use Crest to structure vendor risk reviews against multiple standards simultaneously.

Framework Mapping Accelerates Regulatory Responses

Organisations with a documented mapping between their VRM controls and applicable regulatory requirements respond to regulatory enquiries in significantly less time. The evidence already exists — it just needs to be retrieved, not created on demand.

Common Gaps When India Enterprises Adopt Global Frameworks Without Localisation

The most common failure mode is adopting a global framework and assuming it covers Indian regulatory requirements without explicitly checking. Three gaps appear repeatedly in practice. First, global frameworks do not address concentration risk in the prescriptive way RBI does — an ISO 27001-certified programme can still be non-compliant with RBI's material outsourcing concentration requirements if the specific mapping was never done. Second, DPDPA 2023 contract obligations are distinct from GDPR — assuming a GDPR-compliant data processing agreement satisfies DPDPA is not safe, particularly around data localisation and the rights of Data Principals. Third, India's eCourts database, MCA struck-off company records, GST suspension flags, and RBI defaulter lists are not referenced in any global framework — they are India-specific data sources that must be incorporated into your vendor onboarding due diligence process separately.

Crest's intelligence engine integrates these India-specific sources — GST, PAN, CIN, MCA, eCourts, SFIO, RBI watchlists — alongside global adverse media and sanctions data, giving you a genuinely unified risk picture rather than two separate assessments bolted together. For a deeper view of how measurable impact is achieved through this approach, see how organisations see measurable impact with Crest.

Frequently Asked Questions

What are the main vendor risk management frameworks used in India? +
India's primary vendor risk frameworks come from sector regulators. The Reserve Bank of India issues outsourcing guidelines that apply to banks, NBFCs, and payment aggregators. SEBI mandates third-party risk controls for market intermediaries. IRDAI covers insurers. The Digital Personal Data Protection Act 2023 introduces data processor obligations that extend to vendors handling personal data. Enterprises operating across sectors typically layer these requirements on top of voluntary global standards like ISO 27001 or NIST CSF to create a comprehensive, defensible programme.
How does India's VRM regulatory landscape differ from global frameworks like ISO 27001? +
Global frameworks like ISO 27001 and NIST CSF are voluntary, principle-based standards that organisations adopt to demonstrate maturity. India's sectoral regulations, by contrast, are mandatory and enforceable — non-compliance can attract monetary penalties, regulatory action, or licence revocation. India's frameworks also tend to be more prescriptive, specifying timelines, documentation requirements, and escalation paths that global standards leave to organisational discretion. A robust Indian VRM programme must satisfy both layers: the mandatory floor set by regulators and the best-practice ceiling defined by global standards.
Does the Digital Personal Data Protection Act 2023 affect vendor risk management? +
Yes, significantly. The DPDPA 2023 treats organisations as Data Fiduciaries and any vendor processing personal data on their behalf as a Data Processor. Data Fiduciaries are responsible for ensuring that Data Processors handle data only under a valid contract and comply with the Act's provisions. This means vendor contracts must now include specific data processing clauses, purpose limitations, and data deletion obligations. Vendors must be assessed not just for operational risk but also for data handling practices, adding a new dimension to VRM programmes across all sectors — not just BFSI.
Can a single VRM framework satisfy both Indian regulations and global standards? +
Yes — and for multinational organisations it is essential. The recommended approach is to build on a global framework such as ISO 27001 Annex A controls or NIST CSF as the structural backbone, then overlay India-specific requirements as mandatory addenda. Vendor classification tiers, due diligence depth, and monitoring frequency should be calibrated to the most demanding applicable standard for each vendor. A well-designed framework documents the mapping between each Indian regulatory requirement and its global equivalent, making it easier to demonstrate compliance to multiple audiences — internal audit, regulators, and international clients alike.
What is the RBI's key requirement for outsourcing risk management? +
The RBI's Master Direction on outsourcing requires institutions to maintain a board-approved outsourcing policy, conduct risk-based due diligence before engagement, and include specific contract clauses covering data confidentiality, audit rights, regulatory access, business continuity obligations, and sub-contracting restrictions. Ongoing monitoring is required with annual reviews for material outsourcing arrangements. Critically, the RBI expects regulated entities to retain ultimate responsibility for outsourced functions — you cannot outsource accountability. Material outsourcing arrangements must be reported to the RBI, and concentration risk must be explicitly managed and documented.