Vendor Risk Management Framework: India vs Global (2026)
India's vendor risk regulations are mandatory, sector-specific, and increasingly enforceable. Global standards like ISO 27001 and NIST CSF set the best-practice ceiling. Here is how to build a framework that satisfies both.
If you manage vendor risk at an Indian enterprise or a global company with significant India operations, you are navigating two distinct worlds simultaneously. On one side sit voluntary, principle-based global frameworks — ISO 27001, NIST CSF, SOC 2 — that define what best practice looks like. On the other side sit India's sector regulators: the RBI, SEBI, IRDAI, and now the DPDPA 2023, each issuing prescriptive, mandatory guidelines that carry real enforcement teeth.
Most organisations in India pick one or the other. They either adopt a global framework and hope it covers local requirements, or they build entirely around regulatory checklists and miss the structural rigour that global standards provide. Neither approach is sufficient. This article lays out what each side demands, where they diverge, and how to architect a vendor risk management framework that satisfies both without doubling your workload.
Why VRM Frameworks Differ Across Geographies
The differences between Indian and global frameworks are not merely cosmetic — they reflect fundamentally different approaches to risk governance. Global frameworks like ISO 27001 or NIST CSF were designed to be universally applicable across industries, geographies, and organisation sizes. They define outcomes, not prescriptions: you should assess your third parties, you should have contracts with specific clauses, you should monitor on a risk-based basis. How you do it is largely your decision.
India's regulatory approach, by contrast, is sectoral and prescriptive. The Reserve Bank of India does not just say "manage your outsourcing risk" — it specifies the clauses your contracts must contain, the minimum due diligence steps you must take before engagement, and the scenarios in which you must notify the regulator. SEBI issues similar prescriptions for market intermediaries. This matters because it means Indian enterprises face a dual compliance burden: meet the mandatory floor set by regulators, and aspire toward the best-practice ceiling defined by global standards.
India's DPDPA 2023, modelled partly on GDPR principles, signals a broader trend: Indian regulations are becoming more aligned with global standards over time. Organisations that build a unified framework today will face less rework as this convergence deepens.
Global VRM Frameworks at a Glance
Three global standards dominate how multinational organisations structure their third-party risk programmes.
ISO 27001 — Information Security Management
ISO 27001 addresses vendor risk through Annex A controls — specifically A.15 (Supplier Relationships), which requires organisations to identify security risks related to third parties, include information security requirements in contracts, monitor and review supplier services, and manage changes to supplier relationships. The standard is certification-based, meaning vendors themselves can hold ISO 27001 certification as evidence of their security posture. For organisations sourcing from global vendors, asking for ISO 27001 certification is a widely accepted minimum bar. The ISO 27001:2022 revision strengthened third-party controls further, adding cloud service provider requirements.
NIST Cybersecurity Framework
NIST CSF, developed by the US National Institute of Standards and Technology, organises cybersecurity activities into five functions: Identify, Protect, Detect, Respond, and Recover. Third-party risk management sits prominently in the Identify function. The NIST SP 800-161 publication is specifically dedicated to supply chain risk management and is widely used as a reference by large enterprises and public sector organisations globally. NIST does not offer certification but provides a detailed, actionable control catalogue.
SOC 2 and the Shared Responsibility Model
SOC 2 Type II reports, issued by service organisation auditors, give procurement teams audited evidence of a vendor's controls over security, availability, confidentiality, and privacy over a defined period. Requiring SOC 2 Type II from critical SaaS and technology vendors has become standard practice in North America and is increasingly demanded in India, particularly by BFSI organisations onboarding cloud-based services.
Crest's AI engine maps your vendor universe against 3,400+ data sources — across both Indian regulatory requirements and global risk signals — in a single unified view.
Explore Crest Intelligence →India's Mandatory VRM Regulatory Landscape
India does not have a single, consolidated third-party risk law. Instead, obligations cascade from multiple sectoral regulators, each with jurisdiction over specific industries. Getting this right requires mapping your organisation's regulatory perimeter before building your framework.
RBI Outsourcing Guidelines (Banks, NBFCs, Payment Aggregators)
The Reserve Bank of India's Master Directions on outsourcing are the most detailed vendor risk rules in the Indian market. They apply to commercial banks, cooperative banks, NBFCs, and payment aggregators. Key obligations include: a board-approved outsourcing policy; risk-based due diligence before any outsourcing engagement; mandatory contract clauses covering data confidentiality, regulatory access rights, audit rights, business continuity, and sub-contracting restrictions; ongoing monitoring with annual reviews for material outsourcing; and specific incident reporting timelines. Critically, RBI guidance prohibits outsourcing activities that would amount to licensing, and requires regulated entities to retain ultimate accountability for outsourced functions.
SEBI TPRM Framework (Market Intermediaries)
SEBI's circulars on cyber security and cyber resilience framework for market intermediaries extend third-party risk obligations to stockbrokers, depositories, mutual funds, and investment advisers. These require a risk assessment before onboarding technology vendors, periodic vendor performance reviews, and an incident response process that covers third-party breaches. SEBI has taken a particularly hard line on cloud vendor due diligence, requiring specific assessments of data residency, encryption standards, and exit provisions.
Digital Personal Data Protection Act 2023
The DPDPA 2023 introduced a Data Fiduciary / Data Processor structure that fundamentally changes vendor contracts across all sectors — not just BFSI. Any vendor that processes personal data on your behalf is a Data Processor, and you as the Data Fiduciary remain legally accountable for that processing. This means vendor contracts must now include lawful processing bases, purpose limitations, security obligations, breach notification timelines, and data deletion/return clauses. VRM programmes that previously focused only on financial and operational risk must now incorporate a data protection risk layer for any vendor with access to personal data.
IRDAI (Insurers)
IRDAI's outsourcing and cyber security guidelines for insurers mirror the RBI approach — board-approved policies, due diligence, mandatory contract terms, and ongoing monitoring — with additional requirements specific to policyholder data protection and outsourcing to entities outside India.
India vs Global: Side-by-Side Comparison
| Dimension | Global Frameworks (ISO 27001 / NIST) | India Regulations (RBI / SEBI / DPDPA) |
|---|---|---|
| Nature | Voluntary, principle-based standards | Mandatory, prescriptive regulations |
| Enforcement | Market-driven (certification, customer requirements) | Regulatory penalties, licence action |
| Scope | Cross-industry, geography-agnostic | Sector-specific (BFSI, insurance, data processors) |
| Due Diligence Depth | Risk-based, organisational discretion | Prescribed minimum steps, documented evidence required |
| Contract Requirements | Recommended clauses (Annex A.15) | Mandatory clause lists with specific language guidance |
| Monitoring Cadence | Ongoing, risk-based frequency | Annual minimum for material vendors; more frequent post-incident |
| Incident Reporting | Internal escalation processes | Regulatory reporting within defined timelines |
| Data Protection | GDPR processor agreements (EU operations) | DPDPA 2023 Data Processor contracts (all sectors) |
| Concentration Risk | Best practice guidance | Explicitly managed and reportable (RBI) |
Map Your Vendors Across Every Applicable Standard
Crest scores vendors across 9 risk domains and maps findings to RBI, SEBI, DPDPA, ISO 27001, and NIST requirements — automatically.
Building a Unified Framework: Five Steps
Rather than running parallel compliance programmes, the most efficient approach is to build a single unified framework that explicitly maps Indian regulatory requirements to their global standard equivalents. Here is the architecture we recommend.
Map Your Regulatory Perimeter
Start by identifying every regulatory body with jurisdiction over your vendor relationships. An NBFC with a SaaS HR platform and a cloud data warehouse faces RBI outsourcing rules, DPDPA obligations, and potentially SEBI requirements if any market-facing services are involved. Document the mandatory requirements from each regulator before designing any controls.
Select a Global Framework as the Structural Backbone
ISO 27001 Annex A or NIST CSF Tier 3+ works well as the backbone for most Indian enterprises. Build your vendor risk taxonomy, control domains, and assessment questionnaires around the global standard, then overlay Indian regulatory requirements as mandatory addenda to each relevant control area. This avoids building two separate systems and makes dual reporting easier.
Classify and Tier Your Vendor Universe
Not all vendors carry equal risk. Tier them by criticality (what happens if this vendor fails?), data sensitivity (what data do they access?), and regulatory significance (is this an RBI-material outsourcing arrangement?). Apply enhanced due diligence to Tier 1 critical vendors, standard due diligence to Tier 2, and simplified checks to Tier 3. The tiering logic must align with both your internal risk appetite and the regulatory definition of "material outsourcing."
Design Controls for the Full Vendor Lifecycle
Onboarding, ongoing monitoring, incident response, and offboarding all need defined controls. For each lifecycle stage, document: what evidence is required, who is accountable, how often it must be refreshed, and which regulatory requirement it satisfies. The contract review stage is particularly important — ensure your standard vendor contract template includes both global best-practice clauses and India's mandatory requirements under the applicable sectoral guidelines and DPDPA 2023.
Automate Evidence Collection and Monitoring
A framework is only as good as its execution. Manual spreadsheet-based processes break down quickly as vendor populations grow. A TPRM platform like Crest enables continuous monitoring, automated risk scoring, and audit-ready evidence trails — all mapped to the specific regulatory and global standard requirements relevant to each vendor. This is particularly important for demonstrating compliance during RBI inspections or SEBI audits.
The Compliance Integration Dividend
One underappreciated benefit of building a unified framework is the compliance integration dividend it generates. When your VRM programme is structured around a mapped, documented control set, adding a new regulatory requirement becomes incremental rather than a ground-up rebuild. As India's DPDPA rules are finalised and as global regulations like GDPR or DORA (applicable if you operate in the EU) evolve, your framework absorbs them cleanly.
Organisations that have invested in this architecture also report significant benefits when responding to large enterprise RFPs. Global clients increasingly ask Indian vendors to demonstrate VRM capabilities during procurement — having an ISO 27001-aligned framework with documented India regulatory compliance is a competitive differentiator, not just a compliance cost.
For internal audit purposes, a unified framework also simplifies the audit plan. Rather than running separate vendor risk audits against RBI requirements, SEBI requirements, and ISO controls, a single audit cycle can cover all three if the framework mapping is clean and the evidence is centralised. See how internal audit teams use Crest to structure vendor risk reviews against multiple standards simultaneously.
Organisations with a documented mapping between their VRM controls and applicable regulatory requirements respond to regulatory enquiries in significantly less time. The evidence already exists — it just needs to be retrieved, not created on demand.
Common Gaps When India Enterprises Adopt Global Frameworks Without Localisation
The most common failure mode is adopting a global framework and assuming it covers Indian regulatory requirements without explicitly checking. Three gaps appear repeatedly in practice. First, global frameworks do not address concentration risk in the prescriptive way RBI does — an ISO 27001-certified programme can still be non-compliant with RBI's material outsourcing concentration requirements if the specific mapping was never done. Second, DPDPA 2023 contract obligations are distinct from GDPR — assuming a GDPR-compliant data processing agreement satisfies DPDPA is not safe, particularly around data localisation and the rights of Data Principals. Third, India's eCourts database, MCA struck-off company records, GST suspension flags, and RBI defaulter lists are not referenced in any global framework — they are India-specific data sources that must be incorporated into your vendor onboarding due diligence process separately.
Crest's intelligence engine integrates these India-specific sources — GST, PAN, CIN, MCA, eCourts, SFIO, RBI watchlists — alongside global adverse media and sanctions data, giving you a genuinely unified risk picture rather than two separate assessments bolted together. For a deeper view of how measurable impact is achieved through this approach, see how organisations see measurable impact with Crest.