Walk into any BFSI security review and ask the CISO about their payment gateway's security posture. The answer is almost always a variation of the same sentence: "Our vendor manages that."

It is the most expensive four words in Indian financial security. Only 49% of BFSI institutions have mature third-party risk management controls, according to joint research by BCG and DSCI. The other half — half — are operating under the dangerous assumption that outsourcing a function means outsourcing the liability that comes with it.

They do not. RBI is explicit about this. CERT-In's advisories are unambiguous. And the attackers — who read your vendor onboarding documents far more carefully than your legal team does — are already inside through the side door.

49%
BFSI institutions with mature third-party risk controls (BCG/DSCI)
3+
Recurring gaps RBI inspectors cite in vendor VAPT scope documentation
18k+
Organisations compromised in the SolarWinds-style supply chain wave

What RBI Actually Says About Vendor Scope in VAPT

The 2024 RBI Master Direction on IT Governance, Risk, Controls and Assurance Practices states that regulated entities shall ensure that the IS Audit covers all critical IT assets including those managed or hosted by third parties, outsourced service providers, and cloud environments. The audit scope shall not be limited to internally managed infrastructure and shall include a review of contractual obligations, access controls, and security standards applicable to all vendors with access to customer data or critical systems.

The 2024 Master Direction removed any ambiguity that existed in prior guidance. "Critical IT assets" is defined broadly, and explicitly includes infrastructure and services that your institution does not directly operate but depends upon for regulated activities.

Three gaps that RBI inspection teams consistently document during Information Systems Audits: scope exclusion by default — VAPT engagement letters exclude cloud-hosted and SaaS vendor environments because the bank does not own the infrastructure, a rationale RBI's 2024 direction explicitly rejects; no contractual security testing rights — vendor contracts do not include a clause permitting the regulated entity to conduct or commission independent security audits, blocking compliance before the first test is scheduled; and risk ratings not updated post-incident — a vendor's risk rating is assessed at onboarding and never revisited when that vendor is compromised in a disclosed breach.

RBI Master Direction (2024), Clause 4.7. Regulated Entities shall ensure that the IS Audit covers all critical IT assets including those managed or hosted by third parties, outsourced service providers, and cloud environments. The audit scope shall not be limited to internally managed infrastructure and shall include a review of contractual obligations, access controls, and security standards applicable to all vendors with access to customer data or critical systems.

The 5 Vendor Categories Indian Enterprises Routinely Skip

Most BFSI security teams treat third-party risk as a procurement checkbox rather than a continuous security posture. The result is five categories of vendors with deep access to your systems that sit entirely outside your VAPT perimeter.

1. Payment Gateways. A payment aggregator's management console is compromised via a credential stuffing attack. The attacker now has read access to transaction metadata — not just yours, but every bank that routes through the same aggregator. They do not touch your perimeter. Your SOC never fires an alert. The data exfiltration happens entirely within a system you treat as external. RBI MD 4.7 and PCI-DSS require these in VAPT scope.

2. KYC Providers. KYC providers ingest Aadhaar numbers, PAN data, liveness videos, and bank account details — often from multiple regulated entities simultaneously. A single API key compromise at the KYC vendor creates a cross-institution data breach that no individual bank's SIEM would detect, because the affected data never moved through the bank's own infrastructure. Linked to DPDP Act Section 8 and RBI MD 4.7.

3. Core Banking Software Vendors. CBS vendors require persistent remote access channels for maintenance and updates. These channels represent privileged pathways into the bank's most sensitive systems. When a CBS vendor's own infrastructure is compromised, the attacker inherits those access paths without ever touching the bank's perimeter defences. RBI MD 4.7 and the CBS circular require these to be audited.

4. Cloud Providers (IaaS). Shared cloud environments with misconfigured IAM policies allow lateral movement between tenants. The shared responsibility model review is often incomplete, leaving a bank's cloud environment as a stepping stone into production databases containing customer financial records. Covered under RBI Cloud Guidance (2022).

5. AML and Fraud Platforms. These platforms have access to transaction monitoring rules, suspicious activity data, and privileged vendor access for rule configuration. Compromised access allows rule manipulation and data exfiltration. PMLA Section 12 and risk-based assessment apply.

Outsourcing a function does not outsource the accountability.

What Third-Party Security Testing Actually Looks Like

Effective vendor security testing is not the same as sending a questionnaire. A questionnaire tells you what a vendor claims about their security. A penetration test tells you what their security actually tolerates. For critical vendors, the gap between those two answers is often significant.

The testing methods, from lowest to highest assurance: Security Questionnaire (VSAQ) covers policy, certifications, and controls self-declaration — appropriate for Tier-3 vendors with low data access. SOC 2 and ISO 27001 review provides independent audit of controls at a point in time — appropriate for Tier-2 vendors. API Security Testing covers authentication, authorisation, and data exposure at integration points — required for all vendors with API-level bank integration. Black-box Penetration Test covers the external attack surface of vendor-exposed systems — required for Tier-1 vendors including payment, KYC, and CBS. Supply Chain Red Team simulates the full attack chain from vendor compromise through lateral movement to bank impact — annual exercise for critical infrastructure vendors. Access Privilege Review audits all vendor credentials and sessions for least-privilege compliance — required for all vendors with persistent system access.

Building a Vendor Security Testing Programme Under RBI

A programme that satisfies RBI's 2024 Master Direction requirements and actually reduces supply chain risk exposure has six operational components.

Step 1: Vendor tiering and criticality classification. Classify every vendor by data access level, system connectivity depth, and regulatory sensitivity. Tier-1 vendors (CBS, payments, KYC) require annual penetration testing minimums. Tier-2 (cloud, analytics) require biannual questionnaires plus API security testing. Tier-3 (low-access SaaS) require annual self-assessments.

Step 2: Contractual security testing rights. Every Tier-1 and Tier-2 vendor contract must include an explicit clause granting the regulated entity or its authorised third-party auditor the right to conduct independent security assessments. Without this clause, you cannot test — and the inspection finding writes itself.

Step 3: Integration point mapping. Document every API endpoint, network connection, credential set, and data flow between your systems and each vendor. This is your attack surface map. VAPT engagements without this map produce incomplete results — testers can only test what they can see.

Step 4: Annual VAPT with vendor-scoped engagements. Your annual VAPT Letter of Engagement must explicitly include Tier-1 vendor environments in scope. For vendors that refuse, escalate to contractual compliance review and document the refusal — that documentation protects you during an inspection.

Step 5: Incident and breach notification obligations. Contracts must require vendors to notify you within 6 hours of any security incident that may affect your data or systems — aligning to CERT-In's mandatory reporting timeline. Many contracts still carry 72-hour windows from pre-2022 templates. Update them.

Step 6: Continuous monitoring and risk reassessment. Subscribe to vendor breach disclosure feeds, dark web monitoring for vendor credential exposures, and CVE tracking for CBS and KYC platform software. Re-run criticality ratings whenever a vendor has a disclosed incident — even if your data was not reportedly affected.

The next wave of significant BFSI breaches in India will not originate from unpatched firewalls or weak perimeter defences. They will come through the payment aggregator whose developer portal had default credentials, through the KYC vendor whose S3 bucket was publicly enumerable, through the CBS maintenance VPN whose MFA was misconfigured. The 2024 RBI Master Direction gives you the mandate to close these gaps. What it cannot give you is the organisational will to do so before an incident forces the issue.

Close your security gaps — continuously.