Third-Party Risk Management in India: Vendor Due Diligence, Contract Controls, Data Risk, Monitoring & Board Oversight Guide 2026
A corporate-standard framework for managing vendor, supplier, consultant, agent, technology, logistics and outsourcing risk across the entire third-party lifecycle.
Third parties can create legal, financial and operational exposure even where the company itself follows strong internal controls. Vendors can mishandle personal data, subcontract work without approval, submit inflated invoices, create bribery or conflict risk, fail to maintain licences, disrupt critical operations, leak confidential information or become financially distressed.
A mature third-party risk programme therefore does not stop at obtaining a PAN, GST registration and signed agreement. It determines which third parties matter most, what risk each creates, what evidence supports onboarding, what controls apply during the relationship, and how the company will respond when the risk changes.
1. Build a complete third-party universe
Start by identifying every material external party through which the business depends, pays, sells, stores data, provides services or interacts with customers. Typical categories include suppliers, transporters, warehouse operators, consultants, manpower agencies, recruitment firms, sales agents, distributors, technology vendors, SaaS providers, cloud providers, payment intermediaries, professional advisers, contractors and subcontractors.
The register should capture legal name, ownership, service, business owner, location, contract, spend, data access, system access, customer interaction, government interaction where relevant, subcontracting, renewal date and risk tier.
This wider architecture should connect to the Corporate Risk Mitigation in India pillar.
2. Risk-tier third parties before deciding diligence depth
| Tier | Illustrative characteristics | Expected review |
|---|---|---|
| Critical | Business continuity dependency, privileged systems, sensitive data, major customer-facing service | Enhanced diligence, security review, financial review, audit rights, continuity and exit plan |
| High | High spend, payment handling, subcontracting, regulatory or reputation exposure | Enhanced KYC, ownership/conflict checks, stronger contract and annual monitoring |
| Medium | Routine operational vendor with moderate dependency | Standard diligence, contract and periodic review |
| Low | Low-value, low-access, substitutable provider | Basic verification and commercial controls |
3. Pre-onboarding due diligence
Core diligence may include legal identity, incorporation or registration, tax registrations, beneficial or controlling ownership where relevant, authorised signatories, bank details, licences, litigation or regulatory issues material to the service, financial capability, insurance, references and conflict-of-interest checks.
Enhanced diligence should be used where the vendor will control cash, sensitive data, customer interaction, critical infrastructure, high-value procurement or relationships with public authorities. The objective is not to collect every available document; it is to verify facts that are relevant to the proposed risk.
For fraud-focused onboarding controls, see Vendor & Procurement Fraud Risk in India.
4. Conflict-of-interest and related-party screening
Vendor risk increases materially where employees, directors, promoters or their connected interests have undisclosed relationships with the third party. High-risk functions such as procurement, finance, sales, administration, facilities and logistics should therefore operate periodic conflict declarations.
Where lawful and proportionate, company records can be tested for duplicate addresses, phone numbers, email domains, bank accounts or other indicators that warrant verification. A match is an exception requiring inquiry, not proof of collusion.
5. Contract controls should follow the risk
Third-party contracts should address the actual service and risk profile. Material provisions commonly include defined scope and service levels, pricing and taxes, invoicing evidence, change control, confidentiality, data protection, information security, intellectual property, subcontracting, audit rights, records retention, insurance, representations, compliance obligations, indemnity, liability allocation, business continuity, incident notification, termination, transition support and return or deletion of information.
A contract is not a substitute for vendor governance. It creates enforceable rights; the business must still monitor whether the rights are being used.
See Contract Risk Audit in India for portfolio-level controls.
6. Data processors, SaaS and technology vendors
Where third parties receive personal, confidential or commercially sensitive data, the review should identify data categories, processing purpose, hosting location, authorised users, subprocessors, encryption, access controls, incident response, backup, deletion, return of data and termination assistance.
Companies should evaluate the Digital Personal Data Protection Act, 2023 and applicable rules according to their legally operative commencement position. Existing Information Technology and CERT-In requirements may also be relevant to security and incident response. Contracts should require prompt cooperation where a vendor incident creates an obligation for the company.
For incident response, see Cyber & Data Incident Legal Response in India.
7. Bank-account changes are a high-risk control point
A vendor-bank change can create immediate payment-loss exposure. Changes should be independently verified through an established contact channel rather than solely through the email requesting the change. The system should preserve who requested the change, who verified it, who approved it and when the new account became active.
High-risk changes should trigger enhanced review if they occur immediately before a large payment, involve an unfamiliar domain, bypass ordinary onboarding or repeatedly affect the same vendor group.
8. Subcontractor and fourth-party risk
A critical vendor may rely on other providers that the company never directly selected. Contracts should therefore define when subcontracting is permitted, whether approval is required, which obligations must flow down, and whether the primary vendor remains accountable.
For data, technology, logistics and outsourced operations, fourth-party dependency can be a continuity issue. The company should know whether one hidden subcontractor supports multiple critical services.
9. Ongoing monitoring after onboarding
Monitoring should be risk-based. Useful indicators include service-level failures, repeated complaints, unexplained price changes, frequent bank-detail changes, regulatory notices, financial distress, staff turnover, security incidents, subcontractor changes, insurance expiry, licence expiry, unusual claims and repeated emergency procurement.
Critical and high-risk vendors should be periodically recertified. A vendor that was acceptable three years ago may present a different risk after ownership change, merger, financial decline, data incident or major service expansion.
10. Third-party incident protocol
When a vendor incident occurs, identify the affected service, customers or data; preserve records; activate contractual notification and cooperation clauses; assess regulator, insurer and customer obligations; determine continuity alternatives; and preserve claims or indemnity rights.
The company should avoid terminating a critical vendor impulsively if doing so would destroy access to evidence or create an operational outage. Containment, investigation, replacement and legal strategy should be coordinated.
11. Exit and transition risk
Vendor offboarding should cover access revocation, return or deletion of data, device or credential recovery, transition assistance, final invoicing, unresolved claims, confidentiality, IP, audit evidence and confirmation that subcontractors have also ceased access where required.
Critical vendors should have an exit or substitution plan before a crisis occurs. Dependency without a transition plan can turn a contract dispute into a business-continuity event.
12. Third-party risk scoring matrix
| Risk area | Key question | High-risk indicator |
|---|---|---|
| Financial | Can failure cause material loss or interruption? | High spend, weak finances, dependency |
| Data | What sensitive information is accessible? | Bulk personal/confidential data or privileged access |
| Operational | How replaceable is the provider? | Single-point dependency |
| Integrity | Are conflicts or unusual payment patterns present? | Undisclosed links, override, opaque ownership |
| Regulatory | Can the vendor expose the company to regulatory consequences? | Licence, data, safety or customer-facing dependency |
13. Board and management deliverables
- complete third-party register;
- risk-tier methodology;
- critical-vendor list;
- due-diligence exception schedule;
- conflict and related-party exception register;
- contract-gap matrix;
- data/technology vendor control summary;
- bank-change exception register;
- incident and SLA dashboard;
- expired licence/insurance tracker;
- remediation owner and deadline matrix; and
- critical-vendor exit/continuity plan.
14. 30/60/90-day implementation plan
0–30 days: identify critical vendors, freeze unsupported bank changes, classify data/system access, collect missing contracts and assign business owners.
31–60 days: complete enhanced diligence, remediate contract gaps, obtain conflict declarations, confirm subcontractors, review security and continuity controls, and close expired licences or insurance.
61–90 days: implement periodic recertification, automated expiry reminders, incident dashboards, exception monitoring and board reporting for critical third parties.
15. Frequently asked questions
Is vendor KYC enough?
No. KYC verifies identity; third-party risk also includes data, operational, financial, integrity, contractual and continuity exposure.
Should every vendor undergo the same checks?
No. The review should be proportionate to the vendor’s risk and access.
Who owns third-party risk?
The business function using the vendor should remain accountable, supported by procurement, finance, legal, compliance, information security and other control functions as relevant.
How often should critical vendors be reviewed?
Periodically and whenever a material trigger occurs, such as ownership change, major incident, service expansion, financial distress or regulatory issue.
What is the biggest overlooked third-party risk?
Often it is concentration and dependency: a vendor may be contractually replaceable but operationally impossible to replace quickly.
Authoritative references
- Companies Act, 2013 — India Code
- Digital Personal Data Protection Act, 2023 — India Code
- CERT-In Directions dated 28 April 2022
Author: Adv. Govind Bali, Fastrack Legal Solutions LLP.