Table of Contents
When RBI tightened risk weights on unsecured consumer credit in November 2023, several regulated lenders discovered they did not actually know what was sitting inside loans they had funded through digital lending partners. The vendor questionnaire was complete. The FLDG was in place. The contract had indemnity. None of it answered the actual question: when balance sheet, customers, and regulatory accountability all flow through third parties you do not own, where does the risk live, and who is governing it end to end?
Third-Party and Technology Dependency Risks in Indian Banking, 2023-25
The CrowdStrike outage in July 2024 made global headlines. The more instructive incidents for BFSI leaders are closer to home, and they trace a single pattern.
C-Edge Ransomware Incident
A ransomware attack on C-Edge Technologies, a shared technology services provider, disrupted payment systems across roughly 300 small co-operative and regional rural banks for several days. One fourth-party dependency. Hundreds of regulated entities offline simultaneously.
Paytm Payments Bank Wind-Down
When RBI restricted PPBL operations, the impact rippled across merchants, FASTag users, and partner platforms that had built customer journeys assuming continuity. Concentration risk that looked like a commercial choice in good times became a continuity problem overnight.
The Governance Pattern Underneath
The regulated entity carries the consequence of operational failure, even when the root cause sits at a partner or vendor layer. Concentration and governance gaps become continuity risks overnight.
RBI's Digital Lending Guidelines and the DPDP Act now sit on the same principle: accountability for what happens at a third party stays with the regulated entity. Periodic vendor review is no longer the bar. Continuous oversight is.
From Managing Vendors To Governing The Ecosystem The Bank Actually Operates In
Most BFSI TPRM programmes are organised around one question: are our vendors compliant? It is fine for an audit committee deck and wrong for a CRO. Institutions that are ahead have reframed it. How does our dependency architecture create systemic risk, and what does it take to govern that at the ecosystem level? The reframing produces a different operating model, where the primary control is not a contract clause but a resilience property engineered into how the bank actually runs.
Join Our Newsletter
Get exclusive insights on banking, fintech, regulatory updates and industry trends delivered to your inbox.
"Resilience is not a clause in a contract. It is a property of how the bank is built, and it has to be engineered, not negotiated."
Two Capabilities That Separate The Programmes That Will Hold From The Ones That Won't
- Tier and Monitor by Function, Continuously
An LSP touching credit decisions, a KYC vendor running Aadhaar-based onboarding, and a back-office SaaS do not carry the same risk. Tier them by data access, customer impact, and regulatory exposure, then wire signal-based monitoring on tier-1 partners into portfolio and operational dashboards. Annual reviews cannot detect what changes in a quarter. - Engineer Resilience and Exit-Readiness
Assume every tier-1 partner will eventually fail. Run joint tabletop exercises, test BCP and DR, and assess exit feasibility before it is needed. Map fourth-party concentration: where do multiple critical partners share a common cloud region or upstream stack? That is where correlated failure lives.
The institutions that will set the standard for Indian BFSI risk governance over the next decade are not the ones with the highest vendor questionnaire completion rates. They are the ones that understood the structural difference between managing vendors and governing ecosystems, and rebuilt the operating model to match.
The Board Question
If your largest LSP, payment aggregator, or cloud region went down or into regulatory crisis tomorrow, would the bank know within hours, hold customer service for the next 72, and have an exit path inside 90 days? If the answer is “no” or “we’re not sure,” the programme needs to be redesigned, not tuned.
Cloud migration in BFSI has been framed as an infrastructure project for too long. Procurement timelines, vendor contracts, data centre exits. The framing is what produces lift-and-shift as the default answer, because that is the shape of question being asked.
The banks pulling away from the pack are running a different conversation at the top. What architecture makes us faster on credit decisions, more compliant by default, more profitable per customer, more ready for the next regulatory shift. Cloud is one input into that answer. It is not the answer.
Moving problems to someone else’s server and paying by the hour for the privilege is not transformation. It is a more expensive version of the system you wanted to leave behind. Redesign or regret. There is no third option that survives a finance review at year three.
Rethinking Third-Party Risk for an Ecosystem Bank?
The Digital Fifth works with banks, NBFCs, and insurers on TPRM design, RBI and DPDP alignment, LSP and partnership governance, and the operating model shift from vendor management to ecosystem governance.