Skip to main content
RBI, SEBI, NPCI, DPDP — Aligned to every major Indian regulatory third-party mandate

Compliance-Focused Vendor Risk Assessment: Audit, Monitor, and Govern Third-Party Risk

Your vendors tell you they are secure. ShadowMap shows you what is actually exposed. Security Brigade bridges the gap between questionnaire answers and observable reality with structured, regulator-aligned vendor risk assessments.

6,700+
Assessments
1,000+
Clients
Since 2008
CERT-In Empanelled
20 yrs
In Cybersecurity

Trusted by India's leading enterprises

ICICI Bank
NPCI
HDFC
Mahindra
Aditya Birla
PhonePe
Pernod Ricard
Swiggy
Asian Paints
Yes Bank
Tata Play
Larsen & Toubro
Voltas
DHL Express
Etihad Airways
Amazon Pay
Go Digit
Pharmeasy
BillDesk
Jubilant Foods
UltraTech
Titan
Infosys
Capgemini
Groww
Sephora

The rule underneath all of it

The obligation does not move with the workload

Every instrument below says a version of the same thing: you may outsource the work and you may not outsource the accountability. These are the four states we find.

The obligation does not move with the workload
StateWhat it meansWhat follows
Inventory matches contracts You can name every third party that touches your data or your systems, what each one accesses, and which contract governs it. Rare, and it is the precondition for everything else. Without it, an assessment is a discovery exercise billed as an assurance one.
Assessed at onboarding only Due diligence performed once when the vendor was selected, with no reassessment as the relationship, the access or the vendor itself changed. The commonest position. Risk concentrates in the vendors that have been in place longest, which are exactly the ones assessed against the oldest standard.
Questionnaire in place of assurance A completed security questionnaire on file, self-attested, never tested and never compared against the access the vendor actually holds. Provides a document and not an assurance. It is also the artefact most likely to be produced during an inspection and least likely to survive a question about it.
Sub-contractors unmapped Your vendors are assessed; the parties they in turn rely on are invisible to you. Where concentration risk and single points of failure actually live. Several vendors depending on one upstream provider is a risk none of them will report to you.
Key
  • Assurance is possible
  • A document, not an assurance
  • The risk you cannot see

The question about us

Paragraph 135 points at your auditor too

Paragraph 135 of the RBI Directions requires a bank to satisfy itself thoroughly about the credentials of vendor and third-party personnel who access and manage its critical assets, with background verification behind it. That obligation is inbound as well as outbound: when a bank engages Security Brigade, we are the third party, and the same paragraph applies to us. We think a vendor-risk page that cannot answer the question about its own author is not worth much, so: our consultants are permanent employees, background-verified, under written non-disclosure and security-policy agreements, and named to you before an engagement starts. CERT-In’s own audit policy guidelines make the same point from the buyer’s side: section 12 tells auditees to verify the identity and designations of the audit team and states plainly who must not be fielded on an engagement, including freelancers, interns, moonlighters and third-party consultants. It puts the duty to check on the auditee. We would rather you exercised it. The practical version of that is simple: ask any assessment vendor, including us, for the names of the people who will do the work, their credentials, and their employment status, before the engagement is signed, not after the report arrives.

How we run it

Assurance proportionate to what the vendor can actually reach

Vendor tierWho is in itDepth of assurance
Critical Direct access to production, to customer data, or to a system whose failure stops the business. Includes the upstream providers your critical vendors depend on. Technical assessment of the service as delivered to you, evidence review, and the contract read against the obligation
Material Handles personal or regulated data, or holds standing access that is scoped, not privileged. Evidence review with targeted verification: attestations checked for scope and currency, not filed
Routine No access to regulated data or production systems. Questionnaire and contract check, reassessed on a cycle
Concentration Not a vendor but a pattern: several vendors resting on one upstream provider, or one vendor holding several critical functions. Mapped explicitly, because it is the risk paragraph 126 names and the one no individual vendor will report

Critical

Who is in it
Direct access to production, to customer data, or to a system whose failure stops the business. Includes the upstream providers your critical vendors depend on.
Depth of assurance
Technical assessment of the service as delivered to you, evidence review, and the contract read against the obligation

Material

Who is in it
Handles personal or regulated data, or holds standing access that is scoped, not privileged.
Depth of assurance
Evidence review with targeted verification: attestations checked for scope and currency, not filed

Routine

Who is in it
No access to regulated data or production systems.
Depth of assurance
Questionnaire and contract check, reassessed on a cycle

Concentration

Who is in it
Not a vendor but a pattern: several vendors resting on one upstream provider, or one vendor holding several critical functions.
Depth of assurance
Mapped explicitly, because it is the risk paragraph 126 names and the one no individual vendor will report

Methodology

How a compliance engagement runs

Every engagement follows this process through Lemon, our proprietary audit management platform.

This is the core gap in every vendor risk programme: vendors fill questionnaires saying they are compliant, patched, and secure. But questionnaire answers are self-reported and point-in-time. ShadowMap's Vendor Risk Management module continuously scans the external attack surface of every vendor in your ecosystem and surfaces the truth — exposed services, leaked credentials, misconfigured cloud assets, expired certificates, and shadow infrastructure that never appeared on any questionnaire. Security Brigade bridges both sides. We perform the consulting-led audit that gives you the structured, regulator-ready assessment. ShadowMap gives you the continuous, evidence-based monitoring that keeps vendor risk visible between audits. Together, you move from periodic trust to continuous verification.

Discovery
01

TPRM Questionnaire (What They Say)

Self-reported answers, annual or onboarding only, no external validation, compliance on paper.

Testing
02

ShadowMap VRM (What We Observe)

Continuous external scanning, leaked credential detection, exposed service discovery, attack surface evidence that validates or contradicts questionnaire answers.

Delivery
03

Security Brigade Audit (The Bridge)

Consulting-led assessment that combines questionnaire review, technical validation, ShadowMap intelligence, and regulator-specific control mapping into a single defensible report.

"We needed an assessment on a 3-week timeline because of a partner integration deadline. Security Brigade turned it around in 18 days, including the L2 and L3 reviews. The report was regulator-ready — we submitted it to our partner's compliance team unchanged. When speed and credibility both matter, they're the only call we make."
VP Engineering, Retail & Quick Commerce
Vice President — Engineering

Read more client stories →

Audit + Platform

What does the vendor say? vs. What does ShadowMap observe?

TPRM tells you what vendors claim, submit, and attest. VRM tells you what ShadowMap observes independently across attack surface, credential exposure, and dark-web footprint. Together they close the gap between self-attestation and real exposure.

See the full ShadowMap platform 30-day POC available · Platform Only · Service Only · Hybrid

FAQ

Vendor risk, answered

Scope, depth and the obligation behind it. Talk to our team about your vendor estate.

Contact us
Which regulation requires vendor risk assessment?+
Several, and most organisations are caught by more than one. The RBI Directions, 2026 require a vendor risk assessment process at paragraph 126 with controls proportionate to assessed risk and materiality, and place accountability for security in outsourced and partner arrangements with the bank at paragraph 127. SEBI CSCRF requires suppliers and third parties to be identified, prioritised and assessed under GV.SC.S2. The DPDP Act requires processing on your behalf to be under a valid contract while leaving the security duty with you. Running one programme that answers all of them is materially cheaper than running three.
Is a completed security questionnaire enough?+
For a routine vendor with no access to regulated data or production, usually yes. For a vendor holding production access or customer data it is a starting point and not an assurance: it is self-attested, rarely tested, and frequently describes a scope different from the service you actually buy. The useful check on any attestation is whether its scope covers what the vendor delivers to you, which is a question most questionnaires do not ask.
How do we handle sub-contractors we cannot see?+
By making them contractual instead of invisible: require disclosure of parties who will touch your data, and flow equivalent obligations down. This is where concentration risk lives, and paragraph 126 names concentration risk and single points of failure specifically. Several of your vendors resting on one upstream provider is a risk none of them has an incentive to report, so it has to be mapped deliberately.
How often should vendors be reassessed?+
On a cycle proportionate to tier, and on change. A vendor that gains production access, acquires another company, moves its hosting or suffers an incident should be reassessed then, not at the next annual date. The pattern we see most often is thorough diligence at onboarding and nothing afterwards, which concentrates unassessed risk in the longest-standing relationships.
Can you assess us as a vendor to our customers?+
Yes, and it is a common engagement. Where your enterprise customers run vendor security reviews, an independent assessment with evidence behind it answers a large share of the questionnaire before it arrives, and shortens the review. The same testing evidence supports an ISO 27001 or SOC 2 programme if you are running one.

Start Governing Your Vendor Risk Today

Whether you need a one-time regulator-ready audit, continuous vendor monitoring through ShadowMap, or a hybrid programme that combines both — the first step is a 30-minute scoping call.

Typically responds within 1 business day · No commitment required

Request a Scoping Call