Compliance-Focused Vendor Risk Assessment: Audit, Monitor, and Govern Third-Party Risk
Your vendors tell you they are secure. ShadowMap shows you what is actually exposed. Security Brigade bridges the gap between questionnaire answers and observable reality with structured, regulator-aligned vendor risk assessments.
Trusted by India's leading enterprises
The rule underneath all of it
The obligation does not move with the workload
Every instrument below says a version of the same thing: you may outsource the work and you may not outsource the accountability. These are the four states we find.
| State | What it means | What follows |
|---|---|---|
| Inventory matches contracts | You can name every third party that touches your data or your systems, what each one accesses, and which contract governs it. | Rare, and it is the precondition for everything else. Without it, an assessment is a discovery exercise billed as an assurance one. |
| Assessed at onboarding only | Due diligence performed once when the vendor was selected, with no reassessment as the relationship, the access or the vendor itself changed. | The commonest position. Risk concentrates in the vendors that have been in place longest, which are exactly the ones assessed against the oldest standard. |
| Questionnaire in place of assurance | A completed security questionnaire on file, self-attested, never tested and never compared against the access the vendor actually holds. | Provides a document and not an assurance. It is also the artefact most likely to be produced during an inspection and least likely to survive a question about it. |
| Sub-contractors unmapped | Your vendors are assessed; the parties they in turn rely on are invisible to you. | Where concentration risk and single points of failure actually live. Several vendors depending on one upstream provider is a risk none of them will report to you. |
- Assurance is possible
- A document, not an assurance
- The risk you cannot see
Four instruments, one duty
Whoever regulates you has already asked for this
RBI Directions, 2026
A vendor risk assessment process with controls proportionate to assessed risk and materiality, addressing concentration risk, conflicts of interest and single points of failure, and at paragraph 127 accountability for security risks in outsourced and partner arrangements sitting with the bank.
GV.SC.S2SEBI CSCRF
Suppliers and third-party service providers identified, prioritised and assessed through a cyber-supply-chain risk assessment process, which the clarifications of 28 August 2025 allow to be done in consultation with the entity’s IT committee.
ProcessorsDPDP Act, 2023
Processing by a Data Processor on behalf of a Data Fiduciary must be under a valid contract, and the section 8(4) duty to take reasonable security safeguards stays with the Fiduciary whoever operates the system.
Your enterprise customers
For most organisations the binding constraint is not a regulator but a customer’s vendor security review, which arrives with its own questionnaire, its own evidence expectations and a deal attached to the answer.
The question about us
Paragraph 135 points at your auditor too
Paragraph 135 of the RBI Directions requires a bank to satisfy itself thoroughly about the credentials of vendor and third-party personnel who access and manage its critical assets, with background verification behind it. That obligation is inbound as well as outbound: when a bank engages Security Brigade, we are the third party, and the same paragraph applies to us. We think a vendor-risk page that cannot answer the question about its own author is not worth much, so: our consultants are permanent employees, background-verified, under written non-disclosure and security-policy agreements, and named to you before an engagement starts. CERT-In’s own audit policy guidelines make the same point from the buyer’s side: section 12 tells auditees to verify the identity and designations of the audit team and states plainly who must not be fielded on an engagement, including freelancers, interns, moonlighters and third-party consultants. It puts the duty to check on the auditee. We would rather you exercised it. The practical version of that is simple: ask any assessment vendor, including us, for the names of the people who will do the work, their credentials, and their employment status, before the engagement is signed, not after the report arrives.
How we run it
Assurance proportionate to what the vendor can actually reach
| Vendor tier | Who is in it | Depth of assurance |
|---|---|---|
| Critical | Direct access to production, to customer data, or to a system whose failure stops the business. Includes the upstream providers your critical vendors depend on. | Technical assessment of the service as delivered to you, evidence review, and the contract read against the obligation |
| Material | Handles personal or regulated data, or holds standing access that is scoped, not privileged. | Evidence review with targeted verification: attestations checked for scope and currency, not filed |
| Routine | No access to regulated data or production systems. | Questionnaire and contract check, reassessed on a cycle |
| Concentration | Not a vendor but a pattern: several vendors resting on one upstream provider, or one vendor holding several critical functions. | Mapped explicitly, because it is the risk paragraph 126 names and the one no individual vendor will report |
Critical
- Who is in it
- Direct access to production, to customer data, or to a system whose failure stops the business. Includes the upstream providers your critical vendors depend on.
- Depth of assurance
- Technical assessment of the service as delivered to you, evidence review, and the contract read against the obligation
Material
- Who is in it
- Handles personal or regulated data, or holds standing access that is scoped, not privileged.
- Depth of assurance
- Evidence review with targeted verification: attestations checked for scope and currency, not filed
Routine
- Who is in it
- No access to regulated data or production systems.
- Depth of assurance
- Questionnaire and contract check, reassessed on a cycle
Concentration
- Who is in it
- Not a vendor but a pattern: several vendors resting on one upstream provider, or one vendor holding several critical functions.
- Depth of assurance
- Mapped explicitly, because it is the risk paragraph 126 names and the one no individual vendor will report
Methodology
How a compliance engagement runs
Every engagement follows this process through Lemon, our proprietary audit management platform.
This is the core gap in every vendor risk programme: vendors fill questionnaires saying they are compliant, patched, and secure. But questionnaire answers are self-reported and point-in-time. ShadowMap's Vendor Risk Management module continuously scans the external attack surface of every vendor in your ecosystem and surfaces the truth — exposed services, leaked credentials, misconfigured cloud assets, expired certificates, and shadow infrastructure that never appeared on any questionnaire. Security Brigade bridges both sides. We perform the consulting-led audit that gives you the structured, regulator-ready assessment. ShadowMap gives you the continuous, evidence-based monitoring that keeps vendor risk visible between audits. Together, you move from periodic trust to continuous verification.
TPRM Questionnaire (What They Say)
Self-reported answers, annual or onboarding only, no external validation, compliance on paper.
ShadowMap VRM (What We Observe)
Continuous external scanning, leaked credential detection, exposed service discovery, attack surface evidence that validates or contradicts questionnaire answers.
Security Brigade Audit (The Bridge)
Consulting-led assessment that combines questionnaire review, technical validation, ShadowMap intelligence, and regulator-specific control mapping into a single defensible report.
"We needed an assessment on a 3-week timeline because of a partner integration deadline. Security Brigade turned it around in 18 days, including the L2 and L3 reviews. The report was regulator-ready — we submitted it to our partner's compliance team unchanged. When speed and credibility both matter, they're the only call we make."
Audit + Platform
What does the vendor say? vs. What does ShadowMap observe?
TPRM tells you what vendors claim, submit, and attest. VRM tells you what ShadowMap observes independently across attack surface, credential exposure, and dark-web footprint. Together they close the gap between self-attestation and real exposure.
FAQ
Vendor risk, answered
Scope, depth and the obligation behind it. Talk to our team about your vendor estate.
Contact usWhich regulation requires vendor risk assessment?
Is a completed security questionnaire enough?
How do we handle sub-contractors we cannot see?
How often should vendors be reassessed?
Can you assess us as a vendor to our customers?
Start Governing Your Vendor Risk Today
Whether you need a one-time regulator-ready audit, continuous vendor monitoring through ShadowMap, or a hybrid programme that combines both — the first step is a 30-minute scoping call.
Typically responds within 1 business day · No commitment required