01
Vendor inventory and criticality tiering
Risk: Critical service providers are treated like routine vendors, so oversight effort is not aligned to operational dependency, data access, regulatory exposure or exit difficulty.
Control: Maintain a complete vendor inventory and assign risk tiers using service criticality, data handled, system access, customer impact, compliance sensitivity, concentration and substitutability.
Tests
- Reconcile vendor inventory to AP, procurement, IT and business-owner lists
- Check whether critical vendors have named business owners and review cadence
- Reperform tiering for selected high-spend and high-access vendors
Evidence
Vendor inventory, AP vendor master, contract register, risk-tier methodology, business-owner mapping and last risk review.
02
Onboarding due diligence
Risk: A vendor is appointed before capability, financial health, cyber posture, compliance status, ownership, sanctions, conflict and business-continuity risks are understood.
Control: Risk-based due diligence is completed before onboarding and renewed periodically for critical vendors.
Tests
- Inspect due diligence files for selected critical vendors
- Check whether cyber, privacy, BCP, financial and compliance checks scale with tier
- Review exceptions approved before onboarding
Evidence
Due diligence checklist, financials, ownership declarations, compliance certificates, cyber questionnaire, BCP evidence, conflict declaration and approval note.
03
Contract, audit rights and data clauses
Risk: The contract does not give the entity practical rights over audit, records, incident notification, data return, confidentiality, subcontractors, SLAs or exit support.
Control: Critical vendor contracts include audit rights, records access, SLA/KPI clauses, breach notification, confidentiality, data handling, sub-outsourcing approval and exit/data-return obligations.
Tests
- Read selected critical contracts against the clause checklist
- Verify whether audit and inspection rights are usable, not only legal boilerplate
- Trace renewal or amendment controls for expired and modified contracts
Evidence
Executed contract, SLA appendix, data processing terms, confidentiality clauses, right-to-audit language, amendment log and renewal tracker.
04
SLA, KPI and performance monitoring
Risk: Service failures, missed deliverables and customer-impacting issues continue because SLA performance is not measured, challenged or escalated.
Control: Owners review SLA/KPI performance on an agreed cadence, investigate breaches and track corrective actions.
Tests
- Compare contracted SLA metrics with actual monitoring reports
- Test breach escalation and root-cause records
- Review recurring service credits, complaints and unresolved tickets
Evidence
SLA dashboard, ticket dump, breach log, service-credit working, review minutes, escalation emails and action tracker.
05
Cyber, access and data protection
Risk: The vendor can access systems or data without adequate access review, incident visibility, log retention, encryption, employee controls or secure offboarding.
Control: Vendor access and data handling are governed through least-privilege access, periodic access review, incident reporting, secure transfer/storage rules and offboarding evidence.
Tests
- Match vendor users to approved access lists and business need
- Review vendor admin accounts, shared IDs and leavers
- Inspect incident notification and log-retention evidence for critical systems
Evidence
Vendor user list, IAM export, access approvals, data-flow map, transfer protocol, incident register, logs, offboarding tickets and access-review sign-off.
06
Sub-outsourcing and fourth-party visibility
Risk: The primary vendor further outsources key work to an unknown party, creating data, location, continuity and accountability risk outside the original due diligence.
Control: Sub-outsourcing requires disclosure, approval, contractual flow-down obligations, location visibility and periodic review for critical services.
Tests
- Request subcontractor lists for critical vendors
- Inspect approval evidence for sub-outsourcing
- Check whether contract clauses flow down security, audit, confidentiality and BCP obligations
Evidence
Subcontractor register, vendor disclosure, approval note, fourth-party risk review, location map and contract flow-down clauses.
07
Business continuity and operational resilience
Risk: The entity cannot continue a critical process if the vendor suffers outage, cyber incident, staff disruption, insolvency, data loss or service termination.
Control: Critical vendors have tested BCP/DR arrangements, RTO/RPO expectations, fallback procedures and business-owner review of test results.
Tests
- Inspect latest BCP/DR test evidence and exceptions
- Check whether entity fallback procedures are documented and tested
- Compare RTO/RPO expectations with actual recovery evidence
Evidence
BCP/DR plan, DR test report, RTO/RPO, outage log, fallback SOP, tabletop exercise records and management review.
08
Financial health, concentration and continuity
Risk: The entity depends on a vendor that is financially weak, concentrated, politically exposed, under sanctions pressure or unable to sustain service quality.
Control: Critical vendors are monitored for financial health, ownership change, concentration exposure, litigation, adverse news and continuity risk.
Tests
- Review financial-health checks for critical vendors
- Inspect ownership-change and adverse-news monitoring
- Check concentration by spend, process and geography
Evidence
Financial review, credit report where available, ownership declaration, adverse-news search, concentration report and continuity risk note.
09
Regulatory and client-data obligations
Risk: The outsourcing arrangement breaches sector rules, client confidentiality, data protection, record availability, professional obligations or regulator inspection expectations.
Control: Owners map applicable RBI, SEBI, IRDAI, DPDP, contractual, professional and sector-specific obligations before approving critical outsourcing.
Tests
- Check whether regulatory applicability is documented by vendor type
- Review evidence that records remain available to the entity and auditor
- Inspect how client/customer data is segregated and returned
Evidence
Regulatory applicability matrix, data processing records, client confidentiality terms, record-retention policy, inspection-right clauses and compliance attestations.
10
Exit readiness and transition plan
Risk: The company cannot exit or replace a critical vendor without service disruption, data loss, lock-in, regulatory breach or loss of historical records.
Control: Critical vendors have an exit plan covering alternate arrangements, transition period, data return/destruction, knowledge transfer, handover support and minimum notice.
Tests
- Inspect exit plans for selected critical vendors
- Check whether data return/destruction obligations are practical and tested
- Review transition assumptions for single-source or high-lock-in providers
Evidence
Exit plan, alternate vendor analysis, transition checklist, data-return terms, destruction certificate format, knowledge-transfer plan and notice-period clauses.