CORAA
Resources - Internal Audit

Third-party outsourcing risk.

A third-party outsourcing risk internal audit evaluates how an organization relies on critical external service providers. The audit should cover vendor criticality, due diligence, contracts, SLA monitoring, data and system access, incidents, sub-outsourcing, continuity, financial health and exit readiness - not only purchase invoices.

Download Word checklistBuild data request list
Source signals

Why this belongs in the 2026 audit plan matters

SIA 530

ICAI lists Third Party Service Provider as a specialised Standard on Internal Audit, alongside SIA 520 for IT environment work.

ICAI IASB publications

48%

KPMG reports regulatory compliance as the top driver shaping third-party risk strategy in its 2026 global survey.

KPMG Global TPRM Survey 2026

37%

Cyber risk is the next major driver in the same 2026 third-party risk survey.

KPMG Global TPRM Survey 2026

10 Apr 2023

RBI issued its Master Direction on Outsourcing of IT Services for regulated entities, covering governance, audits, monitoring and exit strategy.

Reserve Bank of India

Scope boundary

This is not just vendor master testing not AP

Use the P2P checklist for vendor onboarding, PO, GRN, invoice, GST/TDS/MSME and payment controls. Use this guide when the risk is dependency: payroll processor, cloud ERP host, logistics partner, call centre, payment gateway, outsourced IT, collection agency, support vendor, AI provider or any service provider that can interrupt operations, expose data or affect compliance.

Lifecycle RCM

Ten areas to test areas

01

Vendor inventory and criticality tiering

Risk: Critical service providers are treated like routine vendors, so oversight effort is not aligned to operational dependency, data access, regulatory exposure or exit difficulty.

Control: Maintain a complete vendor inventory and assign risk tiers using service criticality, data handled, system access, customer impact, compliance sensitivity, concentration and substitutability.

Tests
  • Reconcile vendor inventory to AP, procurement, IT and business-owner lists
  • Check whether critical vendors have named business owners and review cadence
  • Reperform tiering for selected high-spend and high-access vendors
Evidence

Vendor inventory, AP vendor master, contract register, risk-tier methodology, business-owner mapping and last risk review.

02

Onboarding due diligence

Risk: A vendor is appointed before capability, financial health, cyber posture, compliance status, ownership, sanctions, conflict and business-continuity risks are understood.

Control: Risk-based due diligence is completed before onboarding and renewed periodically for critical vendors.

Tests
  • Inspect due diligence files for selected critical vendors
  • Check whether cyber, privacy, BCP, financial and compliance checks scale with tier
  • Review exceptions approved before onboarding
Evidence

Due diligence checklist, financials, ownership declarations, compliance certificates, cyber questionnaire, BCP evidence, conflict declaration and approval note.

03

Contract, audit rights and data clauses

Risk: The contract does not give the entity practical rights over audit, records, incident notification, data return, confidentiality, subcontractors, SLAs or exit support.

Control: Critical vendor contracts include audit rights, records access, SLA/KPI clauses, breach notification, confidentiality, data handling, sub-outsourcing approval and exit/data-return obligations.

Tests
  • Read selected critical contracts against the clause checklist
  • Verify whether audit and inspection rights are usable, not only legal boilerplate
  • Trace renewal or amendment controls for expired and modified contracts
Evidence

Executed contract, SLA appendix, data processing terms, confidentiality clauses, right-to-audit language, amendment log and renewal tracker.

04

SLA, KPI and performance monitoring

Risk: Service failures, missed deliverables and customer-impacting issues continue because SLA performance is not measured, challenged or escalated.

Control: Owners review SLA/KPI performance on an agreed cadence, investigate breaches and track corrective actions.

Tests
  • Compare contracted SLA metrics with actual monitoring reports
  • Test breach escalation and root-cause records
  • Review recurring service credits, complaints and unresolved tickets
Evidence

SLA dashboard, ticket dump, breach log, service-credit working, review minutes, escalation emails and action tracker.

05

Cyber, access and data protection

Risk: The vendor can access systems or data without adequate access review, incident visibility, log retention, encryption, employee controls or secure offboarding.

Control: Vendor access and data handling are governed through least-privilege access, periodic access review, incident reporting, secure transfer/storage rules and offboarding evidence.

Tests
  • Match vendor users to approved access lists and business need
  • Review vendor admin accounts, shared IDs and leavers
  • Inspect incident notification and log-retention evidence for critical systems
Evidence

Vendor user list, IAM export, access approvals, data-flow map, transfer protocol, incident register, logs, offboarding tickets and access-review sign-off.

06

Sub-outsourcing and fourth-party visibility

Risk: The primary vendor further outsources key work to an unknown party, creating data, location, continuity and accountability risk outside the original due diligence.

Control: Sub-outsourcing requires disclosure, approval, contractual flow-down obligations, location visibility and periodic review for critical services.

Tests
  • Request subcontractor lists for critical vendors
  • Inspect approval evidence for sub-outsourcing
  • Check whether contract clauses flow down security, audit, confidentiality and BCP obligations
Evidence

Subcontractor register, vendor disclosure, approval note, fourth-party risk review, location map and contract flow-down clauses.

07

Business continuity and operational resilience

Risk: The entity cannot continue a critical process if the vendor suffers outage, cyber incident, staff disruption, insolvency, data loss or service termination.

Control: Critical vendors have tested BCP/DR arrangements, RTO/RPO expectations, fallback procedures and business-owner review of test results.

Tests
  • Inspect latest BCP/DR test evidence and exceptions
  • Check whether entity fallback procedures are documented and tested
  • Compare RTO/RPO expectations with actual recovery evidence
Evidence

BCP/DR plan, DR test report, RTO/RPO, outage log, fallback SOP, tabletop exercise records and management review.

08

Financial health, concentration and continuity

Risk: The entity depends on a vendor that is financially weak, concentrated, politically exposed, under sanctions pressure or unable to sustain service quality.

Control: Critical vendors are monitored for financial health, ownership change, concentration exposure, litigation, adverse news and continuity risk.

Tests
  • Review financial-health checks for critical vendors
  • Inspect ownership-change and adverse-news monitoring
  • Check concentration by spend, process and geography
Evidence

Financial review, credit report where available, ownership declaration, adverse-news search, concentration report and continuity risk note.

09

Regulatory and client-data obligations

Risk: The outsourcing arrangement breaches sector rules, client confidentiality, data protection, record availability, professional obligations or regulator inspection expectations.

Control: Owners map applicable RBI, SEBI, IRDAI, DPDP, contractual, professional and sector-specific obligations before approving critical outsourcing.

Tests
  • Check whether regulatory applicability is documented by vendor type
  • Review evidence that records remain available to the entity and auditor
  • Inspect how client/customer data is segregated and returned
Evidence

Regulatory applicability matrix, data processing records, client confidentiality terms, record-retention policy, inspection-right clauses and compliance attestations.

10

Exit readiness and transition plan

Risk: The company cannot exit or replace a critical vendor without service disruption, data loss, lock-in, regulatory breach or loss of historical records.

Control: Critical vendors have an exit plan covering alternate arrangements, transition period, data return/destruction, knowledge transfer, handover support and minimum notice.

Tests
  • Inspect exit plans for selected critical vendors
  • Check whether data return/destruction obligations are practical and tested
  • Review transition assumptions for single-source or high-lock-in providers
Evidence

Exit plan, alternate vendor analysis, transition checklist, data-return terms, destruction certificate format, knowledge-transfer plan and notice-period clauses.

PBC list

Evidence to request first evidence

Vendor inventory with risk tier, business owner, service description, data access and system access

Outsourcing and vendor-risk policy, tiering methodology and approval matrix

Critical vendor contracts, SLA appendices, data clauses, right-to-audit clauses and renewal tracker

Due diligence files: financial, cyber, privacy, compliance, ownership, conflict and BCP evidence

SLA/KPI dashboards, ticket exports, breach logs, service-credit workings and review minutes

Vendor user access lists, privileged account reports, leaver/offboarding tickets and access-review sign-offs

Incident register, breach notification records, root-cause analyses and corrective-action tracker

Subcontractor register, sub-outsourcing approvals, fourth-party locations and flow-down contract clauses

BCP/DR plans, test reports, outage history, fallback SOPs, RTO/RPO and business-owner review evidence

Exit plans, data return/destruction clauses, transition plan, alternate-provider assessment and knowledge-transfer checklist

Continuous monitoring

Exception rules worth automating rules

High-risk vendor without current review

Critical or high-risk vendor has no completed risk review within the required cadence.

Expired contract or missing SLA

Active critical vendor has expired contract, missing SLA appendix or unapproved extension.

Repeated SLA breach

Same vendor breaches the same KPI in two or more periods without closed corrective action.

Vendor incident ageing

Open vendor incident remains unresolved beyond severity-based timeline or lacks root-cause analysis.

Subcontractor change without approval

Critical vendor adds or changes subcontractor without recorded business, legal, security or risk approval.

Vendor access after service end

Vendor user account remains active after contract end, project closure or service termination.

Critical vendor without BCP test

Critical vendor has no recent DR/BCP test evidence or unresolved recovery exceptions.

No exit plan for lock-in vendor

Vendor marked critical or hard-to-replace has no exit plan, data-return clause or alternate arrangement.

Reporting

Common observations findings

Critical vendors are not tiered

The vendor inventory does not classify service providers by criticality, data access, regulatory exposure or exit difficulty. As a result, critical payroll, cloud, logistics and payment-service vendors receive the same review cadence as routine procurement vendors.

SLA breaches are tracked but not closed

SLA reports are generated monthly, but repeated breaches are not linked to root-cause analysis, owner action or service-credit review. The control is operating as reporting, not governance.

Sub-outsourcing visibility is incomplete

Contracts require prior approval for subcontractors, but the business does not maintain a current subcontractor register for critical vendors and has not reviewed whether security and confidentiality obligations flow down.

Exit plan is theoretical

The vendor contract contains a termination clause, but there is no tested transition plan covering alternate provider, data return, knowledge transfer, user access removal and business-continuity steps.

Use with

Templates and workpapers resources

Download Word checklist

Short editable RCM format for vendor tiering, SLA, sub-outsourcing, data handling and exit readiness.

Build data request list

Create the PBC tracker for vendor inventory, contracts, SLA reports, incidents, access, BCP and exit evidence.

Build RCM

Convert the lifecycle areas into editable risk, control, test, evidence and reviewer columns.

Use ITGC checklist

Route vendor system access, cloud controls, backups, logs and change-management issues into ITGC fieldwork.

Use P2P checklist

Use P2P for vendor master, PO, invoice, GST/TDS/MSME, payment and AP controls.

Open 2026 risk areas

Place third-party risk inside the wider audit plan with cyber, AI, compliance and monitoring coverage.

Authority limits

Use regulatory sources carefully carefully

RBI outsourcing directions are mandatory for specified regulated entities, not every Indian company. For non-regulated companies, they are useful control benchmarks for governance, SLA, audit rights, subcontractors and exit readiness. This page is not legal, cyber, privacy, tax or regulatory advice; verify DPDP, RBI, SEBI, IRDAI, sector rules, contracts and client facts for the audit period.

Sources

Primary references cited

ICAI IASB - Standards on Internal Audit publications

Lists SIA 520, Internal Auditing in an Information Technology Environment, and SIA 530, Third Party Service Provider.

ICAI IASB - Compendium of Standards on Internal Audit

February 2026 compendium of Standards on Internal Audit, applicable from 1 April 2026.

Reserve Bank of India - Master Direction on Outsourcing of IT Services

Applies to specified regulated entities; useful as a benchmark for governance, monitoring, audit rights, subcontractors and exit strategy.

KPMG Global Third-Party Risk Management Survey 2026

Survey of 851 organizations highlighting regulatory compliance, cyber risk, ERM integration, outsourcing, AI and data-quality gaps.

IIA Risk in Focus 2026

Supports the broader 2026 internal-audit context around cyber, digital disruption, AI and resilience.

FAQ

Questions auditors ask answers

What is a third-party outsourcing risk internal audit?

A third-party outsourcing risk internal audit evaluates how the organization governs critical external service providers across selection, due diligence, contracting, SLA monitoring, data access, incidents, sub-outsourcing, business continuity, financial health and exit readiness.

How is third-party risk audit different from P2P audit?

P2P audit focuses on procurement, vendor master, invoices, GST/TDS/MSME, payments and AP access. Third-party risk audit focuses on reliance on external service providers, especially where the vendor runs a critical process, handles data, connects to systems or affects regulatory obligations.

Does RBI outsourcing guidance apply to every Indian company?

No. RBI outsourcing directions apply to specified regulated entities. Other companies can use the governance, audit-rights, SLA, subcontractor and exit-readiness principles as a control benchmark, but legal applicability must be verified for the entity and sector.

Which vendors should internal audit test first?

Start with vendors that process customer or employee data, run core systems, support payment or payroll processes, affect statutory compliance, serve customers directly, are hard to replace, operate cross-border or have repeated SLA, incident or contract exceptions.

Build RCMOpen internal audit hub