Outsourcing and Third-Party Risk for DISA
Outsourcing moves the work, not the accountability. That one idea answers most questions here.
Most Indian entities now run critical IT through someone else: a core banking vendor's application support team, a cloud provider, a managed security operations centre, a payroll processor. Outsourcing moves the work. It does not move accountability, and that single idea answers most exam questions on the topic.
For banks, RBI replaced its older outsourcing circulars with the Managing Risks in Outsourcing Directions, 2025 (28 November 2025), issued separately for each type of regulated entity. Existing IT outsourcing agreements had to comply on renewal or by 10 April 2026, whichever came first. The ISA 3.0 material predates them.
You save ₹450
- Full-length timed mocks
- Module-wise practice
- Emerging-tech coverage
One payment, no subscription · Valid for 2 months
What a Bank Cannot Outsource
Under the 2025 Directions, a commercial bank outsourcing financial services must not outsource core management functions, including:
- check_circleInternal audit
- check_circleThe compliance function
- check_circleDecision-making such as determining KYC compliance for opening deposit accounts
- check_circleSanctioning loans, including retail loans
- check_circleManaging the investment portfolio
Key Terms
- Material outsourcing
- An arrangement whose disruption could significantly affect the bank's operations, reputation or profitability. Materiality depends on the activity's importance, its effect on earnings, solvency, liquidity, capital and risk profile, reputational impact, its cost as a share of operating costs, and aggregate exposure to that provider.
- Material outsourcing of IT services
- IT services whose disruption or compromise could significantly affect operations, or whose breach could materially affect customers through unauthorised access to, loss or theft of their information.
- Concentration risk
- Dependence on one provider for many services, or on a few providers for critical ones. Banks must assess it.
- Exit strategy
- A documented plan, with scenarios and minimum timelines, for moving the service to another provider or back in-house without breaking continuity.
The Outsourcing Lifecycle an Auditor Follows
Example: a mid-size bank outsourcing its ATM switch and core banking application support.
- 1
Need and risk assessment
Was the decision based on materiality, expected outcomes, cost-benefit and the outsourcing model? Is it covered by a board-approved IT outsourcing policy?
- 2
Due diligence
Financial soundness, past performance, reputation and litigation, the provider's own controls and BCP, concentration risk, and the jurisdiction's legal environment. Also check the provider is not owned or controlled by a director, key managerial person or approver of the deal, or their relatives, unless the board approved an exception.
- 3
Contract
For IT services: access to data, logs, alerts and premises; subcontractor terms; reportable incidents; SLAs; data storage in India where required; right to audit for the bank and right of RBI to inspect; exit and data destruction clauses.
- 4
Monitoring
SLA reports, periodic reviews and audits, an inventory of outsourced services, and incident reporting fast enough that the bank can report to RBI within six hours of the provider detecting it.
- 5
BCP and exit
Provider BCP and DR tested against the bank's needs; exit plan documented; the provider barred from altering or deleting data during transition.
Quick practice on audit concepts. No signup.
When the Auditor Relies on a Service Organisation
In a statutory audit where payroll or transaction processing sits with a service organisation, SA 402 (Audit Considerations Relating to an Entity Using a Service Organization) applies: you understand the service, assess its controls, and may use a service auditor's report under SAE 3402 (Assurance Reports on Controls at a Service Organization). A type 2 report covers operating effectiveness over a period; a type 1 report covers only the description and design of controls at a date. Check the report's period, scope and the complementary user entity controls your client must operate.
How the DISA Assessment Test Tests This
- check_circleAccountability stays with the outsourcing entity. Any option saying responsibility passes to the vendor is wrong.
- check_circleThe most important contract clause for an auditor is the right to audit (and, for banks, RBI's right to inspect).
- check_circleDue diligence comes before signing; SLA monitoring comes after. Questions often scramble the order.
- check_circleCore management functions such as internal audit, compliance and loan sanction cannot be outsourced by a bank. An option that hands a decision-making function to a vendor is the wrong one.
FAQs
Can a bank outsource its internal audit function?expand_more
No. RBI's 2025 outsourcing Directions list internal audit among core management functions a commercial bank must not outsource, along with compliance, KYC decisions, loan sanction and investment portfolio management.
Does a bank need RBI approval to outsource?expand_more
For financial services, the 2025 Directions say no prior RBI approval is needed, whether the provider is in India or abroad. The bank remains fully responsible.
What clauses should an IT outsourcing agreement contain?expand_more
At minimum: scope and SLAs, access to data, logs and premises, incident reporting, subcontractor controls, compliance with the IT Act and data protection rules, data localisation where applicable, right to audit and RBI inspection, dispute resolution, contingency testing, and exit and data destruction terms.
Does outsourcing transfer IT risk?expand_more
It transfers the operation and sometimes the cost, but not the accountability. The board and senior management stay responsible for the outsourced activity.
Next steps
- Cloud Auditarrow_forward
- Acquisition & Vendorsarrow_forward
- ICAI Standardsarrow_forward
- IT Risk Managementarrow_forward
Assessment Test format, timed and scored.
