The Third-Party Risk Reality
The SolarWinds supply chain attack of 2020 — where attackers compromised SolarWinds' build process to push malware to 18,000 organisations including US federal agencies — demonstrated that a vendor's security posture directly determines your organisation's exposure. In India, the CERT-In 2024 Annual Report specifically highlighted supply chain compromise as a growing threat vector for Indian enterprises. ISO/IEC 27001:2022 dedicates an entire control domain (Annex A.5.19–5.22) to supplier relationships and third-party security. DPDP Act 2023 Section 8(2) requires data fiduciaries to ensure that data processors they engage maintain equivalent data protection standards. Organisations that share network access, data, or credentials with vendors without a formal risk assessment programme are running an unmanaged attack surface.
Vendor Risk Tiers — How to Classify Your Vendors
| Tier | Vendor Type | Assessment Requirement | Frequency |
|---|---|---|---|
| Critical | Cloud providers, core banking software, MSSP, DC/DR vendors | Full security questionnaire + onsite or virtual audit | Annual |
| High | IT support vendors, SaaS platforms with PII, network managed services | Security questionnaire + contract DPA clauses | Annual |
| Medium | Business application vendors, courier services, facility management | Security questionnaire, ISO 27001 certificate preferred | Biennial |
| Low | Stationery suppliers, catering, non-IT services | Standard contractual terms only | At onboarding |
Mandatory Contract Clauses for Critical Vendors
Every contract with a Critical or High-tier vendor that involves access to your data or systems must include: a Data Processing Agreement (DPA) compliant with DPDP Act 2023 requirements (for any vendor handling personal data), the right to audit (your right to inspect the vendor's security controls with reasonable notice), incident notification obligation (vendor must notify you within 72 hours of any breach that may affect your data), security standards requirement (ISO 27001 certification or equivalent programme), and sub-processor approval requirements (vendor must inform you of any subcontractors who will process your data).
Continuous Vendor Monitoring
Vendor risk is not static. A vendor that was ISO 27001 certified at onboarding may lose that certification 18 months later. Monitor: ISO 27001 certificate expiry and renewal status, public breach disclosures affecting your vendors, changes in vendor ownership or subprocessor relationships, and NVD/CVE disclosures for software products you depend on. Tooling: SecurityScorecard and BitSight provide continuous external risk ratings for your vendor portfolio based on passive security signals.
Vendor Risk Governance Assessed in IGaaS
InfraVeritas 360 reviews your vendor inventory, contract security clauses, and assessment programme maturity — and maps every gap to ISO 27001 Annex A.5.19–5.22 and DPDP Act 2023 third-party processor obligations.
Assess Your Vendor Risk Programme →