Third-Party Vendor Risk Management: The Supply Chain Gap in Indian Enterprise Compliance

By Arjun Mehta · 9 June 2026

The Third-Party Risk Reality

The SolarWinds supply chain attack of 2020 — where attackers compromised SolarWinds' build process to push malware to 18,000 organisations including US federal agencies — demonstrated that a vendor's security posture directly determines your organisation's exposure. In India, the CERT-In 2024 Annual Report specifically highlighted supply chain compromise as a growing threat vector for Indian enterprises. ISO/IEC 27001:2022 dedicates an entire control domain (Annex A.5.19–5.22) to supplier relationships and third-party security. DPDP Act 2023 Section 8(2) requires data fiduciaries to ensure that data processors they engage maintain equivalent data protection standards. Organisations that share network access, data, or credentials with vendors without a formal risk assessment programme are running an unmanaged attack surface.

Vendor Risk Tiers — How to Classify Your Vendors

TierVendor TypeAssessment RequirementFrequency
CriticalCloud providers, core banking software, MSSP, DC/DR vendorsFull security questionnaire + onsite or virtual auditAnnual
HighIT support vendors, SaaS platforms with PII, network managed servicesSecurity questionnaire + contract DPA clausesAnnual
MediumBusiness application vendors, courier services, facility managementSecurity questionnaire, ISO 27001 certificate preferredBiennial
LowStationery suppliers, catering, non-IT servicesStandard contractual terms onlyAt onboarding

Mandatory Contract Clauses for Critical Vendors

Every contract with a Critical or High-tier vendor that involves access to your data or systems must include: a Data Processing Agreement (DPA) compliant with DPDP Act 2023 requirements (for any vendor handling personal data), the right to audit (your right to inspect the vendor's security controls with reasonable notice), incident notification obligation (vendor must notify you within 72 hours of any breach that may affect your data), security standards requirement (ISO 27001 certification or equivalent programme), and sub-processor approval requirements (vendor must inform you of any subcontractors who will process your data).

Continuous Vendor Monitoring

Vendor risk is not static. A vendor that was ISO 27001 certified at onboarding may lose that certification 18 months later. Monitor: ISO 27001 certificate expiry and renewal status, public breach disclosures affecting your vendors, changes in vendor ownership or subprocessor relationships, and NVD/CVE disclosures for software products you depend on. Tooling: SecurityScorecard and BitSight provide continuous external risk ratings for your vendor portfolio based on passive security signals.

Vendor Risk Governance Assessed in IGaaS

InfraVeritas 360 reviews your vendor inventory, contract security clauses, and assessment programme maturity — and maps every gap to ISO 27001 Annex A.5.19–5.22 and DPDP Act 2023 third-party processor obligations.

Assess Your Vendor Risk Programme →