🪢 Happy Raksha Bandhan!

Outsourcing Governance in Banks: RBI Directions, Due Diligence and Exit (BCP)

BCP By Ashish Jain · IIBF STORE Editorial · 08 August 2026 · Updated 08 Aug 2026 · 10 min read · 2 views
Outsourcing Governance in Banks: RBI Directions, Due Diligence and Exit (BCP)

When a bank hands a process to an outside vendor, the compliance obligation does not travel with it — the Board stays on the hook. That is the core idea behind outsourcing governance in banks: a documented, Board-approved framework that decides what can be outsourced, how a vendor is vetted, what the contract must say, and how the bank exits cleanly if things go wrong. For BCP candidates, this topic sits at the intersection of RBI's outsourcing directions, operational risk management and vendor due diligence, and examiners test it through scenario-based questions on non-outsourcable functions, materiality thresholds and exit planning.

📋 What Outsourcing Governance in Banks Means

RBI's outsourcing framework rests on one non-negotiable principle: engaging a service provider never dilutes the bank's own accountability to customers, depositors and the regulator. Whether a task is done in-house or handed to a vendor, the bank remains fully liable for the outcome, and that liability cannot be contracted away.

Governance starts with a Board-approved outsourcing policy. This policy sets the criteria for deciding what may be outsourced, how risk is assessed before signing a vendor, the approval hierarchy for material arrangements, and the minimum standards every outsourcing contract must meet. Senior management is responsible for implementing this policy day to day, while the risk management and compliance functions independently assess each proposed arrangement before it goes live — a governance chain that ultimately rests on the fit and proper criteria for bank directors who approve the policy at Board level.

The framework applies uniformly to third-party vendors, group or intra-group entities, and offshore providers — a bank cannot dilute oversight simply because the vendor is a sister concern. It also distinguishes between outsourcing an activity (handing over the doing) and abdicating a decision (handing over the judgement), and only the former is ever permissible for functions that touch core banking relationships.

RBI's outsourcing governance framework for banks
RBI's outsourcing governance framework for banks
💡 Exam Tip: If a question asks "who is responsible when the vendor fails," the answer is always the bank's Board and senior management — never the service provider.

🚫 Activities Banks Can Never Outsource

Certain functions carry decision-making authority so central to a bank's fiduciary role that RBI treats them as non-outsourcable, even though the supporting paperwork around them may be handled by a vendor. The clearest example is credit: a bank can outsource loan documentation, data entry or verification calls, but the actual sanction and approval of a credit facility must stay with the bank's own delegated authority — a principle worth revisiting alongside the Loans and Advances — Regulatory Restrictions chapter.

The same logic applies to the KYC compliance framework for banks and account opening: a vendor may collect documents or run video verification, but the final decision to open, continue or close a customer relationship rests with bank staff. Internal audit's independent assurance role, the compliance function's regulatory judgement, and overall policy-making by the Board or senior management are similarly out of bounds — these are supervisory and fiduciary duties, not back-office tasks.

Where a vendor is itself a group entity such as an NBFC providing referral or collection support, the bank must apply the same non-outsourcable-activity test and avoid letting the arrangement blur into delegated credit decisioning, a point that connects directly to the Guarantees, Acceptances and Finance to NBFCs chapter.

Activities banks cannot outsource under RBI norms
Activities banks cannot outsource under RBI norms

🔍 Materiality Assessment and Due Diligence on the Service Provider

Not every vendor contract needs Board sign-off — RBI's framework scales oversight to risk through a materiality assessment. A bank weighs the potential impact of the arrangement on its customers, the cost and scale of the activity relative to the bank's overall business, the reputational and regulatory fallout if the vendor fails, and whether the function being outsourced is itself sensitive, such as one touching customer data or payment processing. Arrangements that cross this threshold are classified as "material" and pulled into a higher band of governance — Board or Board-committee approval, deeper due diligence and closer ongoing monitoring.

Due diligence on the service provider goes well beyond comparing quotations. Compliance teams examine the vendor's financial soundness and ability to invest in the relationship over time, its track record and reputation with other clients, the security of its systems and premises, and whether it has the operational capacity — including its own business continuity arrangements — to support the bank without interruption. Ownership structure matters too: where a promoter, director or their relative has an interest in the vendor, the arrangement needs additional scrutiny to rule out conflicts of interest — precisely the kind of red flag a bank's whistleblower policy in banks is designed to surface if it slips past initial vetting.

Sub-contracting is a recurring blind spot. A vendor that quietly re-outsources part of the work to a fourth party dilutes the bank's line of sight and its ability to enforce standards, so due diligence must confirm whether sub-outsourcing is permitted at all, and if so, under what conditions.

Exit strategy and vendor monitoring checklist for outsourcing
Exit strategy and vendor monitoring checklist for outsourcing
⚠️ Common Mistake: Candidates often assume due diligence is a one-time onboarding step. RBI expects it to be periodic and risk-based, repeated through the life of the contract, not just before signing.

📝 Contracts, Monitoring, Concentration and Offshore Risk

A well-drafted outsourcing contract is the bank's main enforcement tool once the relationship is live. At minimum it must cover confidentiality and data protection obligations that survive termination; an audit and inspection clause giving the bank's internal auditors, statutory auditors and RBI itself the right to access the vendor's records, systems and premises; business continuity and disaster recovery commitments matched to the criticality of the outsourced function; and clearly defined service level agreements with measurable turnaround times, uptime and error thresholds.

Monitoring does not stop once the ink dries. The bank must track actual performance against the contracted service levels, escalate breaches through a defined process, and periodically reassess the risk rating of the arrangement — a vendor that looked low-risk at onboarding can become material as volumes grow. Concentration risk deserves separate attention: relying on a single vendor for multiple critical functions, or on very few vendors across the bank as a whole, creates a single point of failure that RBI expects banks to actively track and diversify against.

Offshore outsourcing adds jurisdictional complexity. Even when data or processing sits outside India, the bank must retain the ability to produce records and grant RBI access on demand, and must factor in country and legal risk — political instability, weak data-protection law, or a foreign court's refusal to honour an Indian regulator's inspection request — before signing.

Activity / ArrangementOutsourcable?Why
Credit sanction and loan approval decisions❌ NoCore credit decision must stay in-house
Data entry, document processing, call centre support✅ YesSupport function under Board-approved policy
Final KYC / account-opening decision❌ NoStatutory compliance responsibility of the bank

🌍 Documented Exit Strategy

Every material outsourcing arrangement needs a documented exit strategy prepared before it is needed, not improvised after a vendor collapses or a contract turns adversarial. The plan should identify how customer service continues without interruption during transition, how data is returned or securely destroyed, the realistic time and cost of moving to an alternate vendor or bringing the activity back in-house, and the trigger conditions — repeated SLA breaches, a security incident, insolvency of the vendor — that activate the exit.

Banks are expected to periodically test critical exit plans rather than let them sit untouched in a policy document, because an exit strategy that has never been rehearsed against a live vendor relationship is only a plan on paper.

🎯 Conclusion: Turn This Into Exam-Ready Recall

Outsourcing governance in banks is one of the more scenario-heavy BCP topics: expect case-based questions that ask you to spot the non-outsourcable activity, judge whether an arrangement is material, or identify the missing contract clause. Anchor your revision to the RBI framework's core theme — accountability never leaves the bank — and the rest of the detail falls into place logically. For the regulatory backdrop on related lending restrictions, see RBI's official guidance at rbi.org.in. To pressure-test your understanding, work through more BCP material on the Banking Compliance Professional tag hub and attempt a timed set on iibf.store/tests.

🧠 Practice MCQs: Outsourcing Governance in Banks

Q1. Which of the following functions can NEVER be outsourced by a bank under RBI's outsourcing governance framework? (a) Data entry and back-office processing (b) Credit sanction and loan approval decisions (c) Call centre operations (d) Document storage and record-keeping

Answer: (b) — Credit sanction is a core fiduciary decision that must remain with the bank's own delegated authority.

Q2. Under RBI's outsourcing governance framework, who bears ultimate responsibility for an outsourced activity's performance? (a) The service provider (b) The bank's Board of Directors and senior management (c) The regulator overseeing the vendor (d) The customer who availed the service

Answer: (b) — Outsourcing an activity never transfers the bank's accountability to the vendor.

Q3. What is the primary purpose of a materiality assessment before outsourcing an activity? (a) To fix the vendor's price (b) To determine the level of risk, oversight and approval the arrangement requires (c) To decide the vendor's office location (d) To calculate the applicable tax on the contract

Answer: (b) — Materiality scales governance: higher-impact arrangements need Board-level approval and closer monitoring.

Q4. Which contractual clause specifically enables RBI and the bank's auditors to inspect an outsourced service provider's records and premises? (a) Indemnity clause (b) Audit and inspection access clause (c) Non-compete clause (d) Force majeure clause

Answer: (b) — This clause preserves the bank's and regulator's visibility into the vendor's operations throughout the contract.

Q5. Why must a bank maintain a documented exit strategy for material outsourcing arrangements? (a) To reduce the vendor's invoice value (b) To ensure business continuity and orderly transition if the arrangement ends or the vendor fails (c) To avoid tax on contract termination (d) To automatically renew the contract each year

Answer: (b) — An untested exit plan can turn a vendor failure into a customer-facing outage; the exit strategy exists to prevent that.

Want chapter-wise mock tests with 100+ MCQs? Start practising free →

What is outsourcing governance in banks?

It is the Board-approved framework a bank follows to decide what activities can be given to outside vendors, how those vendors are assessed and monitored, and how the arrangement is safely exited — while the bank retains full accountability for the outcome throughout.

Can a bank outsource its KYC verification process?

The operational steps — document collection, video verification, data entry — can be outsourced under supervision, but the final decision to open, continue or close a customer account must remain with the bank's own staff.

What must a Board-approved outsourcing policy cover?

It should define what activities may be outsourced, the criteria for assessing materiality and risk, the due diligence standard for vendors, minimum contract clauses, monitoring frequency, and the approval hierarchy for material arrangements.

What happens if a bank's outsourcing arrangement lacks an exit strategy?

Without a tested exit plan, a vendor failure, security incident or contract dispute can disrupt customer service and delay data recovery, which is exactly the operational risk RBI expects a documented exit strategy to pre-empt.

Next step

Practice this topic

Ready to put this into practice?

Take a free mock test, download chapter PDFs, or watch a video class — all included on iibf.store.

Keep reading