In SEBI's 2023–24 inspection cycle, ID.2 — Third-Party Risk Management — was cited as the #2 most common gap across all regulated entity categories, behind only ID.1 (Identity and Access Management). Yet most CISOs treat TPRM as a contract management problem rather than a cyber risk management discipline.
The stakes are significant. SEBI does not distinguish between a breach caused directly by a regulated entity and one caused by a vendor acting on its behalf. The licence holder bears full liability. With DPDP Act penalties of up to ₹250 crore for data protection failures — including those caused by vendors — the cost of an inadequate TPRM programme has never been higher.