32–40: Outsourcing agreement and access rights
Paragraph-level professional implementation page for Outsourcing and IT Governance.
Finin2min Summary — in 2 Minutes
32–40 — Outsourcing agreement and access rights. Cover scope, SLA, audit, RBI access, confidentiality, subcontracting, BCP, termination and records.
Official source and legal ownership
Paragraph-wise Finin2min interpretation
Legal trigger
Cover scope, SLA, audit, RBI access, confidentiality, subcontracting, BCP, termination and records.
Control owner
Business identifies the event; Compliance confirms law; Operations/Technology executes; Independent review tests evidence.
Evidence
Official source snapshot, policy/SOP, system rule, customer/transaction record, maker-checker log, exception approval and regulatory acknowledgement.
Failure consequence
Customer harm, reporting defect, prudential misstatement, supervisory observation, monetary penalty, restriction or remediation.
Practical example
Implementation and evidence controls
- Freeze the applicable entity class, product, transaction date and official instrument version.
- Map every control to its legal owner, enabling provision, responsible function, evidence and escalation route.
- Retain Board/committee approval, policy version, system configuration, maker-checker evidence, exception approval and regulatory filing acknowledgement.
- Re-test the control after an amendment, product change, outsourcing change, merger, customer-risk reclassification or supervisory observation.
Practical Q&A
What is the first test for Outsourcing agreement and access rights?
Confirm entity, product, event date, official paragraph and any stated exception.
Can a portal or system acceptance cure a legal defect?
No. Technical processing does not override the substantive Direction.
What should be retained for review?
The official source version, legal mapping, calculation or decision record, approvals, communications and filing evidence.