Also known as: TPRM; vendor risk management
The process of assessing and monitoring the processors and vendors that handle personal data on your behalf. Under the DPDP Act the Data Fiduciary remains answerable for that data, so a failure at a processor is the fiduciary's exposure.
A DPDP-aware assessment asks narrower questions than a generic security questionnaire: what categories of personal data the vendor holds, whether any leaves India, whether they can delete on instruction and evidence it, and whether their breach notification is fast enough for you to meet your own.
General information about the DPDP Act, not legal advice.