Selling software to an Indian bank, NBFC or insurer is not a sales process in the ordinary sense — it is an onboarding process that a sales conversation eventually triggers. Regulated entities are required to conduct due diligence on their technology suppliers, and that requirement flows down to you as a document pack, an audit, and a set of contractual terms that are largely non-negotiable. Firms that treat this as paperwork to handle after the deal is agreed lose quarters to it.
Prepare the pack before you need it, because assembling it under deal pressure is where timelines slip. What is asked for is fairly consistent: certificate of incorporation and registered details, audited financials for two or three years, GST registration, a security policy set, evidence of independent security testing, your subprocessor list, insurance certificates including professional indemnity and cyber cover, and details of your key personnel. Having all of it current, in one folder, converts a six-week exercise into a two-week one.
Expect a security assessment proportionate to what you will touch. That may be a questionnaire, a call with their information security team, a review of your VAPT report from a CERT-In empanelled auditor, or an on-site or remote audit of your own environment. The RBI's IT governance framework and the sectoral cyber security guidelines shape what they must ask, so the questions are not arbitrary — knowing which framework applies to your prospect lets you anticipate them.
The contractual terms will include things a young company finds uncomfortable, and most of them are not the bank being difficult. Audit rights over your environment. Notification obligations on incidents within tight windows. Business continuity commitments. Restrictions on where data may be processed and on subcontracting. A right for the regulator to inspect. Read these against what you can actually deliver, because agreeing to a notification window your monitoring cannot support is a breach you have scheduled in advance.
Concentration is worth thinking about on both sides. Banks are wary of depending on a small supplier, so expect questions about your financial stability, your key person risk and what happens if you are acquired or fail. Escrow may be requested. Answering these with a straight account of your size and your continuity arrangements works better than projecting more scale than you have — they check, and a supplier who was accurate about being small is more credible than one who was not.
The reason to persist despite all of it is that the barrier works in your favour once cleared. An empanelled supplier with a completed assessment and a signed agreement is enormously advantaged on the next opportunity inside that institution, and the assessment pack you built transfers to the next bank with modest adaptation. The first one is slow. The third is a fraction of the effort, and by then you are competing against firms who have not started.