How do we keep control when we outsource IT or operations?

Keep the knowledge, the data and the right to leave, and measure the provider on the outcomes your customers and regulator care about. The provider's standard contract measures what is cheap for it to meet. Rewrite the service measures and the exit before you sign, while the provider still wants the contract.

Draft for Tamir's review. Not published.

Tamir Khason · Updated · Decision guides

Measure outcomes instead of activity

A contract paid on alerts handled or tickets closed rewards noise. Measure what your customers, patients or members feel: time to detect and contain, confirmed recovery, and whether the same incident comes back. Keep the right to test the provider unannounced.

Classify your systems by the harm their failure causes, and give each class its own response and restoration terms. A server that runs the emergency department needs different terms than an office system. Assign one owner for the complete customer outcome, even when the supplier handles only some steps.

Keep the knowledge and the way out

Decide which roles stay in-house to oversee the provider and hold the knowledge. Keep ownership of your data, logs and documentation, in a format a replacement provider can use. Test the data exchange with the provider's systems before anything moves.

Define an exit with a transition period and the provider's duty to cooperate, and test it on paper. Transfer in stages, with a review before each one. Check the provider's financial stability and what happens to your customers if it fails.

Depending on your seat

If you're on the board, the regulator may hold you responsible for the outsourcing's risks. Ask for the documents the regulator will ask for: what moves, the risk assessment per system, the controls and who verifies them, and the exit plan. Then set a periodic report on risks and incidents.

If you run IT or operations, ask your regulator which responsibilities can't be outsourced, and keep them explicit in the contract. If you're deciding whether to renew a provider, compare ticket closure with recurring failures before you sign again.

What to check before you decide

  • Decide which roles stay in-house to oversee the provider and hold the knowledge.
  • Define service measures by customer, patient or member impact, and keep the right to test them unannounced.
  • Classify systems by the harm their failure causes and attach each class to its own service terms.
  • Keep ownership of data, logs and documentation, with export in a format a replacement can use.
  • Map the regulator's outsourcing expectations to contract clauses and check each one is present.
  • Define an exit with a transition period and the provider's duty to cooperate, and test it on paper.
  • Ask for evidence that past fixes prevented recurrence before you renew.

Questions people ask

Board must approve outsourcing our IT operations under a long contract, what safeguards should directors require?

Require that the fund keeps the knowledge and the rights to leave: documentation, data, named oversight roles in-house, service measures tied to member impact, and an exit with transition. Require a staged transfer with a review before each stage. It depends on which systems touch members directly and on what the fund's regulator expects for outsourcing.

Bank board must approve a cloud outsourcing the regulator holds us responsible for, what should directors require?

Require the documents the regulator will ask for: what moves and its data classification, the risk assessment per system, the controls and who verifies them, the exit plan and the provider's obligations. Approve when those exist and are readable, and set a reporting routine. It depends on the regulator's outsourcing rules and on how critical the systems are.

A logistics provider wants to take over our warehousing on its own systems, how do I keep visibility and the ability to leave?

Require live stock visibility in your systems, data ownership, documented interfaces and an exit with a transition period, and test the interface before the warehouse moves. Judge the provider on how it serves companies your size rather than on the price per pallet. It depends on how your stock data feeds planning and sales, and on what the provider's system can exchange.

What accountability should we require when outsourced onboarding checks create customer complaints?

Assign ownership of the complete customer outcome while defining the supplier's bounded tasks. The arrangement depends on evidence access, correction rights, escalation, and applicable obligations checked by responsible owners.

Should we renew IT support when the same incidents keep returning?

Renew against the service outcome and responsibility for recurrence. The decision depends on root-cause evidence, permanent corrections, and whether the contract rewards closure without prevention.

Outsourcing our SOC, what should the contract measure so the provider is accountable for real incidents?

Measure time to detect and time to contain on scenarios you define, and keep the right to test them unannounced. Keep log ownership and the ability to switch provider without losing history. It depends on what your regulator expects you to retain in-house and on how mature your own detection content is.

Outsourcing hospital IT operations, what service levels and terms protect clinical systems?

Classify systems by clinical impact and give each class its own response, restoration and maintenance terms. Keep the right to direct priorities during an incident and to audit the provider's work on clinical systems. It depends on which systems are life-critical and on how the hospital runs when they are down.

Bank partnering with a fintech for an embedded product, what contract terms cover the regulatory responsibility we keep?

Get audit and oversight rights, defined uptime and incident terms, data handling that matches your obligations, and an exit that keeps serving customers. The regulator treats the fintech as your outsourcing, so the contract must give you what the regulator will ask you for. It depends on your regulator's outsourcing expectations and on how deep the fintech sits in the customer's product.

How I can help with this decision

Ask or talk (Free)
I give my view on which terms in your draft would leave you exposed, and the safeguards providers usually accept.
Review (Pay if it was worth it)
I write an independent review of the outsourcing plan and contract against your operations, risk and regulatory position. I recommend the terms to change, or whether to approve, set conditions or send it back.
Retain (When it makes sense)
I stay available during the first year and at each transfer stage to review service reports, incidents and test results against the contract.