Outsourcing, Due Diligence and Dependencies

Outsourcing, Due Diligence and Dependencies

 

Outsourcing is, for many organisations, the only way to access some services. Nowadays businesses simply cannot be so integrated that they can do everything themselves. There is a reasonable assumption that some outsourced service providers (OSPs) are best in class and the experts in their fields but…

If any of your key business objectives or any of your customer obligations depend on an outsourced provider, you will need to be as familiar with aspects of that provider as you are with your own organisation.

Some years ago, we were engaged to conduct a risk assessment on a client’s business continuity arrangements. As part of the assessment they looked at their primary customer service objective; they realised that ‘what mattered’ most was availability. Internally, they were well prepared for the risks identified and had, for the most part, credible plans in place to protect their business objectives in the event of any of the envisaged failures.

However, their service depended on a banking system that was externally hosted in a data centre. Their customers utilised the system’s online portals to buy goods and services such as airline tickets, health and general insurance, groceries and also, among other things, to gamble. Successful completion of those transactions depended on the availability of our client’s process. Therefore, communication with the hosting data centre was critical.

Our client had developed a recognised dependency on (and a very good relationship with) the hosting service provider. They had written a four-second response time objective into the service level agreements coupled with a Six Sigma uptime clause and, for three years, performance was satisfactory. During that time not only did our client’s business grow significantly but their dependency on the outsourced provider had grown in parallel.

The business continuity due diligence risk assessment that we conducted on their OSP showed them to be an excellent risk through all of its key aspects until we got to this question:

Their ‘Don’t Know’ answer set off alarm bells within the OSP’s technical community.  The data centre was using two key telecom service providers and our question provoked an internal discussion about the fibre route maps of the connectivity providers in and out of their facility. They had discovered a single point of failure. The different fibre trunks ran within a foot of one another for almost fifty metres underground near the building’s carpark, meaning the backup resilience of their connectivity was compromised and they risked a total service failure from a single ‘Black Swan’ event.

The data centre and its telecoms providers worked quickly to mitigate the risk and reroute the cable ducting to re-establish the standard separation required. But our client, though appreciative of the immediate rectification and the speedy response to the identified risk, made the strategic decision to second-source. They added another data centre to their network and in doing so built resilience into the whole of their business process. While this decision resulted in additional cost, it facilitated further growth and represented their coming to a serious understanding of outsource or third-party dependency risk.

You cannot be naive about the risk outsourced service providers represent to your business. You will always retain the responsibility for any consequences of their failings. Continuous monitoring of your providers is extremely important; keep in touch, understand how they are doing, monitor the detail of your service level agreements. You can do this by measuring KPIs and / or KRI’s, or by any other method that will allow you to understand the level of your exposure. The point is not to worry unnecessarily but it is to be as prepared as possible for a potentially disruptive event – a withdrawal from a market; a major price change; a service interruption; an industrial relations issues; a change in ownership; reduced flexibility; or the ever-increasing risk of skill shortage.

One of the great indicators is how well prepared your key providers are for a business disruption event… Do you know?

For details on how CalQRisk can benefit your organisation, contact us today.

Recent News

b&S credit union implement calqrisk

B&S Credit Union implement CalQRisk

B&S Credit Union implement CalQRisk – 90th credit union in Ireland to do so B&S Credit Union have ...
Read More

CalQRisk Announces Partnership with the Welsh Sports Association

CalQRisk is delighted to announce its partnership with The Welsh Sports Association. The Welsh Sports Association (WSA) is ...
Read More
laptop and writing in notebook

What is Good Governance?

What is good governance?  Governance can be defined as: “The system by which entities are directed and controlled. ...
Read More

CalQRisk at The Wheel Charity Summit, 2022

We recently attended The Wheel's Charity Summit, which took place on June 1st, 2022 in Croke Park's events ...
Read More
forward thinking imagery

Incident vs Crisis

What’s the difference between an incident and a crisis? Not every incident/event is a crisis, but it can ...
Read More
Logging in to attend a CalQRisk webinar

Operational Resilience vs Business Continuity 

At first glance, you might think Operational Resilience is just Business Continuity (BC) by another name, but there ...
Read More
Central bank of ireland building

Assessing your Outsourcing Governance Framework

In March 2022, the Central Bank of Ireland fined BNY Mellon Fund Services €10.78 million for 16 regulatory ...
Read More
laptops on a table doing risk reports

Cybersecurity – What are the risks?

With changes to working culture, and more people working from home than ever, businesses can see the importance ...
Read More
IWD2022 employee spotlight

International Women’s Day Spotlight – Fiona Kiely

It's International Women's Day and today we would like to shine the spotlight on our very own Fiona ...
Read More
risk assessment

10 Key Steps to getting Operational Resilience off the ground

It can seem daunting to begin a brand-new process for your business. However, risk assessments are an easy ...
Read More