Outsourcing
Outsourcing is a business practice in which an organization contracts an external provider to carry out processes, services, or activities that would otherwise be handled internally. Companies typically do this to reduce costs or gain capabilities they lack in-house. Because the work is performed outside the organization, the provider relationship must be managed under contract on either a one-off or ongoing basis.
Outsourcing is the contractual transfer of a process, service, or job function to an external provider that would otherwise be performed internally, on either a project or continuing basis. It establishes a direct third-party relationship and therefore falls within the scope of third-party risk management, though the underlying activity remains subject to the outsourcing organization's own accountability. Where the engaged provider further transfers a process, service, or activity to another provider, this constitutes sub-outsourcing, which extends exposure into fourth-party or Nth-party layers that direct third-party oversight may not fully capture. Regulatory expectations for outsourcing arrangements vary by jurisdiction and sector; for example, supervisory guidance in the European banking sector addresses sub-outsourcing explicitly, and such regime-specific requirements should not be treated as universally applicable.
Why it matters
Outsourcing is one of the most common ways an organization takes on third-party risk. When a process, service, or job function is performed by an external provider, the outsourcing organization still remains accountable for the outcome even though it no longer controls the work directly. This gap between accountability and operational control is precisely what third-party risk management exists to address, which is why outsourcing arrangements are typically brought within the scope of a TPRM program rather than treated as ordinary purchasing.
The risk picture is complicated further by sub-outsourcing, where the engaged provider further transfers a process, service, or activity to another provider. This extends exposure into fourth-party or Nth-party layers that direct third-party oversight may not fully capture, since the outsourcing organization often has limited visibility beyond its immediate contractual counterparty. A control or assurance obtained at the direct provider level does not automatically extend to the parties that provider relies upon.
Regulatory attention to outsourcing varies by jurisdiction and sector, and expectations should not be assumed to be uniform. Supervisory guidance in the European banking sector, for example, addresses sub-outsourcing explicitly, but such regime-specific requirements should not be treated as universally applicable. Organizations operating across regions or sectors therefore need to map which outsourcing expectations apply to a given arrangement rather than relying on a single standard.
Who it's relevant to
Inside Outsourcing
Common questions
Answers to the questions practitioners most commonly ask about Outsourcing.