Analysis

IT outsourcing does not transfer responsibility

You delegate the doing. You never delegate the standard. The whole difference between IT outsourcing that holds and outsourcing that drifts sits in that sentence.

Looking up at two glass skyscrapers against a cloudy sky
Delegating the work does not move the responsibility

IT outsourcing is almost always decided for sound reasons: reaching skills you cannot recruit, smoothing a workload, turning a fixed cost into a variable one. The reasoning is sound.

What goes wrong comes afterwards. Once the contract is signed, the temptation is to treat the matter as settled. It is not: it has changed nature. What was a delivery problem has become a governance problem, and the two call on different skills.

What can be delegated

The doing delegates without difficulty: running the systems, monitoring, applying patches, handling routine incidents, keeping backups. These are tasks that can be written down, measured and checked.

What cannot be delegated

Four things stay with you, whatever the contract says:

  • Defining the requirement. A supplier answers what it is asked. If it defines the requirement itself, it will define it to the measure of what it knows how to do.
  • Regulatory responsibility. Where personal data is concerned, the controller answers for its choice of processor and for the instructions it gives.
  • The ability to check. You need to keep someone who can read an operations report and spot what is missing from it.
  • The ability to leave. Without an organised exit, outsourcing becomes dependency, and renewal is negotiated with no leverage.
You delegate the doing. You never delegate the standard — because nobody else has an interest in setting it.

The usual objection

“We do not have the skills in house, which is exactly why we outsource.” The objection holds for the doing. It does not hold for the checking, because checking does not require knowing how to do.

You do not need to know how to administer a server to ask when the last backup restore was tested, nor to notice that nobody answered you. That skill — putting the right requirement to the right person — is acquired far faster than a technical one, and it is the one most often missing.

The minimum arrangement

What the contract must say about that delegation is precisely framed: ten compulsory clauses, three of which are missing almost every time.

A review meeting at fixed intervals. A set of measures chosen by you, not supplied by the vendor. A written report for every major incident. An exit clause you can actually invoke. Four things, none of them expensive, and their absence is always paid for at the same moment: when the relationship turns.

Common questions

Why outsource IT?

Usually for good reasons: accessing skills you cannot hire, smoothing a workload, turning a fixed cost into a variable one. But outsourcing turns an execution problem into a steering problem, which calls for different skills.

What can be outsourced in IT?

Execution: operations, monitoring, patching, routine incidents, backups. Four things, however, stay with the business whatever the contract: defining the need, regulatory responsibility, the ability to check, and the ability to leave.

How do you oversee an IT provider without technical skills?

Checking does not require knowing how to do the work. Asking when backup restoration was last tested needs no technical skill. The minimum set-up: a meeting at fixed intervals, indicators you choose, a written report for each major incident, and reversibility that can actually be triggered.


Next article

IT audit: eighteen checkpoints, and who the report is actually for

Read

A transformation to support?