BPO Partnerships · Compliance

What flows down: compliance and due diligence in a subcontracted programme

In a subcontracted programme the end client's obligations travel through the prime to the partner. What gets asked, who answers for it, and how to settle it per campaign.

InsightsOctober 20266 min readPrime Ad Solutions · BPO Partnerships

In short

  • Confirm in writing that subcontracting is permitted before anything else.
  • Compliance obligations are settled per campaign, not once per partnership.
  • A due-diligence pack prepared in advance saves weeks.

In direct outsourcing, a provider answers to its client. In subcontracting there is a third party whose requirements matter most and who is not in the room: the end client. Its contract with the prime sets rules about data, security and conduct, and those rules travel down the chain to whoever handles the contacts.

This article describes what a prime's vendor-management team typically asks of a delivery partner, and how the two sides divide responsibility. It is a description of practice, not legal advice. The contracts and the law that apply to a specific programme need review by counsel.

The first question: is subcontracting allowed?

Many client contracts restrict or forbid subcontracting, offshore delivery, or both. Some require the client's consent. A partner cannot see that contract, so the practical safeguard is a written statement from the prime that its end-client agreement permits the arrangement. This belongs at the start of the conversation. Discovering a restriction after a team has been hired and trained is expensive for everyone.

The same early check applies to data location. Some clients, particularly in government and banking, require that data never leaves the country. That disqualifies a campaign from offshore delivery outright, and it is better learned in discovery than in due diligence.

What the vendor review covers

  • Security: access control, multi-factor authentication, device and endpoint policy, clean-desk rules
  • Data handling: what agents can see, copy and store, and how access is removed when someone leaves
  • Business continuity: connectivity, power, alternate routing and an incident plan
  • People: screening, training records and the escalation matrix
  • Evidence: certifications and audit reports where the end client requires them

A partner that keeps these documents current can turn a vendor review around quickly. Larger primes, and end clients in finance or healthcare, may ask for independent audit evidence on top. Those take months to obtain, so it is worth asking early which ones a given client expects.

Obligations that depend on the campaign

Some requirements attach to the type of work, not to the partnership. They need to be settled each time a campaign is assigned.

  • Card payments. Any campaign where card details are spoken, typed or stored brings payment-card security standards into scope. Technology that lets the caller enter digits on the keypad can keep card numbers away from the agent and reduce that scope. Campaigns without card capture are simpler, which makes them good candidates for a pilot.
  • Health information. Healthcare clients pass a business associate agreement down the chain, with specific safeguards attached.
  • Consumer contact rules. Outbound calling and texting are regulated. The consent basis comes from the end client, and the statement of work should say who is responsible for consent and for call-recording disclosure on that campaign.
  • Recording. Whether and how calls are recorded, and what callers are told, follows the law of the place the caller is in.

Putting responsibility in the statement of work

The useful habit is to write the answers into each statement of work: which standards apply to this campaign, who holds the consent records, who owns recording compliance, what data the agents can access, and what happens at the end. A general clause that the partner will comply with applicable law tells neither side what to do when a campaign starts.

The partner's own obligations

A partner also has duties of its own that do not come from the prime: the data-protection law of the country it operates in, the rules on transferring personal data across borders, and the law governing its own outreach to prospective clients. A prime's counsel may ask about these, and a partner should be able to explain how it meets them.

In practice

Questions to settle before a pilot: Is subcontracted delivery permitted? Are there data-location limits? Does the campaign involve card or health data? Who owns consent and recording compliance? Which evidence does the end client expect to see?

Tell us the seats you can't fill.

Share headcount, hours, channel and who owns training. We will come back with a recommended model, a shift plan and a pilot outline.