
Frank Gerber
Outsourcing has evolved into a strategic business practice to help companies improve their efficiency and performance. As a consequence, outsourcing service providers are gaining greater influence over their clients' internal control systems.
Outsourcing is a growing trend, especially in the area of information technology. Not least because of the increasing complexity of IT hardware, IT infrastructures and applications. But also with regard to the increasing demands on IT security, more and more companies are using corresponding cloud services, such as Infrastructure as a Service (IaaS) or Software as a Service (SaaS). In addition to IT services, accounting, personnel, purchasing and sales processes are increasingly being outsourced to internal shared service centers (SSC) or as part of business process outsourcing (BPO).
However, the compliance and security risks associated with outsourcing always remain with the outsourcing company itself. As the role of outsourcing service providers continues to grow, so does the need for comprehensive and flexible reporting on the outsourced services.
Service providers are subject to various legal, government and industry-specific regulations. These requirements can result from accounting regulations, but also from requirements of data protection, cyber security and supply chain. This variety of possible regulations that service providers must comply with and report on requires a multidirectional approach. Third Party Assurance reporting helps service providers to efficiently define and audit their approach and control framework. Third Party Assurance Reporting also ensures efficient communication with clients.
A structured approach to auditing service-related control systems increases the quality of the service-related control system and saves service providers time and money, which leads to more satisfied customers, e.g. by reducing the number of requests to audit a service provider's internal controls by different customers and their auditors.
BDO's outsourcing assurance services help clients to define a control framework that meets all legal, regulatory and industry requirements, to optimize the reporting process to third parties and to audit the service-related control system.
The outsourcing of business and IT processes to shared service centers, IT service providers or within the scope of business process outsourcing is associated with transformation risks that can negatively impact the quality of the outsourced processes and controls, data integrity and system availability. These transformation risks can be mitigated by well designed project management and appropriate quality assurance.
Our transformation specialists will guide you through the individual project phases in an audit-oriented manner and provide you with feedback on project risks during the project.
We offer to build up appropriate internal control systems together with you, which cover the requirements in the balancing act between legal/regulatory compliance, efficiency, effectiveness and traceability.
With our experience and experts, we support you in the preparation and execution of audits of service-related control systems. Our step-by-step audit approach has proven its worth, especially for initial audits.
When auditing internationally distributed control systems (IT infrastructures, shared service centers, etc.) we have access to our excellent international BDO network of experts in a total of 167 countries.