Outsourcing changes who performs work, not the practice’s responsibility for its obligations. Due diligence should test governance, security, privacy, capability and recoverability before client information is accessed.

Governance and scope

Document the services, responsible owners, subcontracting position, locations, approval boundaries and oversight cadence. Confirm your licensee’s requirements before appointment.

Security and privacy

Understand how access is granted, authenticated, monitored and removed. Review data location, secure transmission, device controls, incident notification and disposal arrangements. The OAIC explains that APP entities can remain accountable for overseas disclosures in many circumstances.

Service resilience

Ask how the provider handles outages, staff absence, disaster recovery and termination. Test whether critical files and knowledge remain accessible to your practice.

Ongoing assurance

ASIC’s offshore-service-provider review points to periodic risk assessment, access-log monitoring and tested incident response as better practices. Due diligence is a continuing activity, not a procurement document.