You can place the activity outside. You cannot place the accountability there
Clause 8.3 was renamed in the 2024 edition from Outsourcing to externally provided processes, products, technologies and services. The widening is deliberate and it captures a category of arrangement most organisations have never treated as outsourcing at all, which is why nobody is assuring it.
Ask an organisation what it has outsourced and you will get a list of contracts. Facilities management, maintenance, perhaps the whole delivery of a capital programme.
Then ask what determines the maintenance intervals on a major item of plant. On a surprising number of assets the honest answer is a vendor algorithm running inside a monitoring platform, tuned by the manufacturer, whose logic the owner has never seen and could not inspect if it wanted to.
That is not on the outsourcing list. It was procured as a technology, by a different team, under a different approval route, and nobody classified it as placing an asset management activity outside the organisation. Which is exactly what it is.
What the rename does
The 2014 edition had a clause about outsourcing. The 2024 edition replaces it with Clause 8.3, externally provided processes, products, technologies and services.
Read the four nouns. Processes covers the classic case. Products and technologies do not, and their inclusion pulls in things procurement treats as purchases rather than as delegations: platforms, embedded analytics, proprietary control systems, condition monitoring services, data feeds, anything where the organisation buys an output and does not retain the ability to reproduce it.
The distinction the clause is drawing is not commercial. It is about whether the organisation retains the capability to know whether the thing was done properly.
Outsourcing transfers activity. It never transfers accountability, and the gap between the two is precisely where assurance stops without anybody deciding that it should.
The question that separates a purchase from a delegation
For each externally provided item, one question does most of the work:
If the provider is wrong, how would we find out, and how long would it take?
Where the answer involves the provider's own reporting, the organisation has not retained verification capability. It has retained a relationship. That may be an entirely reasonable position, and it is a different risk from the one on the register.
Applied honestly across a real asset base, this question tends to produce an uncomfortable list. Condition assessments performed by the firm that also quotes for the remediation. Reliability data generated by the maintenance contractor whose performance is measured on it. Design verification by a party engaged by the designer. None of those arrangements is improper and all of them are common. What matters is whether anybody has written down that the check and the checked share a source.
Retained capability, and how it disappears
Retained capability is not a document. It is a small number of people who understand the thing well enough to challenge the provider, plus enough independent data to make a challenge stick.
It disappears gradually and for good reasons. The provider is better at the work, so more of it goes to them. The internal specialists have less to do, so the roles are not backfilled when they leave. The provider's system becomes the source of record, because it is the system where the work happens. Within a few years the organisation cannot form an independent view, and nobody made that decision.
On capital programmes there is a sharper version. On the largest programmes, tier one contractors routinely hold more programme information than the owners paying them. During construction this is normal and largely unavoidable. It becomes a transfer problem at precisely the moment the contractor's obligation ends, which is a delivery-stage arrangement producing a handover-stage failure.
Where that information asymmetry lands
, read: Handover is where the cost lands, and the Gulf is now taking deliverySpecify what you will need to operate, not what is easy to produce
The contractual expression of this is narrow and worth getting right, because it is cheap at tender and impossible afterwards.
Most information requirements in contracts describe what the provider can readily generate. The requirement that survives contact with operations describes what the owner will need to make decisions, including in the event the provider is no longer involved.
That means naming, at minimum: the data the owner will hold rather than access, the format it arrives in, whether the owner can extract it without the provider's assistance, and what happens to it at termination. An arrangement where the operating history of an asset lives in a platform the owner stops paying for is one contract renewal away from losing a decade of evidence.
FIDIC's 2017 edition strengthened the delivery-side version of this by moving as-built records and operation and maintenance manuals into Sub-Clause 10.1, making their supply an express requirement of taking over rather than a schedule item. That is a real improvement and it covers documents. It does not reach the data held in a provider's system, which is where an increasing share of the useful record now sits.
Why this sits in delivery rather than in operations
The clause is an asset management system requirement and applies throughout the life of the asset. It is placed here because delivery is when the arrangements are made and the only time they are cheap to change.
Every provision described above is a tender decision. What the owner retains, what data it holds rather than accesses, whether it can verify independently, what happens at termination: all of it is settled in documents written before anybody is appointed, usually by a procurement function optimising for compliant supply at a competitive price within an approval window.
That function is not doing anything wrong. It is pursuing the objective it was given, and nobody told it that the objective was incomplete.
Why the decision sits with someone who was never briefed on it
, read: The competence you need is not in the asset management functionThe framework for this stage sets out how to examine the arrangements, and the neighbouring domains they interact with.
Sources. ISO 55001:2024, second edition, July 2024, ISO standard 83054, Clause 8.3, externally provided processes, products, technologies and services, renamed and widened from Outsourcing in the 2014 edition, and Clause 8.1 on operational planning and control. PMBOK Guide, Eighth Edition, November 2025, which expands its coverage of procurement. ISO 21502:2020, guidance on project management. FIDIC, Conditions of Contract, 2017 edition, Sub-Clause 10.1 on taking over the works. ISO 19650-3, information management during the operational phase of assets. Standards published behind a paywall are cited without a link.
Tags
- ISO 55000
- Procurement
- Contracts
- Assurance
- FIDIC
Related reading
A forecast that never moves is not stable, it is unexamined
Delivery attracts more assurance than the other three stages combined and returns the least for it, because most of that effort measures progress against a baseline nobody has tested. Two numbers reveal more than a quarter of reporting, and both are usually available in an afternoon.
ReadProgramme risk is not the sum of its functions
A capital programme does not simply contain larger versions of procurement, payment and resourcing. It creates chains that run through all of them, and a chain belongs to no function. That makes under-coverage a design problem in the audit plan rather than a question of materiality, and it has a method attached.
ReadEngaging an engineer satisfies the standard. Deferring to one does not.
The 2024 Standards require an internal audit function to obtain the competencies it does not have, which most functions read as permission to bring in an engineer. That is the easy half. The obligations that decide whether the exercise was worth commissioning all start after the engineer has arrived.
Read