At a glance
Key takeaways
- Separate preparation, review and approval.
- Keep work inside client-controlled systems wherever practical.
- Measure exceptions and unresolved items, not just task volume.
- Plan exit, continuity and knowledge transfer before go-live.
1. Define the process boundary
Document where the outsourced process starts and ends. For accounts payable, that could start with an approved invoice entering the workflow and end with a payment proposal ready for authorised release.
The scope should identify inputs, outputs, timing, dependencies, approval points and exceptions. Without this, both teams can be busy while critical work remains ownerless.
- Systems and data sources
- Cut-off times and reporting deadlines
- Client and provider responsibilities
- Approval limits and escalation contacts
- Evidence retained for review and audit
2. Design access around least privilege
Users should receive only the access required for their role. Shared logins destroy accountability and should be avoided. Multi-factor authentication, named users and periodic access reviews are basic control hygiene.
Where personal information may be accessed offshore, the privacy assessment needs to consider the Australian Privacy Principles, contractual safeguards, data location and how the client will supervise the arrangement.
Never allow convenience to erase the audit trail. Named access and explicit permissions are non-negotiable.
3. Preserve segregation of duties
The same person should not create a supplier, enter an invoice and release payment. The precise design will depend on team size, but incompatible duties need to be identified and compensated with review where full separation is not possible.
- Provider prepares; authorised client approver releases
- Master-data changes require independent approval
- Journal preparation is separate from posting approval
- Payroll changes are verified before final release
- Bank-detail changes are independently validated
4. Measure control and quality
A service-level report should do more than count invoices. Include ageing of unresolved items, rework, exceptions, close completion, unreconciled balances and response time.
Metrics must encourage the right behaviour. A target based only on speed can drive premature closure or poor investigation. Combine timeliness with accuracy and control evidence.
5. Transition through a controlled pilot
Start with a stable, measurable process. Complete access testing, sample transactions and a parallel run before switching off the existing workflow.
Use a daily issue log during the first weeks and a formal stabilisation review. Expand only when the initial process is consistently meeting its control and service expectations.
6. Plan for continuity and exit
The client should retain process documentation, system ownership and access to all working records. The agreement should cover handover, data return or deletion, business continuity and transition support.
A good outsourcing relationship should reduce dependency on key people, not replace one dependency with another.
Sources & further reading
Primary guidance
This publication provides general information only. It does not replace accounting, tax, legal, workplace-relations or other professional advice tailored to your circumstances.
