Knowledge

How to change outsourcing scope without chaos: change requests, version control and cost

A new template, report or volume can alter SLA and cost. Control every change from request and impact assessment to acceptance.

How to change outsourcing scope without chaos: change requests, version control and cost

Outsourcing rarely stays unchanged throughout a contract. New document templates, reports, volumes, systems and security requirements appear. Change itself is not the problem. The problem is implementing it through an isolated email without assessing price, SLA or accountability. Small requests then accumulate into an informal scope that nobody priced or tested.

Current UK Government Commercial Agency contract management principles recommend planning change with suppliers and controlling cost through strong change-control mechanisms. ISO 37500 calls for flexibility as business requirements evolve while risks remain governed. A good procedure does not obstruct improvement. It makes change faster because both parties know which information and decisions are required.

Freeze the baseline first

You cannot control change without a current description of the service. The baseline should cover activities, volume and seasonality, SLA and KPIs, roles, systems, inputs, evidence, security rules and pricing. Each document needs an owner, version and effective date.

A simple service may need only a service sheet, operating instruction, responsibility matrix, price catalogue and change log. Link these with the RACI and escalation model.

Use three change classes

  • Standard: small, repeatable and pre-priced, such as adding a recipient to an existing report. It can follow simplified approval.
  • Planned material change: affects volume, technology, staffing, SLA, cost or data. It requires full impact assessment and approval.
  • Emergency: responds to an incident, legal deadline or disruption. It may use accelerated approval but needs a record, expiry date and retrospective review.

Classification avoids two extremes: heavy governance for every minor adjustment and uncontrolled implementation of material changes.

An eight-step Change Request

  1. Register the request. Assign an identifier, owner and date. A message is not yet an approved change.
  2. Describe the business purpose. Explain the problem, current state and required outcome instead of prescribing only a solution.
  3. Assess impact. Check process, capacity, schedule, price, SLA, KPIs, roles, systems, data, security, continuity and subcontractors.
  4. Classify risk and priority. Distinguish convenience from legal obligation, customer deadline or process-stoppage risk.
  5. Prepare cost and options. Separate one-off implementation from recurring cost and offer a simpler alternative where possible.
  6. Approve the decision. The named authority accepts scope, budget, date and acceptance criteria. Silence is not consent.
  7. Test and implement. Pilot material changes on limited volume and define stop and rollback conditions.
  8. Update the baseline. Revise instructions, RACI, SLA, prices, access, continuity and training. Close the request only after confirming the outcome.

What the form should contain

FieldWhy it matters
ID, requester and ownerCreates an audit trail and a single owner of the outcome.
Current and target stateShows exactly what stops and what becomes effective.
Scope and dependenciesReveals effects on systems, carriers, suppliers and teams.
One-off and recurring costSeparates implementation from future unit or fixed fees.
SLA, KPI and riskProtects quality and allows before-and-after comparison.
Data and securityRecords new data, access, recipients, retention and channels.
Test, acceptance and rollbackDefines success and safe return to the previous version.
Approvals, date and versionStates who approved the change and when it takes effect.

Version control: one source of truth

After implementation, three different “current” instructions must not remain in email inboxes. Maintain one approved document set. Each version should state its effective date, owner, differences and related Change Request. Archive superseded versions as obsolete rather than deleting them.

Update operating instructions, templates, system parameters, quality checks and training together. Otherwise an operator may deliver the new service under the old instruction.

Control cost without blocking improvement

Every quotation should separate analysis and configuration from recurring service cost. Check effects on minimum volume, exceptions, materials, transport and work remaining with the client. Our guide to fixed, unit and hybrid pricing helps select the right basis.

Set a lower threshold for operational approval and a higher one for budget approval. A zero-cost change can still require full review when personal data or a critical SLA is affected.

The security and GDPR gate

Ask whether the purpose or category of data, recipients, subprocessors, processing location, retention, access or transfer channel changes. If it does, review documented instructions, the processing agreement, permissions, records and, where required, a data protection impact assessment.

EDPB Guidelines 07/2020 stress that processor agreements should contain concrete information and processing must follow documented instructions. An operating agreement must not silently expand data processing.

Pilot, acceptance criteria and rollback

Pilot with one unit, a small volume or parallel work. Define acceptable accuracy, timing, record completeness, unit cost and incident level before testing. The rollback plan identifies who decides, how the prior version is restored, how transition data is handled and how duplicate execution is prevented.

For changes capable of interrupting service, connect the procedure to the business continuity plan.

Common mistakes

  • Email change without an ID or owner. Nobody knows which decision is current.
  • Price-only assessment. Capacity, security and deadlines are ignored.
  • No recurring cost. A cheap launch creates a permanent charge per item.
  • Test without acceptance criteria. Each party defines success differently.
  • Only one document is updated. Systems, instructions and training conflict.
  • A permanent emergency change. A temporary workaround remains outside full control.

Implement change control in 30 days

  1. Document current scope and baseline records.
  2. Define three change classes, approval thresholds and owners.
  3. Create a one-page Change Request and a change register.
  4. Add cost, data, security and continuity gates.
  5. Set test, acceptance and rollback rules.
  6. Rehearse the process on one real, low-risk change.
  7. After a month, remove unnecessary steps but preserve the decision trail.

If a change concerns correspondence handling, printing, inserting or bulk mailing, talk to BackOffice Outsourcing about the scope and evidence needed for a safe quotation. A precise Change Request shortens the route from an idea to a measurable result.

Sources

Frequently asked questions

Does every small change need a full Change Request?

No. Repeatable low-risk changes may use a simplified route when their scope, price and approval authority were defined in advance. The decision should still be recorded.

Who should approve an outsourcing scope change?

The service owner approves operational impact, the budget owner approves cost, and security or data owners participate when their area is affected.

Can an emergency change be implemented without full analysis?

Accelerated approval is possible, but the change needs an expiry, risk statement and rollback plan. It must later receive full review or be withdrawn.

How do we know whether the change delivered value?

Compare pre-agreed before-and-after measures such as total cost, timeliness, first-time-right quality, exceptions, incidents and retained client effort.

Talk to us

Talk to us
← Back to all articles

Let’s talk about your business correspondence

Verify our company

Check BackOffice Outsourcing’s current credentials on the official services.

Quality, security and business continuity

We work in line with recognised ISO standards that structure our processes and information-security practices.

9001:2015Quality management
22301:2020Business continuity
27001:2023Information security
27002:2023Information security controls