Who is responsible for what in outsourcing? RACI, escalation and clear decision rights
An SLA does not allocate every decision. Assign client and supplier roles, build escalation paths and remove the operational grey zone.

Many outsourcing failures do not start with unwillingness. They start when both parties believe the other one owns the decision. The supplier waits for approval, the client assumes the matter is included, and the deadline continues to run. A contract may define scope and SLA, yet still leave an operational grey zone.
Current UK Government Commercial Agency principles call for clear accountability, roles, responsibilities and governance mechanisms. ISO 37500 covers governance throughout the outsourcing life cycle and recognises that some processes cannot be allocated exclusively to either the client or provider. The operating model must therefore be shared without making accountability vague.
Outsourcing transfers execution, not all accountability
A company may delegate mail collection, registration, scanning, printing, inserting, dispatch and reporting. It still defines the purpose, acceptable exceptions, access and business risk. The provider is responsible for performing the agreed activities correctly, maintaining resources and controls, and reporting problems promptly.
The same principle applies to personal data. EDPB Guidelines 07/2020 explain that a processor acts on documented instructions, assists with defined obligations and provides information needed for audits. The controller does not lose its accountability merely because a supplier is engaged.
RACI in four letters
- R - Responsible: the person or team performing the work.
- A - Accountable: the owner of the outcome who makes the final decision and accepts the result.
- C - Consulted: people whose input is required before a decision.
- I - Informed: people who receive the result or event update.
One activity may have several R, C and I roles, but it should have one A. Two final owners usually means no owner. RACI does not replace the contract, work instruction or procedure. It shows who activates those documents in a specific situation.
Example matrix for business correspondence
| Activity | Client | Provider | Decision or evidence |
|---|---|---|---|
| Define categories and priorities | A/R | C | Approved instruction |
| Collect, register and scan | I | A/R | Register and timestamp |
| Approve the document template | A/R | C | Approved production sample |
| Print, insert and dispatch | I | A/R | Production and dispatch report |
| Decide an unusual item | A | R/C | Exception log entry |
| Handle a security incident | A/C | R | Notice, timeline and actions |
| Change scope or SLA | A/R | C | Approved change request |
This is a starting point, not a universal template. The correct roles depend on contract, data and systems. Every line should also state the evidence required: a register entry, sample approval, report or decision record.
12 decisions that need an owner
- Purpose and business outcome. The client defines why the process exists and which consequences are unacceptable.
- Input readiness. State who confirms file, address and template completeness.
- Sample approval. One owner approves content, personalisation, folding and envelope before production.
- Execution and quality control. The provider organises resources and records agreed checks.
- Access rights. The client approves access; the provider grants, records and removes it under instruction.
- Exceptions. Define what the operator may resolve and what must stop for escalation.
- Incidents. Classification owner, reporting channel and update times must be known in advance.
- Subcontractors and carriers. Assign approval of change and oversight of dependencies.
- Process change. New templates, reports and integrations need ownership, impact assessment and a date.
- Continuity activation. One person decides when to enter contingency mode.
- Monthly acceptance. A named owner closes data, complaints and corrections.
- Exit. Data return or deletion, documents, access and open cases need recipients.
Escalation must define time and decision
A list of phone numbers is not an escalation path. A useful procedure states the trigger, first contact, acknowledgement time, next level, maximum decision time and how the outcome is recorded.
- Level 1 - operational: an isolated exception with no batch-wide deadline impact. Coordinators resolve it in normal work.
- Level 2 - management: likely SLA failure, growing backlog or recurring error. The service owner approves a recovery plan.
- Level 3 - critical: potential security incident, process stop, legal deadline or serious customer impact. Notification is immediate and both parties activate the agreed crisis process.
Separate response time, decision time and resolution time. A provider may acknowledge a problem in five minutes, but should not change document content or the reason for dispatch without the client's decision.
Four governance rhythms
- Daily: urgent items, exceptions, incidents and backlog.
- Weekly: volume, deadlines, first-time-right quality and open actions.
- Monthly: KPIs, cost, root causes, forecast and change decisions.
- Quarterly: business outcomes, risk, scope, continuity and improvement roadmap.
Every meeting should end with decisions assigned to one owner and date. Moving the same point between meetings without a decision is not governance.
Common mistakes
- RACI names roles nobody performs. List real roles and named deputies, not only departments.
- Everyone is consulted. Too many C roles delay simple decisions.
- The provider is A for business risk. Accountability sits with a party that does not control purpose and impact.
- No RACI for exceptions. The matrix covers normal work and fails when it is most needed.
- No update after change. A new system, volume or subcontractor is missing from the matrix.
Implement the model in 30 days
- List 15 to 25 process activities and decisions.
- Assign one A to every line.
- Add the R role, essential C roles and necessary I recipients.
- Attach evidence to every activity or decision.
- Build three escalation levels with timing and deputies.
- Walk through two scenarios: missing data and a security incident.
- After one month, remove unnecessary consultations and add overlooked exceptions.
If transition is still ahead, combine the matrix with our 30-day transition plan. Then connect roles to the service KPI review and business continuity plan. To define scope and accountability for correspondence, print, inserting or bulk mailing, talk to BackOffice Outsourcing before requesting a quotation.
Sources
- UK Government Commercial Agency, Contract management principles, updated 12 December 2025
- ISO 37500:2014, Guidance on outsourcing, confirmed current in 2021
- EDPB Guidelines 07/2020 on controller and processor concepts, Version 2.0
- UK National Cyber Security Centre, Supply chain security
Frequently asked questions
Does RACI replace the contract or SLA?
No. RACI assigns operating roles to tasks and decisions. The contract, SLA, instructions and data processing agreement still define obligations and legal requirements.
Can one activity have two Accountable roles?
It is not recommended. One A prevents disputes over the final decision. Several people may perform the work or be consulted.
Who remains responsible for personal data after outsourcing?
Roles follow the GDPR and the parties' actual decisions. The controller determines purposes and essential means, while the processor acts on documented instructions and remains responsible for its own duties.
How often should a RACI matrix be updated?
After changes to scope, systems, volume, teams or subcontractors, and after any incident that reveals unclear accountability.