The short answer

If a partner can't answer all 12 of these questions fluently on a first call, they aren't ready to handle your data. The checklist works equally well for customer support outsourcing, BPO services, and virtual assistant engagements.

Confidentiality and data security are the two things teams worry about most before outsourcing — and rightly so. The good news: most issues are predictable and preventable. The bad news: too many partners hand-wave their way through security on the sales call and figure it out after signing.

This checklist gives you the 12 questions a serious buyer asks, what good answers sound like, and what should make you walk away.

Why security questions matter before — not after — you sign

By the time you've shared your first customer record, the partner has the leverage. Asking these questions on the first call costs nothing. Asking them after the contract is signed costs everything.

Contract & NDA — questions 1 to 3

1. Will you sign a mutual NDA before we share anything sensitive?

Expected answer: yes, at the company level. Walk if a partner needs to "check" or proposes a one-way NDA that protects only them.

2. Does every agent assigned to my account sign an individual confidentiality agreement?

Expected answer: yes — and they retain a copy on file. This is the question that separates real BPO from gig-economy talent platforms.

3. Will you sign a Data Processing Agreement (DPA) under GDPR / UK DPA / CCPA?

Expected answer: yes, with named sub-processors and a clear list of data categories. If you handle EU, UK or California personal data, this is non-negotiable.

Access & identity — questions 4 to 6

4. How will agents access my systems — through my SSO or shared credentials?

Expected answer: through your SSO (Okta, Google, Microsoft Entra) wherever possible, with shared password manager (1Password / Bitwarden) only for tools that don't support SSO. Shared master credentials in a spreadsheet is a hard no.

5. Is MFA enforced on every agent account?

Expected answer: yes, with hardware keys or app-based MFA. SMS MFA is acceptable as a baseline only.

6. How fast can access be revoked when an agent rotates off my account?

Expected answer: within the hour, by a named person, with a written confirmation. Anything over 24 hours is too slow.

Data handling — questions 7 to 9

7. Where does my data physically live, and where do agents process it from?

Expected answer: precise locations for both. For regulated industries this can be the difference between compliant and not.

8. Do agents process my data on company-managed devices or personal devices?

Expected answer: managed devices for sensitive engagements, with disk encryption, MDM and screen lock standards. BYOD with no controls is a risk most clients can't accept.

9. What's the data retention policy after the engagement ends?

Expected answer: a documented retention period (commonly 30–90 days), a verified deletion process, and a deletion certificate on request.

Operational resilience — questions 10 to 12

10. What's your incident response process if a breach happens?

Expected answer: notification within 24–72 hours, named incident lead, root cause analysis within seven days. If they've never had to do this, ask how they'd handle a hypothetical.

11. Do you sub-contract any of the work?

Expected answer: a clear yes/no, with named sub-processors if yes, and written consent required for any change. Hidden sub-contracting is the source of most data leakage we see in BPO.

12. What happens to my service if your office or country has an outage?

Expected answer: a real business continuity plan — secondary location, work-from-home protocol, failover team. "We've never had to think about it" is the wrong answer.

Red flags that should end the call

  • Asks you to share master credentials over email or chat.
  • Refuses to sign mutual NDAs or DPAs.
  • Can't name sub-processors.
  • No MFA enforcement.
  • No documented offboarding process.
  • "We'll figure it out when it happens" answers on incident response or BCP.

What good security looks like in practice

At Outbridge, the answers to all 12 are documented on our compliance page: mutual NDAs as standard, individual agent confidentiality agreements, GDPR-aligned DPAs, SSO-first access, MFA enforced, same-hour revocation, named incident leads, documented BCP, and zero hidden sub-contracting.

Need to vet a partner — including us?

We're happy to walk you through every answer on this checklist on a 30-minute call. No pitch, no obligation.

Book a call
Security in outsourcing isn't a feature — it's a posture. You can tell within ten minutes of a first call whether a partner takes it seriously.

Once you've cleared a partner on security, the next things to settle are scope, SLAs and price. See our companion guides on outsourced customer support and BPO vs in-house cost.

Frequently asked questions

What security questions should I ask an outsourcing partner?

Cover NDAs, agent-level confidentiality, least-privilege access, MFA, password managers, device security, data location, retention, incident response, business continuity, sub-contracting and audit rights — all 12 are in this guide.

Is outsourcing safe for businesses handling customer data?

Yes — provided the partner enforces NDAs, signs a DPA, controls access through your SSO, and follows clear data-handling rules. Most incidents come from credential sharing, not the model.

Do outsourcing partners sign NDAs?

Reputable partners sign mutual NDAs at the company level and require every assigned agent to sign an individual confidentiality agreement.

What is a Data Processing Agreement (DPA) and do I need one?

A DPA governs how a vendor processes personal data on your behalf. Required for GDPR, CCPA, UK DPA and similar regimes.

How should I grant systems access to an outsourced team?

Through your own SSO or password manager, with role-based least-privilege permissions, MFA enforced — never by sharing master credentials.