ISO 55001:2014
Operation – ISO 55001:2014

ISO 55001:2014 8.3: Outsourcing

Where the organization outsources an activity that could affect whether its asset management objectives are met, it assesses the risks involved and makes sure the outsourced processes and activities are under control. It decides, and documents, how those activities are controlled and brought into the asset management system, covering: which processes and activities are outsourced, together with their scope, boundaries and points where they meet the organization's in-house processes; who inside the organization is responsible for managing them and with what authority; and the processes for sharing knowledge and information with the contracted providers and how far that sharing extends. It makes sure the outsourced resources satisfy the requirements of 7.2 (competence), 7.3 (awareness) and 7.6 (documented information), and that the outsourced activities' performance is monitored under 9.1.

Maintained by Gerard Blokdyk

What else in your programme already covers this

This control maps to 17 controls across 9 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

ISO/IEC 38500:2024 · 9 controls

  • 5.2.3 Purpose: outcomes
  • 5.3.3 Value generation: outcomes
  • 5.4.3 Strategy: outcomes
  • 5.5 Oversight
  • 5.5.3 Oversight: outcomes
  • 5.6.3 Accountability: outcomes
  • 5.8.3 Leadership: outcomes
  • 5.9.3 Data and decisions: outcomes
  • 6.1 Introduction to the model

ISO 22000:2018 · 1 control

  • 8.3 Traceability system

ISO 22301:2019 · 1 control

  • 8.3 Business continuity strategies and solutions

ISO 37001:2016 · 1 control

  • 8.3 8.3 Financial controls

ISO 37301:2021 · 1 control

  • 8.3 Raising concerns

ISO 55001:2024 · 1 control

  • 8.3 Externally provided processes, products, technologies and services

ISO 9001:2015 · 1 control

  • 8.3 Design and development of products and services

ISO/IEC 42001:2023 · 1 control

  • 8.3 AI risk treatment

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Operation – ISO 55001:2014

You are reading one control. How much of ISO 55001:2014 have you already done?

ISO 55001:2014 8.3 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of ISO 55001:2014 your existing evidence covers. Hold ISO 55001:2024 and 27 of 27 ISO 55001:2014 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 0 were rejected on the ISO 55001:2024 pair alone.

Query this from an agent

The graph holds this control, the 17 it maps to, and the evidence behind each claim, over MCP and REST.