ISO 37500:2014
ISO 37500:2014 gives generic, industry-independent guidance on outsourcing across a four-phase life cycle with governance at its centre. Clause 4 sets the contextual model, the reasons for outsourcing (cost, strategy change, capability access, risk transfer), seven key risks (no strategy, poor grasp of environment dynamics, blind cost focus, underestimated business impact, cultural incompatibility, fading process understanding, poor relationship management), the life cycle model and its main outputs, with the business case carried and re-baselined through every phase. Clause 5 sets the outsourcing governance framework: twelve principles, empowered managers, joint governance committees with charters and a relationship matrix, the client's retained organization, cultural differences, and three governance practices (joint objectives, committees, monitor-evaluate-direct) with phase-specific governance including the four exit triggers. Clauses 6 to 9 give the four phases as processes, each with purpose, activities, success factors and outputs: outsourcing strategy analysis (prerequisites, eligible services, organizational impact, strategy, initial business case, decision, project set-up); initiation and selection (service requirements, the outsourcing model and its frameworks, agreement structure, provider identification, shortlisting by RFP, outlining agreements with due diligence and exit management, negotiation and signature); transition (team, governance, refined frameworks and plan, knowledge acquisition, execution of the transfer, deployment of the quality-risk-audit-compliance, asset-knowledge and delivery frameworks, testing, pilot and formal handover with a baseline); and deliver value (service delivery, performance review, issues, changes, optional innovation and transformation, finances, relationships, the agreement, value assurance, and continuation or exit preparation). Guidance, not certifiable; the outsourcing counterpart of ISO 44001 collaborative relationships and the process reference for third-party and outsourcing controls in security, resilience and financial-services rules.
ISO 37500:2014 is a compliance framework from International with 6 domains and 57 controls. The largest domains are Clause 5: Outsourcing governance framework – ISO 37500:2014 (12 controls), Clause 9: Phase 4, Deliver value – ISO 37500:2014 (12 controls), Clause 8: Phase 3, Transition – ISO 37500:2014 (11 controls). Every control below carries what it requires and what an assessor expects to see.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (6)
Clause 4: Outsourcing introduction and model – ISO 37500:2014
| Code | Title |
|---|---|
| iso-37500-2014::4.1 | Contextual model of outsourcing |
| iso-37500-2014::4.2 | Reasons for outsourcing |
| iso-37500-2014::4.3 | Risks of outsourcing |
| iso-37500-2014::4.4 | Outsourcing life cycle model: governance at the centre of four phases |
| iso-37500-2014::4.5 | Summary of main outsourcing life cycle outputs |
| iso-37500-2014::4.6 | Repeating the outsourcing life cycle |
Clause 5: Outsourcing governance framework – ISO 37500:2014
| Code | Title |
|---|---|
| iso-37500-2014::5.1 | General: purpose and principles of outsourcing governance |
| iso-37500-2014::5.2 | Management structure and functions |
| iso-37500-2014::5.3 | Joint governance committees |
| iso-37500-2014::5.4 | Appreciation of cultural differences |
| iso-37500-2014::5.5.1 | General: governance practices across the phases |
| iso-37500-2014::5.5.2 | Develop and maintain joint objectives |
| iso-37500-2014::5.5.3 | Establish governance committee |
| iso-37500-2014::5.5.4.1 | General: monitor, evaluate and direct by well-informed decisions |
| iso-37500-2014::5.5.4.2 | Governance for phase 1: outsourcing strategy analysis |
| iso-37500-2014::5.5.4.3 | Governance for phase 2: initiation and selection |
| iso-37500-2014::5.5.4.4 | Governance for phase 3: transition |
| iso-37500-2014::5.5.4.5 | Governance for phase 4: deliver value, and exit triggers |
Clause 6: Phase 1, Outsourcing strategy analysis – ISO 37500:2014
| Code | Title |
|---|---|
| iso-37500-2014::6.1 | General: purpose of the outsourcing strategy analysis phase |
| iso-37500-2014::6.2 | Check outsourcing prerequisites |
| iso-37500-2014::6.3 | Understand services eligible for outsourcing |
| iso-37500-2014::6.4 | Assess organizational impact of outsourcing of services |
| iso-37500-2014::6.5 | Define outsourcing strategy |
| iso-37500-2014::6.6 | Develop initial business case(s) for outsourcing |
| iso-37500-2014::6.7 | Evaluate and decide |
| iso-37500-2014::6.8 | Set up outsourcing project |
Clause 7: Phase 2, Initiation and selection – ISO 37500:2014
| Code | Title |
|---|---|
| iso-37500-2014::7.1 | General: purpose of the initiation and selection phase |
| iso-37500-2014::7.2 | Detail required services |
| iso-37500-2014::7.3 | Detail outsourcing model |
| iso-37500-2014::7.4 | Define agreement requirements and structure |
| iso-37500-2014::7.5 | Identify potential providers |
| iso-37500-2014::7.6 | Shortlist providers |
| iso-37500-2014::7.7 | Outline agreements |
| iso-37500-2014::7.8 | Negotiate and establish agreements |
Clause 8: Phase 3, Transition – ISO 37500:2014
| Code | Title |
|---|---|
| iso-37500-2014::8.1 | General: purpose of the transition phase |
| iso-37500-2014::8.10 | Test service delivery capability |
| iso-37500-2014::8.11 | Pilot and handover |
| iso-37500-2014::8.2 | Establish transition project team |
| iso-37500-2014::8.3 | Establish outsourcing governance |
| iso-37500-2014::8.4 | Refine delivery frameworks and transition plan |
| iso-37500-2014::8.5 | Refine knowledge acquisition |
| iso-37500-2014::8.6 | Execute transition of knowledge, people, processes and technology |
| iso-37500-2014::8.7 | Deploy the quality, risk, audit and compliance frameworks |
| iso-37500-2014::8.8 | Deploy asset and knowledge management framework |
| iso-37500-2014::8.9 | Deploy delivery frameworks |
Clause 9: Phase 4, Deliver value – ISO 37500:2014
| Code | Title |
|---|---|
| iso-37500-2014::9.1 | General: purpose of the deliver value phase |
| iso-37500-2014::9.10 | Manage the agreement |
| iso-37500-2014::9.11 | Value and business case assurance |
| iso-37500-2014::9.12 | Continuation or end of agreement preparation |
| iso-37500-2014::9.2 | Deliver service |
| iso-37500-2014::9.3 | Monitor and review service performance (ongoing) |
| iso-37500-2014::9.4 | Manage and resolve issues (ongoing) |
| iso-37500-2014::9.5 | Deliver and manage changes (ongoing) |
| iso-37500-2014::9.6 | Deliver innovation (optional, ongoing) |
| iso-37500-2014::9.7 | Deliver transformation (optional) |
| iso-37500-2014::9.8 | Manage finances |
| iso-37500-2014::9.9 | Manage relationships |
What is ISO 37500:2014 and who does it apply to?
ISO 37500:2014 is a compliance framework from International with 6 domains and 57 controls. ISO 37500:2014 gives generic, industry-independent guidance on outsourcing across a four-phase life cycle with governance at its centre. Clause 4 sets the contextual model, the reasons for outsourcing (cost, strategy change, capability access, risk transfer), seven key risks (no strategy, poor grasp of environment dynamics, blind cost focus, underestimated business impact, cultural incompatibility, fading process understanding, poor relationship management), the life cycle model and its main outputs, with the business case carried and re-baselined through every phase. Clause 5 sets the outsourcing governance framework: twelve principles, empowered managers, joint governance committees with charters and a relationship matrix, the client's retained organization, cultural differences, and three governance practices (joint objectives, committees, monitor-evaluate-direct) with phase-specific governance including the four exit triggers. Clauses 6 to 9 give the four phases as processes, each with purpose, activities, success factors and outputs: outsourcing strategy analysis (prerequisites, eligible services, organizational impact, strategy, initial business case, decision, project set-up); initiation and selection (service requirements, the outsourcing model and its frameworks, agreement structure, provider identification, shortlisting by RFP, outlining agreements with due diligence and exit management, negotiation and signature); transition (team, governance, refined frameworks and plan, knowledge acquisition, execution of the transfer, deployment of the quality-risk-audit-compliance, asset-knowledge and delivery frameworks, testing, pilot and formal handover with a baseline); and deliver value (service delivery, performance review, issues, changes, optional innovation and transformation, finances, relationships, the agreement, value assurance, and continuation or exit preparation). Guidance, not certifiable; the outsourcing counterpart of ISO 44001 collaborative relationships and the process reference for third-party and outsourcing controls in security, resilience and financial-services rules. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
What does ISO 37500:2014 actually require?
ISO 37500:2014 has 57 controls organised across 6 domains. The largest domains are Clause 5: Outsourcing governance framework – ISO 37500:2014 (12 controls), Clause 9: Phase 4, Deliver value – ISO 37500:2014 (12 controls), Clause 8: Phase 3, Transition – ISO 37500:2014 (11 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
If I already comply with another framework, how much of ISO 37500:2014 do I already cover?
ISO 37500:2014 does not currently have cross-framework mappings in our system. Check back as we continuously expand our mapping database.
How do I implement ISO 37500:2014?
Start your ISO 37500:2014 compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about ISO 37500:2014 requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 57 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 704 frameworks.
Get Started Free →Free forever — no credit card required