Back to Frameworks

ISO 37500:2014

International
v2014 (first edition)
6 domains
57 controls

ISO 37500:2014 gives generic, industry-independent guidance on outsourcing across a four-phase life cycle with governance at its centre. Clause 4 sets the contextual model, the reasons for outsourcing (cost, strategy change, capability access, risk transfer), seven key risks (no strategy, poor grasp of environment dynamics, blind cost focus, underestimated business impact, cultural incompatibility, fading process understanding, poor relationship management), the life cycle model and its main outputs, with the business case carried and re-baselined through every phase. Clause 5 sets the outsourcing governance framework: twelve principles, empowered managers, joint governance committees with charters and a relationship matrix, the client's retained organization, cultural differences, and three governance practices (joint objectives, committees, monitor-evaluate-direct) with phase-specific governance including the four exit triggers. Clauses 6 to 9 give the four phases as processes, each with purpose, activities, success factors and outputs: outsourcing strategy analysis (prerequisites, eligible services, organizational impact, strategy, initial business case, decision, project set-up); initiation and selection (service requirements, the outsourcing model and its frameworks, agreement structure, provider identification, shortlisting by RFP, outlining agreements with due diligence and exit management, negotiation and signature); transition (team, governance, refined frameworks and plan, knowledge acquisition, execution of the transfer, deployment of the quality-risk-audit-compliance, asset-knowledge and delivery frameworks, testing, pilot and formal handover with a baseline); and deliver value (service delivery, performance review, issues, changes, optional innovation and transformation, finances, relationships, the agreement, value assurance, and continuation or exit preparation). Guidance, not certifiable; the outsourcing counterpart of ISO 44001 collaborative relationships and the process reference for third-party and outsourcing controls in security, resilience and financial-services rules.

Verified

ISO 37500:2014 is a compliance framework from International with 6 domains and 57 controls. The largest domains are Clause 5: Outsourcing governance framework – ISO 37500:2014 (12 controls), Clause 9: Phase 4, Deliver value – ISO 37500:2014 (12 controls), Clause 8: Phase 3, Transition – ISO 37500:2014 (11 controls). Every control below carries what it requires and what an assessor expects to see.

Maintained by Gerard Blokdyk

Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.

Framework Domains (6)

Clause 4: Outsourcing introduction and model – ISO 37500:2014

6 controls
Controls in the Clause 4: Outsourcing introduction and model – ISO 37500:2014 domain of ISO 37500:20146 controls
CodeTitle
iso-37500-2014::4.1Contextual model of outsourcing
iso-37500-2014::4.2Reasons for outsourcing
iso-37500-2014::4.3Risks of outsourcing
iso-37500-2014::4.4Outsourcing life cycle model: governance at the centre of four phases
iso-37500-2014::4.5Summary of main outsourcing life cycle outputs
iso-37500-2014::4.6Repeating the outsourcing life cycle

Clause 5: Outsourcing governance framework – ISO 37500:2014

12 controls
Controls in the Clause 5: Outsourcing governance framework – ISO 37500:2014 domain of ISO 37500:201412 controls
CodeTitle
iso-37500-2014::5.1General: purpose and principles of outsourcing governance
iso-37500-2014::5.2Management structure and functions
iso-37500-2014::5.3Joint governance committees
iso-37500-2014::5.4Appreciation of cultural differences
iso-37500-2014::5.5.1General: governance practices across the phases
iso-37500-2014::5.5.2Develop and maintain joint objectives
iso-37500-2014::5.5.3Establish governance committee
iso-37500-2014::5.5.4.1General: monitor, evaluate and direct by well-informed decisions
iso-37500-2014::5.5.4.2Governance for phase 1: outsourcing strategy analysis
iso-37500-2014::5.5.4.3Governance for phase 2: initiation and selection
iso-37500-2014::5.5.4.4Governance for phase 3: transition
iso-37500-2014::5.5.4.5Governance for phase 4: deliver value, and exit triggers

Clause 6: Phase 1, Outsourcing strategy analysis – ISO 37500:2014

8 controls
Controls in the Clause 6: Phase 1, Outsourcing strategy analysis – ISO 37500:2014 domain of ISO 37500:20148 controls
CodeTitle
iso-37500-2014::6.1General: purpose of the outsourcing strategy analysis phase
iso-37500-2014::6.2Check outsourcing prerequisites
iso-37500-2014::6.3Understand services eligible for outsourcing
iso-37500-2014::6.4Assess organizational impact of outsourcing of services
iso-37500-2014::6.5Define outsourcing strategy
iso-37500-2014::6.6Develop initial business case(s) for outsourcing
iso-37500-2014::6.7Evaluate and decide
iso-37500-2014::6.8Set up outsourcing project

Clause 7: Phase 2, Initiation and selection – ISO 37500:2014

8 controls
Controls in the Clause 7: Phase 2, Initiation and selection – ISO 37500:2014 domain of ISO 37500:20148 controls
CodeTitle
iso-37500-2014::7.1General: purpose of the initiation and selection phase
iso-37500-2014::7.2Detail required services
iso-37500-2014::7.3Detail outsourcing model
iso-37500-2014::7.4Define agreement requirements and structure
iso-37500-2014::7.5Identify potential providers
iso-37500-2014::7.6Shortlist providers
iso-37500-2014::7.7Outline agreements
iso-37500-2014::7.8Negotiate and establish agreements

Clause 8: Phase 3, Transition – ISO 37500:2014

11 controls
Controls in the Clause 8: Phase 3, Transition – ISO 37500:2014 domain of ISO 37500:201411 controls
CodeTitle
iso-37500-2014::8.1General: purpose of the transition phase
iso-37500-2014::8.10Test service delivery capability
iso-37500-2014::8.11Pilot and handover
iso-37500-2014::8.2Establish transition project team
iso-37500-2014::8.3Establish outsourcing governance
iso-37500-2014::8.4Refine delivery frameworks and transition plan
iso-37500-2014::8.5Refine knowledge acquisition
iso-37500-2014::8.6Execute transition of knowledge, people, processes and technology
iso-37500-2014::8.7Deploy the quality, risk, audit and compliance frameworks
iso-37500-2014::8.8Deploy asset and knowledge management framework
iso-37500-2014::8.9Deploy delivery frameworks

Clause 9: Phase 4, Deliver value – ISO 37500:2014

12 controls
Controls in the Clause 9: Phase 4, Deliver value – ISO 37500:2014 domain of ISO 37500:201412 controls
CodeTitle
iso-37500-2014::9.1General: purpose of the deliver value phase
iso-37500-2014::9.10Manage the agreement
iso-37500-2014::9.11Value and business case assurance
iso-37500-2014::9.12Continuation or end of agreement preparation
iso-37500-2014::9.2Deliver service
iso-37500-2014::9.3Monitor and review service performance (ongoing)
iso-37500-2014::9.4Manage and resolve issues (ongoing)
iso-37500-2014::9.5Deliver and manage changes (ongoing)
iso-37500-2014::9.6Deliver innovation (optional, ongoing)
iso-37500-2014::9.7Deliver transformation (optional)
iso-37500-2014::9.8Manage finances
iso-37500-2014::9.9Manage relationships

What is ISO 37500:2014 and who does it apply to?

ISO 37500:2014 is a compliance framework from International with 6 domains and 57 controls. ISO 37500:2014 gives generic, industry-independent guidance on outsourcing across a four-phase life cycle with governance at its centre. Clause 4 sets the contextual model, the reasons for outsourcing (cost, strategy change, capability access, risk transfer), seven key risks (no strategy, poor grasp of environment dynamics, blind cost focus, underestimated business impact, cultural incompatibility, fading process understanding, poor relationship management), the life cycle model and its main outputs, with the business case carried and re-baselined through every phase. Clause 5 sets the outsourcing governance framework: twelve principles, empowered managers, joint governance committees with charters and a relationship matrix, the client's retained organization, cultural differences, and three governance practices (joint objectives, committees, monitor-evaluate-direct) with phase-specific governance including the four exit triggers. Clauses 6 to 9 give the four phases as processes, each with purpose, activities, success factors and outputs: outsourcing strategy analysis (prerequisites, eligible services, organizational impact, strategy, initial business case, decision, project set-up); initiation and selection (service requirements, the outsourcing model and its frameworks, agreement structure, provider identification, shortlisting by RFP, outlining agreements with due diligence and exit management, negotiation and signature); transition (team, governance, refined frameworks and plan, knowledge acquisition, execution of the transfer, deployment of the quality-risk-audit-compliance, asset-knowledge and delivery frameworks, testing, pilot and formal handover with a baseline); and deliver value (service delivery, performance review, issues, changes, optional innovation and transformation, finances, relationships, the agreement, value assurance, and continuation or exit preparation). Guidance, not certifiable; the outsourcing counterpart of ISO 44001 collaborative relationships and the process reference for third-party and outsourcing controls in security, resilience and financial-services rules. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.

What does ISO 37500:2014 actually require?

ISO 37500:2014 has 57 controls organised across 6 domains. The largest domains are Clause 5: Outsourcing governance framework – ISO 37500:2014 (12 controls), Clause 9: Phase 4, Deliver value – ISO 37500:2014 (12 controls), Clause 8: Phase 3, Transition – ISO 37500:2014 (11 controls). Each control defines specific requirements that organisations must implement to achieve compliance.

If I already comply with another framework, how much of ISO 37500:2014 do I already cover?

ISO 37500:2014 does not currently have cross-framework mappings in our system. Check back as we continuously expand our mapping database.

How do I implement ISO 37500:2014?

Start your ISO 37500:2014 compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about ISO 37500:2014 requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 57 controls and track your progress.

Start Your Compliance Journey

Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 704 frameworks.

Get Started Free →

Free forever — no credit card required