ALL INSIGHTS

Certifications That Actually De-Risk an Outsourcing Decision

The vendor arrived for the governance review with a folder of certifications. Thirty pages, colour-coded, indexed. The governance lead worked through it methodically. Most of the certifications covered IT security, data handling, and quality management. None of them addressed what the carrier actually needed to know: could this provider continue to service a regulated insurance book when their primary operations were disrupted?

‍

Why Certification Quality Matters More Than Quantity

‍

CPS 230, in force since 1 July 2025, requires carriers to maintain defensible third-party arrangements for critical operations. Defensible means more than a completed checklist. It means the governance decision is based on substantive assessment, documented, and capable of withstanding APRA scrutiny. In New Zealand, RBNZ governance requirements demand the same standard of rigour from carrier third-party arrangements.

‍

Certifications are the governance shorthand teams reach for when assessing third-party capability. Used well, they are efficient evidence. Used poorly, they create the appearance of rigour without the substance. A folder that proves a vendor is well-organised does not prove that vendor can carry regulated operations when conditions deteriorate.

‍

The wrong certifications produce false confidence. That is a governance risk in its own right.

‍

What Most Certification Folders Actually Contain

‍

ISO 27001 - information security management - and SOC 2 are the most common entries in vendor certification submissions. Both matter. An insurance BPO handling policyholder data should hold them. But they prove that the vendor manages information security well. They do not prove operational continuity.

‍

ISO 9001 - quality management - is similarly ubiquitous and similarly incomplete for this purpose. It proves process discipline. It says nothing about what happens when the process environment is disrupted.

‍

There is a certification that proves a vendor passed an audit. There is a different certification that proves a vendor can keep operating when conditions turn adverse. That second one is ISO 22301, the business continuity management standard. It is substantially rarer than certification folders suggest - and it is the standard most directly aligned with what APRA's CPS 232 requires of business continuity arrangements.

‍

An operating track record in regulated insurance markets is equally probative, and rarely appears in a certifications folder at all. It is harder to present. It is also harder to fabricate.

‍

The Three That Actually De-Risk the Decision

‍

Not all certifications are equal, and some are easier to obtain than they appear. The CRO's checklist should begin with three things.

‍

First: ISO 22301. Business continuity management. This standard proves the vendor has planned, tested, and documented how they continue to operate when their primary environment fails. It requires independent audit and active BCP testing. When it is present, it is material evidence. When it is absent, the question of why needs a clear answer.

‍

Second: ISO 27001 - but reviewed at scope level. The certification may cover the vendor's head office and not the delivery centre servicing your book. Check which operations the scope statement covers.

‍

Third: a verified track record in a regulated insurance environment, on a comparable platform, for clients whose regulatory context mirrors your own. This is the evidence that no certification document can replicate. A vendor who has carried regulated volume under real conditions provides proof of capability that an audit cannot.

‍

What a Rigorous Certification Review Looks Like

‍

A certification folder reviewed with purpose asks four questions of every document.

‍

First: scope. What operations does this certification actually cover? The scope statement is the most important line in any certification document. A certification that covers a different part of the vendor's business than the one being contracted is not evidence of the capability you need.

‍

Second: currency. When was this certification last independently audited? A certification not reviewed in two or more years is historical, not current.

Third: absence. What is not in this folder? The absence of ISO 22301 is a meaningful data point. It should generate a specific question about how the vendor documents, tests, and evidences its business continuity capability.

‍

Fourth: the track record behind it. What regulated-market clients on comparable platforms has this vendor operated for? A certification and a track record together are evidence. A certification alone is a starting point.

‍

Under CPS 230, a governance decision documented with these four questions produces a defensible assessment that APRA can examine and find substantive.

‍

The Conversation Worth Having

‍

ISSI operates as a warm second source on the platforms ANZ carriers already run. Because platform fluency already exists, there is no ramp period before load can be carried. ISO 22301-class business continuity credentials, ISO 27001 information security certification, and an operating track record through PetSure's regulated claims environment are the evidence behind the certification. If the vendor governance review is live, it is worth thirty minutes.

‍

‍

‍

‍

‍

Sources: APRA CPS 230 Operational Risk Management (effective 1 July 2025); APRA CPS 232 Business Continuity Management; ISO 22301:2019; ISO 27001:2022; APRA Quarterly Life Insurance Performance Statistics (2025); IMARC Group Australia BPO Market Report (2025)

No items found.

Recent Insights

Read more
Culture and Social Responsibility

Celebrating Filipino Language through ISSIng Along: OPM Duets

ISSI Corp celebrates Buwan ng Wika through ISSIng Along: OPM Duets.

September 8, 2026
3 min
Read more
Industry Trends

What Great Claims Leadership Looks Like in 2026

Most claims leader job descriptions still read like they were written for a queue-management environment. Manage the team. Deliver the SLA. Produce the quarterly report. The accountability the role actually carries in 2026 is different in character.

August 27, 2026
5 min
Read more
Industry Trends

Systemic Fixes Have a Cost Dividend

Insurance service expenses grew 7% year-on-year at industry level through September 2025, even as carriers ran efficiency programmes. Other insurance expenses as a proportion of premium rose from 15% to 18% in the twelve months to June 2025. These numbers do not move with efficiency interventions alone, because efficiency programmes address the cost of doing the work - not the cost of doing the wrong work.

August 25, 2026
5 min