
Monday morning. The inbound call lines are down. The claims portal is unreachable. The BPO partner reports a platform incident with no restoration timeline. The COO is on the bridge call. The Head of Customer Operations is being asked how long the queue will be by end of day. Nobody has an answer. And somewhere in the back of the room, someone is about to ask about the second source.
Operations outages in insurance BPO are a known risk category, not an edge case. Technology failures, cyber incidents, geographic disruptions, vendor operational difficulties - each represents a plausible disruption event for a carrier dependent on a single BPO partner in a single geography.
The standard response is a BCP document naming a second source. When the outage occurs, the second source activates. The problem is what "activates" means in practice - and how long it takes.
APRA data shows insurance service expenses grew 7% year-on-year to September 2025, even as carriers pursued efficiency programs. Carriers already under cost pressure cannot absorb an unplanned outage cost. The outage is not an abstract risk; it is a cost event that arrives on top of a cost base already moving in the wrong direction.
The visible cost of an operations outage is operational degradation: staff on manual workarounds, higher error rates, reduced throughput, increased management time. These costs are immediate and real.
The tail costs are less visible. The tail outlasts the event by months - AFCA complaints filed retrospectively, policyholders who lapsed during the window, customers who started shopping alternatives and did not stop.
In Australia, AFCA complaints generated during a service disruption extend beyond restoration of service. Policyholders who could not reach their carrier during a claims window, a renewals period, or a payment dispute do not always call back when the lines come back up. In New Zealand, FMA conduct obligations and RBNZ operational resilience expectations create equivalent accountability - a material service failure attracts regulatory attention that does not resolve when the platform is restored.
Policy lapse during the disruption window is the cost most resilience business cases omit entirely. A policyholder who cannot make contact at a critical moment may not renew. That policy does not return.
The standard resilience investment calculation uses probability weighting: estimated probability of an outage multiplied by estimated operational cost equals expected value of the risk. That comparison typically makes the resilience investment look expensive.
The error is in the cost estimate. When the full outage cost is included - the AFCA complaints tail, policy lapse during the disruption window, customer attrition at next renewal, and regulatory scrutiny under CPS 230 (in force 1 July 2025) and equivalent NZ conduct frameworks - the expected value of the risk is materially higher.
The critical variable in the comparison is outage duration. The longer the disruption runs, the larger each tail component becomes. Shortening the duration does not reduce costs proportionally - it can reduce the tail disproportionately, because the complaints and attrition triggers often have thresholds rather than linear scaling.
A warm second source changes the outage duration. Not because it prevents the outage - it does not. But because it can carry load within days of activation, rather than at the end of a ramp measured in weeks.
Every day the warm second source carries operational volume is a day the cost clock stops accumulating. The AFCA complaints tail shortens. Fewer policyholders reach the lapse decision. Fewer customers complete the switching journey. The regulatory scrutiny window is shorter.
The platform fluency that makes a second source warm - operating on the same policy administration system before the crisis, not after - is the specific capability that determines the duration difference. A cold source with a twelve-week ramp cannot reduce the outage cost during those twelve weeks. A warm source is carrying load in days.
ISSI operates as a warm second source on the platforms ANZ carriers already run. Because platform fluency already exists, there is no ramp period before load can be carried. ISO 22301-class BCP credentials have been independently verified. The operating record on carrier platforms including PetSure demonstrates this in practice.
If the cost of an extended outage against the cost of a warm second source arrangement is a live calculation, it is worth thirty minutes.
Sources: APRA CPS 230 (Operational Risk Management, in force 1 July 2025); APRA Quarterly Insurance Performance Statistics (September 2025); AFCA complaint data patterns (general reference)