Most BPO provider evaluations stop right where the real risk begins. The proposal gets compared, the floor gets visited, the certificates get requested, and the contract gets signed. All of that answers one question: how the provider works today. None of it answers the other one: whether they can sustain that operation across the two or three years of the contract.
That second question is what due diligence is for. It isn't a layer of distrust, it's buyer's work. A serious provider expects it and welcomes it, because it separates them from whoever quoted cheaper without the means to back it up.
The difference between impression and verification
A site visit produces impressions: the floor looked orderly, the supervisor answered well, the atmosphere seemed healthy. All of that is useful and it's covered in what to ask on a BPO provider site visit. Due diligence produces something else: documents with a date, an issuer and a validity period.
The practical rule is simple. If a claim in the proposal has no verifiable document behind it, it isn't a fact: it's an intention. That doesn't make it false, but it does take it off the list of things a contract can be built on.
1. Legal existence and who stands behind it
The starting point is dull and frequently skipped: a current certificate of incorporation and legal representation, a corporate purpose that actually covers the service being contracted, how long the company has existed, and who owns it.
What you're looking for there isn't a stamp. It's whether the entity signing is the same one that will operate, whether it has existed long enough to have a track record, and whether the signatory has authority to bind it. A contract signed by someone without the capacity to sign it becomes a problem at exactly the moment you need to claim something.
2. Financial strength
A BPO operation is mostly payroll. The provider pays its people every fortnight and invoices the client afterwards, on terms. That timing gap is the business and also its fragile point: a provider short on cash doesn't stop operating all at once, it degrades in pieces.
The first thing cut when cash is tight is never the agent handling contacts. It's the supervision, the quality analyst, the trainer and the replacement for whoever resigned. The operation stays standing and the metrics start sliding with no visible cause.
It's worth requesting financial statements for the last two or three years and looking at three things: liquidity, debt level and revenue trend. No sophisticated analysis is needed to spot what matters: if the structure can't absorb one month of delayed payment, continuity risk belongs to the client as much as to the provider.
A provider with cash problems doesn't announce it. It starts showing up in attrition and on the dashboard.
3. Labour and social security compliance
This is the point that costs the most to ignore in Colombia, and it should be reviewed with your own legal counsel. In general terms, contracting services through a third party doesn't always fully insulate the contracting company from labour claims, which is why it matters how the team handling your process is employed.
The concrete questions are these: do agents hold a direct employment contract with the provider, or are they engaged through another arrangement? Are social security contributions current and can that be evidenced? Are there ongoing labour disputes, and of what kind? A high volume of claims on the same grounds says more about the operation than any certification does.
None of this is legal advice: it's the list of what's worth putting on the table before signing, so that counsel on each side works from facts.
4. Subcontracting: who actually does the work
Some providers win contracts and then place part of the work with a third party. Sometimes that's legitimate and declared; sometimes it surfaces on day one of the operation.
It's worth asking directly and writing it down: which parts of the service run with their own staff, which with third parties, at which sites, and whether the client has the right to approve a change to that arrangement. An operation that moves to an undeclared site changes the security risk, the continuity risk and sometimes the legal framework applying to the data.
5. Concentration: theirs and yours
Two symmetrical questions almost nobody asks.
- How much the provider's largest client represents in their revenue. If a single contract holds the company up, that client leaving can drag down everyone else's operation.
- How much your account will represent in the provider's capacity. Too small and it will never be the priority when the best supervisor has to be assigned. Too large and the provider has to grow faster than it can recruit and train.
The second one explains more month-four quality problems than anything else. A provider doubling in size to serve a new account is learning to operate at the same time as it operates.
6. References that actually help
A reference the provider picked confirms what the provider already said. To get something out of it, ask for two different things: to speak with the operational contact and not only the commercial one, and for a reference from a client whose contract ended.
That second conversation is the most useful in the whole process. Not to look for a verdict, but to understand how the provider behaved when the relationship was ending: whether they handed over the information, whether they held service levels to the last day, whether they billed for everything they possibly could. That is exactly what the exit clause should already say, a topic we cover in switching BPO providers without breaking the operation.
7. What certifications already cover and what they don't
Information security and continuity standards certify that a management system exists, with a defined scope. That scope is the part to read: a certification can cover one site and not the other, or one process and not the one you care about. What each standard certifies is in BPO provider certifications, and what a continuity plan should contain is in business continuity in BPO.
How to run it without turning it into a project
Due diligence on an outsourcing contract fits on a one-page list with three columns: what is requested, who verifies it on the client side, and the date it was verified. Findings don't get filed away: they become a clause, a condition precedent to signature, or a decision not to proceed.
What doesn't work as evidence: client logos in the proposal, awards, declared years of experience with nothing behind them, and result figures with no methodology. None of that is necessarily false. It simply can't be verified, and therefore can't hold up a decision.
How smartBPO works it
We hand over the legal, financial and labour compliance documentation as part of the contracting process, without it having to be asked for twice, and we state in writing which parts of the service run with our own staff and at which sites. When a new account means growing, we say so with the recruiting and training plan alongside it, because the risk of an accelerated ramp is real and I'd rather discuss it upfront than explain it in month four. We give operational references, not just commercial ones. And we accept verification as a condition precedent to signature: if something can't be evidenced, it shouldn't be in the contract.