When a bank engages an external firm for compliance or reporting work, the engagement usually falls under SBP's outsourcing framework — BPRD Circular 06 of 2019. That framework does not prohibit outsourcing. It requires the institution to make a documented, risk-assessed decision and to keep control of what it has outsourced.
In practice, the burden lands on two desks: the business owner who wants the work done, and the compliance or risk function that must sign off the arrangement. The fastest way through is to demand the right paper from the vendor at the start.
What to ask every vendor for
- A written agreement with scope and service levels. Not a proposal email. Deliverables, timelines, and a named engagement lead.
- Confidentiality terms signed before data moves. If a vendor asks for sample data before an NDA, stop.
- Location of processing, in writing. Where is the data processed, by whom, and does it ever leave Pakistan? Offshore processing raises the assessment burden sharply.
- Audit rights. Your institution — and SBP — should be able to examine the controls relevant to your engagement.
- Business continuity. What happens to your filing deadline if the vendor's office floods in March?
- Exit terms. How does the engagement end? Data returned, copies destroyed, handover documented.
The onshore question
Location of processing is the item that most often stalls onboarding. A vendor who processes onshore, or better, works on the institution's own premises and systems for sensitive datasets, removes an entire category of cross-border risk from the assessment.
Vendor due diligence is not a form-filling exercise — it is the control that keeps an outsourced obligation yours. A vendor built for regulated clients will have every item above ready before you ask.