Specification and the Placement of Vendor Oversight
Specification and the placement of vendor oversight is the question of who, inside a client organization, should manage an outsourced supplier's day-to-day performance: a shared-service vendor team that already holds the contract, the invoicing, the penalty regime and the record of commitments, or the operational line that designs the job and manages the client's own people doing comparable work. The question has no single answer. The variable that decides it is how specified the outsourced work is. Highly specified, scripted work can be overseen at a distance by whoever holds the contract. Work that requires judgment can only be overseen by a party that knows the process well enough to recognize good performance when the numbers do not show it, and that knowledge lives with the business.
This page sets out the trade-offs on each side and the research that bears on them. It is the contingency companion to Vendor Governance Placement, which assigns individual governance functions to parties. This page explains why the assignment of the day-to-day functions should move as the character of the work changes, and where the boundary lies.

The question, stated precisely
Two parties can plausibly hold the day-to-day management of an outsourced supplier.
The shared-service vendor team (a vendor management function that sits alongside the shared workforce management team, and is variously called a vendor management office, a supplier management team, or procurement) signed the contract. It holds the service-level definitions, the invoice reconciliation, the penalty and credit regime, and the record of what was committed. It sees every supplier, so it can compare them. It is independent of the line whose work is being measured. Its weakness is that it stands at a distance from the work itself.
The operational line designs the job that the supplier's agents perform, sets the procedures, trains and manages the client's own agents doing the same or adjacent work, and carries the customer outcome. It sees the supplier's performance from inside the process. Its weakness is that it is not independent, it does not see across suppliers, and it did not sign the contract.
Note what is not in dispute. The commercial functions — contracting, invoicing, penalties, the enforcement of contractual commitments — sit with the shared-service vendor team on every reading of the evidence, because they require cross-supplier comparison and independence from the measured party. The contested territory is the middle: daily quality review, coaching feedback, procedural adherence, staffing and schedule fit, ramp progress, the judgment of whether a supplier is performing well. That is the territory this page is about.
The variable: how specified the work is
Specified work is work whose procedure can be written down completely, whose exceptions are rare and themselves documented, and whose output can be checked against a standard without knowing how it was produced. Data entry, document verification, standard refunds and exchanges, queue-based back-office processing, and scripted first-contact triage are of this kind. Discretionary work is work in which the correct action depends on reading the situation, in which exceptions are frequent and the procedure is a guide rather than a script, and in which the output cannot be fully judged without knowing what the situation was. Disruption recovery, complex itinerary changes, service failures, escalations, and any contact where the customer's problem is not known until it has been diagnosed are of this kind.
The distinction is older than outsourcing research. Perrow's typology of work characterizes any task by the number of exceptions it produces and how analyzable those exceptions are (Perrow 1967). Eisenhardt's term is task programmability, the degree to which the appropriate behavior can be specified in advance (Eisenhardt 1985). In the sourcing literature the same idea appears as codifiability: work that can be codified, standardized and modularized can be disaggregated and moved; work that cannot, resists (Mithas & Whitaker 2007). Aron and Singh sort processes into transparent (measurable and codifiable), codifiable (mostly codifiable, partly measurable) and opaque (neither), and observe that when the quality of the result cannot be measured, the risk of moving the process elsewhere is very high (Aron & Singh 2005).
The argument of this page is that the same property which determines whether work can be disaggregated and moved also governs who can oversee it once moved. The link is a derivation from two literatures rather than a finding reported in either; its limits are stated below.
What control theory says
The organizational-control literature gives the contingency its mechanism. Ouchi's framework holds that there are exactly two conditions under which an organization can control work rationally. It must either know the transformation process well enough to judge whether the right behaviors are being performed, or measure the output well enough to judge whether the right result is being produced (Ouchi 1979). Where the process is understood, behavior control works: observing, directing, correcting the way the work is done. Where the output is measurable, output control works: setting targets and checking results. Where both hold, either works. Where neither holds, the only remaining mechanism is what Ouchi called clan control: shared values, socialization, and the professional judgment of people who have internalized what good work looks like.
Eisenhardt tested the framework in a field study of compensation for retail salespeople across 54 stores and found task programmability strongly related to the choice of control (Eisenhardt 1985). More programmed tasks go with behavior-based control. Less programmed tasks require outcome-based control or elaborate information systems to make behavior observable. Kirsch and colleagues extended the framework to clients directing information-systems projects and found that knowledge of the process is a key antecedent of control, and that clients are unlikely to be as knowledgeable about the process as the professionals performing it (Kirsch, Sambamurthy, Ko & Purvis 2002).

Mapped onto the placement question, the two conditions produce four cases.
| Output measurable | Process known to the overseer | Control mode that works | Who can hold day-to-day oversight |
|---|---|---|---|
| Yes | Yes | Output or behavior control | Either party. The vendor team can manage on contract metrics; the line can manage on procedure. Scripted back office sits here. |
| Yes | No | Output control only | The vendor team on the contract metrics; the line on job design and procedure, which the vendor team cannot see. |
| No | Yes | Behavior control only | The party that knows the process. This requires proximity to the work; a vendor team must first acquire the knowledge. |
| No | No | Relational or clan control | Only a party embedded in the work. Discretionary front-office work, where output measures are proxies and the procedure is a guide, sits here. |
Falling specification moves work toward the lower rows of this table. As work becomes less scripted, output measures become proxies rather than results, and the behaviors that produce good outcomes become harder to state in advance. The control modes that remain available all require the overseer to know the process from inside.
What happens when the overseer lacks process knowledge
The theory would matter less if a vendor team could simply exercise control anyway. The empirical record suggests that it cannot.
A study of 57 outsourced and 79 internal systems projects across 136 organizations found that clients attempt more control in outsourced projects than in internal ones. Yet controls improved performance in internal projects and not in outsourced ones. The authors distinguish attempted control from realized control: anticipated hazards motivate the first, but only specific informational and social prerequisites deliver the second (Tiwana & Keil 2009). A study of 138 matched client-vendor pairs in eight long-term outsourcing arrangements found that clients with technical or relationship-management knowledge use less formal control, while task uncertainty is associated with more of it (Rustagi, King & Kirsch 2008). Read together, the two findings describe a trap: as work becomes more discretionary, clients reach for more formal control, and formal control is the mode least likely to be realized when the client lacks knowledge of the process.
Case research on control portfolios in outsourced projects finds that they begin dominated by outcome controls and that behavior controls are added later, reactively, after performance problems, once enough process visibility has been acquired to make them possible (Choudhury & Sabherwal 2003). A control-mode study conducted on business-process rather than software outsourcing, across 234 paired projects, found the effect symmetric: where the client lacks capability, process control fails and outcome control is what works; where the vendor lacks capability, the reverse (Liu, Wang & Huang 2017). And a study of 198 outsourcing relationships found that losing the underlying capability degrades outsourcing performance and, as a separate effect, erodes the client's ability to manage the relationship at all (Handley 2012).
The cost side points the same way. In a dyadic study of 102 outsourcing relationships, the control and coordination costs borne by the customer rose with the scale of the service and with the geographic distance between the parties (Handley & Benton 2013). Larger engagements are more expensive to oversee, and more expensive still to oversee from a distance.
Learning the business
The mechanism behind all of these findings is the same: to oversee discretionary work, the overseer must know the business the work serves. A vendor team asked to manage a supplier's daily performance on judgment-heavy work is being asked to learn the operation well enough to tell, from a sampled contact and a proxy metric, whether the supplier did the right thing. That is a substantial requirement. The operational line already meets it, having designed the job and managing its own people doing the same work.
The knowledge involved has three properties that make it hard to hold at a distance.
It is cumulative and path-dependent. Absorptive capacity, the ability to recognize the value of new information and apply it, is a function of prior related knowledge and is built over time rather than acquired at need (Cohen & Levinthal 1990). A function that has not been inside the process has less of the base on which the next piece of knowledge lands.
It substitutes for contract. Business familiarity between a client and a supplier reduces both adverse-selection risk (the supplier is not what it appeared) and moral-hazard risk (the supplier will not behave as promised), and its effect shows up not in the price but in how the relationship is managed, with familiar parties moving toward time-and-materials rather than fixed-price forms (Gefen, Wyss & Lichtenstein 2008). The party that knows the work needs the contract less; the party that does not know it can only lean on the contract harder.
It can be spanned, at a cost. Boundary-spanning activity between client and vendor significantly improves the effectiveness of formal controls, because it carries knowledge across the organizational and domain boundaries that formal control cannot cross on its own (Gopal & Gosain 2010). A vendor team can substitute boundary spanners for embeddedness. But a boundary spanner who learns the business and stays with it is, in every respect that matters for control, a member of the operational line who happens to report elsewhere.
That last point resolves what looks like a structural question into a question of proximity. If a vendor team is close enough to a segment of the business to learn it and stay with it, that team can hold the day-to-day performance management for that segment. Whether it reports to operations or to a vendor team is then an org-chart matter. What it cannot do is hold that role for every segment at once, because the knowledge does not generalize across businesses any more than it generalizes across suppliers.
The case for the vendor team
The evidence for embedding is not one-sided, and the case for a vendor team is strongest exactly where the operational line is weakest.
Comparability. A review of 27 studies on procurement organization found that without a central program most organizations do not form an effective supplier evaluation system at all, and that embedded governance fragments supplier intelligence and duplicates administration (Kanepejs & Kirikova 2018). The line sees one supplier; the vendor team sees all of them, on one instrument.
Independence. Performance measurement produces dysfunctional behavior wherever the measured party influences the measure (Ridgway 1956), and the strongest evidence of a gap between reported and real performance comes from audited data in systems where the reporting unit was also the managed unit (Bevan & Hood 2006). An operational line that manages its supplier's performance is also reporting on its own segment's performance. The two are not easily separated.
Resistance to capture. No direct evidence exists that embedded vendor managers become lenient toward the suppliers they manage. The nearest evidenced analogue, auditor tenure, finds that long association produces measurably greater leniency (Favere-Marchesi & Emby 2018). A vendor team that rotates across suppliers is structurally less exposed.
Contractual leverage. The party that holds the penalty regime can act on a finding; the party that does not can only escalate. Where the finding is simple and the response is contractual, keeping oversight with the party that can enforce shortens the loop.
Each of these advantages is real. Each is also strongest where the work is specified, because that is where the vendor team's instrument, a contract metric, is a true measure rather than a proxy, and where the finding it produces is one the contract can act on. As the work becomes discretionary, comparability is comparing proxies, independence is independence from a signal that no longer carries the information, and leverage is penalizing a number that the supplier can move without improving the work.
Trade-offs, side by side
| Criterion | Shared-service vendor team | Operational line | What decides it |
|---|---|---|---|
| Knowledge of the process | Must be acquired, per segment, and maintained | Already held; the line designed the job | Rises sharply with discretion |
| Cost of monitoring | Higher; grows with scale of service and geographic distance | Lower; the line is already watching its own people do the same work | Handley & Benton 2013 |
| Control modes available | Output control on contract metrics; behavior control only after knowledge is acquired | Output, behavior and relational control | Ouchi 1979; Kirsch et al. 2002 |
| Cross-supplier comparison | Native | Absent | Favors the vendor team for any function that compares |
| Independence from the measured line | Native | Absent | Favors the vendor team for measurement and enforcement |
| Speed of correction | Slower; findings travel through escalation | Faster; the coach is in the room | Matters more as exceptions rise |
| Job design and turnover | Cannot be held by the vendor team; the line writes the specification | Native | Holman, Batt & Holtgrewe 2007 |
| Exposure to capture | Lower, with rotation | Higher, with tenure | Favere-Marchesi & Emby 2018 (analogue) |
| Contractual response | Direct | Indirect | Favors the vendor team where findings are contractual |
The pattern in the final column is consistent: the criteria that favor the vendor team are the ones that do not depend on the character of the work, and the criteria that favor the line are the ones that do. That is why the commercial functions stay with the vendor team at every point on the gradient, and why the day-to-day functions move.
When the contract stands in for oversight
A vendor team that cannot exercise behavior control on discretionary work has one instrument left: the contract metric, backed by the penalty. Several literatures bear on what that produces, and they point the same way.
When an agent performs several tasks and only some can be measured, incentives attached to the measurable ones pull effort away from the rest; the optimal response is sometimes to weaken the incentive rather than strengthen it (Holmström & Milgrom 1991). In contact-center contracting specifically, service-level agreements written on the percentile of delay can induce a supplier to prioritize the contracting client's calls only in off-peak hours, exactly when priority is least valuable (Milner & Olsen 2008). Experimental work finds that framing contract terms as penalties raises compliance effort and lowers knowledge-sharing and commitment (Fehrenbacher & Wiener 2019). Formal contracts and relational governance work best as complements, each covering what the other cannot (Poppo & Zenger 2002). A contract asked to carry the whole of oversight on discretionary work is being asked to substitute for a relationship it was designed to accompany.
None of this argues against the vendor team's commercial role. It argues against the vendor team's commercial instrument being used as the day-to-day oversight of work the instrument cannot see.
The placement rule
Three zones follow from the evidence.
Highly specified work (scripted back office, standard transactions, queue processing with documented exceptions). Output is measurable; the process is documented; contract metrics are true measures. The vendor team can hold day-to-day oversight along with the commercial functions, and there are comparability and independence benefits to its doing so. This departs from the devolved default in Vendor Governance Placement, which places day-to-day quality and performance management with the operational line. High specification should be read as a fifth condition under which that default reverses, alongside the four listed there. Job design still sits with the line, because the line writes the specification the supplier follows.
Semi-structured service work (guided contacts with frequent but bounded exceptions). Output measures are partly proxies; the procedure needs interpretation. Behavior control is already the mode that works here, and behavior control requires knowledge of the process, so day-to-day oversight sits with the line even though some of the output is still measurable. The vendor team keeps the contract instrument and independently verifies the measure; it does not manage the supplier's daily performance. This zone is where most disputes over placement occur, because the measurable part of the output invites a vendor team to hold more than it can see.
Discretionary front-office work (diagnosis, recovery, complex change, escalation). Output measures are proxies; the procedure is a guide; good performance is recognizable mainly to someone who knows the business. Day-to-day performance management sits with the party that designs the job and manages the client's own people doing it. A vendor team can hold the commercial functions and the independent measurement instrument, but it cannot hold the judgment.
Three questions assign a body of work to a zone. How often does the work produce exceptions the procedure does not cover? Can the output be judged as right or wrong without knowing what the situation was? Is the procedure a script to be followed or a guide to be interpreted? Rare exceptions, judgeable output and a script place the work in the first zone. Frequent exceptions, output that can only be judged in context and a guide place it in the third. Mixed answers place it in the second.
The boundary between the first and second zones is the learn-the-business threshold: the point past which an overseer must know the operation from inside to tell good performance from good numbers. It sits early on the gradient, at the edge of scripted work, because behavior control needs process knowledge as soon as the procedure requires interpretation. Where a vendor team has crossed that threshold for a given segment, it can hold the role for that segment. Where it has not, assigning it the role produces attempted control without realized control, at rising cost, enforced through an instrument that distorts the work it is meant to protect.
For contact centers, the practical consequence is that the vendor team holds day-to-day oversight only for purely back-office, highly specified work, and that a substantial share of front-office work sits in the third zone, plausibly most of it. The share is an inference, not a measured quantity. The share of contacts that are genuinely scripted is smaller than it appears from the outside, because scripted contacts are the ones most often automated or deflected first, leaving the human queue weighted toward the exceptions. Job design compounds the point: in a survey of roughly 2,500 centers across 17 countries, turnover ran near nine percent where jobs were high-discretion and low-monitoring and near thirty-six percent where they were low-discretion and high-monitoring (Holman, Batt & Holtgrewe 2007). The party that specifies the job holds the strongest lever on the supplier's attrition, and that party is the line.
Where the evidence runs out
No study directly compares shared-service against embedded oversight of an outsourced supplier and measures a service outcome. The control-mode findings above come from information-systems and software outsourcing, with one business-process study; the cost findings come from global sourcing generally; the contact-center findings concern contract design and job design rather than governance placement. The contingency on this page is a derivation from those bodies of work, not a result reported by any one of them. It is consistent with all of them, which is the most that can currently be said.
Two specific claims are weaker than the rest. The capture argument for the vendor team rests on an analogue from auditing, not on outsourcing evidence. And the claim that most contact-center front-office work is discretionary rather than scripted is an observation about automation's selection effect, not a measured share; the proportion will differ by operation and should be established rather than assumed.
A third caveat is structural. Perrow's exception rate, Eisenhardt's task programmability, Rustagi's task uncertainty and Mithas and Whitaker's codifiability are treated here as one underlying variable. They are closely related and were developed independently, and no study establishes that they measure the same construct.
Maturity Model considerations
At L1–L2, one function holds both the commercial and the day-to-day roles, usually the one that signed the contract, regardless of the character of the work. Oversight of discretionary work is conducted on contract metrics, and the gap between reported and delivered performance is not visible.
At L3, the commercial and day-to-day roles are separated, but the split is made once for all suppliers rather than by the character of the work, so scripted and discretionary work are governed the same way.
At L4, placement follows specification: the vendor team holds the commercial functions and the measurement instrument everywhere, day-to-day oversight of highly specified back-office work stays with the vendor team, and day-to-day oversight of all other work sits with the line that designs the job. Boundary-spanning roles are staffed deliberately where the line manages a supplier the vendor team must still compare.
At L5, the specification of each body of work is assessed rather than assumed, the learn-the-business threshold is reviewed as automation shifts the mix of the human queue, and the same oversight design applies across owned, partner and outsourced supply.
See Also
- Vendor Governance Placement — the function-by-function assignment this page explains
- Vendor Ecosystem Restructuring Agenda — where governance placement sits among the other restructuring levers
- BPO and Vendor Management for WFM — the day-to-day management of outsourced supply
- Placement Rules and the Tenure Contract — which work is externally eligible in the first place
- Business Process Outsourcing — the three node types and why they exist
- Supply Elasticity in Workforce Planning — outsourcing as a variance lever
- Quality Management in Contact Centers — the instrument the vendor team should hold
- Speed to Proficiency Curve — why learning the business takes the time it takes
References
- Aron, R. & Singh, J.V. (2005). Getting offshoring right. Harvard Business Review, 83(12).
- Bevan, G. & Hood, C. (2006). What's measured is what matters: targets and gaming in the English public health care system. Public Administration, 84(3).
- Choudhury, V. & Sabherwal, R. (2003). Portfolios of control in outsourced software development projects. Information Systems Research, 14(3).
- Cohen, W.M. & Levinthal, D.A. (1990). Absorptive capacity: a new perspective on learning and innovation. Administrative Science Quarterly, 35(1).
- Eisenhardt, K.M. (1985). Control: organizational and economic approaches. Management Science, 31(2). Field study, 54 stores.
- Favere-Marchesi, M. & Emby, C. (2018). Auditor tenure and leniency. N=140.
- Fehrenbacher, D.D. & Wiener, M. (2019). The dual role of penalty: the effects of IT outsourcing contract framing on knowledge-sharing willingness and commitment. Decision Support Systems, 121. Experiment, N=198.
- Gefen, D., Wyss, S. & Lichtenstein, Y. (2008). Business familiarity as risk mitigation in software development outsourcing contracts. MIS Quarterly, 32(3).
- Gopal, A. & Gosain, S. (2010). The role of organizational controls and boundary spanning in software development outsourcing: implications for project performance. Information Systems Research, 21(4).
- Handley, S.M. (2012). The perilous effects of capability loss on outsourcing management and performance. Journal of Operations Management, 30(1–2). N=198.
- Handley, S.M. & Benton, W.C. (2013). The influence of task- and location-specific complexity on the control and coordination costs in global outsourcing relationships. Journal of Operations Management, 31(3). Dyadic, 102 relationships.
- Holman, D., Batt, R. & Holtgrewe, U. (2007). The Global Call Center Report. ~2,500 centers, 17 countries.
- Holmström, B. & Milgrom, P. (1991). Multitask principal-agent analyses: incentive contracts, asset ownership, and job design. Journal of Law, Economics, and Organization, 7.
- Kanepejs, E. & Kirikova, M. (2018). Centralized vs. decentralized procurement: a literature review. CEUR Workshop Proceedings, 2218. Systematic review, 27 studies.
- Kirsch, L.J., Sambamurthy, V., Ko, D.-G. & Purvis, R.L. (2002). Controlling information systems development projects: the view from the client. Management Science, 48(4).
- Liu, S., Wang, L. & Huang, W. (2017). Effects of process and outcome controls on business process outsourcing performance. European Journal of Operational Research, 260(3). 234 paired projects.
- Milner, J.M. & Olsen, T.L. (2008). Service-level agreements in call centers: perils and prescriptions. Management Science, 54(2).
- Mithas, S. & Whitaker, J. (2007). Is the world flat or spiky? Information intensity, skills, and global service disaggregation. Information Systems Research, 18(3). 300+ occupations.
- Ouchi, W.G. (1979). A conceptual framework for the design of organizational control mechanisms. Management Science, 25(9).
- Perrow, C. (1967). A framework for the comparative analysis of organizations. American Sociological Review, 32(2).
- Poppo, L. & Zenger, T. (2002). Do formal contracts and relational governance function as substitutes or complements? Strategic Management Journal, 23(8).
- Ridgway, V.F. (1956). Dysfunctional consequences of performance measurements. Administrative Science Quarterly, 1(2).
- Rustagi, S., King, W.R. & Kirsch, L.J. (2008). Predictors of formal control usage in IT outsourcing partnerships. Information Systems Research, 19(2). 138 matched pairs.
- Tiwana, A. & Keil, M. (2009). Control in internal and outsourced software projects. Journal of Management Information Systems, 26(3). 57 outsourced and 79 internal projects.
