Outsourcing payments, cash application and bank reconciliation can cut cost and add scale. It also moves sensitive work, and access to the company's bank accounts, to another organization.
The work can be outsourced. The accountability cannot. The controls decide whether that difference is managed or ignored.
What changes when a provider runs your payments?
The provider's staff prepare payments, maintain supplier data and reconcile bank statements. They need system access, bank portal access and clear instructions to do it.
Each of those creates a risk. Supplier data can be changed, payments can be prepared incorrectly and errors can sit unnoticed in reconciliations.
The goal is not to remove the provider's access. It is to make sure no single person, at the provider or at the company, can complete a payment alone.
Which risks rise when payments are outsourced?
Outsourcing does not create new kinds of risk, but it changes where they sit. Three deserve particular attention.
Supplier data changes
A fraudulent request to change a supplier's bank details is the most common attack on payments. When the provider receives those requests, the verification step must not depend on the provider alone.
Duplicate and incorrect payments
Duplicates rise when invoices arrive through several channels. The provider needs duplicate checks, and the company needs a report of payments stopped or recovered.
Reconciliation backlogs
Unreconciled items hide errors and fraud. An aging limit on open items, written into the SLA, keeps the backlog visible.
Which controls should stay with the company?
Some controls are too important to delegate. These should stay inside the company, whatever the provider does.
- Final release of high value payments, above a threshold the company sets.
- Verification of every change to supplier bank details, by calling a known number.
- Approval of new suppliers and of changes to payment terms.
- Ownership of bank mandates and of the list of authorized portal users.
- Review of reconciliation exceptions and unexplained balances.
The provider can prepare, check and document all of these. The company makes the final decision.
Write these controls into the contract, not only into a process document. That makes them part of what the provider is paid to respect.
How should bank access be set up for provider staff?
Provider staff should have named users, never shared logins. Each user gets only the rights the role needs: view, prepare or, rarely, release.
Bank mandates and user rights must match the outsourcing contract. Banks need to know who can act on the accounts and on whose authority.
Access should be reviewed every quarter, and removed the same day someone leaves the provider's team. The contract should require the provider to notify the company of every change.
Worked example: an illustrative role matrix
The table shows an illustrative split of roles for a hypothetical company. The release threshold of USD 50,000 is invented for illustration. Each company should set its own threshold from its payment profile.
| Activity | Provider | Company | Bank control |
|---|---|---|---|
| Create or change a supplier | Prepares and documents | Approves | None |
| Change supplier bank details | Records the request | Verifies by call-back | Alert on new beneficiary |
| Prepare the payment run | Prepares | Reviews totals | None |
| Release payments under USD 50,000 | Releases with second approver | Monitors | Dual approval in the portal |
| Release payments over USD 50,000 | Prepares only | Releases | Dual approval in the portal |
| Daily bank reconciliation | Performs | Reviews exceptions weekly | Automated statement file |
The matrix shows the logic. Every activity has a preparer and a checker, and the highest risk steps stay with the company.
What belongs in the service level agreement?
The SLA turns expectations into measurable commitments. These items should be in it.
- Cut-off times for receiving and releasing payments.
- Accuracy and timeliness targets, with how they are measured.
- How errors, duplicates and returned payments are handled and reported.
- Reconciliation frequency and the maximum age of open items.
- Notification duties for staff changes and security incidents.
- Audit rights for the company and its auditors.
- Exit support, including data handover and parallel running.
What the bank sees
From the bank side, an outsourced payment operation is a set of users acting on the client's accounts. The bank checks those users against the mandate, not against the outsourcing contract.
Banks also see the patterns that signal fraud. New beneficiaries, changed bank details and urgent payments outside normal hours are the classic warning signs.
Most banks offer tools that help: dual approval, beneficiary alerts, payment limits per user and lists of approved beneficiaries. Many clients never switch them on.
A company that sets these tools up with its bank, before the provider starts, adds a layer of control the provider cannot bypass.
How should the transition be run?
Run the old and new processes in parallel for at least one full payment cycle. Compare outputs line by line before switching.
Agree a fallback plan in case the provider cannot run a payment. Someone at the company must still be able to pay salaries and critical suppliers.
Tell the banks about the transition in advance. Mandate and user changes take time, and the first payment run is the wrong moment to discover a missing right.
How should performance be monitored after go-live?
A monthly review against the SLA keeps the arrangement honest. It should use data, not impressions.
- Payments released on time, late and returned, by count and value.
- Duplicates detected and stopped before release.
- Bank detail changes requested, verified and rejected.
- Open reconciliation items by age.
- Access changes made and access reviews completed.
Trends matter more than single months. A slow rise in late payments or open items is an early warning worth acting on.
What does the full controls checklist look like?
Use this list before signing and again before go-live.
- Named bank users for provider staff, with rights limited to the role.
- Final release of high value payments kept with company employees.
- Call-back verification of every bank detail change.
- Dual approval and beneficiary alerts switched on at every bank.
- Segregation between supplier maintenance and payment release.
- An SLA with cut-offs, error handling, audit rights and exit support.
- Quarterly access reviews and same-day removal of leavers.
- A tested fallback for critical payments.
How do you plan the exit?
Plan the exit before signing. Ask how data, documents and open items will be handed back, and how long the provider will support a parallel run.
An exit plan also keeps the relationship healthy. A provider that knows the company can leave cleanly has every reason to perform.
Keep process documentation current throughout the contract. It is the asset that makes any exit, or any change of provider, manageable.
When is outside help worth it?
Most companies outsource payments once or twice in a decade. The controls, bank access and SLA terms are easier to get right with someone who has seen both the bank and the provider side.
Independent finance and treasury BPO advisory covers provider selection, controls, bank access and transition. Payment controls inside the company are covered by treasury process optimization, and approval rules start with the first treasury policy.
This insight reflects general analysis and observations from FIRMA Advisory's work in treasury, banking, and cross-border financial advisory. It does not constitute investment advice, financial advice, or a recommendation in respect of any specific security, transaction, or financial decision. For analysis specific to your organization, contact us at [email protected].