Outsourcing the IT department doesn't remove the governance problem, it relocates it
Image Source: depositphotos.com
A business owner decides to stop managing IT internally and hire an outside provider instead. The thinking is straightforward: technology decisions were eating time nobody had, and a specialist can handle it better anyway.
What often goes unexamined is that "managing IT" was never just the technical work. It included decisions: what gets fixed first when three things break at once, how much risk is acceptable versus how much gets spent to reduce it, which requests are urgent and which can wait. Handing off the technical work doesn't answer any of those questions. It just changes who's positioned to make them, and a lot of businesses never notice they still need someone in that seat.
Governance was never just a technical function
Inside a business running its own IT, someone, an owner, an office manager, an internal IT hire, ends up making a running series of judgment calls that have nothing to do with configuring a server.
- Whether a slow-but-functional system gets replaced now or next year
- Whether a flagged security risk gets fixed this week or scheduled for next quarter
- Whether a new department's request jumps the queue or waits its turn
- How much budget risk reduction is worth, relative to everything else competing for that money
None of these are technical questions. They're business judgment calls that happen to be about technology. Whoever holds that role doesn't need to know how to configure a firewall. They need standing to make a call and enough context about the business to make it well.
Outsourcing moves the technical work and leaves the judgment calls behind
When a business signs on with an outside provider, the technical execution moves out. The judgment calls don't. Someone still has to decide whether a proposed upgrade is worth the cost, whether a flagged vulnerability gets prioritized now or later, whether a department's request is genuinely urgent.
The difference is that before, the person making those calls was usually also the one doing the work, or close enough to it that the two roles were hard to separate. After outsourcing, the person making the call and the provider doing the work are different parties. Someone on the business side needs to own the relationship: reviewing what the provider recommends, deciding what actually gets approved, and having enough standing internally to make that decision without it becoming a political fight in the moment.
A lot of businesses skip formally assigning that role. Not because they've decided it isn't necessary, but because outsourcing feels like it eliminated the need for it. The provider is handling IT now. What's left to manage?
The gap is invisible until a decision has to be made fast
This is where the risk actually shows up, and it's rarely visible in day-to-day operations. Routine tickets get resolved. Systems run. Nothing looks wrong.
The gap surfaces at decision moments: a security incident that needs an immediate call on scope and response, a budget conversation where the provider proposes a meaningful spend increase, a disagreement over whether something the provider flagged is truly urgent or can wait. In each case, someone internally needs to make a call quickly, with context. If nobody's been designated for that role, the business finds out in real time, during the incident or the budget meeting, that there's no clear answer to "who decides this."
What tends to happen instead is default by convenience. Whoever's on the call takes the decision, whether or not they have the standing or the business context to make it well. An office manager approves a technical change they don't fully understand because the provider is asking and someone has to answer. Or a decision stalls entirely because nobody's sure whose call it is, and the delay itself becomes the cost.
Assigning the role is a business decision, not a technical one
Closing this gap doesn't require hiring an internal IT person, which would defeat the purpose of outsourcing an IT department in the first place. It requires designating someone, explicitly, as the internal owner of the provider relationship, with the authority to make the calls that come up.
That person needs three things:
- Enough business context to weigh a provider's recommendation against the company's actual priorities, not just its technical merit
- Standing within the organization to make a call and have it stick, rather than getting second-guessed after the fact
- Enough regular contact with the provider to have context before a decision has to be made under pressure, not cold in the middle of an incident
This doesn't need to be a full-time responsibility. In most small and midsized businesses, it's a part of someone's broader role, an operations manager, a controller, the owner. What it can't be is unassigned, because unassigned doesn't mean nobody's making these decisions. It means whoever happens to be available makes them, without the context or standing to make them well.
The decision that was never actually eliminated
Outsourcing changes where the technical work gets done. It was never going to change whether someone has to decide what gets fixed, funded, and prioritized, because those are business decisions that don't disappear just because the execution moved outside the company. A business that assigns that role deliberately gets a provider relationship that functions the way it's supposed to: fast decisions when they're needed, made by someone with the context to make them. A business that doesn't finds out the role was still necessary, usually at the exact moment it can least afford the delay.