All insights

The outsourcing boundary is a design decision, not a procurement decision

The boundary between insourced and outsourced work is being redrawn by regulation, market structure and AI. Treating it as a procurement event is now an operating model risk.

By Nick Ross6 min read
Editorial illustration for: The outsourcing boundary is a design decision, not a procurement decision

What it is

The line between what an asset manager runs itself and what it hands to a provider is being redrawn from three directions at once.

First, the regulator. On 22 July, the FCA published its findings from engaging with 242 asset management and alternatives firms on financial crime controls. Around 40% outsource parts of their CDD and EDD, mostly to fund administrators. Only 36% of those could evidence full oversight of the provider's onboarding. Some could not describe the process at all. The FCA's reminder was blunt: outsourcing the task does not move the responsibility. It stays with the firm.

Second, the market. The binary choice between insourcing and outsourcing is dead. Managers now mix four shapes across a single operating model: retained functions, co-sourcing (partner runs the process inside the manager's own systems, as Vistra describes), full outsourcing, and lift-outs, where the team transfers with the mandate, as happened when Aegon Asset Management's Budapest operations joined Citi alongside its $380bn middle office. Apex Group's research finds two-thirds of managers who have done a lift-out would do it again.

Third, the platform. Servicers are now selling assembled operating models, not component services. Citi's multi-client Aladdin factory is the clearest example: one shared middle office operated across BlackRock's iShares, Aegon and whoever signs next.

Put the three together and the boundary is no longer a procurement event. It is a living design decision that sits on the operating model, moves over time, and carries accountability whichever side the work sits on.

Why it matters now

Because the cost of a wrong boundary is rising, and it's being measured.

The FCA's data is the first public quantification of the oversight gap in years: most firms that outsource cannot evidence how they oversee what they outsource. That is not a compliance observation. It is an operating model diagnosis. A firm that cannot describe its provider's onboarding process does not have an oversight problem; it has a missing layer in its model, the layer that should connect delegated execution back to accountable owners.

The second reason is that the boundary now moves faster than governance cycles. Lift-outs, co-sourcing pilots, administrator consolidations and platform factories change where work happens every quarter. A boundary decision documented once at contract signature is wrong within a year. Meanwhile the FCA's expectations, and its enforcement record, assume the firm can point to where its responsibilities sit at any moment.

The third reason is that the new tools are changing the economics mid-decision. KPMG's Q1 2026 pulse shows 39% of asset management and private equity organisations now deploying AI agents, with three in four requiring human validation of their outputs. PwC Luxembourg makes the point directly: GenAI is "reshaping the cost-benefit equation entirely" between insourcing and outsourcing. A boundary justified on 2024 cost assumptions is being re-priced underneath the firm by tools nobody budgeted for.

What firms should do

Four things, in order.

Make the boundary explicit on the model

For every process, record whether it is retained, delegated or hybrid, and who owns it. If answering that requires a meeting, the model isn't doing its job. This is the single most valuable artefact a COO can have before a regulator, an auditor or a new provider enters the room.

Build oversight as first-class processes

Sampling, management information, escalation and quality assurance are processes like any other: they need owners, sign-off and re-certification. A contract schedule is not oversight. The difference between the 36% who could evidence oversight and the rest is not headcount; it's process design.

Design for reversibility

The co-sourcing model's quiet lesson is that keeping data in the manager's own environment keeps options open: provider changes stop being data migrations. Any boundary that can't be moved without a two-year programme is a risk, not a commitment.

Re-certify the boundary on a rhythm

Annually, and on triggers: AUM threshold crossings, new strategies, provider changes, material regulatory change. Boundaries drift in the gaps between reviews. The firms the FCA found lacking were not the ones who made bad decisions; they were the ones who never re-made them.

The opmodal perspective

This is the Architecture Canvas methodology applied to the oldest question in operations.

A firm that captures its processes, owners, systems, risks and controls in one live record can answer the boundary questions in hours: what do we run, what do we delegate, who oversees each, and when was each choice last re-certified. A firm running on contracts and tribal knowledge discovers the answers mid-audit, which is precisely how the FCA's 36% statistic gets made.

The interesting shift is that the boundary itself has become a competitive asset. The firms winning mandates, scaling private markets and absorbing new regulation are the ones treating make-versus-buy as a designed, documented, re-certified layer of the operating model rather than a sequence of procurement events. For everyone else, the boundary is not a strategy. It's an accumulation of past decisions nobody can see. And the regulator has just started asking to see it.