ISO/IEC TS 30105‑6 provides guidance on risk management practices for the IT-enabled services-business process outsourcing (ITES-BPO) service provider for the outsourced business processes. It provides guidance for planning, establishing, implementing, operating, monitoring, reviewing, maintaining, and improving the risk management framework for the ITES-BPO services.
ISO/IEC TS 30105‑6 covers:
The guidelines in ISO/IEC TS 30105‑6 align to ISO 31000, elaborating the risk principles, risk management framework, and risk management process from an ITES-BPO perspective.
ISO/IEC TS 30105‑6 on IT Enabled Services-Business Process Outsourcing is useful for:
In an ITES-BPO service provider organization, risks are prevalent due to the nature of the services that are outsourced to service providers. Risks can be financial, regulatory, reputational, technological, etc. These risks can impact the ITES-BPO organization, customers and other interested parties. ISO/IEC TS 30105‑6 provides guidelines that are intended to help an ITES-BPO organization improve its risk management practices by providing sound principles for an effective risk management framework. A process should be in place to assess, treat, communicate, monitor, and report risks, with the goal of creating and protecting value for the organization, customers, and end-users.
ISO/IEC TS 30105‑6 provides guidelines that are intended to support the effective implementation of the risk management process within the ISO/IEC 30105 series through:
ISO/IEC TS 30105-6:2021