Sourcing Strategies
In the CGEIT framework, sourcing strategies fall under the IT Resources domain. They concern how an enterprise obtains the IT capabilities, services, skills and infrastructure it needs to deliver business value while managing risk and optimizing resources. Sourcing is a governance decision, not jus… In the CGEIT framework, sourcing strategies fall under the IT Resources domain. They concern how an enterprise obtains the IT capabilities, services, skills and infrastructure it needs to deliver business value while managing risk and optimizing resources. Sourcing is a governance decision, not just a procurement task. The board and executive management must ensure that sourcing choices align with enterprise strategy, risk appetite, regulatory obligations and long-term objectives. Common sourcing models include: - Insourcing: delivering services with internal staff and assets, which keeps control and protects intellectual property. - Outsourcing: contracting third parties to provide services, which can bring cost efficiency, scalability and specialized expertise. - Offshoring and nearshoring: using providers in other countries, either distant or nearby. - Shared services: consolidating functions across business units. - Cloud sourcing: using IaaS, PaaS or SaaS models. - Multisourcing: combining several providers under an integrated governance model. From a governance perspective, sourcing decisions should start with a clear business case. That case should assess core versus non-core capabilities, total cost of ownership, strategic value, market maturity and internal competencies. Leaders must also evaluate risks such as vendor lock-in, data privacy and sovereignty, security, regulatory compliance, concentration risk and loss of critical knowledge. An important principle is that accountability cannot be outsourced. The enterprise remains responsible for outcomes even when execution is delegated. Effective governance therefore requires strong vendor selection criteria and well-structured contracts. Service level agreements and key performance indicators should be clearly defined, and the enterprise should retain rights to audit. A defined exit or transition strategy is also needed. Ongoing vendor and relationship management keeps providers aligned with business needs. It does this through performance monitoring, periodic reviews, risk assessments and continuous improvement. Frameworks such as COBIT support these practices, for example through the APO10 objective, Managed Vendors. Ultimately, a sound sourcing strategy gives the enterprise the right resources at the right time and cost. It also maintains flexibility, resilience and value delivery while keeping risks within acceptable levels.
Sourcing Strategies (CGEIT – IT Resources): A Complete Exam Guide
Introduction
Sourcing strategies are a core topic in the CGEIT domain on Optimization of Resources (the IT Resources domain). For the exam you need to know how an enterprise decides where its IT capabilities come from. Those capabilities include people, applications, infrastructure, information and services. You also need to know how governance makes sure those decisions create value, manage risk and use resources well. This guide covers why sourcing strategies matter, what they are, how they work in practice, and how to answer exam questions on them.
1. Why Sourcing Strategies Are Important
Sourcing decisions are among the most strategic and costly choices an enterprise makes about IT. They matter for six reasons.
Alignment with business strategy
Sourcing determines whether IT can deliver the capabilities the business needs, at the right speed, quality and cost.
Value delivery
A good sourcing decision can give access to skills, innovation and economies of scale the enterprise could not build itself. A poor decision can destroy value.
Risk management
External sourcing brings several kinds of risk:
- vendor dependency (lock-in)
- data privacy and sovereignty risk
- regulatory and compliance risk
- loss of internal knowledge
- continuity and exit risk
Resource optimization
The CGEIT framework expects the board and executive management to ensure that IT resources are adequate, effective and efficient. Sourcing is a primary lever for this.
Accountability cannot be outsourced
A key governance principle is that an enterprise can delegate the execution of a service. It can never delegate accountability for that service. This principle appears frequently in exam questions.
Long-term impact
Sourcing contracts often run for years. Unwinding them is expensive and disruptive, so these decisions need board-level oversight.
2. What Sourcing Strategies Are
A sourcing strategy is the enterprise-level approach to obtaining IT capabilities and services. It defines what will be done internally, what will be acquired from external providers, and how those providers will be selected, governed and managed over the lifecycle.
Common sourcing models
- Insourcing: The enterprise uses its own staff and assets to deliver IT services. It gives maximum control but may cost more and limit scalability.
- Outsourcing: A third party delivers services under contract. Examples include infrastructure management, application maintenance and help desk.
- Selective outsourcing: Only certain functions are outsourced. Strategic or core functions stay in-house.
- Total outsourcing: Most or all of the IT function is transferred to a provider.
- Co-sourcing: Internal staff and external providers work together, sharing responsibility.
- Shared services: A centralized internal unit serves multiple business units, often run like an internal provider with chargeback.
- Offshoring / nearshoring: Services are delivered from another country. Offshoring often targets labor cost advantages. Nearshoring uses a nearby country, which reduces time zone and cultural gaps.
- Cloud sourcing: Services are consumed as SaaS, PaaS or IaaS. Cloud adds specific concerns: shared responsibility, data location, multi-tenancy and exit strategy.
- Multi-sourcing: Multiple providers are used for different services. This reduces dependency on one vendor but adds integration and coordination complexity. It often requires a service integrator role (SIAM, service integration and management).
- Joint ventures / strategic partnerships: Risk and reward are shared with a partner.
Core vs. non-core
A fundamental concept is separating core competencies from commodity functions.
- Core competencies differentiate the enterprise and create competitive advantage. They are generally kept in-house or tightly controlled.
- Commodity functions, such as data center operations, are typically candidates for outsourcing.
3. How Sourcing Strategies Work: The Lifecycle
Step 1: Strategy and needs analysis
- Start from business objectives and the IT strategy.
- Identify which capabilities are required and whether they are core.
- Assess current capabilities, gaps and maturity.
- Perform a make-vs-buy analysis covering cost, risk, quality, time to market and strategic fit.
Step 2: Business case
- Build a business case that includes total cost of ownership (TCO). TCO should include transition costs, retained organization costs, vendor management costs and exit costs.
- Define expected benefits and how they will be measured.
- The business case should be approved by the appropriate governance body, such as an IT steering or investment committee.
Step 3: Risk assessment
- Evaluate vendor, operational, security, legal, regulatory, financial and reputational risks.
- Consider concentration risk and fourth-party (subcontractor) risk.
- Align with the enterprise risk appetite.
Step 4: Vendor selection
- Issue an RFI, then an RFP, using objective evaluation criteria.
- Perform due diligence on financial stability, references, certifications (e.g., ISO 27001, SOC reports), culture fit and capacity.
- Make sure selection is transparent and free of conflicts of interest.
Step 5: Contract and SLA definition
The contract should cover:
- service scope and service level agreements (SLAs)
- key performance indicators
- right to audit
- data ownership and confidentiality
- security requirements
- regulatory compliance
- penalties and incentives
- change management
- dispute resolution
- business continuity and disaster recovery obligations
- termination and exit/transition clauses
Step 6: Transition
- Plan knowledge transfer, staff transfer if applicable, and parallel running.
- Manage organizational change and communication.
Step 7: Ongoing governance and vendor management
- Keep a retained organization with skills in contract management, architecture, security and business relationship management.
- Monitor performance against SLAs and KPIs using regular reports and reviews.
- Use independent assurance, such as audits and third-party attestation reports.
- Manage the relationship strategically, not just the contract transactionally.
- Review periodically whether the arrangement still meets business needs.
Step 8: Exit or renewal
- Define the exit strategy before signing.
- At renewal, re-evaluate the market, performance and alignment.
- Ensure data return, knowledge transfer and continuity on termination.
Governance roles
- Board: Sets direction, approves major sourcing strategies and ensures risks stay within appetite.
- Executive management / IT steering committee: Evaluates business cases and monitors portfolio-level value.
- CIO / IT management: Executes sourcing, manages vendors and reports performance.
- Business owners: Define requirements and remain accountable for business outcomes.
- Risk, compliance and audit: Provide oversight and assurance.
Relevant frameworks
- COBIT: APO10 Managed Vendors, APO09 Managed Service Agreements, APO07 Managed Human Resources, BAI03 Managed Solutions Identification and Build, EDM04 Ensured Resource Optimization.
- Val IT concepts for value management.
- ITIL supplier management.
4. Key Concepts to Memorize
- Accountability stays with the enterprise.
- Sourcing decisions must be driven by business strategy, not cost alone.
- The right to audit should be included in contracts.
- An exit strategy should be defined up front.
- A retained organization is required to govern providers.
- SLAs must be measurable and linked to business requirements.
- Due diligence comes before selection.
- Cloud requires attention to the shared responsibility model, data residency and portability.
- Multi-sourcing reduces lock-in but increases integration effort.
- Core competencies should generally remain in-house.
5. Exam Tips: Answering Questions on Sourcing Strategies
Tip 1: Think like a governance professional, not a technician.
CGEIT questions look at issues from the board and executive perspective. The best answer usually addresses strategic alignment, value, risk or accountability, rather than technical or operational details.
Tip 2: Business alignment comes FIRST.
When asked what should be done first, or what is most important when considering outsourcing, prefer answers that tie the decision to business objectives and the enterprise or IT strategy. Cost savings alone is rarely the best answer.
Tip 3: Remember that accountability cannot be transferred.
If an option suggests the vendor is now accountable for compliance, data protection or business outcomes, it is almost certainly wrong. The enterprise retains accountability.
Tip 4: Look for the PRIMARY or MOST IMPORTANT qualifier.
Several answers may be true. Choose the one with the broadest governance impact. For example, defining requirements and a business case generally comes before negotiating SLAs.
Tip 5: Know the sequence of activities.
Strategy and needs, then business case, then risk assessment, then vendor selection and due diligence, then contract and SLAs, then transition, then monitoring, then exit or renewal. Questions often test what should happen BEFORE something else.
Tip 6: Right to audit and exit clauses are favorites.
When a question asks about the best way to protect the enterprise in a contract, look for options about the right to audit, clear SLAs, data ownership or exit provisions.
Tip 7: Monitoring must be against agreed, measurable criteria.
The best way to ensure a provider delivers value is to monitor performance against SLAs and KPIs that are aligned with business requirements. Vendor self-reports alone are insufficient. Independent assurance is preferred.
Tip 8: Watch out for the retained organization.
A frequent pitfall is not retaining enough skills to manage the vendor. Answers emphasizing retained capabilities, such as vendor management, architecture and security oversight, are often correct when the question concerns long-term success.
Tip 9: Consider risk appetite.
For questions about cloud or offshoring, check whether the option evaluates risk against the enterprise risk appetite and regulatory requirements, such as data residency and privacy laws.
Tip 10: Eliminate extreme or operational answers.
Options such as "terminate the contract immediately" or "replace the vendor" are usually too drastic as a first step. Prefer escalation through governance channels, root cause analysis, or reviewing contract terms.
Tip 11: Total cost, not just price.
When comparing options, the correct answer typically considers TCO. That includes transition, management overhead and exit costs, not only the vendor's fee.
Tip 12: Board vs. management roles.
The board approves strategy and oversees risk. Management executes. If a question asks who should approve a major outsourcing strategy, look for the board or a governance committee, not the IT operations manager.
6. Sample Question Walkthroughs
Question 1
An enterprise is considering outsourcing its application development. What should the IT steering committee do FIRST?
- A. Issue an RFP to qualified vendors
- B. Ensure the decision aligns with business strategy and is supported by a business case
- C. Negotiate SLAs
- D. Transfer staff to the vendor
Question 2
After outsourcing data center operations, who is accountable for compliance with data protection regulations?
Answer: The enterprise. Execution may be delegated, but accountability remains with the enterprise.
Question 3
Which contract clause BEST enables the enterprise to obtain assurance about a cloud provider's controls?
Answer: The right-to-audit clause, or the right to receive independent assurance reports such as SOC 2.
Question 4
A provider consistently misses SLAs. What should the CIO do FIRST?
Answer: Review performance with the provider under the contract's governance and escalation mechanisms and identify root causes. Do not terminate immediately.
7. Summary
Sourcing strategies decide how an enterprise obtains its IT capabilities, and governance ensures those decisions:
- align with business strategy
- deliver value
- optimize resources
- keep risk within appetite
Unlock Premium Access
Certified in the Governance of Enterprise IT
- Access to ALL Certifications: Study for any certification on our platform with one subscription
- 2995 Superior-grade Certified in the Governance of Enterprise IT practice questions
- Unlimited practice tests across all certifications
- Detailed explanations for every question
- CGEIT: 5 full exams plus all other certification exams
- 100% Satisfaction Guaranteed: Full refund if unsatisfied
- Risk-Free: 7-day free trial with all premium features!