Outsourcing & Material Arrangements
How material outsourcing and critical third-party arrangements are approved, governed and exited.
1. Purpose
This document sets out FLOWA PAY INC.'s policy position and control objectives, published for transparency and to support institutional due diligence. It is reviewed periodically and does not constitute legal advice. FLOWA PAY INC. makes no representation that it holds any licence, authorisation or certification except the FINTRAC Money Services Business registration expressly stated in the Regulatory Disclosures.
Outsourcing a function does not outsource responsibility for it. This policy sets out how FLOWA PAY INC. approves, governs and exits arrangements where a third party performs an activity that is material to our service, our controls or our obligations.
2. What counts as material
An arrangement is material where its failure would materially disrupt the service, compromise data, impair a control relied upon for a regulatory obligation, or affect customers' access to funds. This typically includes infrastructure and hosting, payment and acquiring partners, screening and verification providers, and providers with access to personal or transaction data.
3. Before we engage
- Due diligence proportionate to materiality, covering capability, financial standing, security posture, regulatory standing where relevant, and data-protection practices. See our Vendor Due Diligence policy.
- Assessment of concentration risk and of whether a viable alternative exists.
- Written contract setting out the scope, service expectations, security and data-protection obligations, audit and information rights, sub-contracting restrictions, incident notification and termination rights.
- Clarity on where data will be processed and stored, and on the basis for any cross-border transfer.
- Approval at a level appropriate to the materiality of the arrangement.
4. Ongoing governance
Material arrangements have a named internal owner accountable for performance and risk. Performance, security posture and incidents are monitored, and the provider is reassessed periodically and on trigger events such as a breach, a change of control or a material service failure. Sub-contracting by the provider requires notification, and in material cases consent.
Providers that process personal data on our behalf are engaged under terms meeting applicable data-protection requirements, as set out in our Data Protection policy.
5. Resilience and exit
Material arrangements are covered by our continuity and recovery planning, including the scenario in which the provider becomes unavailable. An exit plan is maintained for each material arrangement, covering how the service would be migrated or brought in house, how data would be returned or deleted, and the expected timeline. Exit plans are reviewed rather than written once.
6. Accountability
We remain accountable to our customers, our partners and the authorities for outsourced activities as if we performed them ourselves. A provider's failure is our failure as far as our obligations are concerned, which is why these arrangements are governed rather than merely procured.