cx-third-party-risklisted
Install: claude install-skill rulebase-co/rulebase-skills
# Third-party risk in outsourced support
You can outsource the work. You cannot outsource the obligation — in most regulated
sectors the accountability for outcomes, and for the personal data, stays with you.
Vendor oversight is normally done through questionnaires and annual certifications, which
tell you what the vendor's policies say. This skill is about the other half: **what the
evidence from the actual work shows**, which is a much better predictor and is usually
available to you already because the conversations flow through your systems.
## Test against the work, not the questionnaire
The strongest oversight evidence comes from data you already hold:
- **Conduct patterns in their conversations.** Obstruction, pressure, misleading
statements, unlogged complaints — run the same conduct checks you run internally, and
compare rates against your in-house teams on comparable work.
- **Complaint identification rate.** A vendor identifying complaints at a materially lower
rate than in-house teams on similar volume is a finding, and a common one, because
logging a complaint often looks like admitting a failure.
- **Vulnerability recognition rate.** Same logic, higher stakes.
- **Redress consistency** between vendor-handled and in-house cases for the same failure.
Vendors frequently have narrower authority, which shows up as customers getting less for
the same problem — that is your finding, not theirs.
- **Access patterns.** Which records their agents opened,