This article forms part of our How Our BPO Service Works page, our complete guide to working with Felcorp Support.
Quality assurance reviews confirm that individual deliverables meet the required output standard. Compliance auditing operates at a different level where it assesses whether the staff member's day-to-day behaviour, data handling practices and operational conduct are consistent with the security and legal compliance framework that underpins the entire engagement.
What Felcorp's compliance auditing does is ensure that the offshore component of the operation does not become a source of compliance risk that the client is unaware of. As custodians of sensitive client data, we also have a fiduciary duty to protect data and adhere to regulatory guidelines and procedures.
What Compliance Audits Assess
Compliance audits are conducted by Felcorp management and cover a defined set of assessment criteria applied to each staff member's operational conduct. Audit activities include:
- Data handling practices: verifying that client data is accessed, stored and transmitted only through approved channels and in accordance with Felcorp's data security protocols
- System access behaviour: reviewing access logs to confirm that the staff member is only accessing systems and data relevant to their assigned work.
- Physical security compliance: confirming adherence to on-site security requirements, including clean desk practices, screen privacy standards, controlled access to secure areas and biometrics.
- Confidentiality adherence: assessing whether the staff member's conduct is consistent with their confidentiality obligations, including communication practices and disclosure to friends and colleagues
- Policy and procedure compliance: verifying that the staff member is operating within Felcorp's documented policies and procedures relevant to their role
Risk Identification and Assessment
Beyond assessing current compliance, the audit cycle includes forward-looking risk identification activities specifically when there are changes in the engagement's scope, the client's business environment or the broader operating context have created new compliance risks that need to be addressed.
Risk identification activities include:
- Reviewing whether any new systems, data types or processes introduced since the last audit require updated security or compliance controls
- Assessing whether the staff member's access permissions remain appropriate given any role or scope changes
- Identifying any operational patterns observed in QA review data that may have compliance implications
- Reviewing whether any changes in the regulatory environment applicable to the client's business affect the compliance requirements for the engagement
Internal Audit Reporting
Each compliance audit produces an internal audit report. This report documents:
- The assessment criteria applied and the findings against each criterion
- Any compliance gaps or risk areas identified, with a severity assessment
- The remediation actions taken or scheduled in response to identified issues
- A compliance status summary for the period assessed
Audit reports are an internal function of Felcorp Support, however, we are able to disclose certain audit activities in our quaterly reporting that are specific to your business.
Compliance is boring, but it is of paramount importance for us. There's no greater feeling that you're revenue streams are protected, legal risks are minimised and there's audit reports to provide evidence. Everything is hunky dory, until it isn't. And when it isn't, it's not often good. Compliance is that quiet confidence, often intangible, but a mark of a truly mature business.
Tobias Fellas — Founder & CEO, Felcorp Support
FAQs
How frequently are compliance audits conducted?
Compliance audits are conducted periodically throughout the engagement. We have different periodic triggers for different audits. We do not disclose our internal audits but we do disclose audits relating specifically to your engagement.
What happens if a compliance issue is identified during an audit?
Where a compliance issue is identified, Felcorp management takes immediate remediation action appropriate to the severity of the finding. Till date, we have had no material compliance breach that has prejudiced or financially impacted any of our clients nor Felcorp Support.
Next Steps
- Read How our BPO Service Works to understand how compliance auditing fits into the full eight-step engagement model
- See our security and compliance page for the broader data security and governance framework
- Start with a BPO Services Trial to see Felcorp's compliance practices operating on a real engagement before committing to a full arrangement


