IT Outsourcing Risk Management Practices in Nigerian Organisations

📖 ABSTRACT/OVERVIEW

IT outsourcing has become a common operational model across Nigerian private and public sector organisations, but systematic risk management practices governing outsourcing relationships are inadequately developed in most contexts. This study examines IT outsourcing risk management practices in Nigerian organisations across banking, telecommunications, manufacturing, and government sectors. A structured questionnaire covering eight risk management dimensions (contract governance, vendor assessment, service level management, data protection, transition planning, exit management, operational resilience, and performance monitoring) was administered to 55 IT outsourcing contract managers, procurement officers, and CIOs across Lagos and Abuja. Findings indicate that initial vendor assessment is conducted systematically by 68 percent of organisations, but ongoing vendor risk monitoring is maintained by only 34 percent. Exit strategy planning is absent from 58 percent of outsourcing contracts reviewed. Data processing agreements addressing NDPR obligations are absent from 44 percent of contracts involving customer data. Service level agreement breach remedies are enforced in practice by only 30 percent of organisations with documented SLAs. Organisations with dedicated vendor management offices show significantly higher risk management maturity scores across all dimensions. The study develops an IT Outsourcing Risk Management Framework for Nigerian Organisations covering all eight risk dimensions with minimum controls and maturity indicators, and recommends its adoption as a governance reference by the Chartered Institute of Information Technology of Nigeria.

Keywords: IT outsourcing, risk management, Nigeria, vendor management, outsourcing governance

Need Complete Chapters of the Above Topic?

Get high-quality, Zero-AI research materials with current citations.

Request via WhatsApp 💬
Departments# Computer Science