Trust Centre

Audit Rights

Annual customer audit rights are included in our standard Data Processing Agreement. We require 60 days written notice, support the audit at no additional charge within scope, and respond in writing to material findings within 30 days.

Key information

At-a-glance governance context

These points summarise the public scope of this page and the main contact or review context around it.

Frequency

Annual audit rights included in the standard DPA

Notice

60 days written notice

Findings response

Written response within 30 days for material findings

Initiate an audit

dpo@upstreambpo.com

Section 1

Audit rights and notice

Annual customer audit rights are included in our standard Data Processing Agreement. Customers exercise those rights without negotiating a separate agreement.

We require 60 days written notice for a customer-requested audit. The notice period lets us assemble documentation, arrange staff availability and confirm scope before the audit begins.

Section 2

Scope

A customer audit covers our information security controls, our data protection practices and our compliance with the Data Processing Agreement executed with that customer.

The scope excludes the areas below. We state the exclusions plainly so that scope is settled before the 60-day notice period starts rather than during the audit.

  • Upstream BPO commercial information.
  • Other customers' data.
  • Systems beyond the scope of the customer's contract.

Section 3

Cost

The customer bears the cost of their own audit, including auditor fees and expenses.

Upstream BPO provides reasonable support at no additional charge within scope. That support covers access, documentation and staff time for interviews.

Section 4

Third-party audit evidence

Customers use third-party audit evidence in place of, or in addition to, a customer audit. Our ISO/IEC 27001:2022 certification under Certificate II-23080301 is available to reviewers, and Statement of Applicability SOA-UBSB-01 dated 12 February 2023 is available under NDA.

For customers whose review is satisfied by certification evidence, this route avoids the cost and scheduling of a full audit.

Section 5

Findings and remediation

Audit findings are shared with Upstream BPO in writing. We respond in writing within 30 days for material findings.

Our written response carries a root-cause analysis, a remediation plan with timelines proportionate to the severity of the finding, and status updates until the finding is closed. Remediation timelines follow the severity classification set out in the Data Processing Agreement.

Reviewer questions

Questions we are asked in security review

Answers are stated in full here so they are quotable directly into a security questionnaire.

Do we have the right to audit Upstream BPO?

Yes. Annual customer audit rights are included in our standard Data Processing Agreement.

How much notice do you require?

60 days written notice for a customer-requested audit.

What does an audit cover?

Our information security controls, our data protection practices and our compliance with the DPA executed with you. It does not extend to Upstream BPO commercial information, other customers' data, or systems beyond your contract scope.

Who pays for the audit?

The customer bears the cost of their own audit, including auditor fees and expenses. Upstream BPO provides access, documentation and staff time for interviews at no additional charge within scope.

Can we rely on your certification instead of auditing?

Yes. Our ISO/IEC 27001:2022 certification under Certificate II-23080301 is available to reviewers, and Statement of Applicability SOA-UBSB-01 is available under NDA.

How quickly do you respond to audit findings?

We respond in writing within 30 days for material findings, with a root-cause analysis, a remediation plan with timelines proportionate to severity, and status updates until closure.

Contact & Escalation

Initiate an audit request, or request the ISO 27001 certificate and Statement of Applicability under NDA, at dpo@upstreambpo.com. We acknowledge security and trust enquiries within 3 business days.

Next Step

Need a deeper governance review?

Send certificate requests, subprocessor list requests, incident reports and vulnerability disclosures to dpo@upstreambpo.com. We acknowledge security and trust enquiries within 3 business days.