All posts
Insights

How Consultancies Screen a Subcontract Delivery Partner Before Putting Their Own Client Name on the Line

Published on 22 Sept 2026

how-consultancies-screen-a-subcontract-delivery-partner-before-putting-their-own-client-name-on-the-line

When a consultancy subcontracts delivery work, it is not just outsourcing labor, it is lending its own reputation to a team it doesn't fully control. The screening process that matters most covers five areas: information security certification, process maturity, seniority mix, communication cadence, and contractual liability.

Consultancies that skip any of these five end up carrying the risk of a subcontractor's mistake without having verified in advance that the mistake was unlikely. This article breaks down what a serious vendor due diligence checklist looks like for this specific buyer, why each item exists, and how to run it without slowing the deal down.

TL;DR

  • Consultancies subcontracting delivery capacity are exposed twice: once to their own client, once to the subcontractor's performance, so due diligence has to be more rigorous than a typical internal hire.

  • Certifications (ISO 27001:2022, SOC 2 Type II, GDPR) are the fastest proxy for whether a subcontractor has documented process, not just good engineers.

  • Seniority mix, not headcount, predicts whether a small consultancy's first funded seat will hold up under a real client deadline.

  • Communication overlap and incident response time are contractual terms, not soft factors, and should appear in the SOW with a number attached.

  • A vendor risk assessment should be run before the first seat is filled, not after the first delivery slips.

About the Author: 724SOFTWARE is a Vietnam-based engineering firm that has been the subcontracted delivery partner behind consultancies' own client-facing projects across fintech, healthcare, and retail, including multi-year Hong Kong trust and digital-asset platforms delivered under another firm's brand. This piece reflects the questions we get asked most often during that exact screening process.

What Makes Subcontract Screening Different From Hiring a Vendor Directly?

A consultancy subcontracting delivery capacity is taking on a liability that a company hiring for its own internal roadmap doesn't carry: if the subcontractor underperforms, the consultancy's client sees a consultancy failure, not a subcontractor failure. The client signed a contract with the consultancy, not with whoever ends up writing the code.

This changes what "screening" means. A product company evaluating a vendor for its own backlog can absorb a slow ramp or a mid-project pivot with internal cost. A consultancy subcontracting delivery for a client engagement has a fixed scope, a fixed deadline, and a client who will remember who they signed with, not who actually built it. That's why due diligence in this buyer category tends to focus on documentable process over portfolio polish: work samples don't tell you whether the team will hit a deadline under a fixed SOW, but a certification audit trail does.

The recurring pattern here is a small consultancy, often 2 to 20 people, that has won a client deal and needs one developer immediately, ramping to five as the scope confirms. That shape of request, one seat first, changes the due diligence sequence: the consultancy is not vetting a company for a five-year relationship yet, it's vetting whether the first hire can be trusted with the funded scope sitting behind seat one.

Which Certifications Actually Matter and Why?

A certification is a substitute for the consultancy's own audit, not a marketing badge. When a consultancy can't send an internal security team to inspect a subcontractor's infrastructure, ISO 27001:2022 (information security management), SOC 2 Type II (operational controls verified over a period of observation, not a point-in-time snapshot), and GDPR compliance (data handling for any client with EU exposure) each answer a specific question the consultancy would otherwise have to ask manually.

ISO 27001:2022 confirms the subcontractor has a documented information security management system, not just good intentions. SOC 2 Type II is worth more than a Type I because it evaluates controls operating consistently over months, which matters if the engagement runs longer than a single sprint. GDPR compliance matters specifically for any consultancy whose client has EU end users or EU-based data subjects, regardless of where the consultancy itself is based.

724SOFTWARE holds ISO 9001, ISO 27001:2022, SOC 2 Type II certification, and GDPR compliance, which is the baseline a consultancy should expect to see documented, not just claimed, before a subcontract SOW is signed.

How Should a Vendor Due Diligence Checklist Be Structured?

A vendor due diligence checklist for subcontract delivery work should be organized by risk category, not by feature list, because the point is to catch failure modes before they happen on a live client engagement. Screening frameworks used by prime contractors in adjacent industries follow a similar logic: verify credentials before the relationship becomes contractual, not after.

Risk category

What to verify

Why it matters for a subcontract

 

Information security

ISO 27001:2022, SOC 2 Type II, GDPR status

Client data exposure becomes the consultancy's liability

Process maturity

Onboarding docs, escalation path, SLA terms

Determines whether delivery is repeatable, not one-off

Seniority mix

% senior engineers on the actual bench, not the sales deck

Predicts whether seat one can operate with light oversight

Communication overlap

Working-hours overlap, incident response time

Determines how fast a production issue gets acknowledged

Contractual clarity

IP assignment, liability caps, termination terms

Protects the consultancy if the subcontractor exits mid-project

Financial stability

Time in business, client retention rate

Signals whether the subcontractor will still exist in 12 months

Vendor risk assessment software can help formalize scoring across these categories when a consultancy is running due diligence across multiple candidate subcontractors at once, turning what is otherwise a subjective gut check into a comparable score sheet.

Why Does Seniority Mix Matter More Than Headcount?

A subcontractor advertising 200 engineers tells the consultancy nothing about who will actually staff seat one. What predicts performance on a fixed-scope engagement is the ratio of senior engineers actually available for placement, because a senior engineer needs less oversight from the consultancy's own project lead, which is the scarce resource in a small consultancy of 2 to 20 people.

Think of it the way a hospital staffs a night shift: having 50 doctors on payroll doesn't matter if the one on call tonight is a first-year resident. The consultancy isn't buying headcount, it's buying the specific person answering the pager at 2am on the client's go-live night. That's why the due diligence question should be "what's the seniority level of the specific engineer joining next week" rather than "how many engineers do you have total."

724SOFTWARE's bench runs 58% senior-level experts, and the delivery model is built to scale from one engineer to 50+ within 2 to 4 weeks, which matters directly for the "one now, five later" shape most subcontract requests take.

How Should Communication and Response Time Be Verified?

Communication overlap is a contractual term, not a cultural preference, and it should be written into the SOW with a specific time window, not left as an assumption. A consultancy managing a client relationship across time zones needs to know precisely when the subcontractor's team is online and how fast a production incident gets acknowledged, because the consultancy is the one fielding the client's phone call if something breaks overnight.

724SOFTWARE operates on a follow-the-sun model with a guaranteed incident response time under 10 minutes, which is the kind of number that belongs in a due diligence checklist item, not a sales conversation. If a candidate subcontractor can't name a specific response time commitment, that's the gap to flag before signing, not after the first incident.

What Contractual Protections Should the Consultancy Insist On?

Screening for capability answers whether the subcontractor can deliver; contractual protections answer what happens if they can't. Detailed instructions and clear expectations set upfront reduce ambiguity around scope, which is one of the most common failure points in subcontracted work. Beyond scope clarity, the consultancy should confirm IP assignment terms, liability caps, and exit provisions before the engagement starts, since these are far harder to renegotiate mid-project when the client deadline is already fixed.

Frequently Asked Questions

What's the difference between subcontracting and staff augmentation for a consultancy?

Subcontracting typically means the subcontractor owns a defined scope of work under the consultancy's contract with the end client. Staff augmentation means individual engineers are embedded directly into the consultancy's own workflow and management structure. Both models require the same due diligence on security and process, but staff augmentation gives the consultancy more direct day-to-day control.

How long should vendor due diligence take before signing a subcontract SOW?

It depends on the complexity of the engagement and the client's own compliance requirements, but certification verification, reference checks, and a scoped pilot engagement can typically be completed within a few weeks if the subcontractor already has documented certifications ready to share.

Should a consultancy require a pilot project before a full subcontract commitment?

Yes, where the funded scope allows for it. A short paid pilot on a defined deliverable tests communication, code quality, and responsiveness under real conditions, which is more predictive than a portfolio review or a sales call.

Does a Vietnam IT company need a local office in the consultancy's country to qualify as a subcontract partner?

No. What matters is working-hours overlap, a documented incident response commitment, and verifiable certifications, not a physical office in the consultancy's home market. A Vietnam-based team operating on a follow-the-sun model can meet the same overlap requirement a nearby vendor would.

What happens if the subcontractor's certifications lapse mid-engagement?

This should be addressed contractually upfront, with a clause requiring notification of any certification status change and a defined remediation period, rather than discovered accidentally during a client audit.

How does seniority mix affect pricing?

A higher proportion of senior engineers generally costs more per hour than a junior-heavy bench, but for fixed-scope, client-facing work, the reduced oversight burden and lower rework risk usually offset the difference. Pricing specifics belong in a direct sales conversation, not a due diligence checklist.

Is ISO 27001 enough, or does a subcontractor also need SOC 2?

They answer different questions. ISO 27001:2022 confirms a security management system is documented and operating. SOC 2 Type II confirms operational controls were observed over a period of months. Consultancies handling regulated client data, such as fintech or healthcare, should expect both.

About 724SOFTWARE

724SOFTWARE is a Vietnam-based technology partner that consultancies and implementation partners subcontract to when they've won client work and need delivery capacity they don't have in house, typically starting with one engineer and ramping to five as scope confirms. The company runs a follow-the-sun support model with under-10-minute incident response, and staffs from a bench that is 58% senior-level experts. As a selected Anthropic partner in Vietnam, engineers are trained to use Claude Code in day-to-day delivery, giving subcontracting consultancies throughput without adding their own management overhead.

If you're screening subcontract delivery partners for an upcoming client engagement, get in touch with 724SOFTWARE at https://724software.com.vn to walk through certifications, seniority mix, and response-time commitments directly.

Share this article

Insights

Shrimpie Tran

AI Engineer

Keep Reading

Explore more from our experts.

View all

Stay ahead with our insights.

Get the latest on software design, strategy, and what's working in the field.

We respect your inbox. Unsubscribe anytime from any email.