AboutServicesMediaInsightsInvestigation FAQContact📞 24H Hotline
0800-090-007
OUTSOURCING RISK · BUSINESS VERIFICATION

Outsourcing due diligence beyond the job titleA customer-service contract may not describe the work actually performed

DATE 2026.09.24
UPDATED 2026.10.02
Relieved Xianyu Risk Advisory

Outsourcing due diligence should follow the work. A contract says customer support, but the daily tasks gradually expand into refunds, account checks or payment instructions. Each request seems small. Together they can change who touches data and money.

Payment-related support is not automatically improper. The question is whether the expanded role was understood, authorised and reviewed. A familiar contact cannot supply the missing approval after a dispute begins.

What to check first

Establish the facts needed for the decision, then identify the missing records.

  • Registration does not describe every daily task.
  • Payment terminology alone is not evidence of crime.
  • Document changes in scope and authority.
  • Start with work records the business lawfully holds.
  • Do not identify private staff or treat charges as convictions.

1. News observation: a gap between the description and the operation

On 23 September 2026, Taichung prosecutors announced charges against 30 people, alleging that two companies operated customer-service bases for cross-border laundering involving NOW PAY and X PAY. Charges are not convictions, and this article does not assume every employee knew of wrongdoing.

Our analysis concerns the general outsourcing question: does the client know what work is performed, who approves it and where data goes? It does not claim access to unpublished evidence in the case.

2. Outsourcing due diligence starts with one work ticket

Ask for an anonymised example showing how a request enters the service, which systems and roles handle it and how it is closed. Compare that workflow with the contract. This is more useful than asking for a general assurance that the vendor complies with everything.

For each use of transaction or identity data, establish necessity, approval, retention and onward recipients. A service can expand legitimately. Data access and payment authority should not expand by assumption alongside it.

3. Review the entity, people, systems and payments separately

01
Entity
Identify who contracts, assigns work and invoices, including authorised subcontracting.
02
Roles
Establish who gives instructions and approves changes without publishing private staff lists.
03
Systems
Match access to the task and plan how it ends when the work stops.
04
Payments
Distinguish relaying information from executing refunds or payment instructions.

4. Does a reference to USDT or KYC prove wrongdoing?

No. A term is not evidence of an offence. Establish what service is actually provided, which permissions or registrations are relevant and whether the documents match the operation. Virtual-asset activity should not be treated as inherently criminal.

Rules differ across jurisdictions. Registration in one place is not a global permission to perform regulated activities. Qualified legal and compliance advisers should assess applicability, using current official sources and a record of the scope examined.

5. What to do when the scope has changed without approval

Preserve contracts, change requests and lawfully held work and access records. Responsible managers should decide which permissions remain necessary. Where restrictions are warranted, document them and avoid destroying the history by casually deleting accounts.

Ask specific questions about the operation: who approved this refund or why did this file go to another entity? Do not ask staff to secretly record colleagues, enter another person’s account or copy customer data to private devices.

6. How Relieved Group can assist

We can compare public company information, the contract and authorised workflow records. Deliverables may include an operating-role map, a timeline, an evidence-gap list and a factual summary for counsel. The scope should match the decision rather than collecting everything available.

We cannot promise to identify every controller through public sources or replace a lawful investigation by authorities. Agree confidentiality, permitted data and intended use before sharing sensitive material.

7. A final reminder: find the approval for the latest added task

Choose the latest task added to the support team and find its approval record. If a chat message is the only authority for handling customer identity data or payments, that change needs a proper review.

Frequently asked questions
Does payment-related customer support imply laundering?
+
No. Handling order or payment information may be legitimate. Establish whether staff answer questions, verify information or actually receive, exchange or direct funds. These roles have different implications. Compare the real workflow with the contract and applicable permissions. A job title or a reference to a virtual asset cannot substitute for evidence about the conduct in question.
Why review operations if the vendor is registered?
+
Registration provides limited entity information, not a complete account of workflows, subcontracting or system access. Use anonymised tickets, authorised process descriptions and public records to check whether the service matches the agreement. Broad registered business activities are not proof of misconduct. The goal is to identify unexplained differences and determine which require clarification or professional assessment.
Can a client inspect outsourced workers’ private messages?
+
Suspicion does not create a right to access private communications. Start with business records the client lawfully holds and keep the scope necessary and proportionate. If other information is required, counsel should assess authority, privacy and the proper process. Do not use impersonation, covert account access or private device collection as a shortcut to establishing facts.
What should change when support starts processing refunds?
+
Clarify whether the role provides information or executes a financial instruction. Identify the approver, permitted recipients, system logs and responsibility for errors. Document the change and assess whether legal, compliance or data-protection review is required. An informal convenience should not become a permanent expansion of authority that nobody has accepted responsibility for.
Should we publicly distance ourselves from a suspicious vendor?
+
Preserve facts and seek legal advice first. A mismatch may reflect outdated documentation or something more serious, and premature accusations can create further exposure. Internal access controls and document requests may be appropriate while the facts are checked. Decisions on termination and public statements should follow the contract, available evidence and actual impact, not a desire to appear decisive.
What is needed for an initial outsourcing review?
+
Provide the entity name, relevant jurisdictions, agreed service and the specific discrepancy. Explain who lawfully holds the relevant records. Do not send passwords, private keys or complete personal datasets at first contact. The adviser should define the review’s limits, permitted sources and deliverables before deciding what further authorised information is necessary.

Sources

CONFIDENTIAL CONTACT

Has outsourced support moved into data or payment operations?

Describe the difference between the agreed service and the current workflow. Do not send passwords, private keys or communications obtained without authority.

📞LINE contact iconWhatsApp contact icon