OutsourcingVN is operated by Netbase JSC, which delivers remote-first from Hanoi, so this guide describes the governance a supplier would like its buyers to insist on. It applies to any remote vendor, and it assumes the operating model has already been chosen.
Contents
- What does governance need to settle?
- How do you onboard a remote vendor?
- What should the weekly cadence look like?
- Worked scenario: escalating a blocked payment integration
- What do Netbase records show about governed delivery?
- Which questions should you ask a remote vendor?
- What are the signs that governance has failed?
- How this guide is sourced and where it stops
- Common questions
- Put governance in place before the first review
What does governance need to settle?
Governance is not a meeting schedule. It is the answer to five questions that a remote team cannot settle by walking over to someone's desk.
| Artefact | Question it answers | Owner | Review rhythm |
|---|---|---|---|
| Decision log | Who decided what, and when? | Buyer's product owner | Updated as decisions are made |
| Weekly written report | What moved, what is blocked, what is at risk? | Vendor's project manager | Weekly, before the review |
| Risk and dependency register | What could stop the next milestone? | Vendor's project manager, with buyer inputs | Weekly |
| Escalation route | Who hears about a problem, at which level, how fast? | Both sponsors | Agreed at onboarding, tested once |
| Access register | Who can reach which system, until when? | Buyer's system owner | Monthly, and at every team change |
| Milestone review record | Was the increment accepted, changed or blocked? | Buyer's acceptor | At each milestone |
Choosing where the team sits and how it is composed is a separate decision, covered by global delivery. Designing the overlap window between time zones is covered by the time-zone collaboration guide. This guide starts after both are settled.
How do you onboard a remote vendor?
-
Week 1: name the people
One product owner and one acceptor on your side; one project manager and one technical lead on the vendor side; two sponsors who own escalation.
-
Week 1: grant access deliberately
Create named accounts, record them in the access register with an end date, and keep production read-only until a written need arises. The data security and compliance guide lists what to settle first.
-
Week 1: agree the report template
Five headings are enough: done, next, blocked, risks, decisions needed.
-
Week 2: run a dry escalation
Invent a blocked dependency and walk it through the route. Fix any step that depends on someone being awake.
-
Week 2: hold the first review
Close it with written decisions in the log, even if the only decision is to continue.
-
Week 4: review governance itself
Drop any artefact nobody read and add any question that went unanswered.
What should the weekly cadence look like?
A weekly rhythm works for most engagements because it is frequent enough to catch drift and slow enough to show real progress. The Scrum Guide (2020 edition) describes a similar principle for its Sprint Review: the event exists to inspect the outcome and decide future adaptations, not to demonstrate activity.
Netbase delivers remote-first from Hanoi in Agile increments with weekly reviews, using AI-assisted engineering under human review. Its delivery runs with weekly reviews and a named project manager, and delivery communication is in English. The Hanoi office works Monday to Saturday, 9:00-18:15 Vietnam time (UTC+7), and support coverage follows those days, so the written report usually lands before a buyer in Europe starts work, and the review sits inside the agreed overlap.
Worked scenario: escalating a blocked payment integration
A retailer's remote team is building checkout. In week six, the payment provider's sandbox rejects the team's test account, and the milestone is due in ten days.
- Day 1. The vendor's technical lead logs the block in the register and flags it in the daily written note. The project manager rates it as a milestone risk.
- Day 2. No answer from the provider. The project manager escalates to the buyer's product owner, because only the account holder can open a support case. The decision log records who owns the next step.
- Day 4. Still blocked. Both sponsors hear about it on a short call; the buyer's sponsor calls the provider's account manager. The vendor re-sequences the milestone so that order history and email receipts are built first.
- Day 6. The sandbox works. The review accepts the re-sequenced plan, records that the milestone date holds, and closes the risk.
Nobody had to discover the problem at the milestone review, which is the whole point.
What do Netbase records show about governed delivery?
For a founder (not named), Netbase delivered a bilingual English and Nepali classifieds platform in six milestones over four months with training and six months of support. The classifieds platform record shows a milestone plan long enough to need a working review rhythm, from requirements and design through deployment.
For another client (not named), Netbase built a WhatsApp Business AI chatbot with intent and conversation-flow handling, an LLM API and CRM synchronisation. It was delivered in milestones from design and prototype to documentation, knowledge transfer and 30 days of support over 4-8 weeks. The WhatsApp chatbot record shows the same governance compressed into a short engagement.
Which questions should you ask a remote vendor?
- Who is our named project manager, and who covers when they are away? A good answer names both people.
- What does your weekly report look like? Ask for a real, anonymised example rather than a template.
- How do you escalate a blocker you cannot resolve? Expect levels, names and a time for each level.
- How do you record decisions made on calls? A good answer is a written note within a day.
- Who can access our systems, and how is access removed? At Netbase, security practices include secure code review and version control, role-based access control, MFA for admin dashboards, contributors under NDA, and NDAs and DPAs on request.
- Which people are Netbase staff and which are specialists or partners? Netbase stays accountable while teams may combine Netbase staff, approved specialists or disclosed partners; the answer should name each.
- What happens at a milestone review if we do not accept? Look for recorded outcomes: accepted, changes requested, or blocked by a dependency.
- How is the lifecycle phased? Netbase follows discovery and strategic alignment, team assembly and architecture planning, agile execution with outcome-based milestones, modular components, training and rollout, then ongoing support.
What are the signs that governance has failed?
- Green reports, late milestones. Signal: every report says on track until the review. Owner: the vendor's project manager, who must report risk earlier.
- Decisions only on calls. Signal: two people remember a decision differently. Owner: the buyer's product owner, who keeps the decision log.
- Escalation that skips a level. Signal: sponsors hear about problems first from the other side. Owner: both project managers.
- Access that never shrinks. Signal: former team members still hold accounts. Owner: the buyer's system owner.
- Reviews without acceptance. Signal: increments are shown but never accepted or rejected. Owner: the buyer's acceptor.
If the model itself is wrong rather than its governance, the project outsourcing versus staff augmentation guide helps compare models, managed outcomes covers governance after launch, and specialist sprints apply the same cadence to one short mission.
How this guide is sourced and where it stops
The guide draws on Netbase's approved facts about its delivery process, communication, working hours and security practices, two delivered records, and the 2020 Scrum Guide for the purpose of a review. The methodology explains how those records are sourced. Neither Work record publishes a governance metric or client feedback, so they show milestone structure, not proof that this governance prevents every delay. The page does not cover contract law or vendor selection.
Plan the next step for your project
Common questions
Less than a large one, but never none. A four-week project still needs a named project manager, a weekly written report, a decision log and one escalation route. What shrinks is the length of each artefact, not whether it exists.
The vendor's project manager should prepare and chair it, because the report is theirs. The buyer's product owner should close it, because decisions are theirs. Splitting the roles this way keeps the review honest about progress and clear about who decided.
Weekly is the baseline for the formal report. Short daily written notes help when time zones barely overlap, but they should not replace the weekly report, which carries risks and decisions needed rather than a list of tasks.
Only what the project managers cannot resolve within the agreed time: a blocked dependency, a disputed acceptance, a security concern or a change that affects the milestone date. Everything else is handled at project level and recorded in the log.
The structure stays the same, but the report should say where AI-assisted engineering was used and confirm that its output passed human review. Any restriction the buyer sets on AI tools belongs in the onboarding agreement, not in a later email.
Put governance in place before the first review
Bring the engagement you are about to start or the one that is drifting. OutsourcingVN is Netbase's own outsourcing-services platform; submit a project and a person will reply with a governance setup sized for it. Custom Product Engineering is the route for a bounded build under this cadence.
Related services and solutions
Custom product engineering for a bounded release outcome
One defined release of your product, built to named outcomes and handed over with acceptance evidence.
Learn More