(a)Contracted activities
include all the activities within the scope of the service provider's
operations, in accordance with the terms of the certificate, that are
performed by other organisations either themselves certified to carry out such
activity or if not certified, working under the service provider's oversight.
A service provider shall ensure that when contracting or purchasing any part
of its activities to external organisations, the contracted or purchased
activity, system or constituent conforms to the applicable requirements.
(b)When a service provider
contracts any part of its activities to an organisation that is not itself
certified in accordance with this Regulation to carry out such activity, it
shall ensure that the contracted organisation works under its oversight. The
service provider shall ensure that the competent authority is given access to
the contracted organisation to determine continued compliance with the
applicable requirements under this Regulation.