Some obligations attach to a named function rather than to a document. The GDPR requires a data protection officer where Article 37 is triggered; NIS 2 places approval and oversight duties on management bodies; ISO 27001 and ISO 42001 both require assigned responsibilities that a certification auditor will ask to see exercised. Role outsourcing supplies that function without the organisation having to recruit every specialist permanently.
The GDPR is explicit that the role may be filled on a service contract. Article 37(6) permits it, Article 39(1) lists the five tasks the officer performs — informing and advising, monitoring compliance, advising on impact assessments, cooperating with the supervisory authority, and acting as its contact point — and Articles 38 and 39 set the conditions that make the appointment real: adequate resources, access to processing operations, no instructions on how to perform the tasks, and direct reporting to the highest management level.
Independence is the requirement most often designed away by accident. Article 38(6) allows a data protection officer to hold other duties only where they create no conflict of interest, which in practice rules out anyone who determines the purposes and means of processing — a head of IT, HR, or marketing supervising their own decisions. An external appointment resolves that structurally rather than by assertion, which is precisely why supervisory authorities look at it.
What outsourcing never moves is accountability. Article 5(2) keeps the controller responsible for demonstrating compliance no matter who performs the analysis, and the same logic applies to a virtual CISO or an embedded engineer: the specialist exercises judgement and produces evidence, while resourcing, risk acceptance, and implementation remain management decisions. A role charter recording duties, exclusions, authority, reporting line, and handover is what makes that boundary operable rather than theoretical.