Technology

IT services & capability centres. Clients buy capability they cannot see.

Every proposal is a promise about people, data and delivery.

IT services and consulting firms, global capability centres, BPM and engineering-services providers, selling delivery capacity to enterprises that audit everything. We build positioning beyond headcount, proof of delivery that procurement can verify, talent brands for capability centres, and AI-assisted delivery with the governance clients now ask for.

The number we move
Win rate on qualified bids
Where we work in IT services & capability centres
  • IT services & consulting
  • Global capability centres
  • Business process management
  • Engineering & R&D services
  • Cloud & digital partners
Rules mapped
8 rules · 5 areas
Disciplines that lead
BrandTechnology
Frameworks we build to
ISO/IEC 27001:2022 — Information security management systemsISO/IEC 27701 — Privacy information management systemsSOC 2 — Trust Services CriteriaGDPR — General Data Protection Regulation (EU) 2016/679DPDP Act 2023 — Digital Personal Data Protection Act, 2023CERT-In Directions 2022 — Cyber incident reporting directionsEU AI Act — Artificial Intelligence Act (EU) 2024/1689ISO/IEC 42001:2023 — Artificial intelligence management systems
Three people work at a long table in a large open-plan office under linear ceiling lights
IT services & capability centresCapability is people, process and proof.

Where the rules biteMap of all forty-one industries

  • Claims Advertising & claims: Sometimes shapes the work
  • Regulator Sector regulator: Often shapes the work
  • Payments Payments: Sometimes shapes the work
  • Data Personal data: Shapes most of the work
  • Security Security & incidents: Shapes most of the work
  • Access Accessibility: Often shapes the work
  • AI AI governance: Often shapes the work

What is shifting

Clients buy capability, and audit everything behind it.

Data law, delivery models, AI rules and procurement evidence are changing what a services proposal has to prove. Each shift names what it demands, with a fact you can check.

A woman draws a management-system diagram on a glass whiteboard
Delivery models are being redrawn.
  1. Offshore work for foreign clients sits mostly outside India’s data law.

    It demandsContracts, controls and evidence built around what still applies: the client’s law, security safeguards and accountability.

    SignalSection 17(1)(d) of the DPDP Act exempts processing of non-residents’ data under contracts with foreign clients from most of the Act, though not from its security duty.

  2. Work from anywhere became the default for voice and data centres.

    It demandsDelivery models built for distributed teams, with security that does not depend on the office.

    SignalThe DoT liberalised its Other Service Provider guidelines in November 2020 and again on 23 June 2021, removing registration and allowing work from anywhere.

  3. Clients ask what AI is in the delivery, and who answers for it.

    It demandsAI-assisted delivery with model inventories, evaluations and accountable people, documented for the client.

    SignalThe EU AI Act’s duties for high-risk systems in Annex III apply from 2 December 2027, after the Digital Omnibus of July 2026 moved the date.

  4. Buyers want the bill of materials with the code.

    It demandsSBOMs and release evidence produced by the toolchain on every release.

    SignalCERT-In’s guidelines of 9 July 2025 name software exporters and the services industry among those urged to make SBOMs a standard practice.

The rulebook

Your client’s law travels with every line of code you ship.

The data law and its offshore exemption, the GDPR, CERT-In, the OSP regime and the EU AI Act, read for a delivery organisation. Your counsel keeps sign-off.

Frameworks we build to

  • ISO/IEC 27001:2022 — Information security management systems
  • ISO/IEC 27701 — Privacy information management systems
  • SOC 2 — Trust Services Criteria
  • GDPR — General Data Protection Regulation (EU) 2016/679
  • DPDP Act 2023 — Digital Personal Data Protection Act, 2023
  • CERT-In Directions 2022 — Cyber incident reporting directions
  • EU AI Act — Artificial Intelligence Act (EU) 2024/1689
  • ISO/IEC 42001:2023 — Artificial intelligence management systems

Frameworks we design and build to — not a claim of certification.

Sector regulator

Often shapes the work

  1. Department of Telecommunications

    DoT Other Service Provider guidelines

    Since 2020–21, OSP centres need no registration, data-based services sit outside the guidelines, the domestic and international distinction is gone and agents may work from anywhere, subject to the remaining conditions.

    We designDistributed delivery models carry the security controls the client expects, wherever the agents sit.

    DoT · OSP guidelines of 5 November 2020, further liberalised on 23 June 2021 Official text: DoT Other Service Provider guidelines

  2. Indian Computer Emergency Response Team

    CERT-In guidelines on SBOM and AI bills of materials

    Minimum elements for software, AI, crypto and hardware bills of materials, which software exporters and service companies are urged to make standard practice.

    We designSBOMs and AI bills of materials are generated on every release and shared in a form clients can read.

    CERT-In · Technical Guidelines on SBOM, QBOM & CBOM, AIBOM and HBOM, version 2.0, 9 July 2025 Official text: CERT-In guidelines on SBOM and AI bills of materials

Personal data

Shapes most of the work

  1. Ministry of Electronics and IT

    DPDP Act, 2023 — processors and the offshore exemption

    Processors act only under a valid contract and the fiduciary stays responsible; processing non-residents’ data under a contract with a foreign client is exempt from most of the Act, though security safeguards and accountability still apply.

    We designData terms and controls are mapped client by client, so each team knows which law governs the data it touches.

    DPDP Act, 2023 · sections 8(1), 8(2), 8(5) and 17(1)(d) Official text: DPDP Act, 2023 — processors and the offshore exemption

  2. European Union

    GDPR — processor duties and standard contractual clauses

    Processors act on documented instructions, use sub-processors only with authorisation and help the controller with breaches and audits; transfers out of the EU rely on mechanisms such as the 2021 standard contractual clauses.

    We designSub-processor lists, records of processing and transfer documents are kept with the delivery, not in a drawer.

    Regulation (EU) 2016/679 · Article 28 · Commission Implementing Decision (EU) 2021/914 of 4 June 2021

Security & incidents

Shapes most of the work

  1. Indian Computer Emergency Response Team

    CERT-In Directions, 2022

    Service providers and companies in India report listed cyber incidents within six hours of noticing them and keep logs of all ICT systems for a rolling 180 days within India.

    We designLogging and incident runbooks are part of every client setup, with the six-hour clock rehearsed.

    CERT-In · Directions under section 70B(6) of the IT Act, 28 April 2022 Official text: CERT-In Directions, 2022

  2. ISO/IEC · AICPA

    ISO/IEC 27001, ISO/IEC 27701 and SOC 2

    The certificates and attestation reports clients ask service providers for; the 2025 edition of ISO/IEC 27701 can now be implemented as a privacy management system on its own, without ISO/IEC 27001.

    We designControls and their evidence come out of the delivery toolchain, ready for your auditors.

    ISO/IEC 27001:2022 · ISO/IEC 27701:2025 · AICPA Trust Services Criteria

Accessibility

Often shapes the work

  1. W3C

    WCAG 2.2 AA

    The accessibility level many public and enterprise buyers write into contracts for the products their suppliers build.

    We designClient deliverables are designed and tested to WCAG 2.2 AA, with the test evidence handed over.

    W3C · WCAG 2.2 Official text: WCAG 2.2 AA

AI governance

Often shapes the work

  1. European Union

    EU AI Act — providers and deployers

    A firm that builds an AI system for a client may be its provider, and the client its deployer; transparency duties apply from 2 August 2026 and high-risk duties for Annex III systems from 2 December 2027 under the 2026 Digital Omnibus.

    We designEach AI component has a named provider, a model card and evaluation results the client can rely on.

    Regulation (EU) 2024/1689, as amended by Regulation (EU) 2026/1744 Official text: EU AI Act — providers and deployers

Compiled 3 October 2026. Our reading of typical programmes, not legal advice. Rules change; your counsel confirms how each one applies to you.

Challenges

Your customers’ problems, and your own.

What we hear in almost every IT services & capability centres brief — on the customer’s side of the screen, and on yours.

Your customers

  1. Capability, not headcount

    Clients want outcomes and accountable teams, not rate cards.

  2. Due diligence that ends

    Security, privacy and AI questionnaires answered once, with evidence.

  3. Continuity through change

    Transitions, attrition and handovers that never show up in the client’s numbers.

A black-line flowchart with small labelled boxes painted across a white wall
Every process a client buys has to be shown, not described.

Your operation

  1. Proof across hundreds of projects

    Case evidence that is anonymised, approved and current.

  2. Many clients, many rulebooks

    GDPR, DPDP and sector rules applied client by client, without a separate process for each.

  3. A talent brand in a crowded market

    Capability centres and service firms compete for the same engineers.

What we build

Six disciplines, weighted for IT services & capability centres.

A typical programme here draws on each discipline in this mix. Every line names what it builds for the industry and links to the capability that does the work.

Leads Core Supports Share of a typical programme, by role · illustrative
  1. 01

    Brand Design

    Leads

    Positioning beyond headcount, and a talent brand for capability and delivery centres.

  2. Evidence portals, delivery dashboards and the integrations clients audit.

  3. Case evidence, points of view and bid content that procurement and AI assistants can cite.

  4. 04

    AI Design

    Core

    AI-assisted delivery with inventories, evaluations and accountable owners.

  5. Account-based journeys and bid pipelines across long deals with many people.

  6. Client portals and internal tools that make delivery visible.

Programmes

Map the evidence first, then tell the story it supports.

The way in collects what clients and procurement ask, and shows which answers you can already prove. Lengths are typical, never promised.

The way in

Proof and due-diligence audit

We collect the questions clients and procurement ask, and show which ones your site, case evidence and controls already answer.

Package
Sprint · Fixed fee
Typical length
2–3 weeks
It sets
Days to clear client due diligence, as a baseline
  • Product experience audit
  • Technical & code audit

What it hands over

  • A question-and-evidence map with the gaps ranked
  • An outline for a client trust and evidence portal
  • Approved answers to reuse in bids and in an assistant
Start here
  1. 02Project · 8–12 weeks

    Positioning and proof system

    A capability story beyond headcount, case evidence in one structure and bid content that stays consistent.

    MovesWin rate on qualified bids

    Services: Brand foundation & positioning · Brand narrative & messaging · Content strategy & editorial plan

    Enquire about Positioning and proof system
  2. 03Project · 8–12 weeks

    Capability-centre talent brand and careers site

    An employer brand built on the work teams own, with a careers site that shows real roles, teams and technology.

    MovesOffer-to-join rate for key roles

    Services: Logo & identity system · Website · Always-on social media management

    Enquire about Capability-centre talent brand and careers site
  3. 04Milestone · 3–6 months

    Governed AI in delivery

    An inventory of AI in the delivery, evaluation sets per use case and the documentation EU clients will ask for under the AI Act.

    MovesShare of AI use cases with an owner and an evaluation set

    Services: AI use policy, rights & disclosure · Brand fidelity evaluation · AI readiness assessment

    Enquire about Governed AI in delivery

How success is measured

The number we moveWin rate on qualified bids

  • Win rate on qualified bids
  • Days to clear client due diligence
  • Offer-to-join rate for key roles
  • Time to stand up a new delivery team

AI, under the rules

AI in the delivery, with an owner for every use.

Each use case keeps one client’s data away from another’s, has an evaluation set and a log, and a person signs off whatever reaches the client.

Use case 01

Bid and questionnaire assistant

Measured byDays to clear client due diligence

Tested forOWASP LLM09 · Misinformation

agent / bid-and-questionnaire-assistant Guarded
  1. TaskDrafts RFP and due-diligence answers from approved policies, case evidence and certificates.
  2. GuardrailApproved sources only; unsupported claims are flagged, never written.
  3. HumanThe bid manager and security lead approve every submission.
  4. LogAnswers with their source documents and versions.

Ships only with its evaluation set, its guardrail and an owner

Use case 02

Delivery knowledge assistant

Measured byAnswer accuracy on each client’s evaluation set

Tested forOWASP LLM02 · Sensitive information disclosure

agent / delivery-knowledge-assistant Guarded
  1. TaskAnswers engineers’ questions from the client’s runbooks, code and tickets.
  2. GuardrailRetrieval is separated by client, so one client’s data never answers another client’s question.
  3. HumanTeam leads review flagged answers every week.
  4. LogQuestions, sources and the client workspace used.

Ships only with its evaluation set, its guardrail and an owner

Use case 03

Change and release summariser

Measured byRelease notes accepted without rework

Tested forOWASP LLM06 · Excessive agency

agent / change-and-release-summariser Guarded
  1. TaskSummarises pull requests and release notes for client reviews and the SBOM.
  2. GuardrailRead-only access: it cannot merge, approve or deploy.
  3. HumanThe release owner approves the notes.
  4. LogChanges summarised and approvals.

Ships only with its evaluation set, its guardrail and an owner

Work and insights

The work, anonymised until clients approve.

Projects in this industry are published once a client approves the write-up. Until then, here is what we have written on the rules that apply.

A typical programme · composite

A global capability centre replaced its generic careers site with a talent brand built on the work its teams own, and gave the parent company’s auditors one evidence portal for its security and privacy controls.

Anonymised and illustrative: the shape a programme takes, never a named client.

Questions

What delivery heads, centre leaders and bid teams ask us first.

Something else on your mind? Ask us directly

Q.01Does India’s DPDP Act apply to work we do for foreign clients?

Largely not, where you process data of people outside India under a contract with a foreign client: section 17(1)(d) exempts that processing from most of the Act. Security safeguards and accountability still apply, and so do the client’s own laws, such as the GDPR. Your counsel confirms the position contract by contract.

Q.02Can you help a new capability centre build its brand?

Yes: positioning inside the parent company and in the hiring market, a careers site built on real roles and teams, and content that shows the work the centre owns.

Q.03How do you handle AI in our delivery for EU clients?

We inventory where AI is used, agree with you who is the provider and who the deployer for each use, and build the documentation, evaluations and human oversight the EU AI Act expects. Counsel confirms each classification.

Q.04Can we publish case studies without naming clients?

Yes. We build an anonymised evidence structure — sector, scale, problem and measured result — that procurement can verify under NDA, and add names only when a client approves in writing.

Let’s build what happens next.

Tell us what you’re building. We’ll answer straight.

Book a discovery call

Three ways to start

  1. 01About 2 minutes

    A quick question

    You get A reply from a lead, not a sales queue

  2. 02About 8 minutesMost useful

    A project brief

    You get Options and a first scope after one call

  3. 03About 15 minutes

    A formal RFQ or RFP

    You get Receipt confirmed and a named bid lead

Every engagement starts with a written scope and a quote agreed before work begins. How each package is priced