Someone pasted a news link into the leadership channel at 11pm and by morning it had a “thoughts?” attached. Your Bengaluru team is 14 people. The contract has 26 months to run. Finance wants to know whether to keep hiring there, legal wants to know whether the MSA has a hole in it, and all anyone has read is a headline quoting unnamed officials.
The useful answer is not a forecast. It is a method.
Policy risk in an offshore outsourcing arrangement is the risk that a change in law or regulation makes your delivery model more expensive, slower, or unlawful. It arrives in five recognisable forms, only one of which touches the delivery model itself, and each can be checked against a primary source in about fifteen minutes. Build the arrangement so any of the five is survivable and you stop needing to guess what comes next.
One caveat, stated once, because it governs everything below. Specific proposals, draft bills and “officials are considering” stories change constantly and most never become anything. This article tells you the status of none of them, and neither does a news story you read three weeks ago. Check for yourself: the Federal Register and regulations.gov for US agency rulemaking, congress.gov for legislation, USCIS for visa policy, the eCFR for what is already in force, and the relevant Indian ministry site plus the Gazette of India for the India side. Minutes, and authoritative. Secondary reporting on an unenacted proposal is a prompt to go and look, nothing more.
The five policy risks that reach an offshore arrangement
Stop tracking events and track channels instead. Conflating these five is most of why the conversation goes badly.
- Immigration and visa rules affecting onsite presence. Who can be physically in the US, on what status, at what cost to the employer. Much of it is administered rather than legislated, so it moves easily. It bites only to the extent your arrangement depends on travel: onsite leads, transition teams, an account manager on an L-1.
- Tax treatment of cross-border service payments. Deductibility, withholding at source, whether anyone’s presence creates a taxable nexus, whether any levy attaches to the payment. Tax can change your unit economics without touching legality at all, which is why buyers under-model it.
- Data localisation and transfer restrictions. Where data may sit, who may access it, what you must do before it crosses a border. Both governments legislate here, and so does every jurisdiction whose residents’ data you hold.
- Government procurement and sector-specific restrictions. Rules that apply because of who your customer is or what industry you are in, not because of any general prohibition. Federal contracts, defence-adjacent work, healthcare, payments, insurance, state and local work. Already dense with real rules, which is why it matters more than hypothetical ones.
- Client-side contractual and reputational constraints. No statute behind it, and often the fastest to hit. Your customer’s procurement team adds a data-location clause. An enterprise security questionnaire starts asking where delivery staff sit. No law changed; your obligations did.
How to check each one yourself, and how to read what you find
Bookmark this section. The skill is cheap and it permanently reduces your dependence on other people’s summaries.
Federal agency rulemaking: the Federal Register. Every US agency action of legal consequence is published there. Search by keyword, then read the document type, the most important field on the page. A Proposed Rule binds nobody: it opens a comment period, typically 30 to 60 days, and may be withdrawn, rewritten or abandoned. A Rule is final, has an effective date and amends the Code of Federal Regulations. A Notice is neither. A Presidential Document, executive orders included, directs agencies; where it affects private parties it almost always does so through later rulemaking, so an executive order with no implementing rule is not yet a compliance obligation. Then check four dates: publication, comment deadline, effective date, and any delayed compliance dates, which often sit a year or more behind the effective date.
The docket: regulations.gov. Every rulemaking has one, holding the comments filed and the agency’s responses in the final rule’s preamble. If you want to know whether a proposal will survive contact with reality, the docket beats commentary about it, and you can file a comment yourself. Alongside it, the Unified Agenda on reginfo.gov lists each agency’s planned actions with a stage and a projected date. A planning document whose dates slip constantly, and still the earliest legitimate signal available, which makes it a better input than a leak.
Legislation: congress.gov. Find the bill, then read the Actions tab rather than the summary. Almost every introduced bill dies in committee, so referral is not progress, it is the default. What tells you something: a markup, a reported bill, a floor vote, reconciled text in both chambers. Check the Congress number too, because bills get reintroduced session after session and the number in a news story may be from a previous Congress and already dead.
Visa policy: USCIS, plus the Federal Register. USCIS publishes the operative rules per classification, cap mechanics, fees and the Policy Manual, which is what adjudicators actually apply. The statutory H-1B cap sits in the Immigration and Nationality Act and has been stable for many years at a base allocation plus a separate allocation for holders of US master’s degrees or higher; confirm the current figures on USCIS rather than from any article, including this one. Fees, filing windows, selection mechanics, evidentiary standards and the extra obligations on H-1B-dependent employers do change, sometimes through fee rules and policy memoranda rather than legislation. If a report says a visa rule changed, that change exists as a Federal Register document, a USCIS policy alert, or nothing.
Rules already in force: the eCFR. Least used, and it answers the question that matters: what binds me today. Current codified text, updated daily, with an Enhanced Content panel showing amendments published but not yet effective. When you read that “US rules prohibit X”, ask for the CFR citation. If there is none, the claim is about a proposal or a misunderstanding.
Tax: IRS primary materials. The IRS publishes the text of every income tax treaty in force, including the India treaty, with technical explanations. For paying a foreign provider, read the source-of-income rules and the withholding regime. Changes arrive as Federal Register regulations and as notices in the Internal Revenue Bulletin.
The India side: the ministries themselves. MeitY for the Digital Personal Data Protection Act and its rules, Finance and CBDT for tax, the Reserve Bank of India for payments and financial data, CERT-In for incident reporting and logging, Commerce and Industry for SEZ and export policy. Statutory instruments appear in the Gazette of India. Indian changes are often announced in a budget speech months before the instrument exists, so the gazette notification is what to look for.
A test that resolves almost every panicked forward you will receive: ask for the instrument. A Federal Register document number, a bill number with an Actions history, a CFR citation, a gazette notification, a USCIS policy alert. If nobody can produce one, there is nothing to comply with.
What already restricts where work happens
Less exciting than a headline, and where the real constraints live. Four families, brief here because the detail is in our piece on modelling access risk in an India engagement.
- The DOJ bulk sensitive data rule, at 28 CFR Part 202 under Executive Order 14117, restricting some transactions that give designated countries of concern and “covered persons” access to bulk US sensitive personal data. It turns on ownership and residency, not your vendor’s nationality, and India is not a designated country.
- Federal procurement, plus ITAR and EAR. Federal contracts carry place-of-performance and personnel clauses that vary by agency. Export control is sharper: releasing controlled technical data to a foreign person is a deemed export requiring authorisation, which catches a foreign national in your own office as much as a team abroad.
- Healthcare. HIPAA imposes no geographic restriction, but the business associate chain and the Security Rule follow the data everywhere, and some payer programmes add offshore disclosure and attestation requirements. Your payer contracts usually restrict more than the statute does.
- Financial services. Supervisors regulate third-party arrangements rather than geography: due diligence, ongoing management, retained oversight, accessible records. Separately, the RBI requires payment system data to be stored in India, a localisation duty on your vendor that can constrain architecture.
None prohibits offshore delivery as such. All change what a compliant offshore design looks like, and three of the four are conditions of particular customer or sector relationships rather than general law.
Why the delivery model is harder to reach than the visa
What follows is analysis of how the instruments work, not a prediction about anyone’s intentions. When a US company buys services performed abroad it is buying a service, not importing labour. No border crossing, no admission, no status to grant or deny, no US worksite. Legally and economically it is a cross-border services transaction, closer to buying cloud hosting or an audit from a foreign firm than to hiring a person. The levers governments use to manage labour markets all operate at the point a person enters and works: admission standards, wage floors, employer attestations, prevailing wage determinations, worksite enforcement. A team in Pune never reaches that point, and there is no general power to stop a US company buying services from a foreign company.
Tax is the most direct lever on the rest, because it changes cost without changing legality. It runs into the treaty network and into the source rules: compensation for personal services is generally sourced where the services are performed, which is why payments for work done wholly outside the United States are generally not US-source income and generally not subject to withholding at source. Procurement can restrict decisively, but only where government is the buyer or funder. Data rules can make particular categories of work impractical offshore, but they operate on data classes and access rather than on outsourcing.
Visas show the shape of it. They can make onsite-heavy delivery expensive or unworkable, and the industry’s observable response over two decades has been higher offshore ratios, local hiring in client countries, and delivery centres outside India. Constraining people movement tends to push work offshore rather than onshore, because the alternative to an onsite engineer is usually an offshore engineer, not a domestic hire at three times the cost. Plenty could still change. The point for your contract is that the channels with the most policy activity are the ones your arrangement can be built to depend on least.
Concentration is the part you actually control
You cannot influence any government’s agenda. You can decide how much of your operation sits behind a single point of failure.
Three exposures, routinely confused. Single-country: all delivery in one jurisdiction, so policy, currency and tax risk land together. That is the one the headline is about. Single-vendor: one provider running several functions, so a ransomware event or an insolvency takes out three processes at once. Nothing to do with geography. Single-site: one building, one city, exposed to flood, grid failure or local disruption. The most common exposure and the cheapest to fix, because it needs no second country.
The arithmetic on a second delivery location, since the vendor selling it will not volunteer the costs. You pay for a second management layer; a second onboarding and knowledge transfer, the real expense, measured in weeks of your senior people’s time rather than in rate card; a second security review and negotiation; duplicated tooling and access administration; and lost volume pricing, because you split the book. Under roughly 15 to 20 people in total it usually costs more than it can return, because those overheads do not shrink with headcount. What it buys is optionality with a short exercise time. A site already live, already holding your context, already running a share of production turns a forced move into a scaling exercise: weeks rather than quarters.
Two cheaper positions suit most mid-market buyers. Documented, tested portability: current runbooks, no tribal knowledge, no vendor-proprietary tooling in the critical path, access provisioned through your identity system rather than theirs, and a migration plan you have walked with a stopwatch. Or a second site inside the same vendor, different city or country, with a contractual right to invoke it, costing almost nothing until used. Two sites in one country do nothing for country-level policy risk, though. Do not let anyone sell you Coimbatore as a hedge against a change in US rules.
The clauses that make a policy shock survivable
Most offshore contracts handle this with boilerplate saying the parties will discuss it. Five provisions do the real work, and you get them at signature or renewal, never during a crisis.
- Change of law, with an allocation rather than an acknowledgement. Who bears increased cost, up to what cap, on what notice, and what triggers renegotiation versus termination. The common failure is a clause letting the vendor pass through any cost arising from a change in law, uncapped, which turns your fixed price into a variable one at their discretion. Cap it, require documented actual cost, and treat legal impossibility and cost increase as different events with different remedies.
- A right to relocate delivery on notice. Your right, exercisable by you, to require all or part of the service be performed from a different location or country within a defined period at a defined price mechanism. Without the price mechanism it is not a right, it is an invitation to renegotiate. Include the reverse: the vendor needs written approval before moving your work, because silent relocation into an unassessed jurisdiction is a common and quiet breach.
- Data-location commitments with audit rights. Name the countries where your data may be stored, processed and accessed, remembering that remote access from a fourth country is a transfer even when storage never moves. Then attach verification: evidence of where systems sit, access logs showing the geography of access, named subcontractors, and a right to test rather than to receive a certificate. A data-location promise with no verification right is marketing copy.
- Termination for regulatory impossibility. A clean exit where performance becomes unlawful or a required authorisation is withdrawn, with no termination-for-convenience fee, a defined transition assistance period at agreed rates, and data return in a specified format plus a deletion attestation. Transition assistance is the part people forget and the part that saves them.
- Who pays for a forced move. Decide in advance, in writing, split by cause. A change affecting the vendor’s own jurisdiction is arguably their risk; one affecting your sector or your customer’s requirements is arguably yours; a mutual regulatory event is a candidate for sharing to a cap. Any of those is defensible. Silence is not, because silence means whoever has leverage at that moment decides.
Add subcontractor disclosure and approval, with flow-down of every location and data obligation. Your policy exposure is that of whichever entity’s staff actually touch the work, and that is often not the entity that signed.
A week’s work that closes most of the gap
Not a programme. Four answers you probably do not have, obtainable in a week without anyone’s permission.
- Days one and two: where do your people and your data actually sit? Not the headquarters, not the logo on the proposal. For every named individual: city, employing legal entity, and whether they are an employee, a contractor or a subcontractor’s staff. For your data: every system holding it, the configured storage region of each, every backup location, and every country it is accessed from, support and monitoring tooling included. Most buyers find a surprise, usually third-country remote access or a backup in an unexpected region.
- Day three: who are the subcontractors and fourth parties? Ask in writing for every entity whose staff or tooling touches your account, your vendor’s own helpdesk, monitoring and HR platforms included. Compare against the approved list in the contract, then ask what share of your team is subcontracted rather than employed. A vendor that cannot answer in two days has told you how it manages your account.
- Day four: what do your own customer contracts promise about data location? This is the trap. You may already have committed, in an enterprise MSA or a DPA signed two years ago, to onshore processing or to a subprocessor list you have since drifted from. Search executed customer agreements for location, residency, subprocessor and cross-border language. If you promise more than you deliver, that is a live issue today, independent of any policy change.
- Day five: how long would a migration actually take? Write it out. People to recruit and onboard, knowledge transfer, access provisioning, data migration, parallel run, longest-lead item. Get your vendor’s number and reconcile the gap. The output is one figure in weeks that you can hand a board. Six weeks and nine months imply completely different decisions about everything above.
Neither panic nor complacency
The complacent position on outsourcing is that nothing ever changes, so there is no need to know where your data sits. The panicked position is that a report about a possible plan justifies unwinding an arrangement that works. Both skip the same step: finding out what is actually in force and what you have actually agreed.
Decide on what is durable: the economics of the arrangement, driven by labour markets, capability depth and your own management capacity rather than by news cycles, and the controls you hold, which are your contract, your architecture, your knowledge of your dependencies and your migration time. Improving those pays off whether or not anything changes. Then treat unverified reporting as a prompt to check a primary source. Fifteen minutes, producing either an instrument you can read or nothing at all. Usually nothing at all. Sometimes a proposed rule with a comment period, which gives you months of notice. Occasionally a final rule with an effective date, and then you execute the plan you already wrote.
If you would rather have someone run the location-and-dependency audit with you, tighten the change-of-law, relocation and data-location clauses before your next renewal, or stand up a small second delivery site so the option exists without the cost of a full duplicate, that is ordinary work for AB7 Solutions. We run contract staffing, staff augmentation, C2C and remote professional teams alongside BPO and KPO delivery, and we cover the security side too, from vendor assessment and VAPT through SOC support, which is where data-location questions get answered properly rather than asserted. We will also tell you when your exposure is small enough that the right move is to document what you have and spend nothing, because a second site you do not need is just a second invoice. Call +1 321 341 7733, email ab@ab7solutions.com or the director directly at director@ab7solutions.com, or see the service list at www.ab7solutions.com.
Sources, all primary and all worth checking yourself rather than taking from this article: Federal Register; regulations.gov; Unified Agenda, reginfo.gov; congress.gov; eCFR; USCIS on H-1B specialty occupations and the USCIS Policy Manual; US Department of State visa information; IRS United States income tax treaties A to Z and Source of Income: Personal Service Income; DOJ Data Security Program and 28 CFR Part 202; ITAR deemed export rule at 22 CFR 120.50 and BIS on the EAR; Federal Acquisition Regulation; HHS on HIPAA business associates and the Security Rule; FTC Safeguards Rule at 16 CFR 314.4; MeitY, Reserve Bank of India, CERT-In, Ministry of Finance and the Gazette of India. No current legislative or executive proposal is described or relied on anywhere above; verify the status of anything you have read elsewhere against these sources.