BLR US
SKILLIGENT
US-focused talent solutions Bangalore · US-hours coverage
Insights / Uncategorized

Uncategorized · 15 min read

Six Documents to Ask Any Offshore Partner For Before You Sign

A practical guide to defining the environment around a role or team before choosing the engagement model.

Six Documents to Ask Any Offshore Partner For Before You Sign

Preparation pays off when it comes to vendor calls. Pose a question about candidate screening practices to an offshore firm, and you’ll get a prepared response designed to suit your query. Request the screening scorecard that the firm used a month back, and you will gain some real insights. The documents are much harder to fabricate than responses; a firm that has a developed operating model already has those ready in a folder somewhere. Here are six that can be requested.

Why Ask for Documents Instead of Answers?

Ask for documents instead of answers, it’s because answers are rehearsed and documents are evidence.

Very few offshore engagements fail on the basis of developer competency. They fail on the basis of governance. Deloitte’s 2024 Global Outsourcing Survey, which interviewed over 500 executives, revealed that the biggest challenges in programs included a lack of benefit tracking, change management issues, and a lack of integration of vendor services into the operating model. Not talent. Process.

This same survey showed that managed and operated services received a satisfaction rating of 88% compared to 71% in traditional staffing models. The difference is not the people; it’s the process surrounding them.

And there is documentation to prove it. A partner who truly manages structured delivery creates scorecards, runbooks, and review logs as part of their day-to-day operations. A partner who simply supplies bodies produces nothing, since nothing in their model produces those results.

So quit asking if your vendor has a process. Start asking what that process delivered last week.

1. The Screening Scorecard

It is the rubric used to grade your candidates against your own position, with an explicit rationale provided for each accept/reject determination.

It is there to fix the problem that is the oldest in offshore staffing: The resume you have approved is not the person showing up. According to practitioners, some vendors provide fifty engineers, but employ only three and substitute others after signing.

Demand three things:

  • The rubric itself, the criteria against which the candidates are graded;
  • At least one redacted completed grading form for any hire;
  • Ratio of accepts/rejects in their latest screening round.

Ask them what background checks run in tandem. India does have its standards for that – NASSCOM and NDML maintain the National Skills Registry, including empaneled background checkers for identity, educational credentials, work history, and criminal background. According to the industry statistics from AuthBridge (in 2024), 78% of Indian IT/BPO companies practice mandatory background verification.

Positive: written rubric, with proof of its actual use.

Red flag: “We assess the technical experience,” and no paperwork. Also, the named senior engineer in the proposal may become unavailable after the contract signing.

2. The Coverage Plan

It identifies the hours of overlap, before anyone has logged any time.

Time zones do not get in the way of offshore projects. Indeterminate availability will. The difference between Bangalore and US working hours is a given; whether that difference costs you one day per decision cycle is solely dependent on whether the overlap is intentional or incidental.

This needs to be spelled out:

  • The exact hours of overlap, stated in your time zone
  • What happens if something goes wrong outside those hours
  • Coverage by named individuals during Indian national holidays and scheduled vacations
  • Which of your regularly scheduled meetings are they supposed to attend

Indian holidays are not the same as US holidays, which always catch people unawares at the start of the year.

Good: specific hours of overlap in the project definition, along with a named backup for each position.

Warning sign: “We’re flexible” or “the team adapts as necessary.” Flexibility with no floor means the hours of overlap evaporate immediately when someone gets busy.

3. The SOP Framework

It records who owns what, how work passes between people, where it’s reviewed, and who’s brought in if there’s a problem.

Its true purpose is to break key-person dependency. Attrition in Indian IT firms has dropped from its peak level; the Big Four had an average attrition of roughly 22.7% in FY22 and have come down to 12-15%, but it hasn’t gone away. In two years of working together, you can be sure that somebody in your project is going to quit. The issue is whether the knowledge walks out the door with him.

Request a sample of the runbook; redacted if necessary. Check for named ownership instead of roles and decision rules that a newcomer will need from day one.

Positive: the process is written down in sufficient detail that work lives on even if the person who does it quits.

Red flag: “all our knowledge is in our heads.” Nope, that’s not institutional knowledge; that’s a single point of failure with a name tag.

4. The Quality Review Record

This shows how work is checked before it reaches you, and by whom.

Quality doesn’t break offshore loudly; quality degenerates. Standards fall a bit every sprint because nobody owns the flagging of problems, and six months later, you are fixing work that you’ve already paid for. In the research conducted by the Standish Group called CHAOS, only a third of all IT projects were completed with success, and the other half were delivered with delay, overbudget, or underscoped.

Here are four key questions that will give you a full picture:

  • What are the review criteria? Are they defined or improvised?
  • Who performs the review and has the power to send work back?
  • What does happen in the case of a failed review?
  • How are the corrective measures documented and closed?

The crucial thing here is separation. The review process should include a second pair of eyes.

Positive aspects: defined review criteria, an independent reviewer, and documentation of issues and their resolution.

Bad sign: QA done by the same person who did the job or mentioned as “the team self-reviews.”

5. The Weekly Operating Report

This is the one-page document that tells you what happened, what’s next, and what’s at risk.

The inability to see progress is the fear keeping US customers up at night. You either micro-manage the people working on the project or fail to manage them at all. Both are disastrous approaches. A weekly status report will solve this without any additional meetings.

Request a genuine redacted sample rather than a template. A template is easy to produce, but a year of good status reports is something else. A valuable status report has:

  • Actual vs. Planned, rather than just tasks completed
  • Blockers with the person responsible named
  • Decisions requiring your intervention this week
  • Known risks before they become issues

Good: a one-page status report that makes known risks surface early and provides the information you need to take action on.

Red flag: An activity log or a list of hours worked. “Completed 47 tickets” is all about motion, not progress, and sets an incentive to inflate numbers.

6. The Handover Record

This captures what’s done, what’s open, what it depends on, and who owns it next.

For most buyers, the quality of the partner will be judged based on the start of the engagement. The real expense lies at the end of the engagement. If handover is not negotiated before signing, it will be done so from a position of weakness afterward, while the vendor holds all of the context, the access, and the undocumented decisions.

Request the handover format at the time of engagement closure and role rotation. Then make sure that your exit plan covers:

  • The transition timeline and notice period
  • Access revocation for all systems and tools
  • Code handover, documentation handover, and credential handover
  • Who, from their side, is responsible for the handover

Handover issues also come up during an engagement. For every single time that there is a rotation off of your account, this document becomes the difference between a seamless handover and three weeks of reinventing the wheel.

Good: a standard handover format and well-defined exit and transition terms within the agreement.

Bad sign: no exit process defined is vendor lock-in under another name.

The Six Documents at a Glance

Each one is created to deal with its own particular failure mode, and there’s always a clue that can be used to detect if your partner actually has one.

This is the complete list, in one place, showing what they protect you from and the right answer to give you pause.

DocumentWhat it preventsBiggest red flag
Screening scorecardResume fraud and post-signing substitutionNo written rubric, only verbal assurances
Coverage planDecision cycles stretching across time zones“We’re flexible” with no defined overlap hours
SOP frameworkKnowledge walking out when someone resignsA process that lives only in people’s heads
Quality review recordStandards are decaying quietly over monthsThe person who did the work reviews the work
Weekly operating reportInvisible progress and surprise delaysAn hour’s log or ticket count instead of status
Handover recordMessy exits and vendor lock-inNo exit or knowledge-transfer plan in writing

Print it, take it to your next vendor call, and work down the first column.

Which Documents Matter Most for Your Engagement?

It depends on how much of the management you’re handing over.

When you’re hiring a single person

Place a heavier weight on the screening scorecard and the coverage plan. You’re purchasing a person’s availability, and you’ll be managing the process yourself. Since the SOP and QA processes are yours to manage, it’s less important how the partner runs them.

When you’re hiring a dedicated resource

The importance of the SOP framework and handover record shifts to the top. Continuity is the whole purpose of a dedicated solution, and it is the very thing that’s lost when one individual takes all the knowledge with him or her.

When you’re hiring a managed pod or white-labeled team

All six apply equally, and the weekly operating report takes precedence over all of them. You’ve outsourced the day-to-day management of your project, but this is your only reliable way to assess if it was done right.

Measure the right things based on what you’re really outsourcing: labor, continuity, or control.

How Should You Request These Documents?

Ask during evaluation, not after the proposal lands.

Timing equals leverage. After you’ve indicated your readiness to sign on the dotted line, it’s only natural for a vendor to agree to supply documents that may never come through, or come too late. Request that information while you’re still shopping around, since it won’t cost anything but an answer.

Include all relevant points in one brief email rather than touching on separate issues in three phone conversations. A list is much easier to address and much easier to compare if answers are provided by two vendors differently.

Make it clear from the get-go that a sample with the information stripped out is perfectly okay for your purposes. You don’t need the actual clients’ data; you need the layout, the requirements, and the structure of those documents.

Set a deadline, which should be between three and five business days, since the documents are supposed to be readily available.

And then just wait to see how they respond.

Before You Sign: The Security and Contract Pack

Your counsel will drive this layer, but a few points are worth raising yourself.

Certifications and attestations

Ask for your organization’s most recent SOC 2 Type II and ISO 27001:2022 certifications – the actual documentation, not an emblem on a webpage. SOC 2 Type II applies to an observation period that can range from a minimum of three months per AICPA requirements to a more conservative six months. For protected health information, SOC 2 does not apply.

Data protection and cross-border transfers

Regarding India’s DPDP Act: It was assented to in August 2023, and the Rules were issued in November 2025. The actual obligations come into effect till May 2027. Ask questions on readiness, not compliance. Regarding the EU data: There is no adequacy decision for India, which means the 2021 Standard Contractual Clauses and transfer impact assessment are required.

Contract terms your counsel owns

  • Clearly defining IP ownership, beyond the work-for-hire provision
  • The limitation of liability, and exceptions to that limitation
  • Protection of key personnel from secret replacement
  • Convenience termination clause, with notice period defined

This is general guidance, not legal advice.

What Should You Verify in the First 30 Days?

Ensure that the documents you have been shown are the documents being used.

The sample proves that the format exists. But it doesn’t mean that the format is implemented in your account. That’s the difference between the two. And there lies the point at which the majority of engagements silently turn into improvisation.

  • Week one: your scope document is drafted and approved, and access, tooling, and permissions are provided prior to starting the process rather than cobbled together after.
  • Week two: You receive a weekly report without requesting it. Otherwise, the rhythm has not been established yet. So let it be known early.
  • Week four: your first QA record has been created, and the overlap hours were sustained during a regular week, which included at least one day with an issue.

Voice out any gaps right now, when the relationship is fresh, and adjustments are still easy. Month one is the latest point at which process adjustment seems routine rather than confrontational.

Conclusion

None of these six documents is exotic; that’s the point. All partners who operate with structured delivery create these documents by default, meaning asking for them will cost a professional company nothing, but reveal an unprofessional one instantly.

What needs watching is the reaction time. A partner who delivers redacted copies of these documents in a few days reveals their business practices. A partner who needs two weeks is building a model for you, and it will not resemble their real practices.

Ask before signing. Once the contract is signed, you will ask your vendor to gain a practice that they did not have before, and this is usually a pointless discussion.

Six documents. One afternoon of review. This is the cheapest due diligence you can ever get.

At Skilligent, we run every engagement on exactly these artifacts, building dedicated technology talent and managed execution teams for US companies from Bangalore.

FAQs

1. What is a screening scorecard?

The Scorecard represents a standard form used to assess all the candidates on a set of criteria that are relevant for the specific job, with an explanation provided for every decision made. Thus, the hiring process becomes documentable, which is the essence of auditability by you.

2. How many of these documents should a vendor share before signing?

They would provide you with a redacted copy of all six of them. The client’s information is, of course, legitimate and confidential; however, the format and criteria are not.

3. What if a vendor refuses on confidentiality grounds?

Confidentiality will guard your information, not the document templates. A partner who cannot provide you with an empty SOP template or even a redacted weekly report does this because there isn’t any. Ask him to create one in a hypothetical scenario and see how much time he spends on that.

4. Is SOC 2 the same as ISO 27001?

No. SOC 2 is an attestation in America, where the auditor will attest to the effectiveness of controls within a period of time. ISO 27001, on the other hand, is an international certification, where the documentation of the security management system meets the standard. Both are requested by many customers, but none deal with health information.

5. Does India’s DPDP Act apply to my US company?

Maybe not directly, but it does apply to your delivery partner, and how compliant they are is what your liability is. The Act was passed in August 2023 with Rules notified in November 2025, and a runway till May 2027. Fines up to Rs 250 crore are applicable for non-compliance with security requirements.

6. Can I send EU customer data to a team in India?

Yes, with the right mechanism. As there is no EU adequacy decision for India, make sure that the 2021 SCCs are in place along with a transfer impact assessment. Make sure that your partner has implemented these documents rather than relying on their DPA for this.

7. What’s the difference between an EOR and a staffing partner?

The Employer of Record becomes the legitimate employer for the workforce that you control and thus helps you to avoid misclassification risks. The managed delivery model employs their own employees who deliver the services as per the scope of the agreement, and thereby helps you to mitigate the risk structurally. Direct engagement of the Indian contractors carries a high risk.

8. Why do offshore failure statistics vary so wildly?

Since most of the figures floating around out there are false. Commonly cited statistics, such as “64% of offshore joint ventures fail within the first year,” supposedly by Deloitte, do not exist in any of their published research findings. Make sure that any statistic used is from an actual study.

9. How much US-hours overlap is realistic from Bangalore?

4-6 hours is the norm and is sustainable, and usually spans the US morning and the Indian evening. Full US hours coverage is possible, but requires a change in both costing and the talent available. Know what you want, and get it in writing.

Share this insight

Need to talk it through?

Tell us what you’re building. We’ll help make the team model clear.

Start a conversation