WIRE OPENAn archive editionSEARCHARCHIVERSS
EST. 2000
UKTECH
THE IT-CONTRACTING & TAX RECORD
LATEST

The checks and balances of outsourcing

Recent discussion on UKTECH - and in the Channel 4 Dispatches programme - has highlighted concerns and breaches of security at Indian call centres or other off-shoring establishments. The National Outsourcing Association (NOA), which works in close conjunction with Indian trade bodies and the Indian government, is fully aware of how seriously Indian industry broaches the issue of data protection and security, and has offered the following opinions.

The NOA looks at the key issues around data security when offshoring to India and what UK companies should bear in mind when they offshore to other countries. It claims:

Indian workers are no less ethical than UK workers: It is important for people to remember that Indian employees are no less errant than employees in the UK or anywhere else. This story (Dispatches) is a question of morality and no matter how hard companies try, it is nigh on impossible to guarantee that every single employee is 100 per cent trustworthy, in the UK or in any other location.

Close management: Companies often make the mistake that once a process is offshored, minimal management is needed, but this isn't the case - because of the distance, increased management is required. This ensures that company procedures are adhered to in every location, not only in Indian locations.

India specific data protection: India is in the process of formalising its equivalent of the Data Protection Act but in the meantime, Indian companies (and other offshore locations) are falling over themselves in a bid to demonstrate compliance. Security breaches occur when a more lackadaisical approach is taken to management or whether you have employed an errant employee - this is as likely to happen in the UK as it is in any other destination. But since Indian call centre workers are paid much less than UK workers it could be argued there is more temptation, especially as the client sums that they may be dealing with are significantly higher than their pay.

Security at call centres: Most companies have strict security measures in place - they do not allow staff to take any writing implements in to their place of work so they cannot copy down sensitive information. In addition, storage devices such as cameras and iPods are banned. The data itself rarely leaves the UK - it is manipulated from India, making it much harder to gain access to a complete set of customer records. Also in addition to physical security, every supplier in this area is following standards like BS7799 to ensure that good operating procedures are in place. Call centre staff only have access to the information they need and do not have the technology at their fingertips to copy or send this information to unauthorised sources. Most offshore companies are aware of misgivings that UK companies may have over security and do their utmost to ensure that all the correct procedures are followed.

What's the NOA doing about it: "Apart from communicating the potential problems, our best practice guides advise companies to really understand the business reasons behind outsourcing/offshoring and the outcomes wanted (or not wanted). Again in this example one result of outsourcing that a financial institution doesn't want is for customer details to be leaked so it needs to ensure that precautions prevent it. The NOA is about to endorse the very first MBA covering outsourcing which will be based on our best practice principles, learning etc. This will ensure that future managers will have the benefits of this knowledge to apply for their organisations."

END OF ARTICLE ▪ FILED FROM LONDON