What to look for in an outsourced team’s AI workflow before you commit 

What to look for in an outsourced team's AI workflow before you commit

Most conversations about outsourced teams follow a familiar checklist: who’s on the team, how they’re onboarded, what the reporting structure looks like, and what it costs. All good questions. 

But there’s one that’s easy to miss which is becoming increasingly important: how does the team use AI, and what happens to your data when they do? That is a question worth asking, because AI use inside a provider’s workflow now touches two things you’re directly exposed to – your data, and the quality of the work that reaches you. Here’s what to ask an outsourcing provider before you commit, and what the answers should sound like. 

Why data security should be at the top of your list   

AI adoption at work has outpaced the governance around it, and the numbers back that up clearly. Verizon’s 2026 Data Breach Investigations Report, covering more than 22,000 confirmed breaches across 145 countries, found that employees regularly using AI on work devices jumped from 15% to 45% in a single year. Two-thirds of them were using personal accounts rather than company-managed ones.  

Shadow AI – AI use that sits outside any approval process – is now the third most common non-malicious insider action in data loss records, a fourfold increase year on year. The most common data type uploaded to unauthorized AI tools is source code. 

That’s the picture even inside companies managing their own staff directly, on devices they control. With an outsourced team, that same visibility isn’t automatic – it’s something you have to build into the agreement from the start. 

Free accounts and business accounts are not the same thing 

Type something into a free or personal AI account and it may be used to train the model. Business versions of the same tools don’t do that – it’s written into the contract – and they give the company visibility over who’s using what. Same tool, same screen, completely different data handling. 

So “we use ChatGPT” tells you nothing by itself. “Our team uses ChatGPT Enterprise on company-managed accounts” tells you what you actually need to know. 

The four questions worth asking

The questionWhat a good answer sounds likeWhat should worry you
Which AI tools does your team use, and on what accounts? Named tools tied to specific tasks, on company-managed business accounts, with approval needed for anything new A vague reference to “using AI,” or no idea whether staff use personal accounts
What can and can’t your team put into them? Clear categories – what’s fine, what never goes in, and a written policy staff have been trained on A policy nobody has read, or no rules at all
Who reviews AI-assisted work before it reaches me? A named person accountable for output, with review as a fixed step in the process “Everyone checks their own work,” or review that disappears when deadlines tighten
How do you know AI is improving quality, not just speed? Both tracked, with figures they can show you – output volume alongside error and rework rates Only speed improvements, with nothing on whether accuracy held

Review is where this shows up in cost. AI produces work faster, so more work arrives needing checking. A provider who’s added review capacity to match will tell you so plainly. One who hasn’t tends to either skip the check or pass it to you. Analysis in late 2025 found roughly 1.7 times more issues in AI-assisted code where review wasn’t built in – a gap that shows up later as rework, or worse, as something that has already been made to production. 

On the fourth question, tracking only speed points to a workflow that hasn’t matured yet, not necessarily a problem. Either way, the answer tells you how developed the process is. 

You don’t need perfect answers to all four. A provider who can talk through each one specifically, without falling back on buzzwords, is describing something real. For more on where AI genuinely helps and where people still need to lead, we covered that in what clients should expect from AI-enabled dedicated teams

What to get in writing 

Three things are reasonable to ask for, and easy for a well-run provider to give. 

  • Ask to see their AI policy. If it arrives the same day, it’s a real document they use. If it takes a week to produce, it’s likely being written for you. 
  • Ask for a line in the contract covering how AI tools handle your data. Most confidentiality agreements were written before AI existed, so they don’t mention it at all. A specific clause closes that gap. 
  • Ask to be told if their approved tools change. A provider’s AI setup this quarter may not be what their team is using next quarter. A simple agreement to notify you means you’re not left guessing. 

What their process should look like 

Ask a provider to walk you through one piece of work from brief to delivery. A well-run workflow tends to look similar across disciplines. 

  • Someone owns the requirement. A person understands what’s needed, and what good looks like, before work starts. 
  • AI supports the work throughout. Ideation, research, first drafts, routine checks – wherever it speeds things up without weakening the output. 
  • A skilled person reviews and reshapes. Business context, judgment, and knowledge of your customers get applied here, because the AI has none of it. 
  • A named person signs off. Nothing reaches you without someone accountable for it. 

The two ends are what protect you. Someone owns the brief, someone owns what ships. A provider should be able to name both people on your account. 

One thing worth raising separately: client communication. Some teams now use AI to draft status reports and client emails. That’s not necessarily a problem, but it’s worth knowing, because it means the person sending you an update may not have written it themselves – and may know the details less well than the email suggests. 

Signs of a mature workflow, and signs of trouble 

Worth trusting Worth questioning
Names their tools and explains where each fits Talks about “leveraging AI” without specifics 
Company-managed business accounts, data excluded from training Can’t confirm whether staff use personal accounts 
Written policy staff have been trained on Policy on paper, unclear if anyone follows it 
Review is a fixed step with a named owner Review depends on individual habit 
Tracks quality alongside speed Only reports on speed 
Same approach across the whole team One enthusiast experimenting alone 
Tells you where AI falls short Claims AI handles everything well 

That last point is more telling than it looks. A provider willing to name where AI doesn’t help has actually tested it, rather than adopted it as a talking point. 

The questions that separate real workflows from good pitches 

By now every provider will tell you they use AI, so that’s not a useful signal anymore. What actually tells you something is whether they can show you their error rates, whether your data sits somewhere they can actually manage, who’s accountable when something goes wrong, and whether they’re willing to put any of it in writing. 

None of that takes long to find out. A ten-minute conversation, asked the right way, tells you almost everything you need to know. 

Once you’ve asked those questions, data security more broadly is worth a closer look. We’ve covered how cybersecurity and data privacy should factor into any outsourcing decision in cybersecurity and data privacy in outsourcing

Scroll to Top
// Script table set class last row