There was a time when business and IT service providers acted as ‘invisible vendors’. Not anymore.
A string of lawsuits in the past two to three years has put them in the legal spotlight over cybersecurity failures, labor violations, and governance lapses. From the TaskUs securities fraud case to the Cognizant H-1B discrimination verdict — it’s clear service providers are equal parties to violations as their enterprise clients.
What changed that let plaintiffs succeed with third-party beneficiary claims directly against BPOs are the facts and metrics, says Braden Perry, a regulatory and enforcement attorney. “The BPO agreements contain detailed data-protection clauses, which were a gift to potential plaintiffs, and where the vendor holds data for millions, then the plaintiffs will go after those deep pockets,” Perry, a litigation, regulatory, and government investigations attorney with Kansas City-based Kennyhertz Perry, told Nearshore Americas.
Data is essential across the entire value chain, from origination to consumption. So we need to strengthen the data foundation on every project. That’s not only the client’s responsibility — service providers have a responsibility to build a strong data foundation too. — Jose De La Ossa, CEO, Only AI & Nexgen

The TaskUs securities fraud lawsuit alleged the company misled investors by faking employee attrition data, inflating Glassdoor ratings, and leaving key business undisclosed. Though it didn’t admit to wrongdoing, the BPO provider settled the class action lawsuit for $17.5 million.
Jose De La Ossa, CEO of Colombia-based tech companies Only AI & Nexgen, shares a service provider’s view on the topic, saying the client alone can be responsible if such failures arise. “The volume of data produced every single day has grown exponentially because of AI. Data is essential across the entire value chain, from origination to consumption. So we need to strengthen the data foundation on every project. That’s not only the client’s responsibility — service providers have a responsibility to build a strong data foundation too,” Jose told Nearshore Americas.
The more significant development is that outsourcing providers increasingly perform functions carrying duties independent of the outsourcing agreement.
— Nick Rowles-Davies, Founder, Lexolent
Not just securities fraud, TaskUs also found its agents — bribed by cybercriminals — stealing sensitive data belonging to U.S.-based crypto firm Coinbase in India last year in January. The company laid off all 226 employees assigned to the client, but one of the crypto investors sued the BPO in a New York court.
Nick Rowles-Davies, a Dubai-based international litigation lawyer, believes less has changed in third-party-beneficiary doctrine than in the legal and operational position of the provider. “The more significant development is that outsourcing providers increasingly perform functions carrying duties independent of the outsourcing agreement,” Rowles-Davies, who is also the founder of Lexolent, which connects lawyers, litigation funders, and investors, told Nearshore Americas.

He points to the ongoing Conduent litigation — a cyberattack exposed sensitive health and personal data of 62.2 million individuals, triggering class action lawsuits — as an example. He cautions the present position should not be overstated, as those contract claims are allegations still being tested, not the final verdict that serves as a precedent. “Those contract claims are allegations still being tested, rather than an established ruling that every customer whose data passes through a provider becomes an intended beneficiary,” says Rowles-Davies.
Are Indemnifications Insufficient?
Though indemnification serves as a legal promise between a BPO service provider and the client in the event of any financial losses or legal disputes, can it stop third-party claims?
Rowles-Davis explains that an indemnity allocates responsibility between the parties to the outsourcing agreement and that it does not extinguish an independent claim brought by someone outside it. “An indemnity is a mechanism for allocating cost, not a grant of immunity from suit…the appropriate architecture is layered: carefully allocated indemnities and defense obligations; sensible liability caps and super-caps; parent guarantees, escrow or other credit support where counterparty risk is real; and insurance sized to the exposure actually carried.”
How can companies avoid lawsuits?
Besides TaskUs and Conduent, several other outsourcing providers have faced litigation, which goes beyond internal metrics manipulation and contractual obligations. Cognizant, for example, was found liable for intentional discrimination in an H-1B employment case that alleged it favoured Indian and South Asian employees. Teleperformance reported a breach in early December 2022. Around 2,631 people were affected. Infosys agreed to a $17.5 million settlement last year to resolve multiple lawsuits filed against its subsidiary, McCamish Systems (IMS), following a ransomware attack nearly two years ago.
This begs a question: how can outsourcing companies avoid becoming the primary defendant in future litigation?
Rowles-Davies argues that service providers should no longer think like subcontractors but principals with board-level accountability. “A provider facing direct legal duties must be governed as an operating principal with its own risk ownership, no longer as a subcontractor working to a client’s schedule. The board should assign identifiable ownership for data protection, employment, government-contract integrity, fraud prevention and public-company disclosure, with regular reporting based on independently tested information.”
Jose advises companies should leverage AI to incorporate HR compliance into workflows. “Identify your traditional compliance requirements, incorporate them into your workflows using AI, and create monitoring of those workflows using technology with humans in the loop. A lot of the current monitoring issues stem from the human-in-the-loop step not being used effectively.”





Add comment