Does the time difference make an India team unworkable?
It is the first objection, and arithmetic answers it. India Standard Time is UTC+5:30 all year. The United States moves its clocks in March and November, so the gap changes twice a year.
| US region | India is ahead by (summer / winter) | A 8:00 to 10:00 local block, in India (summer) |
|---|---|---|
| Eastern | 9.5 / 10.5 hours | 5:30 pm to 7:30 pm |
| Central | 10.5 / 11.5 hours | 6:30 pm to 8:30 pm |
| Pacific | 12.5 / 13.5 hours | 8:30 pm to 10:30 pm |
The pattern is plain. A US morning is an Indian evening, so a shared block means someone on the India side works late, and good teams plan for that openly instead of pretending it is free. What the gap gives you in return is a day that continues while yours is closed: work finished during your night is waiting when you arrive, and the answers you give in your morning reach the team before their day ends.
What does a good daily rhythm look like?
Teams that work well across this gap use a simple pattern and keep to it.
- Fix the shared block. Two to two and a half hours, at the same time every day, with named people from both sides. Anything that needs a conversation goes here.
- Write the handover. At the end of the India day, a short note covers what was finished, what is blocked, what needs a decision and what comes next.
- Review in your first hour. Pull requests, designs and questions are reviewed early in your day, so the India team can act on them before theirs ends.
- Demo weekly. One live demonstration of working software at a fixed time, with the people who can approve or redirect the work.
- Keep an escalation path. A named engineer and a phone number for anything urgent, with a clear definition of what counts as urgent.
Pacific teams get a shorter block that sits late in the Indian evening. Some agree to start their own day a little early once or twice a week to ease it. A good partner tells you this before you sign.
Which contract documents do you need?
- Mutual NDA: signed before the first detailed conversation and covering both sides.
- Master services agreement (MSA): the framework terms for all work, including liability, termination, governing law and dispute resolution.
- Statement of work (SOW): one per phase, with scope, deliverables, acceptance criteria, team, timetable and fees.
- Intellectual property assignment: code, models, prompts, evaluation sets and documentation assigned to you, with any open source use disclosed.
- Data processing terms: who may touch which data, where it is stored, which sub-processors (including AI model providers) are used and what happens at the end.
- Business associate agreement: only where protected health information is involved and your counsel says one is needed.
Most US companies prefer their own paper and a US governing law, and that is a normal request. Have counsel review the final terms on both sides. This guide describes common practice and is not legal advice.
What security evidence should you ask for?
A vendor risk questionnaire is only as useful as the answers. Ask for specifics you can verify.
- A data flow diagram showing where each category of data enters, is stored, is processed and leaves.
- An access model: who can reach production and customer data, how access is granted and removed, and how it is logged.
- Secure development practice: code review rules, secrets handling, dependency scanning and how changes reach production.
- A sub-processor list, including the AI model providers used and what each is allowed to retain.
- An incident process: how problems are detected, who is told and how quickly.
- Honest statements about attestations. A SOC 2 report is issued by an independent auditor about a specific company. If a vendor cannot show one, ask which controls exist and whether they can be described in writing. Be wary of any claim of certification without a report behind it.
If your policy requires a particular attestation from every vendor, say so on the first call. That saves both sides weeks.
How should health data be handled?
HIPAA applies to covered entities and their business associates, and there is no official HIPAA certification for software vendors. For a project that touches protected health information, the practical questions are these.
- Can development and testing use de-identified or synthetic data?
- Does your counsel want a business associate agreement with the vendor, and with any AI model provider that sees the data?
- Where will data be stored and processed, and does the model provider's service suit your obligations?
- How is access logged, and who reviews the logs?
- What is deleted at the end of the engagement, and how is that shown?
A good partner designs for the minimum necessary data and says plainly what it can and cannot support. Final decisions belong to your compliance team and counsel.
Where do these engagements go wrong?
- No single owner on the US side. Decisions stall when three people each hold part of the answer.
- Chat-only handovers. Verbal agreements are forgotten. Written ones can be audited.
- Slow access. Waiting a week for repositories and cloud accounts wastes the first sprint, so provision access before kickoff.
- Vague acceptance criteria. Define what finished means in measurable terms before work starts.
- Skipping the pilot. A short paid pilot on real data shows how a team communicates and handles surprises before you commit more.
How should the first month run?
- Week 0: intro call, mutual NDA and a written proposal with draft MSA and SOW.
- Week 1: security pack delivered and reviewed, access provisioned, shared block and handover format agreed.
- Weeks 2 and 3: a working slice built on real data, the first weekly demo and a baseline to measure it against.
- Week 4: a review against the agreed measure, with a clear choice to continue, change direction or stop, and everything produced already yours.
You can see how this looks in practice on our AI development company page for US teams, try the live support agent demo, or start a conversation. If you are comparing vendors in more than one country, our guide to choosing an AI development company in India lists the questions to ask.