Skip to content
CorpshoreUS

Reference

BPO, IT and AI outsourcing glossary

Plain definitions for the terms that come up most in outsourcing contracts and vendor conversations, from pricing models and SLAs to compliance and AI terminology.

Outsourcing models and contracts

BPO (Business Process Outsourcing)
BPO is the practice of contracting a third-party provider to run a business function that a company would otherwise perform in-house, such as customer service, payroll or accounts payable. Providers typically deliver the service from their own facilities using their own staff, technology and processes. BPO contracts are usually priced per seat, per transaction or per outcome and run for a fixed term with renewal options.
KPO (Knowledge Process Outsourcing)
KPO is the outsourcing of work that requires specialized domain knowledge and judgment rather than routine, repeatable tasks. Examples include financial research, legal document review, actuarial analysis and market research. Because KPO work demands trained analysts and subject-matter expertise, it commands higher rates than standard BPO work and involves closer quality oversight.
ITO (IT Outsourcing)
ITO is the outsourcing of technology functions such as application development, infrastructure management, network administration or technical support to an external provider. Companies use ITO to access specialized skills, reduce fixed headcount or extend coverage across time zones. Scope can range from a single project to full management of a company's IT environment under a long-term contract.
Managed services
Managed services is a delivery model in which a provider takes ongoing responsibility for a defined set of functions or systems, typically under a recurring monthly fee rather than billing for individual tasks. The provider is accountable for outcomes such as system uptime, ticket resolution or process throughput, usually measured against agreed service levels. This model contrasts with staff augmentation, where the client directs the day-to-day work of the outsourced personnel.
Staff augmentation
Staff augmentation is a contracting model in which a provider supplies individual workers who join a client's team and are directed by the client's own managers, filling skill or capacity gaps on a temporary or ongoing basis. The client controls the work assignments and priorities, while the provider handles recruiting, employment and administration of the worker. It differs from a managed service, where the provider retains control over how the work gets done and is accountable for the result.
Dedicated team model
The dedicated team model is an outsourcing arrangement in which a provider assembles a fixed group of staff who work exclusively for one client on an ongoing basis, functioning much like an extension of the client's own department. The client typically sets priorities and direction while the provider handles hiring, HR, facilities and technology. This model suits long-term engagements where continuity and institutional knowledge matter more than short-term flexibility.
Nearshore outsourcing
Nearshore outsourcing means contracting work to a provider located in a nearby country, usually within the same or an adjacent time zone and a short flight away. Companies choose nearshore arrangements to keep close cultural and linguistic alignment, enable overlapping working hours for real-time collaboration and reduce travel time compared with offshore options. A US company outsourcing to a provider in Mexico, Colombia or the Dominican Republic is a typical example of nearshoring.
Offshore outsourcing
Offshore outsourcing means contracting work to a provider located in a distant country, often on a different continent and with little or no overlap in working hours. Companies pursue offshore arrangements primarily to access lower labor costs or specialized talent pools not readily available domestically. Common offshore destinations for US and European companies include India, the Philippines and parts of Eastern Europe.
Onshore outsourcing
Onshore outsourcing means contracting work to a provider located within the same country as the client, sometimes called domestic outsourcing. It eliminates time zone differences and language barriers and can simplify compliance with local labor and data regulations, though labor costs are typically higher than nearshore or offshore alternatives. Companies choose onshore outsourcing when regulatory requirements, data sensitivity or customer expectations call for domestic delivery.
RFP (Request for Proposal)
An RFP is a formal document a company issues to invite qualified vendors to submit competing proposals for a defined scope of work. It typically describes the business requirements, evaluation criteria, timeline and budget parameters, and asks vendors to respond with their approach, pricing and qualifications. Companies use the RFP process to compare vendors on a consistent basis before selecting a provider and negotiating a contract.

Pricing and commercial terms

SLA (Service Level Agreement)
An SLA is a contractual document that defines the specific, measurable level of service a provider commits to deliver, such as response times, resolution times, uptime percentages or accuracy rates. It typically sets targets, defines how performance is measured and reported and specifies remedies, such as service credits, when the provider falls short. SLAs give both parties a clear, objective standard for evaluating whether a service is being delivered as agreed.
KPI (Key Performance Indicator)
A KPI is a specific, quantifiable metric used to track how well a person, team or process is performing against a defined goal. In outsourcing contracts, KPIs are often tied to SLAs and cover measures such as first contact resolution, average handle time or customer satisfaction score. Choosing the right KPIs and tracking them consistently over time lets both client and provider see whether performance is improving, holding steady or declining.
FTE (Full-Time Equivalent)
An FTE is a unit of measure equal to one person working a standard full-time schedule, typically 40 hours a week in the United States. Outsourcing contracts often price and staff work in terms of FTEs, so that 2,000 hours of monthly work might be described as roughly 12.5 FTEs regardless of whether that work is done by full-time or part-time staff. The FTE measure makes it possible to compare staffing levels and costs consistently across contracts and providers.
Per-seat pricing
Per-seat pricing is a billing model in which the client pays a fixed fee for each staff member, workstation or software license assigned to its account, regardless of the volume of work completed. It gives the client predictable monthly costs and is common for dedicated team and staff augmentation arrangements. The tradeoff is that the client bears the cost of a seat even during slower periods, since the fee is not tied to output.
Outcome-based pricing
Outcome-based pricing ties provider compensation to the achievement of specific business results, such as resolved tickets, closed sales, successful loan collections or verified leads, rather than to hours worked or seats staffed. It shifts a portion of performance risk from the client to the provider and aligns incentives around results the client actually values. This model requires clear, measurable definitions of what counts as a qualifying outcome and reliable systems to track and verify it.
MSA (Master Service Agreement)
An MSA is the overarching contract between a client and a provider that establishes the general legal terms governing their relationship, such as payment terms, confidentiality, liability, intellectual property and termination rights. It is typically negotiated once and then remains in place while specific projects are added underneath it through separate statements of work. Using an MSA lets the two parties avoid renegotiating the same legal boilerplate every time they start a new project together.
SOW (Statement of Work)
A SOW is a document that defines the specific scope, deliverables, timeline, staffing and price for a particular project or engagement, typically executed under the umbrella of an existing MSA. It spells out what work will be done, who is responsible for what and how success will be measured, so both parties share a common understanding of the project before it starts. Companies often run multiple SOWs concurrently with the same provider under a single MSA.
TCO (Total Cost of Ownership)
TCO is the full cost of acquiring, operating and maintaining a service, system or solution over its useful life, not just its sticker price. For outsourcing decisions, TCO includes the contracted fees plus costs such as transition, management oversight, technology, training and any productivity loss during ramp-up. Comparing TCO rather than headline price alone gives a more accurate picture of whether outsourcing or an in-house alternative is actually less expensive.

Compliance and data security

HIPAA
HIPAA is the Health Insurance Portability and Accountability Act, a US federal law that sets national standards for protecting the privacy and security of individually identifiable health information. It applies to healthcare providers, health plans and their business associates, including outsourcing vendors that handle patient data on their behalf. Organizations covered by HIPAA must implement specific administrative, physical and technical safeguards and can face civil and criminal penalties for violations.
BAA (Business Associate Agreement)
A BAA is a legally required contract between a HIPAA-covered entity, such as a healthcare provider, and any vendor or business associate that will create, receive, maintain or transmit protected health information on its behalf. It obligates the business associate to safeguard that data using specified security measures, report breaches and limit its use of the information to the purposes stated in the agreement. Any outsourcing provider handling health information for a US healthcare client must sign a BAA before work begins.
PCI DSS
PCI DSS is the Payment Card Industry Data Security Standard, a set of technical and operational requirements established by the major card networks to protect cardholder data during processing, storage and transmission. It applies to any organization, including outsourcing providers, that stores, processes or transmits credit or debit card information. Compliance is validated through periodic assessments and is typically required by contract before a company can outsource payment-related functions.
CCPA
The CCPA is the California Consumer Privacy Act, a state law that gives California residents specific rights over their personal information, including the right to know what data a business collects, to request its deletion and to opt out of its sale. It applies to qualifying businesses regardless of where they are headquartered, as long as they collect data from California residents, which extends its reach to outsourcing providers processing that data on a client's behalf. Amended and expanded by the California Privacy Rights Act, it is often used as a reference standard for US state-level privacy compliance.
GDPR
GDPR is the General Data Protection Regulation, the European Union's comprehensive data privacy law that governs how organizations collect, process and store the personal data of people in the EU. It applies to any company handling that data regardless of where the company itself is located, which means US-based outsourcing providers serving European clients or processing EU resident data must comply as well. GDPR requires a documented legal basis for processing, defined data subject rights and specific contractual terms between data controllers and data processors, and it carries substantial fines for noncompliance.
SOC 2
SOC 2 is an auditing standard developed by the American Institute of CPAs that evaluates a service organization's controls related to security, availability, processing integrity, confidentiality and privacy. An independent auditor examines the provider's systems and processes and issues a report, either a Type I snapshot at a point in time or a Type II report covering effectiveness over a period, usually six to twelve months. Clients commonly request a current SOC 2 report before entrusting a provider with sensitive data or critical systems.
PHI (Protected Health Information)
PHI is individually identifiable health information, such as medical records, diagnoses, treatment history or billing details, that is created, received or maintained by a HIPAA-covered entity or its business associate. It includes any of eighteen specific identifiers, such as name, address or medical record number, combined with health-related data. Outsourcing providers that handle PHI must apply HIPAA's required safeguards and are bound by the terms of a signed BAA.
PII (Personally Identifiable Information)
PII is any information that can be used, alone or combined with other data, to identify a specific individual, such as a name, Social Security number, address, email address or account number. It is a broader category than PHI and is the subject of most general data protection laws, including the CCPA and GDPR. Outsourcing contracts that involve handling customer PII typically require specific data protection clauses, access controls and breach notification obligations.
Least-privilege access
Least-privilege access is a security principle under which a user, system or process is granted only the minimum level of access needed to perform its assigned function, and no more. In an outsourcing context, this means an agent handling billing inquiries might see account balances but not full payment card numbers, and access is reviewed and revoked promptly when it is no longer needed. Applying least privilege limits the damage a compromised account or an insider can cause and is a common requirement in compliance frameworks such as SOC 2 and PCI DSS.
Data residency
Data residency refers to the physical or geographic location where an organization's data is stored, and the legal jurisdiction that governs it as a result. Some laws and client contracts require that certain categories of data, such as health records or government data, remain stored within a specific country or region and not be transferred elsewhere. Outsourcing providers operating across multiple countries need to know exactly where client data physically sits and which storage locations are permitted under each client's contract and applicable law.

Customer operations

CSAT (Customer Satisfaction Score)
CSAT is a metric that measures how satisfied a customer was with a specific interaction, product or service, usually collected through a short post-interaction survey asking the customer to rate their experience on a numeric scale. The score is typically reported as the percentage of respondents who gave a positive rating. CSAT is one of the most common metrics used to evaluate frontline customer service quality on a transaction-by-transaction basis.
NPS (Net Promoter Score)
NPS is a metric that gauges overall customer loyalty by asking how likely a customer is to recommend a company to others, on a scale of zero to ten. Respondents are grouped into promoters, passives and detractors based on their score, and the NPS is calculated by subtracting the percentage of detractors from the percentage of promoters. Unlike CSAT, which measures satisfaction with a single interaction, NPS reflects a customer's broader relationship with a brand.
First response time
First response time is the amount of time that elapses between when a customer submits a request, such as an email, chat message or support ticket, and when they receive their first reply from a live agent or automated acknowledgment. It is tracked as a core service metric because customers generally judge service quality in part by how quickly their inquiry is acknowledged, even before it is fully resolved. First response time targets are commonly written into SLAs, with separate thresholds for different channels or priority levels.
AHT (Average Handle Time)
AHT is the average amount of time an agent spends on a customer interaction from start to finish, including talk time, hold time and any after-call work needed to close out the case. It is one of the primary efficiency metrics in contact center operations and is used for staffing and capacity planning. A lower AHT generally indicates faster service, but providers monitor it alongside quality and resolution metrics so that speed does not come at the expense of a properly handled case.
FCR (First Contact Resolution)
FCR is the percentage of customer inquiries that are fully resolved during the customer's first contact, without the need for a follow-up interaction, transfer or escalation. It is widely regarded as an important indicator of customer service quality because unresolved issues that require repeat contact tend to lower satisfaction and increase overall handling cost. Contact centers track FCR closely and often set it as a key SLA metric alongside AHT and CSAT.
Omnichannel support
Omnichannel support is a customer service approach in which phone, email, chat, social media and messaging channels are integrated so that a customer's history and context carry over no matter which channel they use or switch between. This differs from a multichannel setup, where each channel may operate as a separate, disconnected system. Omnichannel support typically relies on a unified customer relationship management platform that gives agents a single view of every prior interaction, regardless of the channel it happened on.
IVR (Interactive Voice Response)
IVR is an automated telephone system that interacts with callers through recorded prompts and either voice or keypad input, routing them to the right department, agent or self-service option before a human agent gets involved. It is commonly used to triage call volume, collect basic information such as an account number and let callers complete simple tasks like checking a balance without waiting for an agent. A well-designed IVR reduces call center workload, while a poorly designed one is a frequent source of customer frustration.
QA scorecard
A QA scorecard is a standardized checklist used to evaluate the quality of an individual customer interaction, typically covering criteria such as accuracy of information given, adherence to script or process, tone, compliance with regulatory requirements and problem resolution. A quality analyst listens to or reads a sample of interactions and scores each one against the checklist, producing a quantifiable quality rating for the agent and the team. Scorecard results feed into coaching, performance reviews and, in many outsourcing contracts, the SLA metrics reported to the client.

IT and cloud operations

DevOps
DevOps is a set of practices and a cultural approach that combines software development and IT operations teams to shorten the software delivery cycle and improve the reliability of releases. It relies heavily on automation, continuous integration and delivery and close collaboration between developers and operations staff who might otherwise work in separate silos. Organizations adopt DevOps to ship changes more frequently while reducing the risk and manual effort involved in each release.
SRE (Site Reliability Engineering)
SRE is a discipline that applies software engineering practices to IT operations problems, with the goal of building and running large-scale systems that are reliable, scalable and efficient to operate. SRE teams typically define reliability targets, such as service level objectives and error budgets, and use automation to reduce manual, repetitive operational work. The discipline originated at Google and has since become a standard approach to running production systems across the technology industry.
CI/CD (Continuous Integration/Continuous Delivery)
CI/CD refers to a pair of related practices that automate how code changes move from a developer's machine into production. Continuous integration means developers merge code changes into a shared repository frequently, with automated builds and tests running on every change to catch problems early. Continuous delivery, or continuous deployment, extends this by automating the release of validated code to staging or production environments, reducing the manual steps and delay between writing code and shipping it.
Infrastructure as code
Infrastructure as code is the practice of defining and managing IT infrastructure, such as servers, networks and storage, through machine-readable configuration files rather than manual setup through a control panel or command line. These configuration files are version-controlled and can be reviewed, tested and reused the same way application code is, which makes infrastructure changes repeatable and auditable. It is a foundational practice for managing cloud environments at scale and is closely associated with DevOps and CI/CD workflows.
Managed IT services
Managed IT services is an arrangement in which a provider takes ongoing, proactive responsibility for a client's IT systems, such as networks, servers, endpoints and security monitoring, typically for a fixed monthly fee. Rather than billing per incident, the provider is expected to monitor systems continuously, apply patches and updates and resolve problems before they cause significant disruption. This model is common among small and mid-sized businesses that need enterprise-grade IT support without maintaining a large internal IT department.
Help desk tiers (L1, L2, L3)
Help desk tiers describe a layered structure for handling technical support requests based on complexity. Level 1, or L1, handles basic, well-documented issues and initial triage; Level 2, or L2, handles more technical problems that L1 cannot resolve and requires deeper product or system knowledge; Level 3, or L3, involves specialists or engineers who address the most complex issues, including bugs and system-level problems. Tickets escalate upward through the tiers only when the current level cannot resolve them, which keeps routine issues from consuming the time of the most specialized staff.
Uptime SLA
An uptime SLA is a service level agreement that commits a provider to keeping a system or service available and operational for a specified percentage of time, commonly expressed in figures such as 99.9 percent. The agreement also defines how downtime is measured, which outages are excluded, such as planned maintenance, and what remedy the client receives, usually a service credit, if the target is missed. Even small differences in the stated percentage translate into meaningfully different amounts of allowable downtime over a year.
Incident response
Incident response is the structured process an organization follows to detect, contain, resolve and learn from an IT security or operational incident, such as a data breach, service outage or malware infection. A typical incident response plan defines roles and responsibilities, communication procedures, containment and remediation steps and a post-incident review to prevent recurrence. Having a documented and tested incident response plan is often a requirement in compliance frameworks such as SOC 2 and in client contracts involving sensitive data.
Cloud migration
Cloud migration is the process of moving an organization's data, applications and IT workloads from on-premises infrastructure, or from one cloud provider, to a cloud computing environment. It can involve a straightforward lift-and-shift of existing systems with minimal changes, or a more involved re-architecting of applications to take advantage of cloud-native features. Migrations are typically planned in phases to manage risk, minimize downtime and validate that performance, security and cost expectations are met at each step.
Observability
Observability is the ability to understand the internal state of a complex system based on the data it produces externally, typically through logs, metrics and traces. Unlike traditional monitoring, which checks predefined indicators for known problems, observability is meant to help teams investigate and diagnose issues they had not anticipated in advance. Modern IT operations rely on observability tooling to detect problems early, understand root causes and reduce the time it takes to resolve an incident.

AI and data

Data annotation
Data annotation is the process of adding labels, tags or descriptive metadata to raw data, such as images, text or audio, so that a machine learning model can learn from it. Common examples include drawing bounding boxes around objects in an image, tagging the sentiment of a piece of text or transcribing spoken audio. Accurate annotation is a prerequisite for training a reliable model, since the model can only learn patterns that are correctly represented in the labeled data it is given.
RLHF (Reinforcement Learning from Human Feedback)
RLHF is a training technique used to align a machine learning model's behavior with human preferences by incorporating human judgments directly into the training process. Human reviewers typically rank or rate different model outputs for the same prompt, and that feedback is used to train a reward model that guides further training of the main model through reinforcement learning. RLHF is widely used in training large language models to produce responses that people find more helpful, accurate or appropriate.
LLM (Large Language Model)
An LLM is a machine learning model trained on large volumes of text data to understand and generate human language. LLMs are built on neural network architectures, most commonly the transformer, and can perform a wide range of language tasks such as answering questions, summarizing documents, translating text and writing code, often without task-specific training. LLMs form the technical foundation behind most modern conversational AI assistants and generative AI applications.
Model evaluation
Model evaluation is the process of measuring how well a machine learning model performs against defined metrics and test cases before or after it is deployed. Depending on the task, evaluation might measure accuracy, precision, recall, latency or how often a model produces an incorrect or unwanted output. Evaluation is typically run on a held-out data set the model has not seen during training, and it is repeated whenever the model, its training data or its intended use case changes.
Ground truth
Ground truth is the accurate, verified data used as the reference standard against which a machine learning model's output is measured. It is typically established by human experts or through a trusted, independently verified source, such as confirmed diagnoses in a medical data set or manually verified labels in an image data set. The quality of ground truth data directly limits how accurately a model's performance can be measured, since a model cannot be reliably scored against a reference that is itself wrong or inconsistent.
Human-in-the-loop
Human-in-the-loop is a design approach in which a person reviews, corrects or approves a machine learning system's output at one or more points in its workflow, rather than letting the system operate fully on its own. It is commonly used in cases where errors carry high consequences, such as content moderation, medical diagnosis support or fraud detection, and it can also feed corrected examples back into the system to improve future performance. The degree of human involvement can range from reviewing every output to spot-checking only a sample or intervening only when the system flags low confidence.
Data labeling pipeline
A data labeling pipeline is the end-to-end workflow and infrastructure used to move raw data through collection, annotation, quality review and delivery in a format ready for model training. It typically includes task distribution to annotators, tooling for the annotation work itself, quality checks such as consensus scoring or spot audits and a system for tracking labeling progress and cost. A well-run pipeline is designed to produce consistent, high-quality labels at the volume and speed a model training project requires.
Fine-tuning
Fine-tuning is the process of taking a pre-trained machine learning model and continuing its training on a smaller, more specific data set to adapt it to a particular task, domain or style. It allows an organization to customize a general-purpose model, such as a large language model, for a narrower use case without the cost and time required to train a model from scratch. Fine-tuning typically requires a curated, high-quality data set that reflects the target task closely, since the model will learn whatever patterns that data contains.
Inter-rater reliability
Inter-rater reliability is a measure of how consistently different human reviewers or annotators agree when independently evaluating or labeling the same data. It is calculated using statistical measures such as Cohen's kappa or percent agreement and is used to check whether labeling instructions are clear enough to produce consistent results across a team. Low inter-rater reliability usually signals that task guidelines need to be clarified or that additional annotator training is needed before the resulting labels can be trusted as ground truth.
Hallucination (in AI)
Hallucination, in the context of AI, refers to when a model generates output that is factually incorrect, fabricated or unsupported by its source data, while still presenting it in a confident, plausible-sounding way. It is a known limitation of large language models, which generate text by predicting statistically likely sequences of words rather than by verifying facts against a trusted source. Reducing hallucination typically involves techniques such as grounding model output in verified reference documents, human review of outputs and clear evaluation processes that measure factual accuracy.

Build your team with Corpshore US

Tell us what you want to outsource and we will map a team, a model and a timeline. North American accountability, global delivery.

We respond to every US inquiry within 6 hours.