GCCs & IT services in India · data and AI

From cost centre to an intelligent, AI-native capability centre.

Parents now ask their India centres to own outcomes, not headcount. Ticket and transaction volumes outgrow teams, talent is contested in every tech hub, controls are tested by clients and auditors, and the DPDP Act raises the bar on personal data. The answer runs across everything a capability centre does — from the service desk to finance, HR and the AI CoE. DaasLabs is the data and AI services team that helps GCCs and IT service providers make that shift, one domain at a time.

8
Domains, from the service desk to audit
32
Data & AI opportunities mapped on this page
9
DaasLabs service lines, mapped to those domains
6
ML models in our ITSM intelligence platform
Request → decisionIllustrative
Global capability centresCaptive centres of multinationals in Bengaluru, Hyderabad, Pune, Chennai and NCR, moving from cost arbitrage to owning products, platforms and outcomes.
IT & BPM service providersIndian IT services, BPM and KPO firms running service desks, infrastructure, applications and back offices for clients under contractual SLAs.
Enterprise IT & shared servicesInternal IT and shared-service centres of Indian and global enterprises: ITSM, access governance, finance and HR operations.
The story in six chapters

How a capability centre becomes AI-native — and where each part of this site fits

Chapter 1 · The pressure

Seven forces reshaping the capability centre

Capability centres organised around queues — a service desk, an infrastructure tower, a finance back office — are now judged on outcomes across all of them. The centres pulling ahead treat data as a product and AI as an operating capability, not a set of pilots. These are the pressures they are responding to.

Value

From cost arbitrage to capability

Wage inflation in India's tech hubs erodes pure labour arbitrage. Parents expect their centres to own products, platforms and outcomes — and to prove it in numbers the head office trusts.

Data & AI: a GCC value scorecard, a governed use-case pipeline and agents that take routine work out of every tower.

Talent

Every centre competes for the same people

AI, cloud and security skills are contested across Bengaluru, Hyderabad, Pune, Chennai and NCR. When experienced engineers leave, the knowledge of how things are really fixed leaves with them.

Data & AI: knowledge bases and runbooks that capture the fix, copilots for new joiners, and attrition signals for managers.

Volume

Volumes outgrow the teams

Tickets, alerts, invoices and access requests grow with every business unit the centre takes on. Most of the effort still goes on triage, lookup and hand-offs rather than on the fix.

Data & AI: classification, routing and duplicate detection, with agents that draft the resolution for a person to approve.

Controls

SLAs and controls that look green but aren't

Tickets paused without customer contact, bulk closures before month-end, changes that skip the CAB, leavers whose access lingers. Sample-based audits find them months later, if at all.

Data & AI: SLA-integrity analysis and continuous ITGC testing on all the data, with explainable findings.

Regulation

Privacy and security obligations compound

The Digital Personal Data Protection Act, CERT-In's incident-reporting directions, client contracts and the parent's SOX and ISO 27001 controls all ask for traceable data about who did what, and when.

Data & AI: lineage and access evidence behind every control, and personal data handled with purpose and consent built in.

Technology

Tool sprawl inherited from every parent

Each business unit brings its own ITSM tool, monitoring stack, ERP and HRMS. Every new report, model or agent starts with another integration — and none of them agree on who owns what.

Data & AI: one governed data fabric over the existing tools, and APIs turned into governed tools that agents can call.

Governance

Agents with the keys to production

An agent that can create users, restart services or post journals is powerful and risky. Parents and clients expect an inventory, autonomy limits, human approval and an audit trail behind every action.

Data & AI: agent governance — autonomy levels, approvals, execution logs and a kill switch.

See agent governance
So what

Every pressure lands somewhere on the value chain.

The response isn't one platform or one model — it is data and AI applied domain by domain, from the service desk to the audit committee, on a shared, governed foundation.

See where, domain by domain ↓
Chapter 2 · The value chain

Where data and AI pay back across the capability centre

Run IT, build and secure, the business services the centre delivers to the parent, and the capability and control functions on top — the same chain for a captive GCC, an IT services provider or an enterprise shared-service centre, with different emphasis. Select a domain to see the data it runs on, the AI opportunities, and how DaasLabs adds value there.

Domain 1 of 8

IT service management & service desk

Ticket volumes grow faster than the service desk. The same incidents come back under new numbers, SLAs are breached before anyone sees the risk, and engineers spend their day triaging rather than fixing.

Data it runs on

ITSM tickets & commentsIncident, problem & change recordsSLA clocks & pause reasonsKnowledge base & runbooksEngineer rosters & skillsChat, email & portal requests

Data & AI opportunities

  • Ticket classification, routing and duplicate detection
  • SLA-breach risk scoring before the clock runs out
  • Recurring-issue clusters turned into problem records
  • Copilot that answers "why are we breaching?" with the evidence

How DaasLabs adds value

  • One ticket, SLA and knowledge model across every ITSM tool the parent uses
  • Agents draft the triage and the fix; engineers approve and resolve
  • Every reroute, pause and closure logged for client and auditor review
Domain 2 of 8

Infrastructure, cloud & AIOps

Alerts from monitoring, cloud and network tools arrive by the thousand, most of them noise. Cloud spend is reported a month late, and the on-call engineer correlates events by hand at 3 a.m.

Data it runs on

Monitoring & observability alertsLogs & eventsCMDB & service mapsCloud billing & usageChange calendarCapacity & performance metrics

Data & AI opportunities

  • Event correlation and alert-noise reduction
  • Probable-cause suggestions from change history and service maps
  • Incident forecasting for staffing and capacity
  • Cloud cost and idle-resource analytics (FinOps)

How DaasLabs adds value

  • Logs, events, CMDB and tickets joined on one governed fabric
  • Runbook steps drafted by agents; production changes always approved by a person
  • Forecasts the delivery head can staff against
Domain 3 of 8

Application & product engineering

Product and platform teams in India now own whole products for the parent, not tickets. Release quality, test coverage and engineering productivity are judged globally, and AI coding tools arrive faster than the guardrails around them.

Data it runs on

Code repositories & pull requestsCI/CD pipelines & releasesTest results & defectsBacklogs & sprint dataAPI cataloguesArchitecture & design documents

Data & AI opportunities

  • Engineering-productivity and flow metrics across teams
  • Test-case generation and defect triage with GenAI
  • APIs turned into governed tools for AI agents
  • Release-risk scoring from change and defect history

How DaasLabs adds value

  • A delivery data product joining repos, pipelines and defects
  • AI assistants inside the guardrails your parent and clients require
  • Engineers decide what ships; agents prepare the evidence
Domain 4 of 8

Cyber security & access governance

Joiners, movers and leavers are handled through tickets and spreadsheets. Access lingers after people leave, privileged accounts multiply, and security incidents must be reported to CERT-In and to the parent quickly, with evidence.

Data it runs on

Identity & directory dataHRMS joiner / mover / leaver eventsAccess requests & approvalsPrivileged-access logsSecurity alerts & incidentsVulnerability scans

Data & AI opportunities

  • Joiner / leaver reconciliation between HRMS and directories
  • Access-request provisioning with approvals and audit trail
  • Security-alert triage and incident timelines
  • Access-review campaigns prepared for the reviewer

How DaasLabs adds value

  • One identity view across HR, directory and applications
  • Agents provision only after a named approver signs off
  • Evidence for every grant and revocation, ready for the auditor
Domain 5 of 8

Finance & accounting shared services

Record-to-report, procure-to-pay and order-to-cash run for many entities and ERPs at once. Reconciliations, vendor queries and month-end commentary still consume the teams, and the parent expects a faster, cleaner close.

Data it runs on

ERP ledgers (SAP, Oracle)Bank & intercompany statementsVendor invoices & POsCustomer receipts & disputesClose checklistsGST & TDS records

Data & AI opportunities

  • Auto-matching and break investigation across entities
  • Invoice capture and three-way match with exceptions explained
  • Month-end variance commentary drafted by AI
  • Vendor and customer query handling

How DaasLabs adds value

  • Reconciliation, close, FP&A and commentary accelerators configured for multi-entity shared services
  • Agents draft entries and commentary; controllers approve
  • Lineage from source document to the parent's consolidation
Domain 6 of 8

HR & people operations

GCCs compete for the same engineers across Bengaluru, Hyderabad, Pune, Chennai and NCR. Hiring, onboarding and access set-up are slow, attrition signals arrive at the exit interview, and skills data is out of date.

Data it runs on

HRMS & payrollRecruitment pipelineOnboarding & offboarding tasksSkills & certificationsEngagement surveysEmployee helpdesk tickets

Data & AI opportunities

  • Onboarding orchestration: accounts, assets and access on day one
  • Attrition-risk signals from engagement and workload
  • Skills inventory and internal-mobility matching
  • Employee helpdesk answered from policy, with sources

How DaasLabs adds value

  • HR, IT and access data joined so a joiner is productive on day one
  • People decisions stay with managers and HR; agents prepare them
  • Personal data handled under the DPDP Act with purpose and consent
Domain 7 of 8

Data, analytics & AI CoE

Parents ask their India centre to lead AI, not just support it. Use cases multiply across business units, but data access, model risk and value tracking are handled differently by every team.

Data it runs on

Enterprise data platformsUse-case and value pipelineModel and agent inventoryBusiness-unit KPIsData access requestsCost and capacity data

Data & AI opportunities

  • A governed use-case pipeline from idea to measured value
  • Model and agent inventory with evaluations
  • Self-service analytics and natural-language query
  • GCC value scorecard for the parent: cost, capability and outcomes

How DaasLabs adds value

  • A maturity baseline and roadmap the parent and the GCC agree on
  • Shared platforms so each business unit doesn't start from zero
  • Value tracked from business case to realised benefit
Domain 8 of 8

Governance, risk & audit

Client contracts, SOX IT general controls, ISO 27001 and the DPDP Act all ask for proof. SLA figures can be gamed, changes bypass the CAB, and leavers keep access — and each finding is usually discovered by an auditor, months later.

Data it runs on

ITSM & change logsAccess and HR recordsControl libraries (SOX ITGC, ISO 27001)Client contract & SLA termsAudit findings & actionsPolicy & risk registers

Data & AI opportunities

  • SLA-integrity analysis: pauses and closures that hide true breaches
  • Continuous ITGC testing: CAB bypass, terminated-user access
  • Explainable findings with the reasoning chain behind each
  • Control diary of observations, tests and remediation

How DaasLabs adds value

  • Controls tested on all the data, not a sample
  • Findings routed to a named owner with a remediation date
  • Audit-ready evidence for parent, client and regulator

Opportunities and approaches are described qualitatively. Shaded chips are DaasLabs service lines; the others open accelerators. See every service line mapped to these eight domains

DaasLabs in short

A data and AI services team for capability centres — with its own IP

Nine service lines that advise, build, transform and run — delivered on three pieces of DaasLabs IP, so GCCs and IT service providers start from working components rather than a blank page.

Chapter 5 preview · Our supervised digital workforce

How agentic operations work

In our access-provisioning squad, a queue monitor reads the request, a bot does the work in the target system and a notifier closes the loop — but only after a named approver signs off. Every step lands in the execution log.

A new joiner needs access From our build
MONITOR · REQUEST CLASSIFIED
APPROVE · NAMED OWNER
PROVISION · RPA BOT
NOTIFY · TICKET CLOSED
People approve every grant

The queue agent uses an LLM to read the ticket and extract the user, role and permissions. The request waits in a human-in-the-loop approval queue; once approved, the bot creates the user and assigns permissions, and the notifier emails the requester.

See the GCC agent squads
  1. Step 1
    Agents do the work

    Agents read tickets, logs, ledgers and HR events on the governed Data Fabric — the same data your engineers and analysts use.

  2. Step 2
    Policy & autonomy decide

    Each agent has an autonomy level. Anything that touches access, production or a ledger waits for a named approver.

  3. Step 3
    People approve exceptions

    The approver sees the agent's draft, the evidence and the reasoning — approve, edit or reject in one place.

  4. Step 4
    Logged & evaluated

    Every task, tool call and decision lands in the execution log; overrides feed evaluation, and a kill switch halts all agents.

Accelerators

Accelerators, by the service they speed up

Platforms we have built for IT operations, service management and audit, generalised into configurable starting points — plus cross-industry accelerators our teams configure for finance and controls in shared services.

Transform · GCC head, CIO, CISO

GCC & IT services accelerators

Built on a real ITSM estate for an enterprise IT function; each runs on the Data Fabric Framework.

About our Transform services
ITSM Intelligence Platform
Accelerator · Copilot, incidents & predictive SLA

A conversational copilot, full incident lifecycle, executive operations centre, SLA monitor, recurring-issue and ticket-pattern analysis, knowledge base and runbooks — over the ITSM tool you already run.

ML models
Anomaly detectionSLA-breach riskIncident forecast
Covers 6 ML models • 8 copilot intents
SLA Integrity & Audit Intelligence
Accelerator · SLA gaming, ITGC tests & explainable findings

Finds pauses and closures that hide true SLA breaches, tests IT general controls such as CAB approval and leaver access on all the data, explains each finding with its reasoning chain and tracks remediation in a control diary.

Investigation
DetectRoot causeOwnerRemediate
Covers 5-step AI-narrated investigation • 3-level RCA
Access Provisioning Squad
Accelerator · Agents + RPA with human approval

A queue-monitor agent reads access requests with an LLM, an RPA bot creates users and assigns permissions in the target system, and a notification agent closes the loop — orchestrated, approved and logged end to end.

Agent squad
Queue MonitorRPA Provisioning BotNotifier
Covers 3 cooperating agents • approvals & execution logs

Cross-industry accelerators below are configured for shared-services data in an engagement; their demo pages run on banking sample data.

Proof

Built for IT operations, service management and audit

A client result from a finance shared-services engagement, and platforms we have built on a real ITSM estate. Client names are withheld; apart from the card-issuer result, the figures are counts from those builds, not client results. Read the case study.

200+
Regulatory reports automated for a global card issuer's India operations — zero compliance penalties since implementation
6
ML models in the ITSM platform: anomalies, forecasts, resolution time, SLA risk, recurring issues, bottlenecks
5
Steps in the AI-narrated SLA-integrity investigation, detection to remediation
3
Cooperating agents in the access-provisioning squad, with human approval
IT service management · Gulf real-estate group's IT function
ITSM intelligence on the existing tool

Copilot, incident lifecycle, operations centre, SLA monitor and recurring-issue analysis over the group's tickets, engineers and SLAs.

Predictive, explainable service management
Audit & GRC · Same IT function
SLA-integrity investigation

Detection of ticket pauses and closures that mask true SLA breaches, narrated step by step by Azure OpenAI with a three-level root-cause analysis.

From hidden pause hours to true SLA performance
IT controls · Same IT function
Continuous ITGC testing

Change-management and user-access control tests run on all the data, with explainable findings and a control diary of observations, tests and actions.

Findings with the reasoning behind them
Access governance · Same IT function
Agentic access provisioning

Queue-monitor, RPA provisioning and notification agents creating users and assigning permissions in an HR system, with approvals and execution logs.

Human-in-the-loop by design
Finance shared services · Global card issuer's India operations
Finance automation through a US-to-India migration

25 critical finance processes reconfigured for a data-centre move to India, with finance workflows automated end to end through data integration.

200+ reports automated · zero penalties · paid for itself in a year
Also built
More for capability centres
  • MCP Studio: APIs turned into governed agent tools
  • Helios agentic programme management
  • RFP & bid response agents for an IT services sales team
  • Enterprise GenAI chat with RBAC / ABAC on Azure AKS
  • 17-layer LLM security framework & guardrails
  • Risk & RegTech explorer with knowledge graph for a global IT consultancy
  • Data governance platform & DAMA CDMP data-literacy programme
Case study
Finance shared servicesEnterprise IT functionIT services & consulting

Delivered for IT operations, service management and audit

Finance automation for a global card issuer's India operations, an intelligence layer on a real ITSM estate — the IT function of a Gulf real-estate group, with its tickets, engineers, SLAs, change records and HR system — and agent, bid and programme-management platforms we have built for IT services teams. Different problems, the same pattern: govern the data, let agents do the routine work, and keep a person on every decision that matters.

200+
Regulatory reports automated for a global card issuer's India operations, with zero compliance penalties since implementation
6
ML models on live ticket data: anomalies, forecasts, resolution time, SLA risk, recurring issues, bottlenecks
3
Cooperating agents provisioning access, behind a human approval queue
17
Defence layers in our LLM security framework for GenAI applications

The card-issuer figures are client results from our published case study. The other figures are counts from the platforms as built; their demonstration data is the client's or sample data, so we show capabilities rather than results.

Platform 01 · Finance shared services

Finance data automation

Global card issuer's India operations · data-centre migration from the US to India

The challenge

A migration to India under strict regulatory timelines.

  • 25 critical finance processes to reconfigure for the move
  • Strict regulatory reporting timelines
  • Month-end close taking 12+ days, with 30+ staff on overtime

What we built

One finance data ecosystem, end to end.

  • End-to-end automation of finance workflows through data integration
  • Source-to-target data flows mapped, ETL configured
  • A unified finance data ecosystem
  • Reporting continuity through the transition
200+Regulatory reports, 100% automated
ZeroCompliance penalties since implementation
HoursRegulatory updates, from weeks

“The ROI calculation was simple: [it] paid for itself in one year just in avoided overtime costs.” — Finance Automation Head

Platform 02 · IT service management

ITSM Intelligence Platform

Gulf real-estate group's IT function · existing ITSM tool, engineers and SLAs

The challenge

The service desk reacted; nobody saw the breach coming.

  • The same issues returning under new ticket numbers
  • SLA breaches discovered after the fact
  • Workload and bottlenecks invisible by team
  • Questions answered by exporting spreadsheets

What we built

Predictive, conversational service management.

  • Copilot: "why are we breaching SLAs?", with actions to execute
  • Incident lifecycle: create, assign, resolve, close, with SLA clocks
  • Executive operations centre with live KPIs
  • Isolation-forest anomalies, incident forecasts and SLA-breach risk
6ML models
8Copilot intents
LiveOperations centre
Platform 03 · Audit & assurance

SLA Integrity & Audit Intelligence

Same IT function · ITSM, change and access records

The challenge

Green dashboards, uncertain controls.

  • Tickets paused "waiting for user" with no contact
  • Closures bunched before reporting dates
  • Changes deployed without CAB approval
  • Leavers' accounts still active after exit

What we built

Controls tested on all the data, with the reasoning shown.

  • Five-step investigation narrated by Azure OpenAI: detect, root cause, impact, owner, remediate
  • Hidden pause hours and true SLA breaches recalculated
  • Continuous ITGC tests for change management and user access
  • Control diary of observations, tests, findings and actions
5Investigation steps
3Levels of root-cause analysis
AllData, not a sample
Platform 04 · Access governance

Access Provisioning Squad

Same IT function · ITSM queue and the HR system

The challenge

Every access request was a manual ticket.

  • Requests read and re-keyed by the service desk
  • Users created and permissions set by hand
  • Requesters chasing for updates
  • Little evidence of who approved what

What we built

Agents that do the work, after a person approves.

  • Queue Monitor agent reads requests with an LLM and routes them
  • Human-in-the-loop approval queue
  • RPA Provisioning Bot creates users and assigns permissions
  • Notification agent closes the loop; every step in the execution log
3Cooperating agents
1Approval queue
LoggedEvery execution
Platform 05 · IT services sales

RFP & Bid Response Agents

IT services bid team · RFPs, past responses and company content

The challenge

Every bid started from a blank page and a deadline.

  • Requirements buried in long RFP documents
  • Compliance and risk clauses easy to miss
  • Past answers hard to find and reuse
  • Quality review squeezed at the end

What we built

An orchestrated squad from RFP to reviewed response.

  • Document analyst and requirement extractor
  • Compliance checker and risk assessor
  • Response writer grounded on a content repository
  • Quality reviewer before the bid lead signs off
6Specialist agents
1Orchestrator
HumanBid lead signs off
Platform 06 · Delivery & PMO

Helios — agentic programme management

IT services delivery · projects, programmes and portfolios

The challenge

PPM tools record the work; people still run it.

  • Status reports assembled by hand every week
  • Schedule and cost health argued, not computed
  • RAID logs and change control out of date
  • No trail of who changed a commitment, or why

What we built

An agent fleet that runs the project, not a report about it.

  • Paste a brief: charter, team, WBS, RAID and benefits created as records
  • Earned value, float and exposure computed by tools — the model never calculates
  • DCMA 14-point schedule integrity test on every update
  • Agents act only with the user's own permissions; contracts and commitments stop for a named signature
14DCMA schedule checks
0Numbers invented by the model
LoggedEvery read and write

How it works — the same pattern in every build

1 · Sources
ITSM, CMDB, logs, HRMS, ERPTickets, comments, changes, users, documents
2 · Model
Governed data fabricTickets, engineers, services and owners reconciled
3 · Analyse
ML & GenAIAnomalies, forecasts, risk scores, narratives
4 · Act
Agents & RPABehind approvals, autonomy limits and guardrails
5 · Assure
Logs, findings & evidenceExecution logs, control diary, audit trail

The agents, as built

AgentPlatformActs
Queue MonitorAccess provisioningClassifies & routes
RPA Provisioning BotAccess provisioningAfter approval
Notification AgentAccess provisioningEmails requester
ITSM CopilotITSM intelligenceRecommends actions
Requirement ExtractorRFP responseDrafts
Compliance CheckerRFP responseFlags gaps
Response WriterRFP responseDrafts
Quality ReviewerRFP responseReviews

Only the provisioning bot changes a system of record, and only after a named approver signs off.

Also built: tools, guardrails and platforms

MCP Studio — scans REST and OpenAPI specifications, uses GPT-4 to score which endpoints suit agents, and generates and deploys Model Context Protocol servers with OAuth 2.1.

LLM Security Framework — a 17-layer defence-in-depth architecture for GenAI applications: input validation, injection detection, output filtering and monitoring.

Enterprise GenAI platform — a chat platform designed with role- and attribute-based access control, running on Azure Kubernetes Service with Key Vault-managed secrets.

Risk & RegTech explorer — capability catalogue, use-case library and live knowledge graph with a grounded copilot, built for a global IT consultancy's risk practice.

DB Utils MCP server — connects AI assistants to 25+ database systems through the Model Context Protocol. ContractX — contract lifecycle management for client contracts and SLA terms.

Technology

Azure OpenAIscikit-learnIsolation ForestFlaskDjangoSelenium RPAModel Context ProtocolAzure AKSKey VaultChromaDB
Value calculator · IT operations & shared services

What could a supervised agent squad free up?

Enter your own volumes. The estimate compares today's manual handling with agents working the cases and people reviewing only the exceptions. Figures in Indian rupees.

cases
e.g. service-desk tickets, access requests, invoice exceptions or reconciliation breaks
min
₹ / h
%
Cases agents close within policy, with no human touch
min
Time for a person to check the agent's draft and approve
Estimated impact
–
Hours saved per month
–
FTE equivalent (150 h / month)
–
Cost saved per month
–
Cost saved per year
–
Cases per month one supervisor can oversee

Estimate only, not a quote or a DaasLabs result. Manual hours = cases × minutes ÷ 60. Supervised hours = cases × (1 − STP share) × review minutes ÷ 60. Hours saved = manual − supervised. FTE = hours saved ÷ 150. Cost saved = hours saved × cost per hour (× 12 for a year); 1 lakh = ₹1,00,000 and 1 crore = ₹1,00,00,000. Supervisor capacity = 150 h × 60 ÷ ((1 − STP share) × review minutes). Excludes platform and run costs.

Advise · Data & AI maturity assessment

Where is your centre on the maturity curve?

Our assessment scores 12 capability layers — from the secure AI gateway and data fabric to ontology, context engineering, agents and governance — against five stages, using evidence rather than opinion.

  1. 1FoundationalExperiment
  2. 2EmergingPilot
  3. 3OperationalScale
  4. 4SystemicOrchestrate
  5. 5TransformationalAI-native

MIT CISR found enterprises at stages 3–4 perform well above their industry average financially, while those at stages 1–2 perform below it. Source

Start with the outcome you need

Tell us the problem — a service desk that can't keep up, SLAs you don't fully trust, access that lingers after people leave, a close that runs late, a parent asking what the centre is worth. We'll propose an assessment or a 30-45 day pilot, delivered by DaasLabs teams on our framework and accelerators.

Advise Build Transform Run