CW@60: IT outsourcing 60 years on – how technology, risk and regulation reshaped UK IT services

Dimas Abimanyu

September 1, 2026

Computer Weekly 60th anniversary logo

On 22 September 2026, Computer Weekly turns 60. To mark the milestone, we asked some of our friends – experts, parliamentarians, IT leaders and suppliers – for their perspectives on how tech has changed their lives over six decades. What’s changed the most for you since then?

I was lucky enough to work on computers as a civil servant in the 1980s. Having been involved in the first UK public and private sector outsourcings at that time, I thought I would focus on how, within the 60 years of Computer Weekly’s life, outsourcing has developed and shaped the UK IT services market.

When Computer Weekly first began reporting on commercial computing in the mid‑1960s, IT outsourcing (ITO) – as we knew it in the 1980s – had not been invented. Few would have predicted then that organisations would one day hand over critical parts of their IT operations to third‑party suppliers as a matter of routine.

Technology was relatively rare and expensive, systems were quirky and fragile, and IT was tightly bound to the organisation that owned the hardware – mostly mainframes. For those of us at the keyboard, it was hard to imagine the progression from hardware into the dominance of software and then into the prevalence of services, including ITO.

Within Computer Weekly’s lifetime, ITO has not only become commonplace, but integral to how businesses and public bodies operate. While cost remains an important driver in ITO today, there are other powerful factors in play, including the need to integrate and access innovative technologies and processes, relying on skills that are rare in-house. And now ITO is shaped as much by risk, governance, and regulation as by technologies themselves.

Facilities management

The roots of UK ITO lie in the batch processing and time-sharing service bureaux and facilities management models of the 1960s and 1970s – around the time of Computer Weekly’s birth.

These arrangements gave organisations access to computing power without owning it, while responsibility stayed with the customer. But they were seen as an early proof of concept. I remember having to adapt UK government GC Stores contract terms to mainframe acquisition, which meant excluding those sections that specified what kinds of wrapping paper should apply.

In the 1980s, as IT estates grew in scale and importance along with processing complexity, organisations began transferring operational responsibility for core systems to specialist suppliers.

The 1989 Eastman Kodak/IBM/ISSC outsourcing in New York is considered the first reported IT outsourcing anywhere. But the Greater London Council-Hoskyns ITO appears to have preceded it, along with several UK central government ITOs.

My first experience of ITO – then called facilities management – was in the late 1980s. This was the HM Customs & Excise-BT customs handling of import and export freight (Chief) project. These early deals demonstrated that third parties could build and run mission‑critical IT systems and marked the emergence of ITO as a strategic governance decision.

Regulating the market

Regulation soon entered the market and imposed limits. In 1981, the UK government enacted the Transfer of Undertakings (Protection of Employment) Regulations – now universally abbreviated to TUPE. Staff associated with outsourced services often transferred to suppliers on the same terms of employment. This impacted on ITO’s pricing model.

Data protection law in the early 1980s made clear that organisations could outsource processing, but not accountability for their data protection and privacy obligations. With regulation came an even greater need for formal contracts governing regulated areas, along with terms reflecting financial, commercial, operational, and risk-management drivers in ITO transactions.

Photo of lawyer Mark Lewis from Stephenson Harwood

“After 60 years, IT outsourcing in the UK has shifted from being a commercial tactic to a highly regulated, sophisticated operating model”

Mark Lewis

The late 1980s also saw the beginnings of offshore ITO models, with CEO Jack Welch creating GE’s back-office operations in India. Nearshore and offshore ITO have never looked back.

Regulators became concerned about regulatory conflicts between captive and offshore outsourcing destination and customer/user home country regulation. Transferring and processing data offshore called for specific regulation in the UK, following the EU’s regulation.

This heralded the rise and rise of the Indian ITO industry and several of the Indian tier-one providers becoming indispensable players in the UK IT services market today. Contracts had to follow suit, with new operating and ownership structures in captive and build-operate-transfer operations.

During the 1990s and early 2000s, large single‑supplier ITO deals became common. They promised scale, predictability, and global delivery capability. But operational rigidity, cyber risk and regulatory scrutiny exposed their limits.

By the end of the 2000s, buyers had begun favouring multisourcing, modular contracts and explicit exit planning and management, sometimes along with the service integration and management (SIAM) model.

Into the cloud

Cloud computing took off around 2006 and altered the delivery model, but not customer accountability. Organisations increasingly consumed IT as a service, but security, data protection and sector‑specific regulatory duties continued to apply. So much for cloud being “no shore”.  

ITO became more pervasive, but cloud made it less visible in supply chains. That was to become a risk and a regulatory and contractual headache.

As ITO became more complex and distributed, supply chains became more critical and were rightly perceived to pose a potentially serious risk.

Information security has always been a concern once third parties have access to customers’ IT networks, systems, and processes. We have witnessed the development of new information security technical standards and governance models, and with them much more infosec and cyber security contractual concerns and provisions in ITO. Cyber risk has become one of the biggest concerns globally, and not just in ITO.

With the widespread adoption of ITO in regulated sectors came increased regulatory oversight. The UK Financial Conduct Authority (FCA) and Prudential Regulation Authority (PRA), along with EU regulators, adopted new and complex rules governing ITO, including “outsourcing to the cloud” and supply chains.

Today, financial services customers and outsource providers have to grapple with the UK’s operational resilience regime, as well as the EU’s Digital Operational Resilience Act (DORA). For the first time in ITO, systemically important providers will be directly regulated in the UK and Europe.

Networks, IT systems and processes in the UK’s critical national infrastructure (CNI) sectors are regulated by the Network and Information Systems Regulations 2018 (NIS), to be updated by the Cybersecurity and Resilience (Network and Information Systems) Bill currently going through the UK Parliament. Under the bill, datacentres, supply chains, and managed service providers (MSPs), among others, will be covered.

Parallel regimes

Brexit did not materially reduce regulatory obligations. For example, the UK version of GDPR retains core EU principles, as does our financial services operational resilience regulation, soon to be joined by our CNI cyber security and resilience laws. Often, cross‑border outsourcing now operates across parallel UK and EU regimes. Complexity, rather than deregulation, has been the result.

And today AI – especially generative AI and agentic AI – is creating new inflection points. AI‑enabled and agent‑based services mean organisations are no longer about to just outsource implementation, integration and systems, but also autonomous digital work. Governance, accountability, transparency and explainability are rapidly becoming central issues. And they, too, are finding their way into contracts.

Today, “outsourcing” as a description seems to have become unfashionable – if you hear it at all. But it is still outsourcing. After 60 years, IT outsourcing in the UK has shifted from being a commercial tactic to a highly regulated, sophisticated operating model. Each wave of regulation – employment, data protection, cyber security and now AI – has tightened the link between outsourced services and organisational accountability.

For the 40 or so years I have been involved in ITO, it has always struck me how little UK litigation there has been in ITO, relative to the pervasiveness and criticality of IT, its growing complexity and the many IT outsourcings that have actually gone wrong. I have a theory about this. That is for another time.

But, once in several generations, there is a single case that changes our perceptions of ITO and the real-life consequences when it goes wrong. The Post Office Horizon IT scandal is that case. And it is to the massive credit of Computer Weekly and Karl Flinders that the public understands the impact of bad IT outsourcing – and worse – on our lives.

Computer Weekly has watched and reported on the growth of IT outsourcing, and held to account those who have abused it, too. Here’s to another 60 years.

Mark Lewis is a lawyer and senior consultant at Stephenson Harwood LLP in London, and visiting professor in practice in the law school at London School of Economics and Political Science.

S 004