North Dakota buyer guide
Outsourcing software development from North Dakota
A North Dakota buyer guide to international software and agentic-AI delivery: capability leases, inherited data risk, human authority, records, incidents, cost, and exit.

North Dakota outsourcing at a glance
| Proposed work | Default authority lane | Evidence before access or release |
|---|---|---|
| Ordinary application, integration, infrastructure, or test automation | Buyer-owned workspace with least privilege | Named entity and people, repositories, environments, data boundary, dependencies, tests, approvals, runbook, complete cost, and exit package |
| Coding or drafting with public or synthetic material in an AI tool | Approved tool and low-risk prompt lane | Tool and account, model/version, objective, source rights, settings, prompt class, output, evaluator, accepted version, retention, and significant-change trigger |
| Autonomous or semi-autonomous agent that can call tools | Expiring capability lease | Agent/service identity, objective, action allowlist, resource boundary, data class, credential, financial/time/volume limits, human gates, full action trace, abort and rollback, incident path, and expiry |
| Unclassified, customer, employee, operational, regulated, or combined data | Moderate stop gate until classification and purpose approval | Owner, steward, fields, sources, highest contributing class, derived-data analysis, purpose, region, people, systems, retention, and access review |
| High-risk data or consequential production action | Protected enclave and buyer-controlled human authority | Exact governing requirement, approved identities and locations, managed systems, separation, monitoring, evaluation, release owner, recovery, record custody, and tested revocation |
| Covered North Dakota executive-agency AI | NDIT inventory, review, and governance lane | Approved technology, current review, data and business owner, risk assessments, role training, transparency decision, regular accuracy/compliance evaluation, agent activity controls, and records treatment |
| North Dakota public-entity record or record-producing system | Platform-independent records lane | Record/non-record decision, custodian, classification, native or available format, retrieval, redaction, retention, preservation, export, and contract assurance that public access is not impaired |
| Private processing of North Dakota resident personal information | Contracted safeguard and immediate incident-relay lane | Data inventory, owner/licensee and maintainer roles, discovery relay, preserved facts, containment, affected population, notice decision owners, recovery, and evidence custody |
| Prohibited or newly blocked technology on covered State systems | Immediate kill-switch and exception lane | Current standard check, device/network enforcement, stop-work authority, removal evidence, substitute path, and formal exception if authorized |
These rows are not interchangeable. A private startup is not automatically subject to NDIT’s executive-branch policies. A contractor working inside an agency system cannot use that fact to authorize the same data in a personal account. A public record can contain confidential portions, and an AI interaction can create a record without the supplier owning the device. One delivery program therefore needs separate gates connected by a shared evidence model.
The core decision: can authority expire before capability spreads?
International outsourcing changes who can see information, who can act on systems, where logs and prompts persist, and who is available when an action needs approval. Agentic AI adds another change: software may select and sequence actions instead of merely returning text. The practical problem is not whether a provider says it uses agents responsibly. It is whether the buyer can identify and stop each effective actor before its permissions, data, or outputs spread beyond the approved boundary.
A capability lease is an operating record, not a software license agreement. It answers twelve questions:
- Identity. Which legal entity, named person, workload identity, service account, model, and agent version can act?
- Objective. What bounded outcome may the actor pursue, and which adjacent outcomes are excluded?
- Input. Which code, documents, records, data classes, APIs, queues, and signals may it read?
- Action. Which tools and verbs may it use: read, propose, write, merge, deploy, message, purchase, delete, or change access?
- Place. In which country, city, device, network, cloud region, tenant, repository, model service, and subprocessor may the work occur?
- Limit. What time, cost, token, request, record, file, transaction, or change-volume ceiling applies?
- Gate. Which action needs a named human to inspect evidence and authorize continuation?
- Trace. Which prompt, plan, tool call, input reference, output, approval, error, override, and timestamp must be retained?
- Abort. Who or what can stop the actor immediately, revoke credentials, isolate systems, and preserve evidence?
- Recovery. Which rollback, restore, reconciliation, and downstream correction path has been tested?
- Expiry. When does authority end, and what event forces earlier review—model change, new tool, new data, new destination, changed objective, incident, or personnel change?
- Exit. Which source, configuration, data, logs, decisions, credentials, documentation, and deletion or return proof put the buyer back in control?
Give each lease a stable ID and connect it to the work item, access group, machine credential, deployment rule, invoice, and exit register. A person may hold several narrow leases rather than one permanent “developer” role. An agent can propose a patch under one lease but cannot merge it, change production data, or contact a customer without separate authority. When scope changes, issue a new version; do not stretch the old one through a chat message.
The same record should work during normal delivery and an investigation. If a supplier action produces an unexpected result, the buyer can retrieve who or what acted, under which objective, with which inputs, tools, model, credentials, limits, and human approvals. If those facts exist only in the provider’s transient interface, the buyer does not control the work.
Use risk inheritance before international or AI access
North Dakota’s December 2025 Data Classification Policy applies to executive-branch State agencies, including the University System Office, while excluding other higher-education institutions such as campuses and agricultural and research centers. Other State agencies are encouraged to adopt or use it as a frame. It is not a universal private-company statute. Covered buyers should apply it as policy; private buyers may deliberately adopt its logic as an operating model without mislabeling the source as law.
The policy defines three risk levels:
| State policy class | Operational meaning | Outsourcing default for covered work |
|---|---|---|
| Low | Public information whose unauthorized disclosure, alteration, or destruction would have little or no adverse effect | May enter an approved supplier or public-AI lane after integrity, rights, purpose, and tool checks; public does not mean ownerless or safe to alter |
| Moderate | Information whose compromise could have a serious adverse effect; the policy includes operational, personally identifiable, public-employee, and trade-secret examples | Keep in authenticated, reviewed systems; do not place in public non-State-managed AI; require owner, purpose, people, locations, retention, controls, and incident path |
| High | Information whose compromise could have severe or catastrophic effect; examples include credentials, security information, financial/high-risk PII, payment, health, vulnerability, tax, student, criminal-justice, and certain federal data | Default deny international or agent access until exact authority, enclave, identity, system, region, monitoring, recovery, and exit requirements are approved |
Two rules make this especially useful for outsourced AI and analytics. First, information that has not been classified defaults to Moderate. “The vendor needs it now” is not a classification. An unknown export, prompt attachment, log bundle, database view, or support screenshot should stop at the Moderate gate until the owner and steward can classify and minimize it.
Second, derived information can inherit risk. The policy addresses compiled data and says the resulting compilation receives the highest applicable risk level. It also calls for review when data is joined, blended, merged, summarized, or analyzed. That defeats a common shortcut: treating an output as harmless because it no longer looks like its inputs. A summary can expose a protected fact; an embedding can preserve relationships; a model output can infer sensitive attributes; an error log can combine an identifier with a credential; a small aggregated cohort can reveal a person.
Build a risk-inheritance graph for each material work object:
- nodes identify the source object, owner, class, purpose, version, and storage;
- edges identify the transformation, join, prompt, query, code, model, person, and destination;
- derived nodes inherit the highest contributing risk by default;
- a lower classification requires a recorded review of separation, aggregation, de-identification, decoupling, or another actual control;
- any new source, transformation, recipient, or purpose triggers review; and
- the graph points to restricted evidence instead of copying secrets into a broad catalog.
Classification belongs to the object and transformation, not the project name. A farm-management product, financial workflow, energy application, or public portal can contain Low documentation, Moderate operating data, and High credentials in the same repository. Apply tags, access policies, test-data rules, model gateways, logging controls, and release checks to the actual objects.
Connect the four data roles to supplier operations
The State policy separates Data Owner, Data Steward, Data Custodian, and Data User responsibilities. A supplier contract should not blur them into “the vendor handles the data.” Translate the roles into an operating matrix:
| Role | Buyer-side decision | Supplier evidence |
|---|---|---|
| Data Owner | Approves classification, intended use, access, sharing, retention, and acceptable risk | Signed or logged authority tied to the exact object and work package |
| Data Steward | Maintains meaning, quality, handling rules, review, and operational metadata | Schema, definitions, quality checks, lineage, change record, and issue route |
| Data Custodian | Implements storage, access, backup, protection, logging, transfer, and disposition controls | System and region inventory, access logs, backup map, recovery test, transfer and deletion proof |
| Data User | Uses the data only for approved work and protects it in practice | Named identity, training, lease, environment, activity record, output, exceptions, and revoked access |
If one person fills several roles, record the combination and the independent review needed for consequential actions. An overseas developer may be a limited Data User and operate a buyer-approved tool, but should not silently become the Data Owner by choosing a new purpose. A hosting provider may perform custodian functions without deciding retention. An AI platform may be a processor in one operation and reserve broader uses under its terms in another; read the actual agreement and settings.
Review classification at least on the buyer’s applicable schedule and when conditions change. Useful triggers include a new data source, field, join, model, plugin, subprocessor, country, support route, retention setting, user population, consequence, integration, or export. Connect each trigger to the capability lease so an actor cannot keep using yesterday’s authority after today’s material change.
Govern an AI agent as an actor, not a feature label
The current NDIT AI Policy defines an AI agent in terms of autonomy: it may perceive inputs, make context-aware decisions, take digital or physical actions toward defined goals, interact with systems or users, and adapt. It then requires governance that controls and monitors both agentic-AI development and activity and the quality, integrity, and security of input data. That is materially different from approving a chatbot screenshot.
Use five nested controls:
- Tool approval. Identify the product, provider entity, service plan, account, model, version or release channel, plugins, connectors, regions, terms, retention settings, training use, subprocessors, and security evidence. For covered agencies, every AI technology—including free services—belongs in the NDIT vetting and inventory path.
- Agent approval. Identify the agent configuration, objective, system instructions, tools, knowledge sources, memory, allowed actions, evaluator, version, owner, and expiry. A tool can be approved while a dangerous agent configuration is not.
- Run approval. Bind a specific execution to data classes, inputs, budget, time, action limit, environment, and human gates. A safe test run does not authorize production.
- Result approval. Test accuracy, security, rights, fairness, accessibility, operational effect, and failure behavior appropriate to the use. A fluent answer is not acceptance evidence.
- Change approval. Re-evaluate significant changes in the product, model, tools, objective, data, autonomy, recipient, action permissions, terms, or environment. For covered agencies, connect that trigger to the State IT review path.
Keep read, propose, and act permissions separate. An agent that reads a synthetic test repository and proposes a pull request has a different consequence than one that merges code, deploys infrastructure, changes permissions, deletes records, purchases services, or sends a resident communication. Begin with the smallest observable action set and add authority only after a representative test.
Use workload identities instead of shared human credentials. Never give an agent a password copied from a person. For covered State work, the policy separately warns against reusing State-managed passwords in third-party applications outside the State single-sign-on solution. Short-lived credentials, audience restrictions, scoped tokens, network boundaries, secrets brokers, and separate production approval reduce the blast radius.
Log meaning, not only API traffic. The trace should connect the objective, plan, selected tool, material input reference, output, error, retry, approval, action, affected object, and final state. Preserve sensitive content only under the appropriate access and retention rules. A hash or restricted pointer can prove linkage without copying High-risk content into a general observability system.
Keep public AI, licensed AI, and protected enclaves separate
The NDIT policy says users must not put Moderate- or High-risk data into public, non-State-managed AI/ML services; Low-risk public data is permitted. The operational boundary is the service, account, contract, configuration, and data—not the product brand alone. A free public account, enterprise tenant, private model endpoint, and self-hosted model can have different terms and controls.
Create three technical lanes:
| Lane | Allowed input | Required controls |
|---|---|---|
| Public or open experimentation | Approved Low/public or synthetic data only | Approved tool where required, source and IP check, no reused credentials, visible data warning, output evaluation, no production action |
| Licensed managed service | Data expressly approved for that service and configuration | Contract and terms review, tenant/region, identity, retention/training settings, connector allowlist, DLP, logging, evaluation, change monitoring, exit |
| Protected enclave | Precisely approved Moderate/High or otherwise restricted data | Dedicated environment, strong identity, least privilege, isolation, managed endpoints, approved people and locations, controlled model and tools, monitoring, human authority, recovery, evidence, deletion/return |
Do not turn the third lane into a general warehouse. Minimize data and use synthetic, redacted, masked, aggregated, or otherwise approved substitutes when they can prove the requirement. Test that the substitute preserves relevant behavior without carrying the protected facts. When real data is necessary, document why, who approved it, what fields enter, how the output inherits risk, and when access ends.
Prompt injection, malicious documents, and unsafe tool output deserve explicit tests. Treat retrieved content as untrusted input, separate instructions from data, restrict tools and destinations, validate structured outputs, require confirmation for consequential actions, and prevent a document from granting new authority. The agent’s plan cannot expand its own lease.
Make human authority observable
“Human in the loop” is too vague. Record what the human can decide, what evidence the person sees, how much time is available, and whether the person can stop or reverse the action. A reviewer who receives a hundred opaque agent decisions after deployment is not meaningful control.
Use consequence-based gates:
- Draft gate: a person checks sources, purpose, confidentiality, rights, accuracy, and tone before external use.
- Code gate: a qualified reviewer inspects the change, tests, dependency and license effects, security findings, and rollback before merge.
- Data gate: the owner or delegate approves the exact fields, class, purpose, people, system, country, and retention before access.
- Production gate: an authorized buyer role approves a known artifact after environment-specific tests; the supplier cannot self-expand access to pass the test.
- Decision gate: a qualified person reviews material inputs, limitations, alternatives, and consequences before a consequential decision or communication.
- Incident gate: the responder can isolate and preserve evidence immediately, while legal and communications authority stays with the designated buyer owners.
- Exit gate: the buyer verifies export, continuity, revoked access, record handling, and deletion or return rather than accepting a provider attestation at face value.
For covered State work, the AI policy calls for transparency about citizen interaction, outcomes or impacts where applicable, and business purpose. It also calls for clear marking of systems and processes using AI for decision-making or output generation with Moderate- to High-risk data, while the business process owner determines end-user disclosure. Preserve that determination, its owner, the user experience tested, the applicable content/version, and a correction or escalation route.
Private buyers should make their own disclosure and review determination from actual law, contract, product risk, and user expectation. Do not copy an executive-agency policy statement and call it a universal North Dakota consumer-AI rule.
Preserve records across supplier and model platforms
North Dakota Century Code section 44-04-17.1 defines a public-entity record as recorded information of any kind, regardless of physical form or storage characteristic, in the possession or custody of a public entity or its agent and received or prepared for public business or containing information relating to public business. The definition includes preliminary drafts and working papers while excluding unrecorded thought processes or mental impressions. Section 44-04-18 makes public-entity records open unless otherwise provided by law and addresses electronic access, confidential or exempt material, and contracts for record databases.
The NDIT AI Policy reinforces the platform-independent point: open-record treatment is not bounded by a specific system, device, platform, or owner. For covered public work, an outsourcing agreement should therefore prevent a provider’s chat, ticket, model, log, or storage design from making relevant records undiscoverable or unexportable.
Build a record bridge with:
- a record/non-record and confidential/exempt review owned by the public entity, not the overseas provider;
- an inventory of repositories, chat systems, prompt stores, model logs, tickets, build systems, deployment tools, support tools, and backups that may hold records;
- capture rules for material prompts, sources, outputs, edits, approvals, actions, incidents, and release artifacts;
- native or available export formats, metadata, search, linkage, integrity, redaction, and retrieval tests;
- retention, hold, disposition, and defensible-deletion rules applied across active systems and subprocessors;
- contract terms that preserve agency inspection and copying rather than impairing access; and
- an exit export that another team can search, understand, reproduce, and protect.
Do not interpret public records to mean public disclosure of every field. The same chapter recognizes confidential, closed, and exempt material. Classification, access, redaction, and legal review must coexist with retrievability. Likewise, recording everything forever can expose sensitive content and increase cost. Retain the right evidence for the right period under an authorized schedule.
Private companies also need durable operating evidence, but they should not call ordinary corporate material a North Dakota public record. Preserve what contracts, security, quality, tax, employment, litigation, insurance, regulatory, and business-continuity decisions actually require.
Design immediate incident relay before access
North Dakota Century Code Chapter 51-30 applies to its defined private-data breach path. It distinguishes a person that owns or licenses computerized data from a person that merely maintains it. A maintainer must notify the owner or licensee immediately after discovery when covered personal information was, or is reasonably believed to have been, acquired by an unauthorized person. The owner or licensee handles the resident path and, for a breach exceeding 250 individuals, the Attorney General disclosure path. The outside notice standard is the most expedient time possible without unreasonable delay, subject to the stated investigation, restoration, and law-enforcement conditions.
Do not use an outside statutory standard as the supplier’s first-alert service level. The buyer needs time to determine the actual event, role, people, data, encryption, acquisition facts, population, jurisdictions, contracts, and notice obligations. Require an immediate operational relay for any credible confidentiality, integrity, availability, credential, model, or agent event.
The initial packet should include known facts without demanding a premature legal conclusion:
- detecting person or system, discovery time, event time if known, and supplier incident ID;
- affected services, tenants, repositories, models, agents, identities, credentials, devices, networks, regions, people, and subprocessors;
- suspected data fields, classes, record counts, residents or populations, encryption and key facts, and acquisition evidence;
- agent objective, lease, plan, tool calls, prompts or restricted references, outputs, approvals, and affected objects;
- containment taken, systems preserved, logs protected, unsafe actions disabled, and risks of additional action;
- recovery state, rollback or reconciliation status, customer or public impact, and next evidence update time; and
- named technical, security, legal, privacy, records, business, and communications contacts on the appropriate sides.
Let the supplier isolate its environment and revoke its own credentials under pre-authorized safe-containment rules. Keep resident, regulator, law-enforcement, customer, insurer, public-record, and public-communication decisions with the named buyer owners unless an exact agreement says otherwise. Preserve both ordinary delivery evidence and investigation evidence under appropriate holds; an automated cleanup job must not destroy the facts needed to understand the event.
Exercise the relay. Inject an agent that attempts an unapproved tool call, a leaked token, an unexpected subprocessor region, a malicious retrieved document, and a simulated covered-record acquisition. Measure detection, stop time, evidence completeness, update cadence, authority clarity, recovery, downstream reconciliation, and access revocation.
Keep a prohibited-technology kill switch
The May 2026 NDIT Prohibited Technologies Policy applies to executive-branch State agencies. It prohibits technologies listed in the referenced standard on State-owned devices and STAGEnet, supports managed-device removal and network blocking, and allows additions for emerging critical risks. Personally owned devices with prohibited technologies are limited to the guest-network treatment described in the policy. A formal exception path exists; an outsourcing supplier cannot create its own exception.
For covered work, check the current policy and referenced standard at intake, before access, on significant change, and during renewal. Map names beyond the visible application: package, SDK, model endpoint, embedded component, browser extension, mobile app, remote-support tool, hardware, parent company, and transitive dependency may matter to the actual control decision.
Build removal into the capability lease:
- stop new use and affected automated runs;
- revoke tokens, sessions, connectors, network paths, and device access;
- preserve necessary evidence under the incident or review path;
- identify stored, cached, derived, trained-on, logged, and backed-up data;
- remove or isolate the technology through the approved control plane;
- validate a substitute and reconstruct needed outputs through an approved path;
- reconcile records, data, access, costs, and unfinished work; and
- obtain a formal exception only through the authorized process when appropriate.
Private buyers can adopt the same kill-switch discipline for their own prohibited-vendor and supply-chain decisions, but should label it as company policy rather than a claim that the NDIT rule governs them.
Engineer Central and Mountain authority windows
North Dakota spans Central and Mountain time. Do not put “North Dakota time” in a work order. Record the buyer’s actual city or site, its IANA time-zone identifier, each contributor’s city and identifier, the dates of the engagement, and local holidays. Recalculate future overlap through maintained zone data instead of freezing a UTC offset in a sales deck.
Use three coverage modes:
| Mode | Purpose | Minimum design |
|---|---|---|
| Working overlap | Pairing, clarification, review, and ordinary decisions | Sustainable recurring window, named participants, agenda, written outcome, fallback owner |
| Asynchronous relay | Focused build, test, analysis, and overnight progress | Decision-ready packet with context, version, evidence, questions, limits, next safe action, and accepted handoff |
| Urgent authority | Incident, unsafe agent, production failure, or credential event | 24-hour route appropriate to risk, on-call identities, immediate stop authority, secure channel, evidence location, and buyer decision owner |
Mountain-time operations should not inherit a schedule designed for Fargo or another Central-time location without calculation. A buyer with field sites should model each consequential site. An international contributor may have excellent overlap with one location and poor incident coverage for another.
Do not solve time zones with permanent night work. Fatigue raises defect, security, and retention risk. Rotate exceptional coverage, compensate it, cap it, and shift ordinary production into clear asynchronous packets. The best schedule preserves a short high-value decision window and lets detailed work proceed without waiting for meetings.
Select the delivery model from authority and evidence
Choose the commercial form after defining the work and its control plane:
- Fixed-scope project: useful when acceptance, interfaces, data, dependencies, and change control are stable. Require the real team, evidence, and handover—not only a deliverable promise.
- Staff augmentation: gives the buyer more daily direction. The buyer must supply architecture, backlog, supervision, security, records, release authority, and continuity; a staffing label does not resolve worker classification or international engagement questions.
- Dedicated team: supports evolving products when the buyer can maintain priorities, technical authority, access reviews, knowledge distribution, and exit tests.
- Managed service: can own measurable service outcomes, but should not own the only repository, cloud account, model configuration, logs, recovery path, or capability ledger.
- Specialist AI or automation engagement: may accelerate evaluation and integration. Separate advisory, model-building, agent configuration, data processing, production action, and ongoing monitoring authority.
Compare named teams, not countries in the abstract. A destination is only one fact. Verify contracting entity, beneficial and operational ownership where relevant, named people, employment or subcontract chain, cities, devices, systems, cloud regions, model services, language, skill evidence, attrition and replacement rules, security, applicable sanctions and export constraints, intellectual-property chain, insurance, dispute path, incident capability, and exit.
The buyer should own or control repositories, cloud accounts, domains, deployment, production credentials, data, approved model and agent configuration, evaluation suites, logs, records, runbooks, recovery artifacts, and release decisions. The supplier can operate within them under a lease. Ownership language without operational possession is weak exit protection.
Compare complete cost, not an hourly rate
Normalize proposals to a scenario and time horizon. Include:
- discovery, architecture, data preparation, security and privacy review, records design, evaluation, accessibility, documentation, and transition;
- engineering, testing, project leadership, product ownership, design, DevOps, support, and buyer management time;
- AI model, embedding, search, storage, tool-call, observability, evaluation, moderation, and egress charges;
- cloud, development tools, source control, identity, managed devices, connectivity, assurance, insurance, and travel;
- recruiting, onboarding, background checks where appropriate, training, role coverage, replacement, attrition, and knowledge transfer;
- currency, payment, tax, employment and classification analysis, contract administration, and dispute handling;
- rework, defect escape, unsafe action, downtime, data cleanup, incident investigation, recovery, notification, and customer remediation; and
- termination, export, record production, data return or deletion, credential rotation, replacement operation, and stranded-service costs.
Model downside. What happens if a model changes, a free tool is blocked, an agent exceeds its objective, joined data becomes High risk, a subprocessor moves, a key reviewer is unavailable, a Central/Mountain assumption is wrong, or the supplier exits? Price the prevention, detection, recovery, and transition response. A lower rate can be expensive if the buyer must rebuild the authority and evidence system after every change.
Use identical assumptions across proposals. Ask each provider to price the representative pilot, steady state, one material change, one incident exercise, and exit. Record exclusions and buyer dependencies. Discounts should not hide a provider-controlled repository, shared credentials, unbounded model charges, or missing handover.
Run a capability-lease pilot
Choose one real but reversible outcome using synthetic, public, or expressly approved nonproduction data. Use the actual proposed team, tools, model, agent configuration, locations, and buyer reviewers. A credible pilot should include one derived-data transformation and one bounded tool action.
Before the start, require:
- work outcome, acceptance evidence, architecture boundary, data sources, initial classes, and risk-inheritance graph;
- legal entities, named people, cities, devices, systems, service accounts, models, tools, regions, connectors, and subprocessors;
- one capability lease for each human and machine actor, including limits, human gates, trace, abort, recovery, expiry, and change triggers;
- approved test data, access groups, secrets path, logging, record treatment, incident contacts, and buyer-owned repositories;
- dated Central or Mountain overlap, asynchronous packet format, urgent route, and unavailable-owner fallback; and
- source, license, dependency, security, evaluation, deployment, recovery, and exit criteria.
During the pilot, ask the agent or automation to propose a normal change, then attempt an action outside its lease. Introduce a new source that changes the derived object’s risk, a tool-version change, a malicious instruction in retrieved content, and a simulated credential event. The system should stop, preserve evidence, notify the right owner, and require a new decision rather than silently continuing.
At acceptance, have a named human reproduce the relevant result, inspect source and test evidence, explain limitations, approve or reject the artifact, and execute deployment from a buyer-controlled identity. Then revoke the supplier and agent credentials, export the complete evidence packet, recover from a rollback point, and have another qualified person follow the runbook.
Score the pilot on delivered outcome, review quality, risk-inheritance accuracy, lease compliance, unauthorized-action prevention, trace completeness, incident speed, schedule sustainability, complete cost, recovery, and exit. Do not scale because the demo looked polished.
Contract the operating model
The agreement, security terms, data terms, work order, and technical configuration should agree on:
- exact provider entity, named or controlled team, approved countries and locations, employment/subcontract chain, background and training requirements where appropriate, and replacement process;
- outcome, deliverables, acceptance, dependencies, response times, change control, service levels, remedies, and order of precedence;
- owner, steward, custodian, user, controller, processor, maintainer, and other roles by operation rather than globally;
- data and record inventory, classes, purposes, minimization, environments, transfer, regions, access, retention, holds, return, deletion, and evidence;
- tool, model, agent, connector, subprocessor, significant-change, prohibited-technology, and exception controls;
- capability leases, least privilege, separate human and workload identities, action limits, approval gates, logs, abort, rollback, expiry, and periodic review;
- secure development, dependencies, provenance, testing, evaluation, vulnerability handling, release authority, monitoring, recovery, and correction;
- immediate event relay, safe containment, protected evidence, update cadence, investigation cooperation, buyer-controlled notices and communications, and post-event improvement;
- public-record search, export, redaction, retention, preservation, and production requirements when activated by the actual public-entity work;
- confidentiality, IP assignment and contributor flow-down, pre-existing materials, open source, model and data rights, destination-country formalities, and moral-rights treatment where relevant;
- pricing, model and cloud consumption, invoice evidence, currency, taxes, insurance, liability, suspension, termination, transition assistance, and unresolved claims; and
- buyer control of repositories, accounts, domains, credentials, configurations, evaluations, logs, records, documentation, backups, recovery, and portable exit artifacts.
A clause is not a control until both sides can execute it. Test who revokes an agent at 2 a.m., who reclassifies a merged dataset, how a model-version change reaches review, which system preserves a public record, how a maintainer relays an event immediately, and whether an exported build works without the supplier.
North Dakota outsourcing red flags
Pause or reject a proposal when:
- “North Dakota compliant” appears without the exact entity, operation, policy or law, scope, date, source, and qualified reviewer;
- executive-branch AI or data policy is described as a universal private-sector mandate;
- “agent” is a marketing label with no identity, objective, tool list, limits, trace, human gate, abort, or expiry;
- the agent can grant itself tools, credentials, budget, destinations, or production authority;
- unclassified data enters an international or public-AI workflow as if unknown meant Low risk;
- a merged, summarized, embedded, inferred, or model-generated output loses the source data’s risk without review;
- a provider says data remains in the United States while overseas people, support systems, logs, models, or subprocessors can access it;
- approval covers a product name but not its account, plan, model, connectors, settings, region, terms, and significant changes;
- a shared human password or broad permanent token powers automation;
- a public record becomes unsearchable or unexportable inside a supplier platform;
- confidential and public records are confused, causing either improper exposure or an inaccessible archive;
- the supplier waits for a final breach conclusion before alerting the owner or licensee;
- a prohibited or newly blocked technology has no technical kill switch or substitute path;
- “North Dakota time” replaces a city, IANA identifier, engagement date, and named authority window;
- pricing omits model consumption, buyer governance, incidents, recovery, or exit; or
- the provider controls the only repository, cloud account, deployment path, model configuration, logs, records, credentials, or runbook.
Frequently asked questions
Can a North Dakota company outsource software development outside the United States?
Potentially. Define the work, entities, people, data, systems, models, tools, countries, authority, contract, federal and state obligations, destination-country requirements, sanctions and export constraints, tax and employment questions, security, cost, continuity, and exit. Separate ordinary code from protected production data where possible.
Do NDIT’s AI and data policies apply to every North Dakota business?
No. The cited policies state an executive-branch scope with specific higher-education treatment and encouragement for other State agencies. A private buyer may adopt their useful controls, but should not present them as a universal private-company law.
What is a capability lease?
It is an expiring operating record that grants a named human, service, or AI agent only the objective, data, tools, actions, environments, and limits needed for a work package. It also names human gates, evidence, abort, recovery, incident, change-review, and exit paths.
Why treat unclassified data as Moderate?
That is the default in the current NDIT Data Classification Policy for covered work. Operationally, it prevents urgency or uncertainty from becoming permission. The owner and steward can review the actual data and approve the appropriate treatment.
Does a summary or AI output keep the source data’s risk?
Use highest-risk inheritance by default when data is compiled, joined, blended, merged, summarized, analyzed, embedded, or inferred. A qualified owner can lower treatment only after a documented review shows the actual transformation and controls justify it.
Can an approved AI tool perform any task?
No. Tool approval is only one layer. Approve the agent configuration, data, run, actions, human gates, output, and significant changes separately. Keep production and consequential authority narrower than drafting or testing authority.
Are AI prompts or outputs public records for North Dakota agencies?
The answer depends on the actual record, entity, public business, custody, and applicable confidential, closed, or exempt treatment. Current State law defines records without dependence on physical form, and NDIT policy says open-record treatment is not bounded by system, device, platform, or owner. The public entity should make and preserve the specific determination.
How quickly should an overseas supplier report a possible breach?
Immediately under the operating contract. North Dakota’s maintainer path also uses immediate notice to the owner or licensee after discovery for the covered facts. The buyer needs an early factual packet to determine the actual roles, data, acquisition, population, jurisdictions, and outside notices.
Is North Dakota entirely in Central time?
No. North Dakota spans Central and Mountain time. Use the buyer’s actual city or site, an IANA identifier, contributor cities, and the dates of work before promising overlap or urgent coverage.
Which outsourcing country is best for a North Dakota buyer?
There is no universal best country. Compare named teams and locations for the required capability, sustainable overlap, legal and IP chain, data path, authority controls, current destination restrictions, complete cost, continuity, incident support, and exit.
Should a North Dakota buyer choose nearshore or offshore delivery?
Choose after defining decision windows and work packets. Nearshore teams may increase live overlap; offshore teams may extend asynchronous production. Either can work when authority, evidence, quality, security, humane schedules, incident coverage, and handover are engineered.
What should the first pilot prove?
It should prove one accepted outcome with the real team, risk inheritance, bounded human and agent authority, stop behavior, significant-change review, immediate incident relay, buyer-controlled release, reproducible recovery, complete cost, revoked access, and portable exit.
Is Outsourcing.ai located in North Dakota?
No local presence is claimed. This is an online buyer guide, not a North Dakota office, local-business listing, or representation of local employees, customers, State authorization, or completed local work.
Buyer checklist
- Define the outcome, acceptance evidence, consequence level, engagement model, budget, and buyer owner.
- Identify the actual buyer city or site, IANA zone, contributor cities, dates, overlap, handoff, and urgent authority.
- Inventory data, records, code, prompts, models, tools, connectors, systems, credentials, outputs, logs, backups, and subprocessors.
- Assign owner, steward, custodian, and user responsibilities for each material object and operation.
- Apply Low, Moderate, or High classification where required; hold unclassified information at Moderate pending review.
- Build the risk-inheritance graph and re-review every compilation, join, blend, merge, summary, analysis, embedding, inference, or other derived object.
- Separate public/synthetic experimentation, licensed managed services, and protected enclaves.
- Verify the current approved-tool, significant-change, prohibited-technology, and exception paths for covered State work.
- Issue a narrow capability lease to every person, service, workload, and agent; separate read, propose, write, merge, deploy, communicate, purchase, and delete authority.
- Use separate short-lived human and workload identities; never reuse a person’s password for an agent.
- Define meaningful human gates, evidence shown, stop authority, rollback, recovery, and expiry.
- Preserve platform-independent record and action evidence under the correct access, retention, hold, redaction, and disposition rules.
- Contract for immediate factual incident relay and test owner/licensee, maintainer, legal, records, security, recovery, and communication roles.
- Verify entities, people, countries, destination restrictions, sanctions/export requirements, IP chain, insurance, and subprocessor flow-downs.
- Compare complete cost and downside cases with identical assumptions.
- Run the representative pilot with the actual proposed team and tools.
- Test unauthorized action, derived-risk change, model or tool change, malicious input, incident relay, rollback, export, revocation, and replacement-team operation.
- Obtain current legal, privacy, security, records, procurement, tax, employment, export, and intellectual-property advice where applicable.
- Record named human content, source, visual, and legal approval before production publication.
The exit test
Before scale, prove that the buyer can continue without the supplier. Retrieve and validate:
- repositories, accepted artifacts, branches, build definitions, dependencies, model and agent configurations, evaluations, release history, rollback packages, defects, and provenance;
- data and record inventory, classes, ownership, lineage, risk-inheritance graph, transformations, joins, derived values, prompts, outputs, logs, replicas, backups, retention, holds, and authorized deletion or return;
- capability leases, identities, tools, actions, approvals, exceptions, access history, current credentials, expiry, revocation, and orphan-account search;
- AI inventory, review evidence, significant changes, terms and settings, risk assessments, training, transparency decisions, accuracy and compliance evaluation, incidents, and monitoring history where applicable;
- public-record indexes, native or available exports, metadata, search and redaction capability, confidential or exempt handling, preservation, and production tests for covered public work;
- provider entities, contributors, employment or subcontract chain, locations, devices, systems, subprocessors, confidentiality, intellectual-property flow-down, and destination evidence;
- architecture, environments, infrastructure, domains, accounts, secrets, monitoring, runbooks, restoration results, open risks, decisions, owners, support history, and service dependencies;
- incident facts, investigations, decisions, notifications, communications, remediation, recovery, and retained evidence;
- invoices, consumption records, acceptance, licenses, insurance, transition obligations, returned property, deletion evidence, residuals, holds, and unresolved claims; and
- access removal from repositories, clouds, identity providers, model services, support tools, endpoints, networks, password vaults, and every subprocessor path.
Have a replacement team reproduce a build, explain one inherited-risk decision, run an evaluation, locate a material record, rotate a credential, stop an agent, restore a failed component, and execute a controlled release from buyer-held systems. Reconcile each human and machine identity to zero residual authority unless the buyer deliberately renews it.
The durable North Dakota outsourcing model is not a country ranking or a broad promise that AI is supervised. It is a buyer-controlled system in which data risk follows every transformation, capability is leased instead of assumed, consequential action returns to named human authority, records survive the platform, incidents arrive immediately, blocked technology can be removed, and every person and agent can be cleanly replaced. If the proposed team can prove that system in a representative pilot, international delivery can expand capacity without surrendering control. If it cannot, do not scale the engagement.
Evidence ledger
Sources used on this page
- Artificial Intelligence Policy — North Dakota Information Technology. Supports: Current November 2025 executive-branch policy for agentic-AI governance, input quality and security, approved-product inventory, significant-change review, risk assessment, role-based training, public-AI data restrictions, transparency, human accountability, legal review, and platform-independent open-record treatment. Direct source; independently sourced; commercial relationship: none. Verified 8/15/2026 by Outsourcing.ai Editorial Team. Accessed 8/15/2026.
- State of North Dakota Data Classification Policy — North Dakota Information Technology. Supports: Current December 2025 executive-branch policy defining Low, Moderate, and High risk; the Moderate default for unclassified data; owner, steward, custodian, and user roles; annual and change review; and highest-risk treatment for compiled, joined, blended, merged, summarized, or analyzed information pending review. Direct source; independently sourced; commercial relationship: none. Verified 8/15/2026 by Outsourcing.ai Editorial Team. Accessed 8/15/2026.
- Prohibited Technologies Policy — North Dakota Information Technology. Supports: Current May 2026 executive-branch policy for prohibited technologies on state-owned devices and STAGEnet, managed-device removal, network restrictions, emerging-threat additions, and the formal exception path. Direct source; independently sourced; commercial relationship: none. Verified 8/15/2026 by Outsourcing.ai Editorial Team. Accessed 8/15/2026.
- North Dakota Century Code Chapter 44-04 — Duties, Records, and Meetings — North Dakota Legislative Branch. Supports: Current official text defining a record without dependence on physical form, including preliminary drafts and working papers, and requiring public access to public-entity records while protecting confidential or exempt material in electronic systems. Direct source; independently sourced; commercial relationship: none. Verified 8/15/2026 by Outsourcing.ai Editorial Team. Accessed 8/15/2026.
- North Dakota Century Code Chapter 51-30 — Notice of Security Breach for Personal Information — North Dakota Legislative Branch. Supports: Current private-sector breach definitions and owner-or-licensee, maintainer, resident, and Attorney General notice paths, including immediate maintainer relay and the threshold above 250 individuals for Attorney General disclosure. Direct source; independently sourced; commercial relationship: none. Verified 8/15/2026 by Outsourcing.ai Editorial Team. Accessed 8/15/2026.
- Artificial Intelligence Risk Management Framework — National Institute of Standards and Technology. Supports: Maintained federal methodology for governing, mapping, measuring, and managing AI risk across design, development, deployment, use, evaluation, and retirement. Direct source; independently sourced; commercial relationship: none. Verified 8/15/2026 by Outsourcing.ai Editorial Team. Accessed 8/15/2026.
- Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile — National Institute of Standards and Technology. Supports: NIST AI 600-1 risk-management profile for generative-AI risks and actions involving governance, content provenance, evaluation, incident disclosure, third parties, and lifecycle monitoring. Direct source; independently sourced; commercial relationship: none. Verified 8/15/2026 by Outsourcing.ai Editorial Team. Accessed 8/15/2026.
- Secure Software Development Framework — National Institute of Standards and Technology. Supports: Maintained secure-development methodology for preparing organizations, protecting software and build environments, producing well-secured releases, preserving provenance, and responding to vulnerabilities. Direct source; independently sourced; commercial relationship: none. Verified 8/15/2026 by Outsourcing.ai Editorial Team. Accessed 8/15/2026.
- IANA Time Zone Database — Internet Assigned Numbers Authority. Supports: Maintained time-zone identifiers and transition rules for calculating dated overlap between North Dakota buyer locations and proposed international delivery cities. Direct source; independently sourced; commercial relationship: none. Verified 8/15/2026 by Outsourcing.ai Editorial Team. Accessed 8/15/2026.
- Directory of Intellectual Property Offices — World Intellectual Property Organization. Supports: Official destination-country intellectual-property office links for researching software, invention, copyright, design, model, and contributor-rights questions without assuming one North Dakota contract resolves every jurisdiction. Direct source; independently sourced; commercial relationship: none. Verified 8/15/2026 by Outsourcing.ai Editorial Team. Accessed 8/15/2026.
Next scheduled review: October 15, 2026. Corrections: hello@outsourcing.ai.
