Sooner or later every integration programme runs into the same question: where does the work actually get done? And it usually arrives dressed up as a cost conversation — offshore is cheaper, onshore is dearer, pick your budget. 💰
That framing quietly costs people money and sleep, because it treats the decision as a single lever pulled once for everything. It isn't. The real question isn't "cheap or safe?" It's "which work needs control, and which work needs scale?" — and you can answer that differently for different parts of the same programme. Let's unpack it. 👇
Cost and control aren't opposites you trade off along one line. They're two different questions:
The mistake is answering both questions with one word. Put everything onshore and you overpay for work that never needed it. Push everything offshore and you'll eventually route sensitive design through the wrong place and find out the hard way.
| Model | Choose it for | What runs here |
|---|---|---|
| 🛡️ Onshore | Security, probity, data residency | Senior architecture, governance, regulated and sensitive work |
| 🌍 Offshore | Cost efficiency and scale | High-volume build and run where sensitivity is lower |
| 🔀 Hybrid | The best of both | Onshore leadership and governance, offshore delivery — blended by workstream |
Onshore buys you proximity and defensibility. When your security director, your regulator or your board needs to know exactly where sensitive work happened and who's accountable, onshore answers cleanly.
Offshore buys you scale. For the high-volume build-and-run that makes up much of an integration estate — where the data isn't sensitive and the work is well-patterned — offshore delivers more capacity per pound, without touching anything that needs protecting.
Hybrid is where most mature programmes land, because it stops treating the choice as all-or-nothing. Senior architecture and governance sit onshore, close to the sensitive decisions. High-volume delivery sits offshore, where it's efficient. And the split is drawn by workstream, so each piece of work runs where it belongs.
The delivery model isn't one lever you pull for the whole programme. It's a line you draw through it — and you get to decide where.
The trick to a hybrid model that doesn't leak is that the split follows sensitivity, not convenience. A few principles keep it honest:
Keep the sensitive decisions and the sensitive data onshore. Architecture that touches regulated systems, anything involving privileged or personal data at rest, and the governance that has to be defensible — these stay close.
Send the well-patterned, low-sensitivity volume offshore. Once the patterns are set and the guardrails are in place, high-throughput build against non-sensitive data scales safely offshore.
Govern both halves the same way. The point of a governed platform is that it doesn't care where the builder sits — the same standards, reviews and controls apply onshore and offshore alike. That's what makes hybrid safe rather than just cheaper.
Revisit the line as the work changes. A workstream that starts sensitive may not stay that way, and vice versa. The split should flex with the work, not calcify.
"Isn't offshore just a security risk full stop?" Only if you draw the line by cost instead of by sensitivity. Offshore delivery against non-sensitive data, on a governed platform with the same controls as onshore, isn't a risk — it's efficiency. The risk comes from routing the wrong work there, which is a design choice you control.
"Won't a hybrid model be harder to manage?" It's harder to manage badly and easier to manage well. A governed platform means one set of standards regardless of where the hands are. What's genuinely hard to manage is a single-location model that's overpaying for half its work or exposing the other half.
You don't need to restructure your whole delivery model to benefit from thinking this way. You need to draw one honest line:
🎯 Split your current work into "needs control" and "needs scale" — most programmes have never done this explicitly.
🛡️ Keep the sensitive design and data onshore; move the well-patterned volume offshore.
🚀 Govern both halves identically, and prove the blend on one workstream before you apply it across the programme.
Guidance reflects delivery experience across onshore, offshore and hybrid models; the right split depends on your regulatory, security and commercial context.
🤝 The ask is a short look at your programme and where the line should sit — so you get the cost of offshore where it's safe, and the control of onshore where it counts.