Governance and IP — The Unglamorous Work That Keeps a Center Safe
Entity structure, data protection, and controls aren't the exciting part of a GCC, but they're what stands between you and a very bad quarter.
The launch photos from a new Global Capability Center are always the same — a ribbon, a leadership team, a wall with the company logo. What you don't see in the photo is the entity structure, the data-protection framework, and the control environment underneath it all. That's the part I get paid to worry about, and it's the part that determines whether the center is an asset or a liability.
Get the entity right, because it's hard to redo
The legal structure you choose shapes your tax position, your transfer-pricing obligations, and how painful it will be to change course later. In India, for instance, the choice of entity type and the way you document intercompany service agreements has direct consequences for how transfer pricing gets assessed — and transfer pricing is one of the more common flashpoints in tax audits for captive centers. This isn't a place to save money on advice. Set it up properly the first time, with local counsel who does this for a living, because unwinding a badly structured entity is slow, expensive, and visible to regulators.
The same care applies to the intercompany agreements that govern who owns what. If your center is developing software, analyzing data, or creating anything, the contracts need to state unambiguously that the IP belongs to the parent. I've reviewed setups where this was assumed rather than documented, and "assumed" is not a word you want to rely on when ownership of a valuable codebase is questioned.
Data protection is now a first-order concern
A finance or engineering center touches sensitive data by definition — customer records, financial details, source code, sometimes regulated personal data crossing borders. Depending on where your data subjects live and where your center sits, you may be dealing with GDPR, India's data-protection regime, sector rules, or all of them at once. Cross-border data flows in particular need a deliberate design, not a hope that nobody asks.
Practically, that means access controls scoped tightly to roles, encryption in transit and at rest, logging you can actually audit, and a clear answer to the question "who can see this data and why." When a client tells me everyone on the team can access everything because it's easier, I know we have work to do before anything sensitive lands there.
Controls more broadly are where governance becomes real. Segregation of duties in finance processes, maker-checker workflows, documented approvals — the same discipline you'd expect in any well-run operation, now applied across a distance and a time zone. The distance is exactly why you can't be casual about it. You're not walking past someone's desk to sanity-check the work.
The thread tying all of this together is alignment to HQ. A center runs safely when its risk appetite, its policies, and its ethical standards are genuinely the parent's — not a diluted local interpretation. That comes from real oversight: a governance cadence that connects the center to headquarters, internal audit that actually visits, and leaders on both sides who talk often enough to catch drift early.
None of this shows up in the ribbon-cutting photo. But two years on, the centers that invested here are calm, auditable, and trusted with more and more valuable work — while the ones that skipped it are firefighting a data incident or arguing with a tax authority. I know which photo I'd rather be in.
