Data Security & Legal Risk
Is my data safe with a team based in Pakistan?
Data security is our primary product — not an afterthought. Every seat in our facility uses endpoint-protected hardware with USB ports disabled via Windows Group Policy, DNS-filtered internet that blocks personal social media and non-work traffic, and CCTV-monitored workstations with 30-day footage retention. Your team member works on your servers via VDI (Virtual Desktop Infrastructure) or VPN, meaning no client data ever rests on a local drive in Pakistan. We provide a signed Data Security Addendum as part of every Master Services Agreement. We are also actively pursuing SOC 2 Type II certification for enterprise clients.
Are there legal risks for my US or UK company?
Our EOR structure is specifically designed to minimise your legal exposure. Annex Talent is the legal employer of record in Pakistan — your firm has no direct employment obligations under Pakistani law, no Pakistani tax registration requirements, and no exposure to local labour law. Our Master Services Agreement is drafted under English or Delaware law and explicitly addresses Permanent Establishment (PE) risk. We recommend every new client has the MSA reviewed by their own legal counsel, which we actively support by providing full documentation. We do not hide potential risks — we build contracts that address them.
How do you handle GDPR / UK GDPR compliance?
Your data never leaves your systems. Your team member accesses your software via VPN or VDI — the data remains on your servers, in your jurisdiction. Pakistan is not an adequacy country under UK GDPR. The lawful mechanism for international transfer in this model is Standard Contractual Clauses (SCCs), incorporated into our Data Processing Agreement (DPA), combined with the VDI-first architecture that ensures data residency in your jurisdiction. This is the same mechanism used by major professional services firms globally. We provide a pre-drafted DPA on request. For regulated entities (FCA-supervised firms, etc.), we can support your compliance team's due diligence with a full technical and organisational measures (TOMs) document.
What if my client or regulator asks where my team is located?
This is worth thinking through carefully before you start. For most UK accounting firms: ICAEW and FRC guidance permits offshore work provided appropriate oversight, quality controls, and data security measures are in place — all of which the Annex model provides. For US firms: offshore accounting and bookkeeping work has no general prohibition. For FCA-supervised or SEC-regulated entities, outsourcing to third parties requires notification and in some cases prior approval — we can support your regulatory notification process. We provide a standard client disclosure template and recommend you review obligations with your compliance officer before commencing.
Operations & Infrastructure
What if the power or internet goes down in Pakistan?
We built the "Iron Dome" infrastructure precisely because Pakistan's grid can be unreliable. Industrial generators sized for full-load operation maintain 100% uptime during load-shedding. UPS systems bridge the gap during generator start-up. Dual commercial-grade fiber connections from separate providers, plus Starlink satellite backup, are all managed via SD-WAN for seamless automatic failover — your team's active VoIP calls and VDI sessions continue uninterrupted when primary connectivity fails. We contractually guarantee uptime in your Service Level Agreement. This is not a promise — it is an engineered outcome.
How does my team member communicate with my existing staff?
Exactly as any remote employee would. Your team member uses your email domain (e.g., sarah@yourfirm.com), your Slack or Teams workspace, your project management tools, and your video conferencing platform. GMT+5 provides 4–5 hours of overlap with UK business hours and 2–3 hours of overlap with US East Coast afternoons. In practice, most clients find the overlap is more than sufficient for daily stand-ups, client calls, and ad-hoc communication. For US West Coast firms, we can arrange adjusted working hours within a reasonable range by agreement.
Who owns the hardware? What happens to it if I terminate?
All hardware is owned by Annex Talent. On termination, we recover the equipment within 5 business days, conduct a secure wipe of the device, and deactivate all client system access. The client has no hardware liability and no logistics responsibility. If the client wishes to terminate mid-pilot, no hardware charge applies — the full cost of hardware procurement and configuration is absorbed by Annex Talent as part of the pilot risk.
Talent Quality & Vetting
How is this different from hiring on Upwork or using a BPO agency?
Three fundamental differences. First, you interview and approve every single person before they join — there is no agency assigning you a stranger. Second, your team member works exclusively for you, uses your email domain, follows your SOPs, and reports directly to your managers — not to us. Third, they work from a physically secure, power-redundant, CCTV-monitored facility with commercial-grade IT security — not from a home with consumer broadband and a personal laptop. A freelancer on Upwork is a contractor who may or may not be available tomorrow. An Annex Talent team member is an employee of your virtual back office.
What vetting do you conduct before presenting candidates?
Four-stage vetting before any CV reaches you. (1) Criminal background check via local police station character certificate — mandatory regardless of seniority. (2) Degree and qualification verification by direct contact with the issuing institution (Pakistan has a significant fake-degree problem that we eliminate at this stage). (3) Recorded English fluency assessment — both written and spoken, reviewed by a second Annex evaluator against a defined rubric. (4) Live technical assessment — bookkeeping exercise in Xero/QBO for accountants, a timed coding challenge for developers, a data exercise for operations candidates — assessed against defined pass criteria. If a candidate does not pass all four stages, they do not appear in your shortlist.
Is the ACCA qualification actually equivalent to UK / US accounting standards?
Yes — and this is not a marketing claim. The ACCA (Association of Chartered Certified Accountants) is a UK-originated professional body with a globally standardised examination curriculum conducted in English. ACCA members in Pakistan sit the same examinations as ACCA members in London, covering IFRS, audit, taxation, and financial management to the same standard. Pakistan has one of the highest concentrations of ACCA-qualified professionals outside the UK — many trained at Big-4 firms (Deloitte, KPMG, EY, PwC all have substantial Pakistan practices). This is not approximate equivalence — it is the same qualification, assessed to the same standard.
Commercial Terms & Engagement
What happens if we want to terminate the engagement?
During the 90-Day Pilot: you can exit any time with zero fees. Annex Talent absorbs the severance and wind-down costs. After the pilot: 30 days written notice. We manage all employee separation under Pakistani labour law — final salary calculation, EOBI deregistration, social security settlement, and system access revocation — within 5 business days. There are no multi-year lock-ins or financial penalty clauses. If you want the team member to continue with you directly (direct hire), a placement fee equivalent to 3 months of the total billing applies — this is standard practice across the staffing industry and protects the investment we made in recruiting and vetting the individual.
What if the team member resigns or doesn't work out?
If a team member resigns within the first 90-Day Pilot period, we provide a replacement candidate at no additional shortlisting cost — the pilot clock resets from the point a replacement starts. After the pilot period, if a team member is terminated for performance reasons, we manage the separation under Pakistani labour law and provide a replacement shortlist within 10 business days. If they resign voluntarily, the same replacement process applies with a 10-business-day shortlist turnaround. We are the employer and take full responsibility for HR events.
Can I scale from one person to multiple team members?
Yes — this is by design. The typical Annex Talent client journey starts with one dedicated seat on the 90-Day Pilot, reaches the Go decision at Day 90, and then adds additional seats as confidence in the model grows. We can support multi-function teams across finance, IT, and operations within the same facility. For teams of 5 or more, we discuss dedicated floor space and custom SLA arrangements. There is no minimum or maximum seat count after the pilot — scaling is on your timeline.
How quickly can you get someone operational?
From JD submission to your first shortlist of 3 pre-vetted CVs: 5 business days. From approved hire to operational workstation (Day 1 of the Pilot): 10 business days. This assumes the selected candidate is available to start promptly, hardware procurement does not hit unusual supply delays, and IT configuration is standard. For highly specialised roles (e.g., Big-4 audit-trained senior manager), the shortlist timeline may extend to 10 business days. We confirm realistic timelines at the feasibility study stage.
Still Have a Question?
We answer every enquiry personally — no chatbots, no auto-responders. Email us directly and we will respond within one business day.