Human Resource Security Manual¶
HUMAN RESOURCE SECURITY MANUAL
Contents¶
• Document collection as part of on-boarding process 4
• Terms and Conditions of employment 5
• Screening: Background verification (BGV) process 6
• Off boarding process for exit employees 6
• Termination process of absconding employees 7
Version History¶
| Version Number |
|
|
|
|
|---|---|---|---|---|
| 0.1 |
|
|
|
|
| 0.2 |
|
|
|
|
| 0.3 | 28/Aug/2026 | Knowledge kernel, AI/agents, control alignment | Knowledge steward | [Name] |
Objectives¶
The objective of this manual is to outline the procedures, guidelines, and responsibilities regarding the protection of sensitive information. The policy will aim to ensure that all HR activities are carried out in a secure and controlled manner, thus reducing the risk of security breaches and other security incidents. The purpose of this manual is to integrate information security requirements in the Company’s HR processes including pre-employment, during employment and post-employment.
Scope¶
The HR Security Policy applies to all employees and covers all aspects of HR operations, including recruitment, employee onboarding, personal data management, and termination procedures in-order to maintain an effective work environment.
Requirement¶
• Prior to employment¶
Prerequisite¶
The Recruitment Team shall collect the following documents to extend the offer to the candidate:
For US:
-
Photo Identification (i.e. passport, driver's license) o Educational Certificates o Pay slips from the last 3 months, Last offer or relieving letter or experience letter.
-
Background Check Authorizations
For India:
-
Resume o Aadhar Card o Pan Card
-
Educational Certificates
-
Photo Identity Proof – Passport / Photo ID with Self- attestation o Pay slips from the last 3 months, Last offer or relieving letter or experience letter.
Interview Process¶
Candidates who meet the requirements should go through the Level 1 and Level 2 interview process to proceed with the Offer Letter.
Release of the Offer Letter¶
The Recruitment Team shall review the internal salary band for deciding the Cost To Company (CTC) of the candidate and will do the basic pre-employment verification checks. Upon the final CTC approval from Delivery Head and CHRO, the HR team will release the offer with the salary breakup to the candidate.
Confirmation on Date of Joining¶
The Recruitment Team shall follow up with the candidate to understand the earliest possible dates for joining. Date of joining is notified to the HR Team after the confirmation received on the same from the candidate.
Acceptance of Offer Letter from Employee¶
Candidate’s acceptance of the offer letter is mandatory to close the pre-joining formalities. The Recruitment Team follows up with the candidate in case of no confirmation.
• Document collection as part of on-boarding process¶
- The HR team will ensure the candidate submits the below set of documents.
For India:
|
|
|---|---|
| Identity |
|
| Education |
|
| Employment (where applicable) |
|
For Global:
|
|
|---|---|
| Identity |
|
| Education |
|
| Employment (where applicable) |
|
- The document collection and screening checks for onboard employees will be completed within
15 business days from the day of joining and if drug tests are required it can take up to 20 days. In case of falsification of documents or misrepresentation of data, HR will take disciplinary action as per the policy.
- For BGV, a third- party vendor holds the records for us within their database.
Screening Process - Risk Flag and Results
| Risk Flag | BGV Status |
|---|---|
| Green |
|
| Amber |
|
| Red |
|
-
Employees whose screening has not been completed or whose screening results in a risk flag (Red) or amber status shall require appropriate approvals from CHRO for the onboarding process to continue.
-
Relevant documents, including but not restricted to copy of proof of identity, copy of employment contract, if applicable, are retained for a minimum period of 7 years from the date on which employee stops providing services. o In case of Disciplinary issues, relevant actions will be taken according to the Misconduct Disciplinary Action policy and process.
• Terms and Conditions of employment¶
-
Employees joining will sign the Non-Disclosure Agreement (NDA) and/or the Proprietary Information and Invention Assignment Agreement (“PIIA”) and shall adhere to all the terms & conditions and the organization’s policies and procedures.
-
Terms and Conditions of employment shall be agreed and acknowledged by employees before and after joining.
• During employment¶
• Internal transfers¶
-
The Training Needs for all the Roles in every Department shall be identified.
-
The Corporate IT Head/Country IT Manager periodically shall review the training needs. o The IT Department shall maintain and publish a Training Plan and Calendar periodically. o All training programs must have a process of capturing formal feedback for the same.
-
All Details related to the Trainings conducted should be documented for retention requirements.
-
The Corporate IT Head shall Review and Monitor the training details and feedback on a periodic basis.
-
the employees undergo the Information Security Awareness Program at the time of induction and annually. o The Information Security Awareness Programme is developed in line with tecciance ISMS policies and procedures.
-
Yearly training calendar, records of the training conducted, including attendance and assessments are maintained by CISO.
• Screening: Background verification (BGV) process¶
o Majority of the employees are done with the BGV check, whereas some are with exception. o BGV will be done for all tecciance hires.
• Training¶
-
Every new joiner receives an induction training/session within 5 business days of onboarding.
-
All new joiners are required to undergo training on information security awareness. In subsequent years, each employee must take a refresher course and get certified with a minimum score (80%) o Every employee is made aware of the organizations’ security policy/ code of conduct policy/ acceptable usage policy including ISMS roles and responsibilities. o There is a formal disciplinary process for employees who have committed a security breach.
-
Employee records are maintained in the company’s HR portal.
• Employee off boarding¶
• Off boarding process for exit employees¶
| S. No | Activities | Responsibility |
|---|---|---|
|
||
| 1 | Employee to submit resignation request through email notifying reporting manager, delivery manager, delivery head and HR Team. |
|
| 2 | Once reporting Manager approval is provided, the exit process shall be initiated by the HR Team and the
|
HR Team |
| 3 | Exit Clearance from all support functions to be obtained on or before the last working day and get sign-off in the Exit
|
Employee |
| 4 | System Access and Physical Access will be revoked within 24 hours of employee exit from the organization. | IT Team |
• Termination process of absconding employees¶
Those who avail unapproved leave for 3 continuous working days and do not intimate the manager or HR by any means will be treated as absconded. HR will try to reach out to the employee over the phone or personal email as per records and will request immediate reporting to work. Access shall be revoked on the 5th day of an employee Absconding while in parallel attempting to establish conduct with the employee or initiating the termination procedures if the employee is not contactable.
Disciplinary action¶
Any violation of the Policies and Procedures and breach to information security shall be reported to Chief Operation Officer (COO) & CHRO. tecciance Leadership Team shall be informed of the violations on a regular basis.
-
Disclosure of tecciance information to unauthorized people through deliberate or careless action. o Performing actions that compromise integrity of tecciance information.
-
Unauthorized access or use of tecciance’s assets (e.g., Hacking, Network intrusion, Spam, spreading virus or malware)
-
Theft, destruction, defacement, or misuse of tecciance information assets.
-
Deliberate / Willful damage to tecciance property
-
Committing security breaches and violating the Information Security and Privacy Policies and Procedures
The above examples are illustrative of the type of behavior that will not be permitted but are not intended to be an all-inclusive listing. All employees shall undergo Disciplinary action as mentioned in the HR Disciplinary Process.
Refer ‘tecciance – HR – Misconduct & Disciplinary Action Policy’.