Public informationWebsite policies and approved public statements.
Controlled evidenceConfidential records shared when relevant and authorised.
Engagement scopeFinal controls recorded in signed schedules and statements of work.
Entity evidence
Corporate registrations
Request the available identity and authority information for the entity proposed to contract and deliver the service.
- Registration record and registered address
- Authorised representative details
- Relevant tax-registration information
Process review
Employment operations
Review how the selected employment model will handle the employee lifecycle and divide responsibilities.
- Employment-document workflow
- Onboarding, leave and HR administration
- Performance, conduct and exit responsibilities
Process review
Payroll and tax administration
Review the proposed payroll cycle, funding model, employee records and administration responsibilities.
- Payroll calendar and funding timetable
- Payslip and reconciliation approach
- Salary-tax and contribution responsibilities
Provider scope
Background screening
Define proportionate checks for the role, location and access profile, subject to notice, consent and provider capability.
- Identity and right-to-work checks
- Employment, reference or qualification checks
- Role-specific screening options
Policy review
Data protection
Review how candidate, employee and client information is collected, accessed, shared, retained and removed.
- Privacy notices and processing purposes
- Access, sharing and retention controls
- Data-processing responsibilities
Control scope
Information security
Select and review the security baseline around devices, identities, access, monitoring and incident escalation.
- Device and endpoint controls
- Identity and access lifecycle
- Incident and offboarding procedures
Asset controls
Equipment and asset management
Review the ownership, assignment, support, inventory, recovery and disposal model for workforce equipment.
- Approved equipment specification
- Asset assignment and inventory records
- Recovery, wipe and disposal process
Site controls
Workplace safety
Review the workplace model and applicable facility, access, safety, power and connectivity arrangements.
- Site and access-control scope
- Power, connectivity and emergency arrangements
- Facility-provider responsibilities
Risk review
Permanent Establishment screening
Assess role authority, local sales, contract activity, supervision and workplace factors before selecting the operating model.
- Role and authority questionnaire
- Customer and contract activity review
- Specialist escalation where required
Exit controls
Secure offboarding
Agree coordinated people, access, device, data and workplace actions before an employee or contractor exits.
- Access-revocation responsibilities
- Equipment recovery and evidence
- Data return, transfer or removal steps
Policy schedule
Insurance
Review the insurance requirements relevant to the selected service and any available policy information.
- Required coverage categories
- Available limits and exclusions
- Client and provider responsibilities
Continuity scope
Business continuity
Review practical resilience requirements for people, power, connectivity, workplace and critical operational support.
- Remote-work and alternate-site options
- Connectivity and power resilience
- Communication and recovery responsibilities
Specialist review
Professional advisers
Identify questions that require qualified legal, tax, employment, privacy or other specialist interpretation.
- Question and jurisdiction defined
- Appropriate adviser review coordinated
- Advice reflected in the agreed scope
Evidence is shared according to relevance, availability, confidentiality and authorisation. Final legal, tax, employment, security and operational responsibilities are governed by signed agreements.