Due Diligence and Ongoing Monitoring

 View Only
  • 1.  Due Diligence - Human Resources Vendors

    This message was posted by a user wishing to remain anonymous
    Posted 02-26-2021 01:02 PM
    This message was posted by a user wishing to remain anonymous

    Hello, 


    Would someone be able to give me some information regarding due diligence for Human Resources. For example I'm in the process of reviewing HudsonMann as we will be utilizing their product for AAP process. What are some of the documents I would need to request from them? 

    Thanks!


  • 2.  RE: Due Diligence - Human Resources Vendors

    Posted 03-03-2021 10:03 AM

    Some might mistake this engagement as a simple consulting arrangement. However, HR firms are almost always dealing with sensitive data (your employee data). As such, those HR firms must meet or exceed the same information security and privacy protection standards for which your company would be held accountable. I would suggest obtaining documents detailing Information Security and Privacy, including: 

    • Attestations or certifications for security controls, processing integrity, confidentiality, and privacy of their data systems. These certifications might include an SSAE SOC2 Type II, ISO/IEC27001 Certifications, Penetration Testing reports, or other Third-Party Audits.
    • Information Security Program Documents, including policies and a list of controls
    • Technical and procedural measures for network protection through a firewall
    • Data Security policies that cover:
      • Data classification and encryption methodologies
      • Data loss prevention
      • Data retention and destruction
      • Documented incident response policy, standards, and processes
      • Data security and confidentiality protections against threats or hazards
      • Data privacy and confidentiality

    Additionally, to create an effective AAP (Affirmative Action Plan) process, HR Firms must follow robust compliance requirements. A significant reason to pursue an AAP would be to enable regulatory reporting, such as an OFCCP (Office of Federal Contract Compliance Programs) report. I would want to review an inventory of the regulations they will consider for the AAP, making sure they are up to date.  

    I would also request a recent copy of their general compliance policy and employee compliance training plan. The compliance policy and training plan should have been reviewed and or updated within the last 12 months.

    Those are my thoughts. Does anyone have anything to add?



  • 3.  RE: Due Diligence - Human Resources Vendors

    Posted 03-06-2021 03:51 AM
    Hello,
    If I understand the question right, the query is regarding documents to be asked from Human Resource function.
    The key documents I would ask are:

    1. Background and criminal check policies. Random samples that I would choose to test effectiveness of controls.
    2.Information Security training and awareness plan.
    3.Infomation security training content.
    4. Organization structure.
    5. Disciplinary process and samples if any.
    6. Policy regarding (timeliness of) employee termination and transfer-outs. Random samples to test control effectiveness.

    Hope this helps.

    Cheers
    Midhu