This is the multi-page printable view of this section. Click here to print.
Human Resources
- 1: Code of Conduct
- 2: Conflict of Interest Policy
- 3: Anti-Slavery Policy
- 4: Environmental and Cultural Heritage Policy
- 5: Offboarding of a Contractor Procedure
- 6: Onboarding of a Contractor Procedure
- 7: Onboarding of an Employee Procedure
1 - Code of Conduct
General Expectations
Always treat fellow employees, clients, and suppliers with the utmost respect and courtesy. Interactions should be friendly, professional, and focused on excellent service.
Unacceptable Behaviours
Engaging in any of the following actions may result in disciplinary measures, including reprimand, warning, suspension, or dismissal.
1. Disobeying the Law and Instructions
Examples of things you should consider to remain compliant with the law and Vaxa’s policies include:
- Compliance with Professional Codes: Follow all Professional Codes of Conduct or Ethics relevant to your work.
- Legal compliance: Adhere to all laws related to Vaxa’s operations.
- Company policies: Comply with all Vaxa policies and procedures in this handbook.
- Instructions from management: Carry out any reasonable and lawful instructions from your manager.
- Health and safety: Follow health and safety regulations and do not encourage others to violate them.
- Prohibited items: Do not possess firearms, weapons, illegal drugs, or drug paraphernalia on company property.
2. Respect for Others
- Professional conduct: Treat clients and colleagues with respect. Avoid using threatening, obscene, profane, or abusive language, gestures, or behaviour.
- Violence: Do not engage in physical or verbal violence.
- Disorderly conduct: Refrain from horseplay or disruptive behaviour.
- Discrimination: Do not unlawfully discriminate against anyone.
- Harassment and bullying: Avoid harassing or bullying clients or employees.
- Victimisation: Do not victimise anyone who reports a breach of this code or any other policy.
- Dress code: Wear uniforms if provided, or dress according to Vaxa’s standards if uniforms are not supplied.
3. Integrity
- Conflict of interest: Declare any real or perceived conflicts of interest promptly; see below section on Conflict of Interest.
- Bribery: Report any attempted bribery immediately.
- Confidentiality: Do not disclose any confidential or official information without authorisation.
Reporting of any breaches or concerns in any shape are encouraged. Refer to our Responsible Disclosure Policy for more information.
4. Diligence
- Smoking policy: Do not smoke in areas where it is prohibited.
- Punctuality: Be at your workplace and ready to work at your scheduled start time.
- Timekeeping: Personally clock in and out at the beginning and end of your shift.
- Work ethic: Focus on your duties and avoid wasting time during working hours.
- Substance use: Do not come to work under the influence of alcohol or illegal drugs. Do not bring alcohol or illegal substances onto Vaxa property.
- Internet and technology use: Do not access or share pornography, hate speech, or illegal content using company equipment or personal devices used for work. See the Acceptable Use of Technology Policy for more information.
- Online conduct: Avoid posting offensive, defamatory, threatening, discriminatory, bullying, inappropriate, false, sexist, derogatory, or malicious comments or materials online or on social media.
- Communication: Inform your manager promptly upon completing tasks or if there are any delays.
- Attitude: Maintain a cooperative and positive attitude.
- Personal devices: Do not use personal electronic devices like smartphones, music headsets, wearables, or handheld games during work hours unless authorised.
5. Economy and Efficiency
- Care for company property: Take proper care of Vaxa equipment and tools. Do not neglect or abuse them.
- Theft and damage: Do not wilfully damage, destroy, or steal property belonging to colleagues or Vaxa.
- Honesty: Provide truthful information when requesting leave or other accommodations.
- Attendance: Avoid unexcused absences from work.
- Use of resources: Do not use Vaxa equipment, property, or supplies for personal purposes without prior authorisation.
Conflict of Interest
Avoid any interests, influences, or relationships that might conflict—or appear to conflict—with the best interests of Vaxa or our clients. If your loyalty could be divided, disclose the situation promptly to your manager and remove yourself from any related decision-making processes.
Refer to the Conflict of Interest Policy for more information.
2 - Conflict of Interest Policy
Purpose
The purpose of this Conflict of Interest Policy is to ensure that all employees of Vaxa act in the best interests of both the company and our clients. This policy aims to prevent situations where personal interests could interfere with professional duties and responsibilities, thereby providing assurance to our clients that we diligently and transparently manage potential conflicts on their behalf.
Scope
This policy applies to all employees, contractors, consultants, officers, and directors of Vaxa, covering all interactions with clients, suppliers, competitors, and other stakeholders.
Roles & Responsibilities
| Role | Responsibility |
|---|---|
| Employees | Disclose any actual or potential conflicts of interest promptly. Avoid participating in decisions related to the conflict. Ensure client interests are not compromised. |
| Managers | Receive conflict disclosures, provide guidance, and implement measures to mitigate conflicts. Communicate with clients as necessary to assure them that conflicts are managed appropriately. |
| HR | Maintain records of disclosures, monitor compliance, provide training on conflict of interest matters, and support transparency with clients. |
| Senior Management | Ensure systems are in place to manage conflicts effectively and provide clients with assurance regarding our conflict management practices. |
Policy Statements, Standard, or Procedure
All employees must avoid any interests, activities, or relationships that conflict—or appear to conflict—with the best interests of Vaxa and its clients. The following guidelines must be followed to ensure our clients can trust in our integrity and the impartiality of our services:
Disclosure of conflicts:
- Employees must promptly inform their manager or the HR Department of any actual or potential conflicts of interest, especially those that could affect client interests.
- Disclosures should be made in writing, detailing the nature of the conflict and any potential impact on clients.
Avoidance of participation:
- Employees with a conflict must remove themselves from any decision-making processes related to the conflict, particularly those affecting clients.
- They may provide information or expertise if it benefits Vaxa and the client but should not influence decisions.
Client interests:
- Employees must prioritize the interests of clients above themselves or Vaxa in all business dealings.
- Any conflicts that could adversely affect a client must be managed promptly and effectively to prevent negative impacts.
- Confidentiality of client information must be maintained at all times.
Examples of potential conflicts:
- Financial interests:
- Owning a significant financial stake in a company that does business with Vaxa or its clients.
- Engaging in business transactions with Vaxa or clients for personal gain.
- Personal relationships:
- Supervising or influencing employment decisions about a close friend or family member involved in client-related work.
- Being in a position to affect client projects involving someone with whom you have a close personal relationship.
- External affiliations:
- Holding a position (e.g., advisor, consultant, employee) with a competitor, customer, or supplier that could affect client interests.
- Accepting secondary employment that affects your ability to serve clients effectively.
- Gifts and benefits:
- Accepting gifts, entertainment, or other benefits of more than nominal value from any competitor, customer, supplier, or client.
- Offering or receiving bribes or kickbacks that could influence client-related decisions.
- Acting upon confidential information:
- Using confidential client information for personal gain or to benefit others.
- Disclosing confidential client information to unauthorized parties.
- Financial interests:
Guidelines for Gifts and Entertainment:
- Gifts of nominal value (e.g., promotional items, modest meals) may be accepted if they do not influence, or could be perceived to reasonably influence, business decisions or compromise client interests.
- Any gift or benefit exceeding a nominal value must be reported to the HR Department.
- Cash gifts of any amount are strictly prohibited.
Conflict resolution:
- Upon disclosure, management will assess the situation and determine appropriate actions to protect client interests.
- Possible actions include restructuring job duties, reassigning projects, or other measures to eliminate the conflict. Employees wil not be penalized for disclosing conflicts of interest appropriately.
- Clients will be informed as necessary to maintain transparency and trust.
Client communication:
- When appropriate, clients will be informed of any conflicts of interest that could affect them and the steps taken to manage these conflicts.
- Vaxa commits to maintaining open communication with clients regarding our conflict management practices.
Exceptions
Any exceptions to this policy must be approved in writing by the Managing Director. Requests for exceptions should include a full explanation of the circumstances, justification, and an assessment of potential impacts on clients.
Compliance & Monitoring
Monitoring:
- The HR Department should maintain a register of all disclosed conflicts of interest, including those related to client engagements.
- Regular reviews shall be conducted to ensure compliance with this policy and verify that client interests are protected.
Non-Compliance:
- Violations of this policy may result in disciplinary action, up to and including termination of employment.
- Legal action may be taken if the conflict results in unlawful activities or breaches of client contracts.
Reporting Violations:
- Employees are encouraged to report any suspected violations of this policy, especially those that could affect clients.
- Reports can be made confidentially to the Compliance Officer or through the whistleblower disclosure process detailed here.
Client audits:
- Vaxa may allow clients to audit our conflict of interest management processes as part of contractual agreements or regulatory requirements.
- Audit findings will be addressed promptly to improve our conflict management practices.
References
3 - Anti-Slavery Policy
Purpose
This policy outlines Vaxa’s commitment to ensuring, to the best of our ability, that there is no modern slavery in any part of our business operations or supply chain. We are dedicated to acting ethically and with integrity in all business dealings and relationships, in compliance with the Modern Slavery Act 2018 (Cth).
Scope
This policy applies to all employees, contractors, suppliers, service providers, and any other parties working on behalf of Vaxa.
Roles & Responsibilities
| Role | Responsibility |
|---|---|
| Management | Implement anti-slavery measures and ensure legislative compliance. Include anti-slavery clauses in contracts and assess supplier compliance. |
| Employees | Report any concerns or suspicions regarding modern slavery practices. |
Policy Statement
We are committed to:
- Prohibiting Modern Slavery: Including specific prohibitions against the use of forced, compulsory, or trafficked labour, or anyone held in slavery or servitude, in all our contracts.
- Ethical Expectations: Expecting our service providers, suppliers, and contractors to share our commitment to act lawfully and ethically, ensuring modern slavery does not occur within their organisations or supply chains.
- Due Diligence: Conducting due diligence on suppliers to assess their compliance with anti-slavery measures.
- Training: Providing training to employees on modern slavery risks and indicators.
- Reporting Mechanisms: Encouraging the reporting of any concerns related to modern slavery.
Under the Modern Slavery Act 2018 (Cth) ‘Act’, we are not required to publish a Modern Slavery Statement as we have an annual consolidated revenue of less than $100 million. However, we are committed to ensuring that modern slavery does not occur within our operations or supply chain.
Prohibited Practices
Vaxa explicitly prohibits all employees, workers, contractors, agents, suppliers, and any other parties acting on our behalf from engaging in any of the following practices, in any part of our operations or supply chain:
- Forced labour, child labour and human trafficking: Any form of forced or compulsory labour, child labour, or human trafficking.
- Worst forms of child labour: Hazardous child labour, being work performed by a person under the age of 18 that jeopardises their physical, mental, or moral well-being, including work performed for long hours, during the night, or under other particularly difficult or dangerous conditions.
- Child labour: The employment or engagement of any person below the applicable minimum age for completing compulsory schooling, and in any case not less than 15 years of age (or the applicable local legal minimum age where higher).
- Withholding of identity or immigration documents: Confiscating, destroying, concealing, or otherwise denying workers access to their identity documents, immigration documents, work permits, or other personal documents.
- Discrimination: Discrimination before hiring, on the job, or upon leaving employment on the basis of race and/or colour, sex, religion, political opinion, national extraction, age, HIV/AIDS status, disability, nationality, sexual orientation, family responsibilities, or trade union membership or activities.
- Recruitment fees: Charging workers or potential workers, directly or indirectly, any fees or costs associated with their recruitment or employment.
- Commercial sexual exploitation: Procuring or facilitating commercial sex acts at any time during the length of a work contract.
Worker Protections
Vaxa is further committed to ensuring that:
- Freedom to leave employment: Workers, including migrant workers, may cancel their work contract at any time without financial penalty, subject to giving reasonable notice in accordance with local law or an applicable collective agreement.
- Fair wages: Wages meet applicable host country legal minimum wage requirements or, where no legal minimum wage applies, are aligned with the prevailing wage for the relevant sector.
- Freedom of association: Workers have the right to form and join trade unions of their own choosing, to bargain collectively, and to engage in peaceful assembly, in conformance with local law.
- Transparent work agreements: Workers, including those engaged through recruiters, are provided with detailed and accurate work agreements or equivalent work papers, in a language they understand, prior to commencing work (and prior to relocation, where relocation is required).
- Document and age verification: All workers undergo document checks, including verification of proof-of-age documents, before commencing work, to confirm they are legally permitted to work in accordance with applicable law and Vaxa policy.
Definitions
The term ‘modern slavery’ describes situations where coercion, threats or deception are used to exploit victims and undermine their freedom. Coercion, threats and deception can be explicit or implicit.
The Act defines modern slavery as including eight types of serious exploitation; trafficking in persons, slavery, servitude, forced labour, forced marriage, debt bondage, the worst forms of child labour and deceptive recruiting for labour or services.
The worst forms of child labour means extreme forms of child labour that involve the serious exploitation of children, including through enslavement or exposure to dangerous or hazardous work — that is, work performed by a person under the age of 18 that jeopardises their physical, mental or moral well-being, including work performed for long hours or during the night. The worst forms of child labour does not mean all child work.
Child labour means work performed by a person below the age for completing compulsory schooling, and in general not less than 15 years of age.
Under Australian law, modern slavery is defined in the Act. In the event of any inconsistency between this policy and the Act, the Act will prevail.
Exceptions
No exceptions to this policy are permitted.
Compliance & Monitoring
We will ensure compliance by:
- Regular Audits: Conducting regular audits of our operations and supply chain.
- Supplier Risk Assessments: Requiring suppliers to complete a modern slavery risk assessment prior to onboarding, and at least annually thereafter as part of ongoing supplier engagement.
- Policy Review: Reviewing and updating the policy annually.
- Reporting: Monitoring reports of any concerns related to modern slavery.
References
- Modern Slavery Act 2018 (Cth)
- Vaxa’s Code of Conduct
4 - Environmental and Cultural Heritage Policy
Purpose
This policy outlines Vaxa’s commitment to clearly communicate environmental and cultural heritage expectations, meet legal requirements, and progress beyond compliance towards innovation and excellence. It aims to drive continual improvement in managing matters affecting the environment and cultural heritage.
Scope
This policy applies to Vaxa, its officers, employees, contractors (where applicable), and any other personnel notified that this policy applies to them.
Roles & Responsibilities
| Role | Responsibility |
|---|---|
| Management | Implement and uphold the policy, allocate resources, and set objectives and targets. |
| Employees | Adhere to policies, understand and manage environmental and cultural heritage risks. |
| Contractors | Comply with Vaxa’s environmental and cultural heritage policies and procedures. |
Policy Statement
Vaxa is committed to:
- Developing policies and systems: Establishing, maintaining, and communicating policies, processes, and systems to drive continual improvement in environmental and cultural heritage management.
- Setting objectives and allocating resources: Setting challenging objectives and targets, and allocating resources to achieve our organisational goals related to the environment and cultural heritage.
- Empowering employees: Sustaining a high level of performance by empowering employees to take ownership of environmental and cultural heritage outcomes.
- Partnering with stakeholders: Collaborating with regulators, traditional owners, Indigenous communities, and other stakeholders as appropriate.
- Community engagement: Responding appropriately to community expectations on environmental and heritage matters.
- Environmental protection: Protecting the environment by prioritizing pollution prevention, biodiversity preservation, and sustainable natural resource management.
- Cultural heritage respect: Respecting and protecting Indigenous and non-Indigenous heritage, including active participation and consultation with Indigenous communities.
- Sustainable future: Building a sustainable future through safe, efficient, and sustainable energy solutions.
Vaxa personnel should:
- Adhere to policies: Follow all relevant policies, processes, and systems for environmental and cultural heritage management.
- Risk management: Understand and manage environmental and cultural heritage risks during all phases of their work.
- Lead by example: Demonstrate commitment through actions and dedication to environmental and cultural heritage performance.
- Take action: Address any acts or situations that may result in harm to the environment or cultural heritage.
- Collaborate and communicate: Engage collaboratively to effectively communicate and improve Vaxa’s environmental and cultural heritage performance.
- Support indigenous participation: Encourage and facilitate Indigenous participation in projects and decision-making processes.
Exceptions
Any exceptions to this policy must be approved by senior management and properly documented.
Compliance & Monitoring
Compliance with this policy will be ensured by:
- Regular audits: Conducting regular audits and assessments of environmental and cultural heritage practices.
- Reporting: Recording and reporting any breaches in accordance with applicable policies and procedures.
- Training: Providing training to employees and contractors on environmental and cultural heritage responsibilities.
- Performance reviews: Reviewing environmental and cultural heritage performance against set objectives and targets.
- Legal compliance: Ensuring all activities comply with relevant legislation, regulations, codes of practice, and guidelines.
References
- Vaxa’s Code of Conduct
- Environmental Protection and Biodiversity Conservation Act 1999 (Cth)
- Aboriginal and Torres Strait Islander Heritage Protection Act 1984 (Cth)
- Native Title Act 1993 (Cth)
5 - Offboarding of a Contractor Procedure
Purpose
The purpose of this procedure is to outline the steps to be followed when offboarding a contractor from Vaxa’s systems and applications. It ensures that the offboarding process is conducted securely, efficiently, and in compliance with Vaxa’s policies and legal requirements.
Scope
This procedure applies to all contractors engaged by Vaxa, including temporary staff, consultants, and third-party vendors. It covers the steps to be taken by the IT team and the Onboarding Lead (or designated manager) to remove access to Vaxa’s systems and applications when a contractor’s engagement ends.
Roles & Responsibilities
| Role | Responsibility |
|---|---|
| Contractor | Cooperate with the offboarding process and return any Vaxa-owned assets. |
| HR or Legal | Inform the IT team and Onboarding Lead of the contractor’s end date and provide any necessary documentation. |
| Onboarding Lead | Initiate the offboarding process and ensure all steps are completed. |
| IT | Disable access to M365, revoke session tokens, and remove access from other systems. |
Procedure
Important: Offboarding must be initiated as soon as the contractor’s engagement ends, or as directed by HR or Legal. The Onboarding Lead (or designated manager) is responsible for initiating this process and ensuring all offboarding steps are completed, but will be supported by the IT team.
1. Initiation of Offboarding Process
- Trigger: Offboarding should begin immediately once the contractor’s term is concluded, or upon receipt of a termination request from HR or Legal.
- Responsibility: HR or Legal to inform the IT team and Onboarding Lead of the end date.
- Documentation: Capture the final date of access and reason for offboarding in the contractor’s personnel record.
2. Disable and Remove Access from Microsoft Entra / M365
- Action: Disable the contractor’s M365 account as soon as possible (preferably within 24 hours of termination notice).
- Log in to the Microsoft 365 Admin Centre using an admin account (admin.microsoft.com).
- Navigate to Users > Active Users.
- Locate the contractor’s account and select Block sign-in. This will prevent any further access to M365 services.
- Remove from Groups:
- Open the user’s profile in the Admin portal.
- Under Groups, select Manage groups.
- Remove the contractor from OS_x_Contractors and any other groups granting access to resources.
- Licence Removal:
- While still in the user’s profile, navigate to Licences and Apps.
- Unassign all Microsoft 365 licences, including Business Basic, Business Premium, or any other assigned licence.
- Navigate to Licences and reduce the number of purchases licences to reduce costs.
3. Revoke Session Tokens and Invalidate Access
- Action:
- Visit entra.microsoft.com and log in with an admin account.
- In the Entra/Azure AD portal, under the user’s profile, select Authentication methods and ensure no active sessions remain.
- Use the “Revoke Sessions” option to invalidate all existing refresh tokens, blocking any chance of re-entry.
4. Removal of Access from Other Systems
Cloudflare Access Portal:
- Navigate to Vaxa’s Cloudflare Access administration portal.
- Remove the contractor’s seat and revoke any sessions.
Productive (Project Management Tool):
- The contractor’s account in Productive is tied to their M365 identity.
- With M365 access removed, they will no longer be able to log in.
- Confirm that no direct, non-SSO logins exist.
- Reassign any of the contractor’s tasks, projects, or responsibilities to internal staff. This step is usually performed by the Project Manager or Onboarding Lead
- Remove the licence from the contractor’s account to reduce costs, if required.
Client Sites and Third-Party Services:
- Remove the contractor from any client SharePoint sites, Teams channels, or external portals.
- Revoke permissions from BitWarden, production IT environments (e.g. Google Cloud, AWS), scheduling software (e.g. Cal.com), LMS platforms, or any other services the contractor was granted access to.
- Ensure no residual accounts or API keys tied to the contractor’s identity remain active.
5. Data Retrieval and Handover
- Mailbox and Data:
- If required, preserve the contractor’s mailbox content by placing it on eDiscovery hold (if applicable) or exporting mailbox data for legal and compliance purposes.
- Transfer ownership of any SharePoint documents, Teams files, or OneDrive data to a designated internal staff member. This is usually best done by converting to a Shared Mailbox and assigning access to the relevant person.
- Productive Project Handover:
- Verify that all time entries and expense records are finalised.
- Ensure that any non-completed tasks are reassigned to another user.
6. Hardware and Physical Asset Recovery
- Action:
- If the contractor was issued any Vaxa-owned devices (e.g. laptops, phones, security tokens), arrange for their immediate return.
- Perform a factory reset or secure wipe of returned hardware to remove any residual data.
7. Notification and Confirmation
- Communications:
- HR or Legal to confirm with IT once all steps have been completed.
- Notify the Onboarding Lead that the contractor’s offboarding is finalised.
- Record Keeping:
- Document the completion of offboarding steps in the contractor’s personnel file.
- Retain any necessary access logs or audit reports in line with compliance requirements.
The contractor may be notified with an email to their personal email, similar to the following:
Subject: Vaxa Offboarding Notification
Dear [Contractor Name],
This email is to confirm that your access to Vaxa’s systems and applications has been disabled in line with the conclusion of your engagement. If you have any questions or require further information, please contact [Onboarding Lead’s Name] at [Onboarding Lead’s Email Address].
Thank you for cooperation.
Best regards, [Onboarding Lead’s Name]
Compliance and Monitoring
The Onboarding Lead or IT Manager should periodically review the offboarding process to ensure all steps are followed consistently. Identify any gaps or risks and update this procedure as needed.
Exceptions
If a contractor requires partial offboarding (e.g. retaining access to certain systems for a defined period), ensure it is documented by the Onboarding Lead. Any deviation from this process must be approved by HR or Legal and recorded for audit purposes.
6 - Onboarding of a Contractor Procedure
Purpose
Contractors may be engaged by Vaxa to provide services that are not part of the core business. This procedure sets out the steps to onboard a contractor at Vaxa, including the documentation required and the process for setting up access to systems and facilities. This is important to ensure we’re consistently implementing requirements/controls placed upon contractors e.g. under our Security Policy.
Scope
The scope of this procedure is limited to contractors engaged by Vaxa, usually on a day-rate or similar arrangement. It doesn’t include employees or vendors providing a product. It also doesn’t include the accounting or payment process for contractors e.g. setup in Productive/Xero etc.
Roles & Responsibilities
| Role | Responsibility |
|---|---|
| Contractor | Provide the required documentation to complete the onboarding process, and adopt the required controls placed upon them by Vaxa |
| Onboarding Lead | Ensure the contractor provides all required information and provide this information to IT for setup. |
| IT | Set up the contractor in the required systems and provide access to the required facilities. |
| Legal | Issue the contract to the contractor and ensure it is signed and returned in accordance with the organisational requirements, and requirements provided by the Onboarding Lead |
Procedure
Contractor Engagement
A suitable contractor must be found; the process for finding and engaging a contractor is outside the scope of this procedure. However, in selecting a suitable contractor, one must consider:
- The contractor’s experience and qualifications
- The contractor’s availability
- The contractor’s reputation
- The contractor’s cost
- The contractor’s ability to meet the requirements of the role
Consider whether an NDA is required prior to sharing any sensitive information with the contractor regarding the job.
You should get verbal approval from the contractor on these matters before proceeding to the next step.
Screening
Under our Personnel Security Policy, we are implementing requirements for screening of contractors. Generally, most contractors we engage are classified as Level 1, and so have limited screening requirements.
At the time of writing this procedure, we haven’t implemented checks for Level 2 and above contractors. We endeavour to make this change soon.
Document Exchange
Contract
The first step here is to sign contracts. To do so, we require the following information:
- Contractor details
- If a sole trader:
- Full name
- Phone number
- If a company:
- Company name
- Signatory and witness details for the contract
- Name
- Position
- If no witness is available, then we require a mobile phone number of the signatory
- If a sole trader:
- Contract specifics
- Proposed job title for use in Vaxa systems
- Fees, including specification on structure e.g. fixed fee, daily/hourly rate, and GST inclusive/exclusive
- Scope of Works
- Start and end date
- Any required insurances, otherwise standard insurances will be required
- Optionally, a custom restraint period otherwise 3 months will be applied
- Optionally, place of work otherwise we’ll assume their office/as directed by Vaxa
- Optionally, key personnel / designated personnel
- Optionally, headshot photo for use in Vaxa systems
- Internal signatory/witness details
- In line with Vaxa policy, signatories must be a Director; specify the Director who will sign the contract
- Any client SharePoint sites the contractor will be working on
- Any project budgets the client will need access to in Productive (usually to track time/expenses against)
- Who the contract will report to i.e. who is the Manager
Provide this information the Legal team, who will issue the contract. The contract shall be sent to Vaxa’s internal signatory/witness first for vetting, and only once signed will it be sent to the contractor for signing.
To doIs there a structured form we could create for this information, to make it easier for all the information to be provided at once?
Remember, signed contracts are automatically filed away into the Contract Register via the Vaxa Link integration.
Insurances
The contractor must provide evidences of the required insurances.
If this was customised in the contract, then defer to the contract. Otherwise, the standard insurances required are:
- Public liability insurance @ $10m
- Professional indemnity insurance @ $2m
- Workers compensation for the contractor’s employees (if applicable)
Vaxa requires copies of these insurances to be provided before the contractor can commence work.
To doWhere should we store copies of these insurances?
IT Setup
IT setup cannot commence until contracts are signed, per our Security Policy.
Once the contract is signed, Legal shall inform the IT team will be notified to set up the contractor in the required systems. The IT team will reference the contract and onboarding information to set up the contractor in the required systems.
Entra / M365 accounts
The first step is to create a new user in M365/Entra. This will take the format of:
- Name: as defined in contract/onboarding information
- Position: as specified in contract
- Phone number: as specified in contract
- Email:
first.last@vaxagroup.com - Licence: M365 Business Basic
- This provides basic access to email, Teams, SharePoint, and online Office apps (but not desktop apps).
- This is sufficient for most contractors, but if they require more access, then the IT team will need to be informed.
- By default, we won’t issue access to any Client Sites, so if the contractor requires access to a Client Site, then the IT team will need to be informed.
We first create the account within the Admin portal:
- Visit admin.microsoft.com and log in with an admin account
- In the left-hand menu, click on
Users, thenActive Users - In the toolbar, click
Templatesand selectContractor (Business Basic)orContractor (Business Premium)depending on the level of licensing required - Fill in the details like first name, email, etc, then at the bottom of the pane, click
Add user- This will automatically issue a licence to the user, but you may need to double check we have enough licences purchased.
- Find the newly created user in the list of Active users, and select it.
- Assign the contractor’s manager (usually the Onboarding Lead).
- In the pane that appears, under
GroupsclickManage groups - Use the
Assign membershipsbutton to assign access toOS_x_Contractorsgroup at a minimum, and any other required groups.
We then need to setup authentication for the contractor within Entra:
- Visit entra.microsoft.com and log in with an admin account
- In the left-hand menu, click on
Users, thenAll Users, and click on the newly created contractor user - Click on
Authentication methodsin the left-hand menu, thenAdd authentication method - In the pane that appears, select the
Temporary access passmethod and configure it as follows:- TAPs are limited to up to 24 hours. You should make it as short as possible, but long enough for the contractor to receive the email and set up their account.
- You can delay the start time if the contract isn’t due to start for a while but make sure you communicate this to the contractor.
- One-time use is OK, but generally not required; usually we leave it set to
No.
- Click
Addto finalise the TAP creation. - Save the TAP code into a Bitwarden Send and copy the link.
We then need to inform the contractor of their new account and how to set it up. To do so:
- Fetch the contractor’s personal email address (not the Vaxa one) and draft a new email to them using the below template.
- Send the following email to the contractor, and CC the Onboarding Lead and IT team.
Subject: Setting up your Vaxa account
Hi [Contractor Name], welcome aboard.
Your Vaxa account has been setup and just requires a few final setup steps from you, stepped out in these instructions. Please note this is a time-sensitive process so please complete it as soon as possible.
Your Temporary Access Pass is available here: [Bitwarden Send Link]
Once you’ve setup your account, you can access Productive (our time tracking and project management tool) via Cloudflare Access here: vaxagroup.cloudflareaccess.com. Simply sign in with your new Vaxa account, then click the tile called Productive.
We’ve also provided you access to:
- [List any other systems the contractor has access to e.g. client site]
If you have any issues, please contact reach out to me directly.
Warm regards,
The contractor will receive an email with the onboarding instructions, temporary access pass, and IT’s contact details. The temporary access pass cannot be issued for more than 24 hours.
IT will assign the contractor to the OS_x_Contractors group in M365. This provides basic levels of access to SSO-linked systems, and some Sharepoint sites etc.
Productive
By being assigned to the OS_x_Contractors group, the contractor will automatically be given access to Productive. This is our project management tool, and the contractor will be able to log their time and expenses here. IT will provide instructions on how to use Productive.
Accounts in Productive are only issued upon first sign-in, so the contractor must sign in, then IT will be able to assign them to the correct projects. These instructions will be provided in the onboarding email.
Other systems
The contractor will be advised of our Cloudflare Access portal for apps at vaxagroup.cloudflareaccess.com. This is where they can access other systems including Productive.
Noted limitations
By default, the contractor will not have access to:
- Client Sharepoint sites (except those specified)
- BitWarden
- Production IT environments (e.g. Google Cloud, AWS)
- Scheduling software (e.g. Cal.com)
- LMS
Exceptions
Some contractors may require different onboarding procedures. If this is the case, the Onboarding Lead should work with the contractor to determine the best course of action. This should be documented in the onboarding documentation.
Compliance & Monitoring
The Onboarding Lead is responsible for ensuring this procedure is followed for each relevant contractor.
We don’t yet have artifacts in place to monitor compliance with this procedure. This is a gap we need to address.
To doWhat artifacts could we put in place to monitor compliance with this procedure?
References
7 - Onboarding of an Employee Procedure
Purpose
This procedure establishes a standardized and compliant process for onboarding employees at Vaxa, whether they are casual, part-time, or full-time. It ensures consistent implementation of:
- Australian employment law obligations (Fair Work Act 2009)
- ISO27001 information security requirements
- DISP insider threat management controls
- Personnel screening and background check requirements
- System access and identity management controls
This procedure is critical to ensuring we properly vet, onboard, and integrate new employees while managing insider risk and maintaining compliance with our legal and regulatory obligations.
Scope
This procedure applies to all employees engaged by Vaxa, including:
- Full-time employees: Permanent staff working standard full-time hours
- Part-time employees: Permanent staff working regular but reduced hours
- Casual employees: Staff engaged on an as-needed basis with casual loading
This procedure does not cover:
- Contractors (see Onboarding of a Contractor Procedure)
- Vendors or suppliers providing products/services
- Volunteers or unpaid interns
Roles & Responsibilities
| Role | Responsibility |
|---|---|
| Employee | Provide required documentation to complete the onboarding process, complete mandatory training, and adopt required controls and policies |
| HR Lead | Manage the employment contract process, Xero setup, superannuation enrolment, Fair Work compliance, and ensure all administrative requirements are met |
| Hiring Manager | Define role requirements, determine screening level, conduct interviews, provide onboarding context to IT and HR, and manage probationary period reviews |
| IT | Set up the employee in required systems, provision access based on role and security level, provide devices as required, and deliver IT orientation |
| Legal | Review employment contracts for compliance, ensure Fair Work Act adherence, manage any employment-related legal risks |
| Security Officer | Oversee background screening process, conduct security awareness training, ensure DISP and ISO27001 compliance, monitor insider threat indicators |
Procedure
Position Approval & Role Definition
Before commencing recruitment, ensure:
- Budget approval has been obtained for the position
- Position description is current and accurate, including:
- Role title and reporting line
- Key responsibilities and deliverables
- Required qualifications and experience
- Employment type (casual/part-time/full-time)
- Salary range or wage rate
- Working arrangements (office/remote/hybrid)
- Screening level is determined based on the role’s access requirements:
- Level 2 (Standard): Most employees with typical system access
- Level 3 (Sensitive Access): Employees with access to sensitive information, financial systems, or who could cause significant reputational damage
- Level 4 (Executive): Directors and senior leaders with strategic decision-making authority
See the Personnel Screening Policy for detailed screening level criteria.
Candidate Selection
Initial Recruitment
- Advertise the position through appropriate channels
- Review applications against selection criteria
- Conduct initial screening interviews
- Perform preliminary reference checks
- Shortlist candidates for detailed assessment
Pre-Offer Considerations
Before extending an offer, consider whether:
- An NDA is required prior to sharing sensitive information during the interview process
- The candidate requires any workplace adjustments or accommodations
- There are any conflicts of interest that need to be managed (see Conflict of Interest Policy)
Background Screening
Under our Personnel Screening Policy, all employees must undergo comprehensive background screening via our approved provider, Certn. The screening level determines the depth of checks required.
All employment offers must be conditional on successful completion of background screening.
Level 2 (Standard) - Mandatory Checks
All employees at Level 2 and above must undergo:
- 100 points of ID verification: Passport, driver’s license, birth certificate, or equivalent
- Right to work in Australia: Citizenship, permanent residency, or valid work visa
- 5-year address history: Verified and cross-referenced against sensitive countries
- National police check: Must be less than 12 months old at time of engagement
- Character references: Two references verified and documented
- Referee checks: Professional references from previous employers
- Social media assessment: Review of publicly available social media profiles
- Qualification and experience verification: Verification of claimed credentials directly with issuing institutions
Level 3 (Sensitive Access) - Additional Checks
In addition to Level 2 checks, Level 3 employees require:
- Employment history verification: Detailed verification including Defence-related work (if applicable)
- Credit check: Basic public record credit check (mandatory for those with financial system access)
- Professional membership verification: Direct verification with professional bodies where membership is required for the role
Level 4 (Executive) - Additional Checks
In addition to Level 2 and 3 checks, Level 4 employees require:
- ASIC checks: Banned & Disqualified Persons, Enforceable Undertakings Register, and Australian Directorships
- Comprehensive credit check: Detailed financial history assessment
- Enhanced employment history: Comprehensive verification of all previous roles and responsibilities
Screening Process
- Hiring Manager confirms screening level requirement with Security Officer
- HR Lead initiates screening via Certn once candidate accepts conditional offer
- Candidate provides required documentation and consents to screening
- Certn conducts checks and provides outcome report
- Security Officer reviews screening outcomes and approves or raises concerns
- Only upon successful screening can final employment offer be confirmed
Note: Screening must be completed before the employee’s start date. No system access or onboarding can commence without successful screening completion.
Employment Offer & Contract
Conditional Offer Letter
Once a suitable candidate is identified and preliminary checks are positive, issue a conditional offer letter including:
- Position title and classification
- Employment type (casual/part-time/full-time)
- Proposed salary/wage (including casual loading if applicable)
- Superannuation contribution details (currently 11.5%, increasing to 12% from 1 July 2025)
- Leave entitlements (varies by employment type - see below)
- Probationary period (6 months standard)
- Proposed start date
- Reporting manager
- Working arrangements and location
- Condition: Offer subject to satisfactory background screening and reference checks
Employment Contract
Once screening is successfully completed, Legal will prepare the employment contract. The following information is required:
Employee Details:
- Full legal name
- Date of birth
- Residential address
- Contact phone number
- Email address (personal)
- Emergency contact details
- Tax File Number (TFN)
- Superannuation fund details
Employment Specifics:
- Position title for Vaxa systems
- Employment type (casual/part-time/full-time)
- Salary/wage and payment frequency
- Hours of work (for part-time) or minimum engagement (for casual)
- Superannuation fund and contribution rate
- Leave entitlements based on employment type
- Probationary period terms (6 months)
- Notice period requirements
- Place of work and working arrangements
- Any specific conditions or requirements
- Applicable Modern Award or Enterprise Agreement
- Optionally: headshot photo for use in Vaxa systems
Internal Details:
- Direct manager/supervisor
- Any client SharePoint sites the employee will require access to
- Project budgets in Productive the employee needs access to
- System access requirements (e.g., BitWarden, production environments, finance systems)
- Device requirements (laptop, phone, etc.)
Provide this information to Legal, who will prepare the contract. The contract shall be sent to the employee for signing, and once returned, the onboarding process can proceed.
Signed contracts are automatically filed in the Contract Register via the Vaxa Link integration.
Employment Type Considerations
Full-Time Employees:
- Standard 38 hours per week (or as specified in contract)
- Full annual leave entitlement (4 weeks per year, accruing progressively)
- Full personal/carer’s leave entitlement (10 days per year, accruing progressively)
- Entitled to public holidays without loss of pay
- Notice period as per Fair Work Act or contract (typically 1-4 weeks)
- Eligible for all employee benefits and programs
Part-Time Employees:
- Regular guaranteed hours (e.g., 20 hours per week)
- Pro-rata annual leave based on hours worked
- Pro-rata personal/carer’s leave based on hours worked
- Entitled to public holidays (pro-rata)
- Notice period as per Fair Work Act or contract
- Eligible for employee benefits (may be pro-rata)
Casual Employees:
- Casual loading (typically 25%) in lieu of leave entitlements
- No annual leave or personal/carer’s leave
- Not entitled to paid public holidays (receive loading instead)
- Minimum notice periods may not apply (check Modern Award)
- May convert to permanent after 12 months (Casual Conversion provisions under Fair Work Act)
- System access and training may be limited to essential requirements only
Pre-Start Administrative Setup
Once the contract is signed, HR Lead commences administrative setup before the employee’s start date.
Xero Payroll Setup
- Create new employee record in Xero
- Enter personal details (name, DOB, address, contact details)
- Record TFN and tax-free threshold election
- Set up superannuation details (fund name, member number, contribution rate)
- Configure pay template:
- For full-time/part-time: ordinary hours, salary rate
- For casual: casual hourly rate with loading
- Set up leave entitlements (if applicable)
- Record bank account details for salary payments
- Assign to appropriate pay calendar
- Configure any automatic deductions or allowances
Required Documentation
Ensure the employee provides the following before commencing:
- Tax File Number Declaration (ATO form)
- Superannuation Standard Choice Form (if choosing their own fund)
- Bank account details for salary payments (BSB, account number, account name)
- Proof of identity (certified copy of passport, driver’s license, or birth certificate)
- Work eligibility documents:
- Australian citizens: Birth certificate or passport
- Permanent residents: Visa evidence
- Temporary visa holders: Valid work visa with appropriate conditions
- Academic qualifications (original certificates or certified copies)
- Professional memberships (if relevant to role)
- Working with Children Check (if role requires contact with minors)
- Driver’s license (if role requires driving)
Insurance & Workers Compensation
- Ensure employee is covered under Vaxa’s workers compensation insurance
- Add employee to professional indemnity policy if required
- Update public liability insurance if employee numbers change significantly
IT & Systems Setup
IT setup cannot commence until the employment contract is signed, per our Information Security Policy.
Once the contract is signed, HR Lead notifies IT to commence system provisioning. IT will reference the contract and onboarding information provided by the Hiring Manager.
Entra / M365 Accounts
Step 1: Create User in M365 Admin Portal
- Visit admin.microsoft.com and log in with an admin account
- Navigate to
Users→Active Users - Click
Templatesand selectEmployee (Business Premium)template - Complete the form with:
- First name and last name (as per contract)
- Display name (First Last)
- Username:
first.last@vaxagroup.com - Position title (as per contract)
- Department (as applicable)
- Office location (if relevant)
- Mobile phone (as provided)
- Click
Add userto create the account- This automatically assigns an M365 Business Premium license
- Verify sufficient licenses are available before creation
- Locate the newly created user and assign their manager (usually the Hiring Manager)
- Navigate to
Groupsand clickManage groups - Assign to
OS_x_Employeesgroup at minimum - Assign to any additional role-based groups:
OS_x_Finance(for finance team members)OS_x_Technical(for engineers and technical staff)OS_x_Consultants(for client-facing consultants)- Client site access groups (as specified by Hiring Manager)
Step 2: Configure Authentication in Entra
- Visit entra.microsoft.com and log in with an admin account
- Navigate to
Users→All Usersand select the new employee - Click
Authentication methodsin the left menu - Click
Add authentication method - Select
Temporary Access Passand configure:- Lifetime: As short as practical but long enough for employee to set up (recommend 24 hours)
- Start time: Immediate or delayed to start date
- One-time use: Set to
No(allows multiple setup attempts if needed)
- Click
Addand copy the TAP code - Save the TAP into a Bitwarden Send with:
- Expiration matching TAP lifetime
- Deletion on first access for security
- Copy the Bitwarden Send link for the welcome email
Step 3: Send Welcome Email
Draft an email to the employee’s personal email address (not their Vaxa email, as they can’t access it yet) and CC the Hiring Manager and IT team:
Subject: Welcome to Vaxa - Setting up your account
Hi [Employee Name],
Welcome to the Vaxa team! We’re excited to have you joining us on [Start Date].
Your Vaxa account has been created and requires a few setup steps from you. Please follow these instructions to set up your authentication.
Important: This is a time-sensitive process - your Temporary Access Pass expires in 24 hours, so please complete the setup as soon as possible.
Your Temporary Access Pass: [Bitwarden Send Link]
Once you’ve completed the authentication setup, you’ll be able to access:
- Email and Microsoft 365: Your Vaxa email is
first.last@vaxagroup.com - Productive: Our project management and time tracking tool - access via Cloudflare Access
- Teams: For communication and collaboration
- SharePoint: For document management and client sites
[If applicable: We’ve also provisioned your access to:
- [List any additional systems, client sites, or specialized tools]]
Before your first day, please:
- Complete the authentication setup (instructions linked above)
- Set up your email signature (template will be provided on your first day)
- [Complete any pre-start training modules assigned in the LMS - we’ll send separate instructions]
If you have any questions or encounter any issues, please don’t hesitate to reach out to me directly.
We look forward to seeing you on [Start Date]!
Warm regards, [IT Team Member Name] IT Team, Vaxa
System Access Provisioning
By being assigned to the OS_x_Employees group, the employee will automatically receive access to core systems. Additional access is provisioned based on role and screening level:
All Employees:
- M365 Services: Email, Teams, SharePoint, OneDrive, Office apps (online and desktop)
- Productive: Project management and time tracking (accessed via Cloudflare SSO)
- Cloudflare Access Portal: vaxagroup.cloudflareaccess.com
- BitWarden: Password manager (all employees receive access)
- LMS: Learning Management System for training and compliance
Role-Based Access (as specified by Hiring Manager):
- Client SharePoint sites: Specific client workspaces as required
- Productive project budgets: View/edit access to project budgets for time/expense tracking
- Scheduling software (Cal.com): For client-facing staff requiring appointment scheduling
- Production IT environments: Engineers only (Google Cloud, AWS, Azure, etc.) - requires Level 3 screening minimum
- Finance systems (Xero, banking): Finance team only - requires Level 3 screening minimum
Access Approval Process:
- Standard access (as above): Automatic via group membership
- Privileged access (production systems, finance, etc.): Requires evaluation per Evaluation of Privilege Requests Procedure
Device Provisioning
For eligible employees, IT will provision corporate devices:
Full-Time Employees:
- MacBook (model based on role requirements) - standard issue
- Mobile phone if required for role
- Security key/hardware token for Level 3/4 employees
- Peripherals as required (monitor, keyboard, mouse, headset)
Part-Time Employees:
- Device provisioning based on role requirements and hours worked
- Generally provided for 20+ hours per week roles
Casual Employees:
- Device provision rare - usually BYOD arrangements
- If provided, must be returned immediately upon cessation
Device Setup:
- Configured per macOS Software Management policy
- Enrolled in MDM (Mobile Device Management)
- Standard software suite installed
- Added to asset register
- Asset tag applied
- Employee signs device acceptance form
Security & Compliance Onboarding
Security onboarding is mandatory for all employees and must be completed before they can access systems containing OFFICIAL or higher classified data.
Mandatory Security Training
All employees must complete the following training, ideally before their start date or on day one:
Information Security Awareness (LMS module)
- Understanding Vaxa’s security framework
- ISO27001 and DISP requirements overview
- Your role in maintaining security
Data Classification Training (LMS module)
- Understanding data classification levels
- Applying protective markings
- Handling requirements by classification
- See Data Classification Policy
Insider Threat Awareness (In-person or recorded briefing)
- Understanding insider risk indicators
- DISP compliance requirements
- Reporting obligations and processes
- See Insider Threat Statement
Privacy & Confidentiality (LMS module)
- Personal information handling
- Privacy Act obligations
- Client confidentiality requirements
- See Privacy Policy
Cyber Incident Response (LMS module)
- Recognizing security incidents
- Reporting procedures
- Phishing and social engineering awareness
- See Cyber Incident Response Plan
Policy Acknowledgments
All employees must read and acknowledge the following policies before commencing work. HR will track acknowledgments and maintain records:
- Code of Conduct - behavioural expectations and standards
- Information Security Policy - overarching security framework
- Data Classification Policy - data handling requirements
- Privacy Policy - personal information management
- Conflict of Interest Policy - disclosure obligations
Additional policy acknowledgments for specific roles:
- Privileged Access Policy - for Level 3/4 employees with elevated access
- Finance-related policies - for those with financial system access
Security Briefings
The Security Officer (or delegate) will conduct:
Initial Security Briefing (Day 1 or Week 1):
- Identity and access management (IAM) requirements
- Multi-factor authentication (MFA) setup and usage
- Password manager (BitWarden) setup and best practices
- Physical security (office access, visitor management, clean desk)
- Reporting security incidents and concerns
- Social engineering and phishing awareness
- Secure communication practices
DISP Insider Threat Briefing (if handling Defence-related work):
- Enhanced insider threat awareness
- Reporting obligations specific to Defence contracts
- Security clearance requirements (if applicable)
- Contact procedures for Defence Security incidents
First Day Induction
The Hiring Manager coordinates the first day experience to ensure the employee feels welcomed and prepared.
Welcome & Orientation
Morning:
- Welcome by Hiring Manager and team
- Office tour (if office-based) including:
- Workstation/desk allocation
- Kitchen and amenities
- Meeting rooms and bookable spaces
- Emergency exits and assembly points
- First aid facilities
- Introduction to team members and key stakeholders
- Overview of probationary period expectations
IT Equipment Handover:
- If devices were shipped to employee: Unboxing and setup assistance
- If devices issued in-office: Handover and asset acknowledgment signing
- Login credentials verification
- MFA device setup confirmation
- Email signature configuration
- Calendar and scheduling setup
Operational Setup
Productive Training:
- How to log time to projects
- Expense claiming process
- Project budget visibility
- Time approval workflows
- Mobile app usage (if applicable)
Communication Tools:
- Teams channels and etiquette
- Email best practices
- SharePoint site navigation
- File storage structure (OneDrive vs SharePoint vs local)
- Video conferencing setup and protocols
Work Processes:
- Project management workflows
- Client communication protocols
- Documentation standards
- Code of conduct practical applications
- Escalation procedures
Administrative Completion
Health & Safety:
- WHS induction
- Emergency procedures and evacuation plan
- First aid officer identification
- Incident reporting procedures
- Ergonomic workspace setup
- Mental health and wellbeing resources
Physical Access:
- Building access cards/keys issued
- Parking arrangements (if applicable)
- After-hours access procedures (if required)
- Visitor sign-in process
Additional First Day Tasks:
- Employee photo for directory (if not provided earlier)
- Completion of any outstanding forms
- Super fund enrolment confirmation
- Banking details verification
- Emergency contact confirmation
Probationary Period Management
All employees are subject to a 6-month probationary period during which performance and suitability are assessed.
30-Day Review
Conducted by: Hiring Manager
Purpose: Early check-in and course correction
Review areas:
- Settling in and cultural fit
- System access is complete and functional
- Initial training completion status
- Early performance indicators
- Any support needs or concerns
- Access rights are appropriate for role
Documentation: Brief notes in personnel file
90-Day Review
Conducted by: Hiring Manager with HR input
Purpose: Mid-probation formal assessment
Review areas:
- Performance against initial goals
- Competency development
- Training and development needs
- System access audit - confirm appropriate privileges
- Cultural alignment and team integration
- Any performance concerns requiring action
Documentation: Formal review meeting notes, performance feedback record
6-Month Probationary Review
Conducted by: Hiring Manager with HR Lead
Purpose: Confirm permanent employment or extend/terminate probation
Review areas:
- Overall performance against position requirements
- Achievement of probationary goals
- Competency levels
- Cultural fit and values alignment
- Attendance and conduct
- Recommendation: Confirm, extend, or terminate
Outcomes:
- Confirm employment: Probation successfully completed, becomes permanent employee
- Extend probation: Further time needed (typically 3 months), with clear improvement plan
- Terminate employment: Not suitable for role, notice given per Fair Work requirements
Documentation: Formal probation completion letter or extension/termination notice
During Probation
Reduced notice periods apply:
- First month: 1 day notice (either party)
- After first month: 1 week notice (either party)
Access Reviews:
- IT conducts access audit at 30 days to confirm appropriate provisioning
- Any changes to access based on evolving role understanding
Ongoing Compliance & Monitoring
Access Reviews
Per our IAM Policy, access must be regularly reviewed:
- Privileged access (Level 3/4, production systems, finance): Quarterly review by System Owners
- Standard access (general employees): Bi-annual review
- Role changes: Immediate access review and re-provisioning
Continuous Monitoring
The Security Officer monitors for insider threat indicators including:
- Unusual system access patterns
- Data exfiltration attempts
- Policy violations
- Performance issues or behavioural changes
- Financial distress indicators
- Unexplained affluence
See Insider Threat Statement for reporting procedures.
Ongoing Training & Awareness
- Annual security awareness refresher: All employees (LMS)
- Data classification updates: As policy evolves
- Role-specific training: As technologies and processes change
- Privacy Act updates: When legislation changes
- Ad-hoc security bulletins: As threats emerge
Re-Screening
Per the Personnel Screening Policy:
- Level 3/4 employees: Periodic re-screening at intervals determined by risk assessment
- All employees: May be re-screened if:
- Significant role change requiring elevated access
- Security concern arises
- Extended international travel to sensitive countries
- Required by client contracts
Performance Management
- Regular 1-on-1 meetings with manager
- Annual performance reviews
- Development plans and training opportunities
- Promotion and progression pathways
- Documented performance concerns and improvement plans
Exceptions
Some employees may require modified onboarding procedures due to:
- Remote/interstate location requiring different logistics
- Specialized roles with unique system requirements
- Expedited onboarding for urgent business needs (screening still mandatory)
- Client-specific requirements or clearances
Exception Process:
- Hiring Manager documents the exception requirement and justification
- HR Lead reviews for compliance implications
- Security Officer assesses for security risks
- Documented approval required before proceeding
- Exception and mitigating controls recorded in personnel file
Emergency Access: In rare cases where urgent access is required before full onboarding completion:
- Screening must still be successfully completed
- Contract must be signed
- Temporary limited access may be granted pending full provisioning
- Security Officer must approve emergency access requests
- Full onboarding must be completed within 2 weeks
Compliance & Monitoring
Responsibilities
- HR Lead: Monitors completion of all administrative onboarding steps, tracks policy acknowledgments, maintains onboarding documentation
- IT: Monitors system provisioning timeliness, tracks access requests, conducts access reviews
- Security Officer: Monitors screening completion, tracks security training completion, oversees DISP compliance
- Hiring Manager: Ensures timely onboarding progression, conducts probationary reviews, provides onboarding experience feedback
Metrics & Reporting
The following metrics should be tracked quarterly:
- Time from offer acceptance to screening completion
- Time from contract signing to first day access provisioning
- Security training completion rates (target: 100% within first week)
- Policy acknowledgment completion rates (target: 100% before day one)
- Probationary period success rate
- Employee onboarding satisfaction scores
Audit & Review
- Annual procedure review: Ensure process remains compliant with evolving legislation and standards
- Quarterly compliance audit: Sample recent onboardings for procedural adherence
- Access provisioning audit: Verify Access aligns with approved requests and role requirements
- Screening compliance check: Confirm all employees have appropriate screening for their level
Non-Compliance
Failure to follow this procedure may result in:
- Delayed employee start dates
- Compliance violations (Fair Work, privacy, security)
- Insider threat risks
- Audit findings
- Regulatory penalties
Non-compliance should be reported to HR Lead and Security Officer for remediation.
References
- Personnel Screening Policy - Defines screening levels and requirements
- Information Security Policy - Overarching security framework
- IAM Policy - Identity and access management requirements
- Code of Conduct - Employee behavioural expectations
- Data Classification Policy - Data handling requirements
- Insider Threat Statement - DISP insider threat awareness
- Onboarding of a Contractor Procedure - Related procedure for contractors
- Evaluation of Privilege Requests Procedure - Privileged access approval process
- Fair Work Act 2009 - Australian employment legislation
- Privacy Act 1988 - Australian privacy legislation
- AS 4811:2022 - Employment Screening standard