ÃÛ¶¹ÊÓÆµ has three external staff categories (I, II & III) and prior to vetting checks commencing, the candidate should be assigned to a category. Once the staff category is identified, the applicable vetting checks can be selected. The criteria for each category is based on access to ÃÛ¶¹ÊÓÆµ premises and systems; the detailed information below will help determine the correct staff category.Â
Category I
This category means those external staff having
- a GPN or ÃÛ¶¹ÊÓÆµ Logon ID; AND
- access to ÃÛ¶¹ÊÓÆµ systems[1]/ÃÛ¶¹ÊÓÆµ valuables (e.g. treasury room); AND/OR
- access to ÃÛ¶¹ÊÓÆµ's confidential information
[1]ÃÛ¶¹ÊÓÆµ systems means any software, hardware, telecommunications or other systems or equipment owned by ÃÛ¶¹ÊÓÆµ or a ÃÛ¶¹ÊÓÆµ affiliate or licensed, leased or provided as a service by a third party to ÃÛ¶¹ÊÓÆµ or a ÃÛ¶¹ÊÓÆµ affiliate.
Staff in this category
- must be registered in ÃÛ¶¹ÊÓÆµ's HR system and therefore have a GPN (Groupwide Personnel Number)
- may not necessarily have access to a ÃÛ¶¹ÊÓÆµ building
Groups concerned are
- staff augmentation onsite or offsite, billable (contractor and offshore development center with ÃÛ¶¹ÊÓÆµ Logon)
- staff augmentation onsite, non-billable (supplier account manager with ÃÛ¶¹ÊÓÆµ Logon)
- managed services onsite or with ÃÛ¶¹ÊÓÆµ Logon (driven by delivery of a service)
- auditors engaged by ÃÛ¶¹ÊÓÆµ to fulfil services (e.g regulatory requirements)
- professional services onsite or with ÃÛ¶¹ÊÓÆµ Logon (consultants, advisory, audit, legal, facility management for sensitive infrastructure)
Category II
Suppliers who engage ÃÛ¶¹ÊÓÆµ category II staff are contractually bound to warrant that any and all such staff have completed background screening before providing services to ÃÛ¶¹ÊÓÆµ. For this category of staff, suppliers are not required to follow ÃÛ¶¹ÊÓÆµ staff vetting process as no onboarding on ÃÛ¶¹ÊÓÆµ system takes place. Background screening requirements may differ depending on the service provided to/roles performed for ÃÛ¶¹ÊÓÆµ.
This category includes external staff with
- access to confidential / strictly confidential information, data or physical documents, AND
- no access to IT applications / systems / infrastructure (without ÃÛ¶¹ÊÓÆµ Logon) or sensitive infrastructure, AND
- may have limited access to ÃÛ¶¹ÊÓÆµ premises for facility management duties or construction work
Staff of this category
- have no ÃÛ¶¹ÊÓÆµ Logon
- are not registered in the ÃÛ¶¹ÊÓÆµ HR system and therefore do not have a GPN
- could have limited access to a ÃÛ¶¹ÊÓÆµ building via access control system (CH only)
Groups concerned are
- Professional services offsite and without ÃÛ¶¹ÊÓÆµ Logon (consultants, advisory, audit, legal, business process outsourcing, software as a service) with access to confidential / strictly confidential information
- Construction workers
- Event staff onsite or offsite
Category III
This category includes external staff with
- unsupervised physical access to ÃÛ¶¹ÊÓÆµ premises, AND
- no access to IT applications / systems / infrastructure (without ÃÛ¶¹ÊÓÆµ Logon) or sensitive infrastructure, AND
- no access to confidential / strictly confidential information, data or physical documents
Staff of this category
- must be registered in the ÃÛ¶¹ÊÓÆµ HR system and therefore must have a GPN
- have no ÃÛ¶¹ÊÓÆµ Logon
Groups concerned are
- Staff augmentation onsite, non-billable (supplier account manager without ÃÛ¶¹ÊÓÆµ Logon; badge holder)
- Managed services onsite and without ÃÛ¶¹ÊÓÆµ Logon
- Professional services without ÃÛ¶¹ÊÓÆµ Logon (facility management)
- Benefits services onsite (hair dressers / fitness trainers / dry-cleaning worker / massage services / physiotherapists / dentists / doctors / etc.)
- Business University trainers
Visitors
Generic definition for a visitor: An individual who does not require a GPN and/or full-time access to ÃÛ¶¹ÊÓÆµ premises. Visitors are not classified as external staff and in general, visitors are not vetted per se unless local requirements dictate otherwise (ID check or similar). Access to secure areas should be controlled and clients/visitors (non ÃÛ¶¹ÊÓÆµ GPN owners) must be escorted by ÃÛ¶¹ÊÓÆµ authorized staff at all times.
Please note: If any person without a GPN requires access to a ÃÛ¶¹ÊÓÆµ building, this person must be escorted if in restricted/non-public ÃÛ¶¹ÊÓÆµ premises and will be considered as a visitor. Also, access cards will only be delivered to persons having an active GPN, which means that such staff would be category I or III.