Background Verification for IT, ITES, and Software Companies in India: Data Security and Compliance Guide
Background verification for IT, ITES, and
software companies in India is a data security and regulatory compliance
requirement because every employee, from a junior developer to a senior
architect, has access to proprietary source code, client databases, customer
personal information, and production systems, making identity verification
through government databases like the Income Tax Department (PAN), Election
Commission (Voter ID), and EPFO (UAN) via platforms like Compose1 Verify a
foundational control that satisfies SOC 2, ISO 27001, and client contractual
obligations while protecting the company from resume fraud, moonlighting risks,
and insider threats.
India’s IT and ITES sector employs over 5
million people directly and millions more indirectly. The industry includes IT
services companies (TCS, Infosys, Wipro, HCL Tech, and thousands of mid-size
firms), product and SaaS companies, BPO and KPO operations, captive centres
(Global Capability Centres) of multinational corporations, IT startups, and
freelance and contract technology workers. Each of these segments handles
sensitive data that belongs to clients, customers, or the company itself.
The defining characteristic of IT
employment is access. A software developer has access to source code worth
crores of rupees in development investment. A database administrator can view,
modify, or export millions of customer records. A BPO agent handles customer
personal information, financial data, and health records. A DevOps engineer has
production server access and deployment credentials. A QA engineer sees
unreleased product features. A data analyst works with business intelligence
that competitors would pay for.
Every one of these individuals is a
potential insider threat if their identity is unverified and their background
is unknown. The IT industry learned this the hard way through high-profile
incidents of data theft by employees operating under false credentials, resume
fraud that placed unqualified individuals in critical technical roles, and
moonlighting employees who leaked proprietary information to competitors.
Why IT
Companies Cannot Skip Background Verification
Client Contracts
Mandate It
Enterprise clients, especially in
BFSI, healthcare, government, and regulated industries, include background
verification requirements in their service agreements with IT vendors. A
typical enterprise MSA (Master Service Agreement) specifies that all personnel
with access to client data must be background-verified before access is
granted, that verification records must be maintained and available for audit, and
that the IT vendor bears liability for any security incident involving an
unverified employee.
For IT services companies, a single
client contract can be worth Rs 10 crore to Rs 500 crore annually. Losing that
contract because of a verification gap in the deployed team is a business
catastrophe. Having downloadable PDF verification reports from Compose1 Verify for every team member
provides audit-ready documentation that satisfies client compliance requirements
within minutes.
Compliance
Frameworks Require It
SOC 2 (Service Organization Control 2):
The Trust Services Criteria under SOC 2 include requirements for personnel
security. Companies undergoing SOC 2 audits must demonstrate that they verify
employee identities and conduct background checks as part of the hiring
process. An IT company without systematic verification will face findings in
its SOC 2 audit report, which clients read carefully.
ISO
27001: The Information Security Management System
standard includes controls related to human resource security. Annex A controls
specify pre-employment screening requirements. ISO 27001-certified companies
must have documented verification procedures for all employees with access to
information assets.
GDPR
and Data Protection: IT companies handling data of
European citizens under GDPR, or Indian citizen data under DPDP Act 2023, must
implement appropriate security measures, including verifying the identities of
personnel who access personal data.
PCI
DSS: IT companies that process, store, or transmit
payment card data must comply with PCI DSS requirements, which include
background checks for personnel with access to cardholder data environments.
Resume Fraud Is
Rampant in IT
The IT industry has one of the highest
rates of resume fraud in India. Studies and industry reports consistently
indicate that 30 to 60 percent of IT resumes contain some form of
misrepresentation. This ranges from inflated experience (claiming 5 years when
the actual is 3), fabricated employer names (listing companies the candidate
never worked at), inflated designations (claiming “Lead” or “Architect” when
the actual role was “Junior Developer”), and fake educational qualifications.
The consequences of resume fraud in IT
are not just financial. An underqualified developer writing code for a banking
application creates security vulnerabilities. An inexperienced database
administrator managing a healthcare database creates compliance risks. A
fabricated “Senior Architect” leading a project creates delivery failures.
UAN verification through EPFO records is
the most effective check against experience fraud. The EPFO database shows
actual employers, contribution dates, and member IDs. A candidate claiming 8
years at three companies whose UAN shows 3 years at one company has been caught
before they write their first line of code.
Data Breach Cost Is
Enormous
The average cost of a data breach in
India is estimated at Rs 17 to Rs 19 crore (based on IBM’s Cost of a Data
Breach Report adapted for Indian markets). For IT companies, the cost includes
direct financial losses, client contract penalties, regulatory fines,
reputational damage, customer churn, and remediation expenses.
While not every breach involves an
insider, insider threats (employees with legitimate access who misuse it)
account for a significant percentage of data security incidents. An insider
operating under a false identity is the worst-case scenario because they cannot
be traced after the incident.
The IT
Company Verification Framework
Check 1:
PAN Verification (All Employees)
Why: Confirms identity against the
Income Tax Department database. PAN is the foundational identity document that
links to the employee’s financial and tax identity. Every IT employee, from
intern to CTO, should have a verified PAN.
What
it reveals: Registered name, date of birth, PAN
status (active, inactive, deactivated).
Compliance
value: PAN verification satisfies the identity
confirmation requirement in SOC 2, ISO 27001, and client MSA background check
clauses. The verification report from Compose1
Verify provides timestamped, downloadable proof of the check.
How
to do it: Enter PAN on Compose1 Verify. Result in 2
to 3 minutes. Cost: Rs 50 to Rs 200.
Check 2:
Voter ID Verification (All Employees)
Why: Cross-confirms identity through a
second independent government database. The combination of PAN + Voter ID
provides dual-database identity confirmation, which is the standard that
enterprise clients and auditors expect.
What
it reveals: Registered name, age or date of birth,
father’s or husband’s name, constituency details.
Cross-record
analysis: Compose1 Verify automatically compares
PAN and Voter ID results. Matching name and date of birth across both databases
provides high-confidence identity confirmation. Mismatches are flagged for
review.
How
to do it: Enter Voter ID in the same Compose1 Verify
session. Result in 2 to 3 minutes. Cost: Rs 50 to Rs 200 additional.
Check 3:
UAN Employment History (Critical for IT Hiring)
Why: This is the most important
verification check for IT companies after identity confirmation. UAN
verification through EPFO records reveals the candidate’s actual formal
employment history, including employer names, contribution dates, and member
IDs.
What
it catches:
Experience inflation: Candidate claims 7
years. UAN shows 4 years of EPFO contributions. The 3 missing years are either
fabricated or informal employment.
Employer fabrication: Candidate claims
they worked at a well-known IT services company. UAN shows no EPFO record from
that company.
Designation mismatch: While UAN does not
show designations, the employment timeline and employer names can be
cross-referenced with the resume to spot inconsistencies.
Moonlighting detection: Overlapping EPFO
contributions from two employers during the same period indicate concurrent
employment, which violates most IT company policies.
Who
needs this: Every IT hire where experience
determines the role, salary band, or client deployment. This includes
developers, testers, DBAs, DevOps engineers, architects, project managers,
business analysts, and team leads.
How
to do it: Enter UAN on Compose1 Verify. Result in 5
to 30 minutes. Cost: Rs 200 to Rs 500.
Check 4:
DL Verification (Field and Travel Roles)
Why: IT companies with field engineers,
client-site consultants who drive to locations, or company vehicle users need
DL verification.
Who
needs this: Field service engineers, implementation
consultants who travel to client sites, employees using company-provided
vehicles, IT support staff who travel between office locations.
How
to do it: Enter DL number and DOB on Compose1
Verify. Result in 2 to 5 minutes. Cost: Rs 50 to Rs 200 additional.
IT
Industry-Specific Fraud Scenarios
Scenario
1: The Developer with Fabricated Experience
A mid-size IT services company in Pune
hires a “Senior Java Developer” at Rs 18 LPA based on a resume claiming 6 years
at two well-known IT companies. The developer is deployed on a BFSI client’s
core banking project. Within 2 months, code reviews reveal fundamental gaps.
The developer struggles with design patterns, writes insecure code, and cannot
handle the complexity expected at their experience level. The client raises
quality concerns. A belated UAN check reveals 2 years at one small company (not
the two listed on the resume) with a significant gap year in between.
Cost: Rs 3 lakh in salary paid during the
2-month period, potential contract penalties from the client for quality
issues, cost of replacing the developer mid-project, and reputational damage
with the client.
UAN verification costing Rs 300 would
have exposed the fabricated experience before the offer letter was issued.
Scenario
2: The BPO Agent Who Stole Customer Data
A BPO operation in Hyderabad processes
insurance claims for a US healthcare client. A process agent with access to
customer PII (names, SSNs, addresses, medical records) downloads 15,000
customer records over 3 months. The data theft is discovered during a routine
audit. Investigation reveals the agent used a PAN belonging to a relative. The
agent’s actual identity is unknown. The real person whose PAN was used has no
connection to the BPO.
The BPO faces HIPAA violation liability
(the US healthcare client’s compliance obligation flows down to the vendor),
contract termination, potential legal action in US courts, and the cost of
notifying 15,000 affected customers.
PAN + Voter ID verification through Compose1 Verify would have caught the
identity mismatch (the PAN name would not match the agent’s actual identity)
before any system access was granted.
Scenario 3:
The Moonlighting Architect
A SaaS product company in Bangalore
hires a “Solution Architect” at Rs 45 LPA. The architect has access to the
product roadmap, proprietary algorithms, and client deployment architectures.
Six months in, the company discovers that the architect is simultaneously
employed at a competing SaaS company, working on a similar product. Proprietary
architectural decisions made at the first company appear in the competitor’s
product within weeks.
The company’s trade secrets are
compromised. Legal action is complex because the architect’s dual employment
was not detected at hiring.
UAN verification showing overlapping EPFO
contributions from two employers would have flagged the concurrent employment.
While moonlighting may have started after joining, it establishes a pattern
that can be re-verified periodically.
Scenario
4: The IT Support Technician with a Fake Identity
An IT company outsources desktop
support to a staffing agency. One of the deployed technicians has admin access
to employee laptops and the company’s internal network. After 4 months, the
company detects unauthorized data transfers from executive laptops.
Investigation reveals the technician used a fake PAN and a borrowed Voter ID.
The technician’s real identity is unknown. Sensitive business communications,
financial projections, and M&A data have been exfiltrated.
Independent PAN + Voter ID verification
of agency-deployed technicians would have caught the identity fraud before
network access was granted.
Verification
Across IT Company Types
IT Services Companies
IT services companies deploy teams on
client projects. Each team member’s verification status directly affects client
compliance.
All
employees: PAN + Voter ID before offer letter
issuance. UAN for all experienced hires.
Client-deployed
staff: Verification must be completed before client
site access or VPN credentials are issued. Maintain per-client verification
portfolios showing that every deployed team member is verified. Share PDF
reports with clients during audits.
Contract
and agency staff: Require staffing agencies to
provide document numbers for all deployed personnel. Run independent
verification through Compose1 Verify. Do not rely on the agency’s verification
claims.
Annual
cost for a 500-employee IT services company: 500 x
Rs 500 (PAN + Voter ID + UAN) = Rs 250,000. With 25 percent annual attrition
(125 new hires), ongoing annual cost is approximately Rs 310,000.
BPO and KPO Operations
BPO operations have high employee
volumes, high attrition, and direct access to client customer data.
All
agents and associates: PAN + Voter ID before first
day on the production floor. No exceptions. An agent who handles customer data
without verified identity is a data breach waiting to happen.
Team
leads and managers: Add UAN verification to confirm
experience claims.
Process: Integrate verification into the recruitment pipeline. After
conditional offer acceptance, collect PAN and Voter ID numbers. Run
verification on Compose1 Verify
before the joining date. If verification fails or raises flags, investigate
before granting system access.
Scale
considerations: A BPO with 2,000 agents and 60
percent annual attrition processes approximately 3,200 verifications per year.
At Rs 300 per verification, the annual cost is Rs 960,000. For a BPO billing Rs
50 to Rs 100 crore annually, this is less than 0.1 percent of revenue.
Product and SaaS
Companies
Product companies have smaller teams
but higher per-employee risk because each employee has deeper access to
proprietary technology.
All
technical staff: PAN + Voter ID + UAN. Developers,
testers, DevOps engineers, data scientists, and product managers all have
access to the product’s source code, architecture, and customer data.
Founding
team hires: In early-stage startups, every hire is
critical. A CTO with fabricated experience or an engineering lead with a fake
identity can destroy the company. UAN verification is not optional for senior
hires.
Annual
cost for a 100-person SaaS company: 100 x Rs 500 =
Rs 50,000. Negligible for any funded startup.
Global Capability
Centres (GCCs)
GCCs of multinational corporations
operate under the parent company’s global compliance framework, which
invariably includes background verification requirements.
All
employees: PAN + Voter ID + UAN. The parent
company’s compliance team typically mandates comprehensive verification.
Verification
timing: Complete all verification before the
employee’s start date. GCC compliance audits are rigorous, and gaps in
verification timing are flagged.
Documentation: Maintain verification records in the format required by the parent
company’s compliance framework. PDF reports from Compose1 Verify are compatible
with most global documentation standards.
Building
an IT Company Verification Policy
Pre-Employment
Verification Gate
No employee receives system access
(email, VPN, source code repository, database, production environment) until
PAN + Voter ID verification is completed. No experienced hire receives a final
offer letter until UAN verification confirms their employment history. These
are zero-exception policies.
Verification
Timing in the Hiring Pipeline
The ideal sequence is: conditional
offer issued, candidate accepts, candidate provides PAN and Voter ID numbers
and UAN, HR runs verification on Compose1 Verify within 24 to 48 hours,
verification passes, system access is provisioned on the joining date.
If verification raises flags (name
mismatch, fake PAN, fabricated employment history), the conditional offer is
withdrawn before the candidate joins. This prevents the cost and disruption of
terminating an employee after they have already started.
Contract
and Agency Staff Verification
IT companies increasingly use contract
staff from staffing agencies. These contractors often have the same system
access as permanent employees. The verification policy must cover all
contractors with the same rigour as permanent hires.
Require staffing agencies to provide
document numbers (not just photocopies) for all deployed personnel at least 5
business days before their start date. Run independent verification through
Compose1 Verify. Issue system credentials only after verification passes.
Periodic Re-Verification
Annual PAN re-verification catches
deactivations and status changes. For employees in sensitive roles (database
administrators, security team, finance system users), consider more frequent
re-verification. UAN re-verification annually helps detect moonlighting that
may have started after the employee joined.
Client Audit Readiness
Maintain a verification register
showing every employee’s PAN verification date and result, Voter ID
verification date and result, UAN verification date and result (for experienced
hires), and PDF report locations.
For client-deployed teams, maintain
separate verification portfolios per client project. When a client audit
request arrives, the verification documentation should be available within 24
hours.
Incident Response
Integration
When a data security incident occurs,
the first personnel action is to verify the involved employee’s verification
file. If the employee was properly verified, the reports demonstrate due
diligence. If the employee was not verified or verification was incomplete,
this becomes a separate compliance issue requiring immediate remediation and potentially
affects the company’s legal position.
Cost
Analysis: IT Company Verification
Cost of Verification
PAN + Voter ID per employee: Rs 100 to
Rs 400. UAN per experienced hire: Rs 200 to Rs 500 additional. DL per field
engineer: Rs 50 to Rs 200 additional. Annual re-verification: Rs 100 to Rs 300
per employee.
Cost of Not Verifying
One resume fraud hire (salary
overpayment + replacement cost): Rs 5 to Rs 20 lakh. One data breach incident:
Rs 17 to Rs 19 crore (industry average). One client contract lost due to
compliance gap: Rs 1 to Rs 100 crore in annual revenue. One SOC 2 audit
finding: Remediation cost Rs 5 to Rs 50 lakh, plus client confidence impact.
One moonlighting-related IP theft: Legal costs Rs 10 to Rs 50 lakh, plus
competitive damage.
The Business Case
For a 500-employee IT company spending
Rs 3 lakh annually on verification, the cost per employee per year is Rs 600.
The average annual CTC of an IT employee is Rs 8 to Rs 25 lakh. The
verification cost is 0.02 to 0.08 percent of payroll. This is not a line item
worth debating. It is a compliance and security control that pays for itself by
preventing a single incident.
Frequently Asked
Questions
Is
background verification mandatory for IT companies in India?
There is no single Indian law that
says “IT companies must verify all employees.” However, the combined effect of
client contractual requirements (MSAs that mandate verification), compliance
frameworks (SOC 2, ISO 27001, PCI DSS), data protection laws (DPDP Act 2023),
and industry best practices makes verification effectively mandatory for any IT
company that works with enterprise clients or handles sensitive data. Compose1 Verify provides the digital
verification infrastructure to meet these requirements.
How do I
verify a developer’s claimed experience?
UAN verification through Compose1
Verify checks the candidate’s EPFO records, which show actual employers and
contribution dates. If a developer claims 6 years at three companies, the UAN
check reveals the actual employment timeline. Cost: Rs 200 to Rs 500. Time: 5
to 30 minutes. This single check catches experience inflation, employer
fabrication, and concurrent employment.
Should IT
companies verify contract staff from agencies?
Absolutely. Contract staff typically
have the same system access as permanent employees. They access the same source
code repositories, databases, and production environments. Require agencies to
provide document numbers for all deployed personnel. Run independent
verification through Compose1 Verify before granting system access. Cost: Rs
100 to Rs 400 per contractor. The alternative is giving unverified individuals
access to your client’s data.
How does
verification help with SOC 2 and ISO 27001 compliance?
SOC 2 Trust Services Criteria and ISO
27001 Annex A controls require pre-employment screening and identity
verification. Verification reports from Compose1 Verify provide timestamped,
downloadable PDF documentation that auditors accept as evidence of compliance.
Maintaining a verification register for all employees demonstrates systematic
implementation of personnel security controls.
How much
does IT employee verification cost?
PAN + Voter ID costs Rs 100 to Rs 400
per employee. Adding UAN for experienced hires costs Rs 300 to Rs 900 total. No
subscription, no contract, no minimum volume on Compose1 Verify. For a
200-employee IT company, annual verification cost (including attrition
replacements) is Rs 80,000 to Rs 250,000. For context, that is less than the
monthly salary of one senior developer.
Can
startups afford background verification?
At Rs 100 to Rs 400 per hire,
verification is affordable from the first employee. A 20-person startup spends
Rs 2,000 to Rs 8,000 to verify the entire team. Compose1 Verify has no
subscription fee or minimum commitment. For startups especially, where every
hire is critical and a bad hire can derail the company, verification is not a
luxury. It is survival.
How do I
detect moonlighting through verification?
UAN verification shows EPFO
contribution records. Overlapping contributions from two employers during the
same period indicate concurrent employment. While not all moonlighting involves
EPFO-registered employment, a significant portion does. Periodic UAN
re-verification (annually or semi-annually) through Compose1 Verify helps
detect moonlighting that started after the employee joined.
What
verification do BPO agents need?
Every BPO agent who accesses client
customer data needs PAN + Voter ID verification at minimum. BPO agents handle
sensitive personal information (names, addresses, financial details, health
records) daily. An agent operating under a false identity who steals customer
data is untraceable. Verification costs Rs 100 to Rs 400 per agent. For a BPO
with 500 agents and 50 percent attrition, annual verification cost is
approximately Rs 225,000.
Every
Line of Code and Every Data Record Depends on Verified People
IT companies protect their systems
with firewalls, encryption, access controls, and security monitoring. But the
most fundamental security control is knowing who your people are. Every
developer, every tester, every DBA, every BPO agent, every contractor with
system access should have a government-database-verified identity and a
confirmed employment history.
Digital verification makes this standard
achievable at IT industry scale. Minutes per check. Under Rs 500 per employee.
Audit-ready PDF reports for every compliance framework. The alternative is
trusting your source code, your client data, and your company’s reputation to
people whose identities you have not confirmed.
Visit
compose1.com/verify to verify your IT workforce. PAN, Voter ID,
UAN, and DL checks in minutes. From code to compliance, know who has access.