ERMSRecords & compliance

Employee Record Management System

The service record, and the proof behind it.

The permanent personnel record: service book, appointment and posting history, verified documents, statutory and compliance records, retention schedules that actually execute, legal hold, and an audit lineage that answers questions decades after everyone involved has left. The record of truth that HRMS writes to and reads from.

SpecificationERMS
Modules
8
Purpose
System of record, not system of process
Retention
Per record class, scheduled and executed
Immutability
Append-only history with reason codes
Answers
Pension, verification, RTI, inspection, litigation
Pairs with
Education HRMS — one staff identity

Built for

  • Universities and affiliating bodies
  • Government-aided colleges and schools
  • Education trusts with long-serving staff
  • Multi-campus institutions
  • Institutions facing inspection, RTI, or pension queries

§ 01

The questions asked years later

An institution's hardest personnel questions are never about this month. They are about 1998. A retired teacher's pension calculation needs their exact date of joining, every posting, every increment, and every period of leave without pay. An RTI request asks for the selection committee's recommendation for an appointment made eleven years ago. A court asks whether a promotion followed the seniority list in force at the time. A regulator asks for evidence that qualifications were verified before appointment, not after.

Every one of those has an answer somewhere — usually in a physical file in a steel almirah, sometimes in a scanned folder nobody has indexed, occasionally only in the memory of someone who has retired. The failure mode is not that the record was never created; it is that nobody can prove it is complete, that nothing was removed, or that the version produced today is the version that existed then.

That is a records-management problem, and it has an established discipline with real answers: classify records, assign each class a retention period, control access by class rather than by person, hold a chain of custody, put a legal hold on anything under dispute, and dispose on schedule with the disposition itself recorded. An HR system does none of this, because it is optimised for the current month. This is the other half.

§ 02

Module ledger

Every module below is built around one property: the record can be produced later, completely, with proof that it is what it claims to be.

01

Service book & posting history

The spine of the personnel record — the digital equivalent of the service book, with every entry attributable and none of them silently editable.

  • Date of joining, confirmation, and every subsequent status change
  • Posting, department, campus, and designation history with effective dates
  • Pay scale, grade, increment, and revision history with the order behind each
  • Probation, confirmation, and seniority position at each point in time
  • Leave without pay and break-in-service periods, recorded distinctly
  • Deputation, lien, and transfer records across institutions in a group
  • Append-only entries — a correction is a new entry with a reason, never an overwrite
02

Document vault & verification

Not a folder of scans. Each document is classified, its verification status recorded, and its authenticity traceable to who checked it and when.

  • Qualification certificates with verification status and verifier identity
  • Experience certificates and previous-employer records
  • Identity, address, and statutory registration documents
  • Appointment orders, promotion orders, and transfer orders
  • Contracts, extensions, and terms of appointment with version history
  • Checksum on every stored file, so silent alteration is detectable
  • Expiry tracking for documents that lapse, with escalation before they do
03

Retention schedule & disposition

The module that distinguishes a records system from a filing cabinet. Every record class has a retention period, and disposal happens on schedule and is itself recorded.

  • Record classes with a defined retention period each
  • Retention clock triggered by the correct event — exit, retirement, or creation
  • Disposition review queue before anything is destroyed
  • Authorised disposal with approver, date, and certificate of destruction
  • Permanent classes flagged and excluded from disposal entirely
  • Retention report — what is held, under what rule, and for how much longer
04

Legal hold & dispute records

When a record is under dispute, retention stops being the rule. Hold overrides disposal, and the hold itself is auditable.

  • Hold placed on an individual, a class, or a date range
  • Disposal blocked while a hold is active, with no override path
  • Case reference, authority, and scope recorded against the hold
  • Notification to record custodians when a hold is placed or lifted
  • Disciplinary proceedings, enquiry reports, and outcomes as their own class
  • Hold history retained after release — including what was preserved
05

Access control & chain of custody

Who saw a personnel file, when, and under what authority. In a records system this log is not a feature — it is part of the record.

  • Access by record class, not by blanket personnel-file permission
  • Purpose declared at access for restricted classes
  • Every view, export, and print logged with actor, time, and origin
  • Custody transfer recorded when responsibility moves between offices
  • Access review reports for internal audit
  • The staff member's own view of their record, and a log of who else looked
06

Statutory & compliance registers

The registers an inspection asks for by name, maintained continuously instead of assembled the week before.

  • Qualification-norm compliance per appointment, checked at the time
  • Sanctioned versus actual strength history by department and category
  • Reservation and roster registers where the institution maintains them
  • Statutory registration records — EPF, ESI, and gratuity eligibility
  • Faculty ratio history for AICTE, NAAC, and AISHE reporting
  • Inspection and audit observation register with closure tracking
07

Retrieval, RTI & verification response

The output side. Producing a complete, defensible answer to an external question, with exemptions applied correctly.

  • Service history pack generated in full, from the record
  • RTI response assembly with third-party and exemption handling
  • Employment and experience verification for external requesters
  • Pension and terminal-benefit data pack on retirement
  • Point-in-time reconstruction — what the record said on a given date
  • Every response logged as an access event against the record
08

Digitisation & legacy intake

Most institutions start with physical files. Bringing them in properly is the project, and doing it badly produces a searchable mess.

  • Bulk scanning with per-document classification, not folder dumps
  • Indexing against the staff identity with duplicate detection
  • Gap report — which records are incomplete, and for whom
  • Original-file location recorded where physical originals are retained
  • Quality sampling and acceptance before the physical file is retired
  • Legacy records placed under the correct retention class on intake

§ 03

A record's life

Read as a custody chain rather than a process. The record outlives the employment, the software, and usually the people who created it.

  1. 01

    Creation

    Opened at appointment with the selection trail, appointment order, and verified qualifications attached — created once, never re-keyed.

  2. 02

    Accrual

    HRMS writes events as they happen: postings, increments, promotions, long leave, disciplinary outcomes. Each arrives as an append-only entry with its order attached.

  3. 03

    Verification

    Qualifications and experience checked, with the verifier's identity and date recorded — so 'was this verified' has an answer, not an assumption.

  4. 04

    Access

    Read by HR, audit, or the staff member under a declared purpose. Every access is logged and becomes part of the record's own history.

  5. 05

    Hold

    If a dispute, enquiry, or litigation arises, a legal hold is placed. Disposal is blocked with no override while it stands.

  6. 06

    Exit

    The service record is sealed on relieving, and the retention clock starts against the correct class and trigger event.

  7. 07

    Retrieval

    Years later: a pension query, an RTI request, a verification, or a court direction. The record is produced complete, with a point-in-time view if asked.

  8. 08

    Disposition

    At the end of retention, reviewed and either retained permanently or disposed under authority — with the disposal itself recorded and certified.

§ 04

Who sees what

Access here is by record class rather than by person. Nobody holds a blanket 'personnel file' permission, including the head of HR — that is the control, not an inconvenience.

Who sees what
RoleCan seeCan do
Records officerRecord inventory, retention status, holds, and the access log — not restricted content by defaultClassify records, run disposition review, place and lift holds, manage custody transfer
HR officeService history and documents needed for an active process, under a declared purposeWrite events from HRMS, request verification, assemble packs within authority
Establishment / pension sectionComplete service history for the individuals they are processingGenerate service packs, compute qualifying service, respond to pension queries
Internal auditRead-only across records and the complete audit trail, with no ability to alter anythingReview appointments, promotions, and disposals against policy; raise observations
Public information officerRecords within the scope of a specific RTI request, with exemption flags appliedAssemble the response, apply exemptions, log the disclosure against the record
Registrar / managementAggregate compliance registers, strength history, and observation closure — not individual filesApprove disposal authority, sign statutory registers, direct holds
Staff memberTheir own complete record, and a log of who else has accessed itRaise a correction request with evidence; corrections append rather than overwrite

§ 05

Record classes and retention

Indicative classes. Actual periods are set to your service rules, the applicable state or central instructions, and any standing legal advice — they are configuration, not code.

Service book
Permanent — retained beyond retirement for pension and verification
Appointment & selection
Long-term — selection trail, orders, and qualification evidence
Pay & increment orders
Long-term — required for terminal benefit computation
Disciplinary & enquiry
Long-term, hold-sensitive, restricted access class
Leave & attendance detail
Medium-term — summarised into the service record before disposal
Payroll registers
Per statutory requirement for tax and provident fund
Medical & personal
Shortest viable, tightly restricted, minimised at intake
Access & audit log
Retained at least as long as the record it concerns

§ 06

What it connects to

Deliberately narrow. A record system with a wide integration surface is a record system with a wide attack surface, and this one holds the material that matters most.

Institutional systems

  • Education HRMS — event write-through on appointment, posting, and exit
  • Education ERP identity and campus scope
  • Payroll registers for statutory retention
  • Single staff identity across the suite

Verification & issuance

  • DigiLocker issuance of service and experience certificates
  • External employment-verification requests with a logged response
  • Qualification verification against issuing-institution records

Storage & integrity

  • Write-once storage for sealed records where required
  • Checksum verification on every stored document
  • Encrypted backup with restore rehearsal
  • Data residency in an Indian region where required

Reporting

  • AICTE, NAAC, and AISHE faculty and ratio history
  • Inspection and audit observation registers
  • Statutory register exports for filing

§ 07

Ground it stands on

A records system's obligations pull in two directions at once, and holding both is the actual design problem. The Digital Personal Data Protection Act, 2023 requires that personal data not be kept longer than the purpose requires, and that it be erased when the purpose is served. Service rules, pension regulations, tax law, and provident-fund rules require that specific records be kept for decades. Neither obligation yields to the other — the resolution is a retention schedule that is granular per record class and actually executes, rather than a policy that says 'as long as necessary' and never deletes anything.

The Right to Information Act adds a third pressure, particularly for government-aided and public institutions, which receive a steady volume of requests about appointments, promotions, and seniority. Answering from an indexed record with exemption handling built in turns a recurring institutional burden into a query. Answering from a steel almirah does not.

The Information Technology Act's provisions on electronic records matter for anyone planning to retire physical files. An electronic record's evidentiary usefulness depends on being able to demonstrate integrity and the reliability of the system that produced it — which is why checksums, append-only history, and a complete access log are foundational here rather than nice-to-have.

Implemented against

  • DPDP Act 2023 — storage limitation, erasure, and purpose limitation on personnel data
  • Retention schedules per record class, aligned to service rules and statutory requirements
  • Disposal executed on schedule, under authority, with a certificate retained
  • Legal hold overriding disposal with no override path while active
  • RTI response assembly with third-party notice and exemption handling
  • Append-only history — corrections add an entry with a reason, never overwrite
  • Checksums and integrity verification on every stored document
  • Complete access log retained at least as long as the record it concerns
  • Access scoped by record class, with no blanket personnel-file permission

§ 08

What it replaces

Compared against the arrangement almost every institution actually has: physical files, a shared drive of scans, and one person who knows where things are.

What it replaces
AspectAlmirah, shared drive, and institutional memoryThis platform
CompletenessAssumedReported — gap analysis names what is missing, and for whom
IntegrityA file could have been altered and nobody would knowAppend-only history and checksums; alteration is detectable
RetentionNothing is deleted, everA schedule per class, executed under authority and recorded
AccessWhoever has the almirah keyBy record class, with purpose declared and every access logged
Pension queryDays of searching, then a reconstructionA service pack generated from the record
RTI requestA manual search and a hopeful redactionAssembled with exemptions applied and the disclosure logged
LitigationHope nothing was disposed ofA legal hold that blocks disposal outright
"What did the record say in 2014?"UnanswerableA point-in-time reconstruction

§ 09

Rollout

Digitisation is the long pole and always takes longer than expected — not because scanning is slow, but because classification and gap resolution are human work. We scope it from a sample rather than from a file count.

  1. 01Week 1–4

    Classification & schedule

    • Record classes defined against your service rules and statutory obligations
    • Retention period and trigger event agreed per class, in writing
    • Access model designed by class, with restricted classes identified
    • A sample of physical files audited to size the digitisation honestly
  2. 02Week 5–10

    Current staff intake

    • Serving staff records digitised, classified, and indexed to the staff identity
    • Gap report issued — incomplete records named, with an owner per gap
    • HRMS event write-through connected so the record stays current from day one
    • Staff self-view released, which surfaces errors faster than any audit
  3. 03Week 10–20

    Legacy & retired staff

    • Retired and former staff records digitised, prioritised by pension activity
    • Historical registers and orders indexed against the correct individuals
    • Physical original locations recorded before any file is retired
    • Quality sampling and formal acceptance per batch
  4. 04Ongoing

    Disposition, holds & handover

    • First disposition review run, with disposal authority exercised and certified
    • Legal hold procedure tested against a live or historical case
    • RTI and verification response packs rehearsed against real past requests
    • Records-officer runbook and custody procedure handed to your team

Talk to an engineer

Bring one retired employee's file.

We will show what a complete service pack looks like — and, more usefully, what is missing from the file you brought.

  • Your data stays yours — NDA on request before anything is shared
  • A working demonstration, not a slide deck
  • Written scope and an honest timeline before any commitment

We reply within one business day.

We use these details only to respond to your enquiry. See our privacy policy.

§ FAQ

Questions we are actually asked

Is this not just the HRMS with extra storage?

No, and the difference is worth being precise about because it decides whether you need one product or two. HRMS answers questions about now: this month's leave, this cycle's payroll, this year's appraisal. ERMS answers questions asked later, by someone external, who will not accept 'we think so' — a pension section, an RTI applicant, an inspection team, a court. That changes the engineering entirely: append-only rather than editable, retention scheduled and executed rather than infinite, access by record class rather than by role, and an access log that is itself part of the record.

Do we need both?

A small private institution with fifteen years of history and no pension liability can run HRMS alone and keep documents in it. A university, a government-aided college, or any institution with long-serving staff, pension obligations, RTI exposure, or a live inspection cycle needs the record layer separately — because the thing that fails is not storage, it is being able to prove completeness and integrity years later. We will tell you which you are during scoping rather than selling you both by default.

Can we really delete personnel records? Our instinct is to keep everything.

Keeping everything is itself a compliance failure under the DPDP Act's storage-limitation principle, and it is also a liability — data you hold is data you can be asked to produce and can lose. The resolution is granularity: service books and appointment records are permanent classes and are excluded from disposal outright, while daily attendance detail, superseded drafts, and medical records held longer than their purpose are not. The schedule is agreed in writing with you, and nothing is disposed of without review and recorded authority.

What does digitising our physical files actually involve?

Scanning is the easy part. The work is classification — deciding what each document is, which record class it belongs to, and which individual it belongs to — plus resolving the gaps that scanning exposes, because incomplete files are the normal finding rather than the exception. We scope from an audited sample of your actual files rather than from a file count, and we issue a gap report with an owner per gap instead of quietly indexing an incomplete record as if it were complete.

Can it show what a record looked like at a past date?

Yes — that is what append-only history is for. Because entries are added rather than overwritten, and every entry carries its effective date and the order behind it, the system can reconstruct the state of a record as of any date. This is the capability that answers 'was the seniority list correct at the time of that promotion', which is a question institutions face regularly and can rarely answer.

Who can see a disciplinary record?

Only roles explicitly granted that record class, and only with a declared purpose, and every access is logged and visible to the staff member concerned. This is the sharpest example of why access is by class rather than by seniority: a head of HR needs to run leave and payroll without automatically being able to read every enquiry report in the institution.

What happens if we replace the system in fifteen years?

You export everything: records, documents, history, and the audit log, in open formats with the checksums intact. A records system that cannot be migrated out of has failed at its own purpose, since the whole premise is that the record outlives the software. We would ask any vendor in this category the same question, and treat a vague answer as disqualifying.