HR Technology

Australia’s offshore workforce is growing; do employers know who has access anymore?

Article cover image

As offshore workforces expand, Australian employers need stronger identity, affiliation and access checks to know exactly who is accessing sensitive systems.

By: Fred Slikker


On 31 July, Australia joined ten international partners in warning businesses about fraudulent North Korean, or DPRK, IT workers using false identities, third party proxies and AI-generated personas to secure remote jobs and contracts. For Australian employers, the consequences extend beyond cyber risk. The Department of Foreign Affairs and Trade (DFAT) has warned that employing or paying a North Korean IT worker may constitute a serious criminal offence under Australian sanctions law. Businesses also face the potential theft of intellectual property, data, personal information and funds.


It is an extreme example, but it exposes a much wider gap in how businesses manage remote and external workers. Australian organisations routinely use offshore teams for payroll, finance, HR, IT and customer service. These workers often need access to sensitive systems, yet the business granting that access may know the supplier far better than it knows the individual.


This should not lead employers to view offshore workers with greater suspicion. The more useful response is to apply consistent checks to everyone receiving sensitive access, wherever they are based.


Supplier approval does not establish someone’s identity


Businesses usually put considerable effort into selecting an external provider. Procurement may assess the supplier’s experience, security practices, financial position and ability to deliver the work. Those checks remain important, but they tell the business about the supplier rather than each person working under its name.


Delivery teams change throughout a contract; work may move to another office, temporary staff may join or part of the service may be subcontracted, often without the employer receiving a clear record of who has changed.


The gap appears when a change within the supplier does not make its way back to the business granting access. An account may remain active because the provider is still approved, even though the person using it has changed.


A polished CV, credible portfolio, video interview and scanned identity document are still commonly treated as evidence that a candidate is genuine. AI-generated profiles and manipulated documents make that assumption increasingly unsafe. Employers still need to verify each person receiving access, rather than relying entirely on checks completed by a recruiter, labour-hire firm or service provider.


Three checks are needed


There are three separate questions behind every external account: who is this person, who do they represent and what are they allowed to access?


The first is identity. Remote identity verification should establish that the person is real, the information and documents presented are legitimate, and the person completing the check is physically present. Liveness detection should form part of this process to confirm that a real person is completing the check in real time, rather than relying on a photo, recording or manipulated image. The verified identity should then be bound to an individual account and a strong authentication method, so the organisation can establish that the person returning to the account is the person who was originally verified.


The second is affiliation. A genuine identity does not prove that someone currently works for the approved supplier. The employer needs confirmation from a credible source that the person is employed, contracted or otherwise authorised to act on the supplier’s behalf. That relationship also needs to remain current. A worker may leave the supplier, move to another project or have their role changed without the organisation granting access being told.


The third is authorisation. Once identity and affiliation have been established, the employer’s identity and access systems determine what the person can do. A legitimate supplier employee does not automatically need access to customer records, payroll information or financial systems.


Treating these as separate checks prevents proof of identity from being mistaken for proof of employment or authorisation. The same standard should apply to onshore and offshore workers. The sensitivity of the access, rather than the person’s location, should determine how strong the checks need to be.


HR’s role across the worker lifecycle


HR and people leaders have an important role because they help determine how workers enter, move through and leave an organisation. However, they cannot manage the external access alone. Procurement, IT, security, the relevant business owner and supplier each hold part of the information needed to make and review access decisions. 


At onboarding, HR should ensure that every contingent worker has an individual record. This should record that their identity has been verified, together with the verification date and assurance level, their employer or sponsoring supplier, role, internal owner and expected contract period. Businesses should avoid retaining copies of identity documents unless they are genuinely required.


During the engagement, HR should trigger a recheck when the worker changes roles, projects or suppliers. Extending a contract should not automatically extend someone’s system access. It should prompt confirmation that the person still has a valid affiliation and that their authorisations remain appropriate.


At offboarding, HR needs to ensure that the worker’s departure reaches IT and every other team responsible for downstream systems. Removing someone from a supplier’s delivery list does not automatically close their company accounts.


HR, procurement and IT therefore need a shared record of each external worker. Without one, a change reported to the supplier or business team may never reach the people responsible for system access. Every external worker should also have a named internal owner. That person should be able to explain why the worker needs access and confirm when it should change or end.


Five steps HR leaders can take now


Businesses do not need to retreat from offshore delivery or impose excessive checks on legitimate workers. They need a consistent process that follows each person throughout the engagement. HR and people leaders can begin with five steps:


  1. Maintain one record for every external worker. Include their verified identity, supplier, role, internal owner and engagement period. Avoid unnecessarily retaining copies of identity documents.

  2. Require suppliers to disclose personnel changes. New workers and subcontractors should be checked before receiving access.

  3. Match checks to the role. Apply stronger verification where workers can access payroll, customer, financial or other sensitive information.

  4. Build in review triggers. Recheck affiliation and authorisations when a worker changes role, project or supplier, or when a contract is extended.

  5. Link offboarding to account removal. A worker’s departure should trigger action across every system they can access.


HR leaders should begin by identifying every external worker with access to sensitive systems and checking whether each account has a verified user, a current supplier relationship and a named internal owner.


These controls should apply consistently to onshore and offshore workers. The aim is not to make distributed work more difficult, but to ensure that trust in a supplier does not replace accountability for the people working under its name.


About the author: Fred Slikker, Managing Director at Digidentity since 2020, has a proven track record of leading international businesses. With his focus and customer-centric mindset, Fred sets the company's strategic direction and works, among other things, on developing Digidentity's portfolio of identity management solutions. He is also one of the driving forces behind developing partnerships with (semi-)government bodies and the business market.

Loading...