Document Code: NeftalyP035
Version: 1.0
Approved By: Chief Executive Officer (CEO)
Date Approved: 31 October 2025
Review Date: 28 November 2026
NeftalyP035-1 Policy Overview
NeftalyP035-1-1 The Neftaly Human Capital Archiving Management Policy (NeftalyP035) establishes a consistent and secure framework for the preservation, storage, retrieval, and disposal of all official Neftaly Human Capital documents and records.
NeftalyP035-1-2 This policy ensures that information is retained in accordance with legal, operational, and governance requirements while supporting efficient access, confidentiality, and long-term data integrity.
NeftalyP035-2 Purpose
NeftalyP035-2-1 The purpose of this policy is to:
- NeftalyP035-2-1-1 Define the principles and procedures governing the archiving and record retention process.
- NeftalyP035-2-1-2 Ensure all Human Capital and Royal documents are systematically managed and preserved.
- NeftalyP035-2-1-3 Promote transparency, accountability, and information security.
- NeftalyP035-2-1-4 Protect Neftaly’s intellectual, operational, and historical data assets.
- NeftalyP035-2-1-5 Support compliance with applicable data protection and record retention regulations.
NeftalyP035-3 Scope
NeftalyP035-3-1 This policy applies to:
- NeftalyP035-3-1-1 All Neftaly Royal Divisions, Royal Directors, Deputy Chiefs, Officers, and Human Capital.
- NeftalyP035-3-1-2 All physical and digital records including contracts, communications, reports, training materials, HR files, and governance documents.
- NeftalyP035-3-1-3 All systems and repositories used for archiving, including Neftaly’s internal document management system and physical archives.
NeftalyP035-4 Policy Statement
NeftalyP035-4-1 Neftaly is committed to maintaining a secure, accessible, and compliant archiving system that ensures the retention and preservation of all critical records and documents throughout their lifecycle.
NeftalyP035-4-2 No document may be altered, destroyed, or removed without proper authorization in accordance with the approved retention schedule and disposal protocols.
NeftalyP035-4-3 All archiving activities must align with Neftaly’s Confidentiality (NeftalyP108), Authorisation (NeftalyP045), and Data Privacy (NeftalyP370) policies.
NeftalyP035-5 Guiding Principles
- NeftalyP035-5-1 Integrity: Records must remain complete, authentic, and unaltered.
- NeftalyP035-5-2 Accessibility: Authorized personnel must be able to retrieve records efficiently.
- NeftalyP035-5-3 Confidentiality: Sensitive information must be protected from unauthorized access.
- NeftalyP035-5-4 Compliance: All archiving practices must adhere to legal, regulatory, and policy requirements.
- NeftalyP035-5-5 Accountability: All Royal Officers are responsible for the accuracy and security of records under their care.
NeftalyP035-6. Categories of Archives
| Category | Type of Record | Retention Period | Responsible Authority |
|---|---|---|---|
| Operational Archives | Reports, meeting minutes, performance logs | 7 years | Royal Directors |
| Human Capital Archives | Contracts, onboarding, training records | 10 years | Chief Human Capital Officer |
| Financial Archives | Invoices, budgets, receipts | 7 years | Chief Finance Officer |
| Strategic Archives | Policies, governance documents, board decisions | Permanent | CEO / Royal Secretary |
| Legal Archives | Agreements, licenses, intellectual property records | 10 years minimum | Legal Officer |
| Digital Archives | Emails, system logs, electronic files | 5 years | ICT Officer |
| Cultural & Historical Archives | Company milestones, media releases, awards | Permanent | Royal Communications Officer |
NeftalyP035-7. Procedures and Processes
NeftalyP035-7-1 Step 1: Document Classification
- NeftalyP035-5-7-1-1 Each document created or received must be classified by type and importance.
- NeftalyP035-5-7-1-2 The Archiving Classification Form (NeftalyF035-01) must be completed by the responsible Officer.
- NeftalyP035-5-7-1-3 Classification categories include: Confidential, Public, Restricted, and Internal Use Only.
NeftalyP035-7-2 Step 2: Archiving Preparation
- NeftalyP035-7-2-1 Documents are reviewed for completeness and proper labeling.
- NeftalyP035-7-2-2 Digital documents must be converted to approved formats (PDF/A, CSV, DOCX).
- NeftalyP035-7-2-3 Physical records must be scanned and indexed into the Neftaly Digital Repository (SDR).
NeftalyP035-7-3 Step 3: Archiving and Indexing
- NeftalyP035-7-3-1 The Royal Secretary or delegated Archiving Officer uploads and categorizes all documents into the repository.
- NeftalyP035-7-3-2 Metadata including document code, title, author, department, and retention period must be entered into the Archiving Register (NeftalyR035-01).
- NeftalyP035-7-2-3 Backup copies are stored in secure cloud or off-site storage.
NeftalyP035-7-4 Step 4: Access and Retrieval
- NeftalyP035-7-4-1 Authorized Human Capital may request access using the Archive Access Request Form (NeftalyF035-02).
- NeftalyP035-7-4-2 Requests are reviewed and approved by the Royal Director or Chief Human Capital Officer.
- NeftalyP035-7-4-3 The Access Log (NeftalyR035-02) records all retrievals and returns.
NeftalyP035-7-5 Step 5: Retention and Review
- NeftalyP035-7-5-1 The Royal Secretary conducts annual reviews to identify records due for disposal or extended retention.
- NeftalyP035-7-5-2 The Archiving Review Checklist (NeftalyD035-01) is used during inspections.
- NeftalyP035-7-5-3 Records under legal hold or audit investigation must not be destroyed until cleared.
NeftalyP035-7-6 Step 6: Disposal and Destruction
- NeftalyP035-7-6-1 Expired records are disposed of securely following authorization from the Chief Human Capital Officer and Royal Legal Officer.
- NeftalyP035-7-6-2 Physical records are shredded; digital files are permanently deleted using certified data destruction tools.
- NeftalyP035-7-6-3 A Record Disposal Certificate (NeftalyD035-02) must be completed for every disposal.
NeftalyP035-8 Roles and Responsibilities
| Role | Responsibilities |
|---|---|
| Chief Executive Officer (CEO) | Provides strategic oversight and final approval for archiving framework. |
| Chief Human Capital Officer (CHCO) | Oversees compliance, review, and disposal of Human Capital records. |
| Royal Directors | Ensure departmental archiving procedures are followed. |
| Deputy Chiefs | Support record classification and access control processes. |
| Royal Secretary | Maintains the Archiving Register, supervises storage, and ensures audit readiness. |
| ICT Officer | Manages digital repositories, security, and data recovery. |
| Audit and Compliance Division | Conducts periodic checks and reports on archiving compliance. |
NeftalyP035-9 Templates and Documentation
| Code | Document Name | Purpose |
|---|---|---|
| NeftalyF035-01 | Archiving Classification Form | Categorizes and identifies documents for archiving. |
| NeftalyF035-02 | Archive Access Request Form | Authorizes retrieval of archived records. |
| NeftalyD035-01 | Archiving Review Checklist | Assists in periodic review and verification. |
| NeftalyD035-02 | Record Disposal Certificate | Certifies authorized record destruction. |
| NeftalyR035-01 | Archiving Register | Tracks all archived records. |
| NeftalyR035-02 | Access Log Register | Records access and retrieval activity. |
NeftalyP035-10 Compliance and Audit
- NeftalyP035-10-1 Unauthorized alteration, deletion, or distribution of archived records is a disciplinary offense.
- NeftalyP035-10-2 All archives must comply with the Protection of Personal Information Act (POPIA) and internal Neftaly governance standards.
- NeftalyP035-10-3 The Royal Audit Committee conducts annual audits to ensure adherence.
NeftalyP035-11 Review and Amendment
- NeftalyP035-11-1 The Chief Human Capital Officer and Royal Governance Committee must review this policy annually.
- NeftalyP035-11-2 Amendments are recorded in the Policy Amendment Register (NeftalyR025-01).
- NeftalyP035-11-3 All changes must be approved by the Chief Executive Officer.
NeftalyP035-12 References
- NeftalyP035-12-1 Neftaly Human Capital Data Privacy Management Policy (NeftalyP370)
- NeftalyP035-12-2 Neftaly Human Capital Confidentiality Management Policy (NeftalyP108)
- NeftalyP035-12-3 Neftaly Human Capital Risk Management Policy (NeftalyP428)
- NeftalyP035-12-4 Neftaly Human Capital Disposal Management Policy (NeftalyP155)
- NeftalyP035-12-5 Neftaly Human Capital Authorisation Management Policy (NeftalyP045)
NeftalyP035-13 Frequently Asked Questions (FAQs)
- What is the purpose and scope of the NeftalyP034 Approval Management Policy?
- Who is the executive sponsor and policy owner for NeftalyP034?
- What types of Human Capital actions require formal approval under this policy?
- What are the guiding principles behind the HC approval framework? (e.g., Segregation of Duties, Accountability, Transparency, Efficiency)
- Where can I find the official, master version of this policy?
- How does this policy integrate with the company’s broader Delegation of Authority (DoA) Framework?
- Who is governed by this policy? (All Employees, Managers, HR, Finance, Executives)
- What is the definition of an “Approval Authority” versus a “Recommender”?
- How are approval authority limits defined? (By role, job grade, department, monetary value, risk level)
- Where is the Master Delegation of Authority Matrix published?
- How often is the DoA Matrix reviewed and updated?
- What is the process for requesting a temporary increase or delegation of approval authority (e.g., for acting roles)?
- What is the policy on “self-approval”? Is it ever permitted?
- What are the consequences of bypassing or violating the approval chain?
- What is the policy on approving actions for relatives or close associates (Conflict of Interest)?
- How are electronic approvals and digital signatures treated versus wet-ink signatures?
- What is the policy’s stance on “blanket approvals” or standing authorizations?
- How does the policy ensure compliance with internal controls and audit requirements?
- How are approval workflows designed to mitigate fraud risk?
- What is the “Four-Eyes Principle” and where does it apply in HC approvals?
- What is the policy on retrospective approvals? Under what circumstances are they allowed?
- How are urgent or after-hours approvals handled when approvers are unavailable?
- What is the escalation path for a stalled or contested approval?
- What is the role of the HR Business Partner in the approval process?
- What is the role of Finance in HC-related approvals?
- How does the policy interface with Procurement policies for vendor-related HC approvals?
- What is the approval process for actions that have both a financial and a headcount impact?
- How are global vs. local approval authorities managed in a multinational context?
- What is the process for granting system access rights to be an approver in the HRIS/Workflow system?
- How are approval authorities managed during organizational restructuring?
- What training is mandatory for managers and approvers on this policy?
- How is the effectiveness and efficiency of the approval framework measured?
- How often is the NeftalyP034 policy itself reviewed and updated?
- What is the process for suggesting improvements to approval workflows?
- Who is the final arbiter for disputes regarding approval authority or process?
- How does the policy support delegation and empowerment while maintaining control?
- What is the policy on approving actions that deviate from standard salary bands or grades?
- How are approvals managed for confidential or sensitive HC actions (e.g., terminations, serious disciplinary actions)?
- What is the policy on documenting the rationale for an approval decision?
- How are approvals audited for compliance?
- What is the policy regarding verbal approvals? Are they valid?
- How does the policy handle matrix reporting structures where dual approvals are needed?
- What is the policy for approving actions related to the Executive Leadership Team?
- How are approval thresholds adjusted for inflation or currency fluctuations?
- What is the process for an employee to query why an approval is required for their request?
- How is the principle of “least privilege” applied to approval authorities?
- What is the policy on delegating approval authority during extended leave (e.g., sabbatical, long-term sick leave)?
- How does the policy ensure approvers have the necessary information to make an informed decision?
- What is the policy on using automated rules for low-risk, high-volume approvals?
- How is the approval framework aligned with Neftaly’s risk appetite?
- What is the process for an approver to decline a request? What justification is required?
- How are approval workflows customized for different business units with unique needs?
- What is the policy on approving overtime, bonuses, or payments that could be seen as discriminatory?
- How does the policy ensure timely approvals to maintain business agility?
- What is the role of Internal Audit in relation to this policy?
- How are approval records retained and archived for legal and audit purposes?
- What is the policy on approving use of external consultants or contractors for HR projects?
- How does the policy manage approvals for system changes that affect HC data or processes?
- Who is the first point of contact for interpreting this policy?
- What is the appeals process if a request is unfairly denied?
Category 2: Approval Processes – Core Employee Lifecycle (FAQs 61-150)
Hiring & Appointment:
61. What is the approval workflow for creating a New Position or Requisition?
62. Who approves the job description and grading for a new role?
63. What is the approval process for hiring above the midpoint of a salary band?
64. Who must approve an Offer Letter? Does it differ by level/grade?
65. What approvals are needed for a signing bonus or relocation package?
66. What is the process for approving a contract for a Fixed-Term, Temporary, or Interim employee?
67. Who approves the use of a recruitment agency and the associated fees?
68. What is the approval chain for hiring a contractor/consultant through a statement of work (SOW)?
69. How are approvals managed for Internal Transfers or Promotions?
70. Who approves a candidate who is a relative of an existing employee?
Compensation & Benefits:
71. What is the approval workflow for the Annual Merit Increase budget and individual allocations?
72. Who approves an Off-Cycle Salary Increase or adjustment?
73. What approvals are needed for a Promotion Increase?
74. What is the process for approving a Market Adjustment to retain a key employee?
75. Who approves Bonus payments (individual, team, spot awards)?
76. What is the approval chain for Long-Term Incentives (e.g., stock options, RSUs)?
77. Who approves changes to an employee’s Benefits election (e.g., upgrading medical aid)?
78. What approvals are required for a Car Allowance or other cash allowances?
79. How is the approval for a Study Assistance or bursary request managed?
80. Who approves exceptional Leave Cash-Out requests?
Changes in Terms:
81. What is the approval process for changing an employee’s Working Hours or moving to Part-Time status?
82. Who approves a formal Flexible Work Arrangement or permanent remote work request?
83. What approvals are needed for a Change in Job Title (without a grade change)?
84. What is the process for approving a Secondment to another department or country?
85. Who approves an Acting Allowance for someone covering a higher-graded role?
86. What approvals are required for a Demotion or role change with reduced responsibilities?
Time & Attendance:
87. Who approves Overtime requests and confirms the hours worked?
88. What is the approval workflow for Time Sheet submission and authorization?
89. Who approves Leave Requests (Annual, Sick, Family Responsibility, Unpaid)?
90. What is the process for approving Leave of Absence (e.g., sabbatical, maternity/paternity beyond standard)?
91. Who approves Time Off In Lieu (TOIL)?
92. What approvals are needed for Shift Pattern changes or swaps?
Separation & Offboarding:
93. Who approves an employee’s Resignation acceptance and sets the release date?
94. What is the approval workflow for initiating a Termination (Performance, Misconduct, Redundancy)?
95. Who approves the Severance Package or separation agreement terms?
96. What approvals are needed for an early release date (pay in lieu of notice)?
97. Who approves the final Exit Payment calculation?
98. What is the process for approving the re-hire of a former employee (Boomerang)?
Category 3: Approval Processes – Talent, Development & Operations (FAQs 151-250)
Learning & Development:
151. What is the approval workflow for an employee to attend an External Training Course or conference?
152. Who approves the associated budget for training (course fees, travel, accommodation)?
153. What approvals are needed for a Coaching or Mentoring program engagement?
154. How is approval managed for Membership Fees to professional bodies?
155. Who approves participation in a formal Development Program (e.g., leadership academy)?
Talent & Succession:
156. What approvals are needed to place an employee on a Succession Plan or High-Potential (HiPo) list?
157. Who approves the nomination for an Internal Talent Mobility program?
158. What is the approval process for creating and funding a new Internship or Graduate Program role?
HR Operations & Expenses:
159. Who approves Employee Reimbursements (travel, entertainment, out-of-pocket expenses)?
160. What is the approval workflow for Team Event or Staff Function budgets?
161. Who approves the purchase of HR Software or technology tools?
162. What approvals are needed for an HR Consultant or external service provider engagement?
163. Who approves changes to HR Policies or procedures?
164. What is the process for approving a Employee Recognition Award (non-monetary)?
165. Who approves the distribution of Employee Surveys?
166. What approvals are required for accessing and using Employee Data for analytics or reporting?
Workplace & Facilities:
167. Who approves a Workstation setup or relocation request?
168. What is the approval process for IT Hardware/Software requests outside the standard issue?
169. Who approves Building Access requests for employees or contractors?
170. What approvals are needed for Remote Work Equipment purchases (chair, desk, monitor)?
Category 4: System, Workflow & Digital Enablement (FAQs 251-350)
- What is the primary system used to manage HC approval workflows? (e.g., SAP, Workday, Oracle, bespoke)
- How do I access the approval portal or inbox within the HRIS?
- What training is available for using the electronic approval system?
- How do I submit a request that requires approval?
- As an approver, how do I view the details of a pending request?
- How do I approve, decline, or request more information on a pending item?
- Can I delegate my approval authority electronically while I am on leave? How?
- What is the process for setting up an Automated Approval Rule in the system?
- How are approval workflows configured for different transaction types?
- Who are the system administrators for the approval workflow engine?
- What is the process for requesting a new approval workflow or modifying an existing one?
- How are approval chains dynamically determined (by cost centre, manager hierarchy, employee type)?
- What happens in the system if an approver is unavailable (Out of Office)?
- How do escalation rules work? After what period is a request escalated?
- Can I approve requests from my mobile device? Is there an app?
- How do I track the status of a request I have submitted?
- What notifications are sent to requestors and approvers (email, system alert)?
- How are digital audit trails of approvals maintained in the system?
- What is the process for recovering or re-instating a rejected/cancelled request?
- How are supporting documents (e.g., business case, quotes) attached to an approval request?
- What is the integration between the HRIS approval system and the Finance system for budget checks?
- How is a “hard stop” enforced in the system if a required approval is missing?
- What reporting is available on approval cycle times, bottlenecks, and approver performance?
- How do I run a report on all approvals I have given or received?
- What is the data retention policy for completed approval records in the system?
- How is the system tested when a new approver is added or the DoA matrix changes?
- What is the business continuity plan if the approval system is down?
- How are system-generated approval emails formatted to prevent phishing attempts?
- What is the process for a mass approval (e.g., approving annual increases for an entire team)?
- How are conditional approvals handled in the system (e.g., “approve if budget is available”)?
- Can external approvers (e.g., board members) access the system? How is their access managed?
- What is the process for an approver to recall an approval given in error?
- How are version controls managed for approval templates and forms?
- What is the Single Sign-On (SSO) integration for the approval portal?
- How is data privacy (POPIA/GDPR) maintained within the approval system?
Category 5: Templates, Documents & Forms Repository (FAQs 351-450)
Each FAQ points to the document repository location.
Policy & Governance:
351. Where is the NeftalyP034 Full Policy Document?
352. Where is the Delegation of Authority (DoA) Matrix (Interactive/PDF)?
353. Where is the Approval Authority Delegation Form (for temporary acts)?
354. Where is the Conflict of Interest Declaration Form relevant to approvals?
Request & Justification Forms:
355. Where is the New Position Requisition & Business Case Form?
356. Where is the Salary Exception Request Form (for above-band offers/adjustments)?
357. Where is the Bonus & Incentive Payment Approval Form?
358. Where is the Promotion & Salary Increase Recommendation Form?
359. Where is the Off-Cycle Adjustment Justification Template?
360. Where is the Contractor/Consultant Engagement Request Form (SOW)?
361. Where is the Training Request & Justification Form?
362. Where is the Conference Attendance Approval Form?
363. Where is the Flexible Work Arrangement Proposal Form?
364. Where is the Acting Allowance Request Form?
365. Where is the Employee Reimbursement Claim Form (with approval block).
366. Where is the Team Event Budget Request Form.
367. Where is the Study Assistance Application Form.
368. Where is the Severance Package Calculation & Approval Form.
Approval Routing Slips & Checklists:
369. Where is the Standard Offer Letter Approval Routing Slip?
370. Where is the Termination Approval Checklist & Routing Form?
371. Where is the Exit Interview & Final Payment Authorization Form.
372. Where is the New Hire Onboarding Cost Approval Checklist.
System & Process Guides:
373. Where is the Step-by-Step Guide to Submitting an Electronic Approval Request?
374. Where is the Approver’s Quick Reference Guide for the HRIS.
375. Where is the Approval Workflow Configuration Guide for System Admins.
376. Where is the Approval Process Flowchart for major transaction types.
377. Where is the Escalation Protocol Document.
Logs & Registers:
378. Where is the Manual Approval Log Template (for use when system is down)?
379. Where is the Retrospective Approval Register.
380. Where is the Approval Authority Audit Trail Report Template.
Category 6: Compliance, Controls & Exception Handling (FAQs 451-500)
- How does Internal Audit test compliance with the approval policy?
- What is the process for investigating a suspected fraudulent approval?
- How are segregation of duties (SoD) conflicts detected and resolved in approval chains?
- What is the quarterly attestation process for managers regarding their approval activities?
- How are we ensuring compliance with SOX or similar regulations for financial-related HC approvals?
- What is the process for a Post-Payment Audit of approved transactions?
- How are approvals for Related Party Transactions (e.g., hiring a board member’s relative) specially controlled?
- What is the Whistleblowing Procedure for reporting approval abuse?
- How are approval limits and workflows adjusted following a merger or acquisition?
- What is the process for handling an approval where the approver has a personal interest?
- How are “emergency” approvals retrospectively documented and ratified?
- What is the protocol when an approval is found to have been based on incorrect information?
- How are approval workflows suspended or modified during a crisis (e.g., pandemic, natural disaster)?
- What is the process for an employee to formally dispute an approval decision that affects them?
- How are approval records presented during external audits or legal discovery?
- What is the Data Integrity Check process for approvals migrated from a legacy system?
- How are manual overrides of system-enforced approval rules logged and authorized?
- What is the process for approving a variance to the standard policy itself?
- How are approval authorities reconciled during year-end budget closure?
- What is the Three-Way Match process for approvals involving PO, receipt, and invoice (for HR vendors)?
- How are currency conversion rates applied to approval thresholds for global transactions?
- What is the process for approving a payment to an employee in a sanctioned country?
- How are tax implications (PAYE, VAT) verified as part of the approval for certain payments?
- What is the process for an approver to declare they feel pressured to approve a request?
- How are approval KPIs (cycle time, first-pass yield) monitored and improved?
- What is the Root Cause Analysis (RCA) process for frequent approval bottlenecks or rejections?
- How is the approval framework adapted for new business models (e.g., joint ventures, startups within the group)?
- What is the process for certifying that all required approvals are in place before a high-value action is executed (e.g., C-suite hire)?
- How are approval workflows tested as part of User Acceptance Testing (UAT) for new HR systems?
- What is the process for archiving and disposing of approval records after the retention period expires?
- How are “maker-checker” principles implemented in system configuration?
- What is the process for approving a change to the core HR data that feeds approval rules (e.g., cost centre, reporting line)?
- How are approvals managed for actions that span multiple fiscal years?
- What is the process for a manager to verify their delegated approval authority is correct in the system?
- How are approvals integrated with project governance for HR-led projects?
- What is the process for handling an approval where the designated approver is the subject of the request?
- How are ethical considerations factored into approval guidelines (e.g., approving excessive executive pay)?
- What is the process for calibrating approval thresholds across different departments to ensure fairness?
- How are system-generated approval alerts designed to prevent “alert fatigue” for busy approvers?
- What is the business continuity process for approvals if a key approver leaves the company unexpectedly?
- How are approvals for sustainability or ESG-related HR initiatives governed?
- What is the process for approving a data breach response plan involving employee data?
- How are approvals managed for accessing employee data for AI or machine learning projects?
- What is the protocol for approving a press release or external communication about a senior appointment?
- How are social media background checks approved as part of the hiring process?
- What is the process for approving a “garden leave” clause or other restrictive covenants?
- How are approvals handled for participating in industry salary surveys?
- What is the process for approving the destruction of physical approval documents?
- How is the principle of proportionality applied to approval workflows (simpler process for low-risk items)?
- Who is ultimately accountable to the Board for the design and effectiveness of the HC Approval Management Framework?
500 FAQs for Neftaly Human Capital Archiving Management Policy, Procedures, Processes, Templates, Documents and Forms NeftalyP035
500 FAQs for Neftaly Human Capital Archiving Management Policy, Procedures, Processes, Templates, Documents and Forms (NeftalyP035)
Category 1: Policy & Governance Fundamentals (FAQs 1-70)
- What is the purpose and scope of the NeftalyP035 Archiving Management Policy?
- Who is the executive sponsor and policy owner for NeftalyP035?
- What is the definition of “Archiving” versus “Backup,” “Storage,” and “Disposal” in the HC context?
- What are the legal and regulatory drivers for this policy? (e.g., POPIA, National Archives Act, BCEA, LRA, King IV, ISO 15489)
- What types of HC records are covered by this policy? (Employee files, recruitment, payroll, learning, performance, disciplinary, etc.)
- Who is governed by this policy? (All employees, HR staff, Records Managers, IT, Line Managers)
- What are the core principles of the policy? (Integrity, Confidentiality, Authenticity, Usability, Compliance)
- Where can I find the official, master version of this policy?
- What is the role of the Designated Information Officer / Data Protection Officer in archiving?
- What is the role of the HC Archivist / Records Manager?
- What is the governance structure (e.g., Records Management Committee) overseeing this policy?
- How does this policy align with Neftaly’s overall Information Management and Data Governance strategies?
- What is the definition of the Records Lifecycle (Creation, Use, Maintenance, Archival, Disposal)?
- What are the different classification levels for HC documents (e.g., Public, Internal, Confidential, Restricted)?
- What is the Retention Schedule and where is it published?
- Who is responsible for developing and maintaining the HC Retention Schedule?
- How often is the retention schedule reviewed and updated for legal changes?
- What is the policy on archiving records related to ongoing litigation or investigation (Legal Hold)?
- What are the consequences of non-compliance with this policy (e.g., fines, reputational damage, legal liability)?
- How does the policy ensure compliance with cross-border data transfer rules when archives are stored offshore?
- What is the policy on the use of cloud-based archiving services?
- How are audit trails for archived records maintained?
- What is the process for conducting an internal audit of HC archives?
- How often is the NeftalyP035 policy itself reviewed?
- What training is mandatory for HR personnel on records management and archiving?
- What is the policy on personal liability for improper archiving or disposal?
- How does the policy address the archiving of records for entities acquired through mergers & acquisitions?
- What is the policy on archiving records for divested or closed business units?
- How are physical and electronic records managed under a single policy framework?
- What is the “Single Source of Truth” principle for HC records?
- What is the policy on employees taking copies of records for personal use?
- How does the policy support business continuity and disaster recovery planning?
- What is the process for declaring a record as “Vital” or “Mission Critical”?
- What are the roles and responsibilities of Record Creators, Custodians, and Users?
- How is the policy communicated to all new and existing employees?
- What is the process for reporting a suspected breach of archiving protocols?
- How does the policy interact with the IT Acceptable Use and Data Security policies?
- What is the policy on using personal devices or cloud storage (Dropbox, Google Drive) for HC records?
- How are metadata standards for electronic archives defined and enforced?
- What is the policy on archiving voice recordings, video interviews, and biometric data?
- How are legacy records (pre-policy) to be managed?
- What is the policy on archiving records in languages other than the company’s official language?
- How does the policy ensure accessibility for persons with disabilities to archived records (where required)?
- What is the process for granting a policy exception or deviation?
- What is the appeals process if an archive request is denied?
- Who is the first point of contact for archiving queries?
Category 2: The Retention Schedule & Legal Compliance (FAQs 71-140)
- What is a Retention Schedule and why is it critical?
- Where is the Master HC Records Retention Schedule located?
- How is the retention period for each record type determined?
- What laws dictate retention periods in South Africa? (e.g., Basic Conditions of Employment Act – 3 years for payroll, Skills Development Act – 5 years for WSP, etc.)
- How are international regulations (GDPR, HIPAA) considered for global employees?
- What is the difference between “Operational,” “Legal,” and “Historical” retention periods?
- What is the retention period for Job Application forms and CVs (successful vs. unsuccessful)?
- What is the retention period for Employee Personnel Files (from hire to post-termination)?
- How long must we keep Payroll Records, Tax Certificates (IRP5), and Leave Records?
- What is the retention period for Disciplinary Records (final warnings, hearing minutes)?
- How long must Performance Appraisals, Promotion, and Increment records be kept?
- What about records related to Workplace Injuries (OHS) and Medical Confidentiality?
- How long are EEA1-EEA4 forms and other Employment Equity records retained?
- What is the retention period for Training Records and Skills Development documentation?
- How long must we keep records of Grievances, Whistleblowing, and Investigations?
- What is the retention for Employment Contracts, Addendums, and Secondment Agreements?
- How long are Pension and Provident Fund contribution records kept?
- What about records for employees who are Minors?
- When does the retention “clock” start? (Date of creation, date of transaction, end of fiscal year, termination date?)
- What is a Legal Hold and who can initiate one?
- What is the process for placing records under a Legal Hold?
- How are records under Legal Hold flagged in the archive?
- What is the process for releasing a Legal Hold?
- What happens if a retention period expires while a record is under Legal Hold?
- How are changes in legislation (new laws, amended acts) monitored and incorporated into the schedule?
- Who is responsible for the legal review of the retention schedule?
- How are industry-specific retention requirements (e.g., for financial services, healthcare) managed?
- What is the process for archiving records for employees who have been on long-term leave or suspension?
- How are retention periods applied to duplicate records or copies?
- What is the minimum retention period recommended for records with no specific legal requirement?
Category 3: Procedures – Active Records Management & Preparation for Archive (FAQs 141-220)
- What are “Active” records and how should they be managed day-to-day?
- What is the standard Filing Plan / Classification Scheme for HC digital folders?
- What are the naming conventions for HC documents and files?
- What metadata (author, date, document type, employee ID) must be captured for all HC records?
- What is the procedure for declaring a record as “Inactive” ready for archiving?
- What is the Annual Records Review and Clean-Up process for HR departments?
- What is the Records Transfer List / Form used when sending records to archive?
- How are records prepared for physical archiving? (Removing staples, using acid-free boxes, labeling)
- How are records prepared for digital archiving? (File format standardization, PDF/A, virus scan, indexing)
- What file formats are acceptable for long-term digital preservation? (e.g., PDF/A, TIFF, CSV)
- What file formats are not recommended for archiving and should be converted? (e.g., .docx, .xlsx)
- What is the process for ensuring scanned copies are of sufficient quality and are OCR’d (Optical Character Recognition)?
- Who is responsible for the quality check of records before they are archived?
- What is the process for archiving emails containing HC information?
- How are records from collaborative platforms (Teams, Slack) captured for archiving?
- What is the process for archiving data from the HR Information System (HRIS)?
- Are system reports considered records? How are they archived?
- What is the procedure for archiving signed wet-ink documents after they have been digitized?
- How are bulk records (e.g., a year’s worth of payslips) prepared for archive?
- What is the process for handling records that are incomplete or damaged?
Category 4: Procedures – Physical Archiving & Storage (FAQs 221-300)
- Where are the Physical Archive Storage Facilities located?
- Who manages the physical archive facility? (In-house team or third-party vendor?)
- What are the environmental controls required for physical archives? (Temperature, humidity, fire protection)
- What are the security controls for the physical archive? (Access logs, CCTV, alarmed)
- How do I request to Deposit physical records into the archive?
- What is the Archive Box Labeling Standard?
- How is an Archive Location Reference Code (e.g., shelf/box/file number) assigned and recorded?
- Where is the Archive Master Index / Register maintained?
- How do I request to Retrieve a physical file from the archive?
- What is the Records Retrieval Request Form?
- What is the turnaround time for retrieving a physical file?
- Can original physical files be removed from the archive, or are copies provided?
- What is the “Issue and Return” log procedure for tracking physical file movement?
- What are the rules for handling and viewing physical archives in a reading room?
- How are records protected from pests, water, and light damage?
- What is the process for conducting a physical inventory of the archive?
- How often are physical inventories conducted?
- What is the disaster recovery plan for the physical archive (fire, flood)?
- What insurance is in place for physical archives?
- How are archives transported securely to and from the storage facility?
Category 5: Procedures – Digital Archiving & E-Discovery (FAQs 301-380)
- What is the Digital Archive System / Platform used at Neftaly? (e.g., SharePoint Records Center, dedicated EDRMS, cloud service)
- What are the technical specifications for the digital archive (WORM storage, encryption, geographic redundancy)?
- How are digital records ingested into the archive system?
- What is the process for bulk ingestion of legacy digital records?
- How are Metadata Schemas applied automatically during ingestion?
- What is the Digital Preservation Strategy to ensure files remain readable over decades (format migration, emulation)?
- How is data integrity verified in the digital archive (checksums, fixity checks)?
- What are the Access Control Lists (ACLs) and permissions for the digital archive?
- How do I search for a record in the digital archive?
- What advanced search functionalities are available (full-text, metadata, date range)?
- How do I request access to a confidential digital archive record I am not automatically authorized to see?
- What is the Audit Trail capability of the digital archive system? Can it track every view, print, or download?
- How are digital records retrieved for business use? Is there a “check-out” function?
- What is the process for exporting records from the digital archive?
- What is E-Discovery and how does the archive support it?
- What is the process for responding to a legal e-discovery request?
- How are relevant records identified, collected, and produced in a legally defensible manner?
- How does the system support Legal Hold at the digital level?
- What is the process for creating a defensible Chain of Custody report for digital evidence?
- How are backups of the digital archive managed? Are they considered separate from the archive?
- What is the business continuity plan for accessing digital archives if the primary system fails?
- How is the digital archive tested for recovery as part of disaster recovery drills?
Category 6: Procedures – Access, Retrieval & Security (FAQs 381-450)
- Who is authorized to access the HC archives?
- What is the principle of “Need to Know” and “Least Privilege” applied to archive access?
- What is the process for an employee to access their own personnel file?
- What is the process for a manager to access the files of their current team members?
- What is the process for HR to access archives for business purposes?
- What is the process for Internal Audit, Legal, or External Auditors to access archives?
- What is the process for law enforcement or a regulator (e.g., Information Regulator, CCMA) to request access?
- What verification is required before fulfilling an access request?
- Are there fees associated with archive retrieval for certain request types?
- What is the expected turnaround time for different types of access requests?
- How is the confidentiality of sensitive records (health, discipline, investigation) maintained during retrieval?
- What secure methods are used to transmit retrieved records (encrypted email, secure portal)?
- Can archives be accessed remotely? What are the security protocols?
- What is the process for reporting a potential security breach or unauthorized access to the archive?
- How is user activity in the digital archive monitored for suspicious behavior?
- What is the process for revoking archive access when an employee changes roles or leaves?
Category 7: Procedures – Disposal & Destruction (FAQs 451-520)
- What is the Records Disposal process?
- Who authorizes the disposal/destruction of records?
- What is the Disposal Schedule linked to the Retention Schedule?
- How are records due for disposal identified? (System alerts, manual review)
- What is the Certificate of Destruction / Disposal Authorization Form?
- What is the process for verifying that no Legal Holds apply before disposal?
- What are the approved methods for Destroying Physical Records? (Shredding, pulping, incineration)
- Are there specific requirements for destroying highly confidential records?
- Do we use an approved, bonded third-party destruction vendor? What is the due diligence process?
- What is the process for witnessing or auditing the destruction of physical records?
- What are the approved methods for Destroying Digital Records? (Secure delete, degaussing, cryptographic erasure)
- How is destruction of data from backup tapes or cloud storage managed?
- How is the destruction of hardware (hard drives, servers) containing HC data managed?
- What documentation is kept as proof that destruction was carried out properly?
- How long are destruction certificates themselves retained?
- What is the process for disposing of legacy media (floppy disks, microfiche, tapes)?
- What happens if a record is mistakenly destroyed?
- Is there an option for “Archival Purgatory” or extended review before final destruction?
Category 8: Templates, Documents & Forms Repository (FAQs 521-600)
Each FAQ points to the document repository.
Policy & Governance:
521. Where is the NeftalyP035 Full Policy Document?
522. Where is the HC Records Retention Schedule (Interactive/PDF)?
523. Where is the Records Management Roles & RACI Matrix?
524. Where is the Legal Hold Notice Template?
Procedural Forms:
525. Where is the Records Transfer List / Archive Deposit Form (Physical & Digital)?
526. Where is the Records Retrieval / Access Request Form?
527. Where is the Archive Box Label Template?
528. Where is the Records Inventory Spreadsheet Template.
529. Where is the Metadata Capture Sheet for digital ingestion.
530. Where is the Disposal & Destruction Authorization Certificate.
531. Where is the Certificate of Witnessed Destruction.
Guidelines & Manuals:
532. Where is the HC File Plan & Classification Guide?
533. Where is the Naming Convention Standard for HC Documents?
534. Where is the Guide to Preparing Records for Archive (Physical & Digital)?
535. Where is the Digital Preservation Technical Guidelines.
536. Where is the E-Discovery Response Playbook.
537. Where is the Archive User Manual for the digital system.
538. Where is the Vendor Due Diligence Checklist for archive/destruction service providers.
Logs & Registers:
539. Where is the Master Archive Index / Register Template?
540. Where is the Access & Retrieval Log Template.
541. Where is the Legal Hold Register.
Communication:
542. Where is the Privacy Notice for Employees Regarding Record Keeping.
543. Where is the Template Communication for Archive Retrieval Delays.
Category 9: Technology, Systems & Integration (FAQs 601-700)
- How does the HRIS integrate with the digital archive for automatic record retirement?
- What APIs are used for system-to-system archiving?
- What is the Archive System’s Service Level Agreement (SLA) for uptime and access?
- How is the performance and capacity of the digital archive monitored?
- What is the process for upgrading or migrating the digital archive system?
- How are compatibility and readability checks performed during system upgrades?
- What is the data model used within the digital archive?
- How is full-text indexing configured for searchability?
- Can the archive system integrate with Data Loss Prevention (DLP) tools?
- How is blockchain or other immutable ledger technology considered for archive integrity?
- What is the process for extracting data from the archive for analytics (ensuring de-identification)?
- How are records from decommissioned legacy systems (old HR software) archived?
Category 10: Special Cases & Scenarios (FAQs 701-800)
- How are records for CEO and Executive Leadership archived and secured?
- What is the process for archiving records related to a Whistleblower whose identity is protected?
- How are records for Minors or Apprentices treated differently?
- How do we archive records for employees in jurisdictions with stricter rules (e.g., EU under GDPR)?
- What is the process for archiving records from an Employee Wellness Program (EAP)?
- How are Biometric Data (fingerprints, facial recognition) archived and disposed of?
- What about archiving Video Recordings from interviews or workplace security cameras?
- How are records managed for employees on International Assignment?
- What is the process for archiving records post- Merger, Acquisition, or Divestiture?
- How do we handle archives for a Closed Business Unit or Liquidated Subsidiary?
- What is the process for an employee to request a correction to their archived record?
- How are historical archives used for Cultural Heritage or Company History projects?
- What is the process for donating non-confidential historical records to a public archive or university?
Approved By:
Neftaly Malatjie
Chief Executive Officer
