Key takeaways
- There is no single statutory list of onboarding documents. What you collect should follow from the role, the entity, applicable registrations and your own policy.
- Collect against a documented requirement matrix, so every request has a stated reason and the form stops accumulating fields by habit.
- Employment records hold high-impact personal and financial data. Access should follow job responsibility, not convenience.
- Email inboxes and open shared drives are not a system of record — they have no access control, no retention rule and no audit trail.
Common document groups
Most onboarding requirements fall into a handful of groups. Framing them this way is more useful than a flat list, because it makes the reason for each request explicit — and the reason is what determines whether you should be asking at all.
| Group | Typical contents | Why it is collected |
|---|---|---|
| Identity and address | Government identity and address evidence | Confirming who the employee is and where they are based |
| Tax | PAN information | Payroll and tax record accuracy |
| Banking | Account details and supporting proof | Salary payment to the correct account |
| Education and licences | Certificates, registration numbers | Role eligibility, where genuinely relevant |
| Prior employment | Relieving or experience documents | Employment history and notice-period position |
| Statutory identifiers | UAN, ESIC details where applicable | Provident fund and insurance records for eligible employees |
A safer review workflow
Request documents through an authenticated or expiring link, validate file type and readability at upload, restrict reviewer access to those who need it, record rejection reasons, and re-request only the affected item.
The re-request behaviour matters more than it sounds. When a single failed document reopens the entire form, previously approved fields become editable again — and the record of what was approved, and when, is lost.
- 01
Issue an authenticated link
Not an email attachment and not a public URL. The link should expire, and access should be traceable to the candidate.
- 02
Validate at the point of upload
Check file type, size and readability immediately. A candidate who is still in the form can retake a photo in seconds; the same fix after review takes a day.
- 03
Restrict who can view each class
Bank and identity documents warrant narrower access than a joining form. Reviewer permissions should follow the document class, not the folder it happens to sit in.
- 04
Record the rejection reason
"Rejected" without a reason produces a second failed upload. State what was wrong and what is needed instead.
- 05
Re-request the single failed item
Reopen that document alone and leave approved data untouched, so the audit trail for the rest of the submission survives.
Retention and access
Define who may view each document class, why it is retained, and when it is deleted. Employment records often contain high-impact personal and financial information, so access should follow job responsibility rather than convenience.
Retention is the part most often left undefined. A document kept indefinitely because nobody decided otherwise is a liability that grows quietly, and "we still have it" is rarely the answer an employer wants to give.
- State a retention period per document class, and a reason for it
- Separate active employee records from post-exit retention
- Log access to identity and financial documents
- Delete on schedule rather than on request
- Review access rights when someone changes role, not only when they leave
Frequently asked questions
Which documents are mandatory for onboarding in India?
There is no single universal list. Requirements follow from the employer's own policy, the role, the location, applicable registrations such as provident fund or employees' state insurance, and the benefits offered. Build a documented matrix rather than copying another company's list.
Can we collect documents over email or WhatsApp?
It is common but poor practice. Neither has access control appropriate to identity and financial documents, neither supports a retention rule, and neither produces an audit trail of who viewed what. Use a system where the document is the record and access is governed.
What should happen when a document cannot be provided?
Treat it as an exception with a documented decision rather than an automatic rejection. Record what was requested, what the candidate provided instead, who reviewed it and on what basis the decision was made.
Primary references
This resource provides general HR operations information and is not legal, tax or regulatory advice. Requirements vary by organisation and employee circumstances.
