Subcontractor management policy
Purpose
This policy sets out how Kyros Software Ltd (Co. 16915277) selects, manages and monitors subcontractors. It ensures that subcontracted work meets the same standards we apply to our own operations.
Scope
This policy applies to all subcontractors engaged by the company, including freelance developers, specialist consultants and any other third parties performing work on our behalf.
Selection criteria
Before engaging a subcontractor, we assess:
- Technical competence — relevant skills, experience and track record for the work required.
- Security — ability to meet our information security requirements, including vetting to BPSS where required by the client contract.
- Data protection — understanding of and compliance with UK GDPR and the Data Protection Act 2018.
- Modern slavery — confirmation that the subcontractor complies with the Modern Slavery Act 2015.
- Insurance — appropriate insurance where required by the engagement.
- Right to work — confirmation of the right to work in the UK where applicable.
- References — where the subcontractor is new to us, we seek references or evidence of previous work.
Agreements
All subcontractors must sign a written agreement before commencing work. Agreements include:
- Scope of work and deliverables
- Payment terms (we pay within 30 days of invoice)
- Confidentiality and non-disclosure obligations
- Data processing agreement (where the subcontractor will handle personal data)
- Intellectual property assignment
- Security requirements, including acceptable use and access controls
- Compliance with all applicable company policies, including anti-bribery, equality and diversity, and modern slavery
- Termination provisions
- Liability and indemnity
Onboarding
Before a subcontractor begins work:
- Access is provisioned on a least-privilege basis.
- Multi-factor authentication is enabled on all accounts.
- The subcontractor is briefed on relevant policies and security procedures.
- Any required vetting (e.g. BPSS) is completed.
Performance monitoring
- Work is reviewed through code review, regular check-ins and milestone deliverables.
- Issues are raised promptly and documented.
- Feedback is provided at the end of each engagement or at regular intervals for longer-term arrangements.
Data protection requirements
Where a subcontractor processes personal data on our behalf or on behalf of our clients:
- A data processing agreement is in place before processing begins.
- The subcontractor acts only on documented instructions.
- Data is processed in the UK or EEA unless otherwise agreed with the data controller.
- The subcontractor implements appropriate technical and organisational security measures.
- Personal data is returned or securely deleted at the end of the engagement.
Modern slavery requirements
All subcontractors must:
- Confirm they comply with the Modern Slavery Act 2015.
- Not use forced, bonded or child labour.
- Report any concerns about modern slavery to us immediately.
Access management
- Subcontractor access is reviewed at least quarterly.
- Access is revoked immediately upon completion or termination of the engagement.
- Subcontractors must not share credentials or access with third parties.
Termination
Either party may terminate the arrangement in accordance with the written agreement. On termination:
- All access is revoked within 24 hours.
- All company and client data is returned or securely deleted.
- Any company equipment is returned.
- A handover of work in progress is completed.
Review
This policy is reviewed annually. The next review is due September 2027.