20 Essential HR Policies for Indian Enterprises
Every undocumented expectation in a 2,000-person enterprise is a grievance, an inconsistency, or a legal dispute waiting to surface, twenty templates to formalize those expectations this quarter.

Table of contents
One unstitched HR platform to manage your entire workforce, from Hire to Re-Hire.
Talent Management solutions built for growing and exceptional people
Built-in compliance tools that update with changing regulations
Automated payroll, attendance, and leave management
Insights that help HR leaders make faster, better decisions

Key Takeaways
- 20 essential HR policies covered across conduct, contracts, leave, safety, grievance, travel, and hiring, with sample clauses for each.
- Every policy section includes ready-to-adapt template elements and real policy language your team can customise immediately.
- A five-step playbook walks you from gap analysis and risk prioritisation through drafting, approval, and tracked rollout.
- Statutory compliance details live in our separate regulatory guide, keeping this guide focused on practical implementation.
- Enterprises with 1,000+ employees across locations benefit most from unified HCM platforms like ZingHR for automating distribution, acknowledgements, and enforcement.
In over a decade of working with CHROs and HR heads across 1,200+ enterprises, one pattern keeps showing up in almost every first conversation: most HR teams lack clear, written policies for all aspects of employee management. They have a leave policy and something resembling a POSH document because those are legally mandatory. But ask about a documented grievance redressal process, a formal work-from-home framework, or a fraud policy with teeth, and you get a pause.
The issue is rarely about awareness. HR leaders know these policies matter. The challenge is that building them from scratch (getting the language right, making them enforceable, rolling them out across locations, and keeping them current) is genuinely hard when you're also running recruitment cycles, managing payroll, and handling the 47 other things on your plate.
So this guide is the practical version, built for practitioners. We have a separate statutory compliance resource covering the legal framework in depth.
Here, the focus is on 20 HR policies your enterprise actually needs, what each one should say, sample language you can adapt, and the rollout steps that make them stick.
Why This List, and Why Now
Three things make this conversation urgent in 2026.
First, hybrid work is here to stay. Most enterprises I work with have some form of remote or flexible arrangement, but fewer than half have a documented policy governing it. That gap creates real data security and performance management risk, hiding in plain sight.
Second, employee expectations have shifted. Candidates evaluate your policy framework before they accept an offer. When offer acceptance rates hover around 56% in competitive markets, your published policies on pay transparency, DEI, and workplace flexibility are part of your employer brand, whether you've designed them to be or otherwise.
Third, consistency at scale requires documentation. In a 200-person company, culture and norms can be transmitted through conversations. At 2,000 or 10,000 employees across multiple states, every undocumented expectation is an inconsistency waiting to become a grievance, an audit finding, or a wrongful termination claim.
The 20 HR Policies at a Glance
Before we go deep on each one, here's the full list organised by the area of workforce governance they address.
An overview of HR policies every organisation must have
.webp)
Workplace Conduct Policies
These six policies set the behavioural and cultural foundation. In client conversations, I often call them the "day-one policies" because a new hire should encounter all of them in their first week.
1. Code of Conduct
What it does: Defines what "professional behaviour" actually means in your organisation, as a set of specific, enforceable expectations rather than a vague aspiration.
Why most versions fall short: The Code of Conduct documents I see from new clients tend to be either painfully generic ("employees shall maintain the highest standards of integrity") or so long that the entire workforce ignores them. The best codes are specific enough to guide a manager making a real-time decision.
What your template should include:
- Purpose and scope: One paragraph confirming the policy applies to every employee, contractor, intern, and third-party associate, across on-site, remote, and company-sponsored event contexts.
- Behavioural standards with examples: Go beyond listing values. Translate them into observable behaviours. Here's what that looks like:
- Reporting mechanism: Name the channel (an ethics hotline, an HR portal, a designated email), confirm reports can be anonymous, and state whistleblower protection explicitly.
- Consequences: Specify that breaches trigger a documented investigation and may result in actions ranging from a written warning to termination. Steer clear of vague language like "appropriate action will be taken."
Rollout tip: Go beyond emailing the document. Run a 30-minute walkthrough session for each department where the HRBP covers the top 5 scenarios employees actually encounter (social media posts about the company, accepting gifts from vendors, conflicts of interest in hiring). Make it real.
2. Equal Opportunity Policy
What it does: Commits the organisation to making every employment decision (hiring, promotion, training access, compensation) on the basis of merit and qualifications alone.
What your template should include:
- Protected characteristics: List them explicitly: caste, gender, religion, age, disability, sexual orientation, marital status, pregnancy, ethnic origin, and any other characteristic protected under applicable law.
- Scope of application: State the policy applies to recruitment, onboarding, performance reviews, compensation decisions, training nominations, promotion cycles, and disciplinary proceedings.
- Annual audit commitment: This is the part most enterprises skip. Include a clause committing to an annual equal opportunity audit.
- Complaint process: Provide a confidential reporting channel and confirm protection against retaliation for employees raising concerns.
3. Anti-Bullying Policy
What it does: Draws a clear line between tough feedback (acceptable) and bullying behaviour (prohibited), and gives employees a concrete process for reporting it.
Why it matters more than most enterprises think: In my experience, bullying is the single biggest driver of quiet attrition in mid-management layers. People rarely file formal complaints. They simply leave. A well-communicated anti-bullying policy may fail to eliminate the behaviour entirely, but it gives people a path beyond resignation.
What your template should include:
- Definition with specific examples. Vague definitions ("behaviour that creates a hostile environment") are unenforceable. Be explicit.
- Three-step investigation process:
- (1) Receive and acknowledge the complaint within 48 hours.
- (2) Gather evidence by interviewing the complainant, the respondent, and witnesses, and reviewing communication records.
- (3) Determine corrective action: mediation, formal warning, role reassignment, or termination.
- Confidentiality and protection from retaliation: State both explicitly.
4. Sexual Harassment Policy (POSH)
What it does: Fulfils your legal obligation under the POSH Act, 2013 and provides a clear, safe complaint-to-resolution process.
The implementation gap I see most often: Most enterprises have a POSH policy document. Far fewer have a functioning Internal Complaints Committee that meets regularly, a complaint process employees actually know how to use, or a training programme that goes beyond a checkbox annual session. The document is necessary but insufficient on its own.
What your template should include:
- Definition with categories: Sexual harassment includes physical contact and advances, demands or requests for sexual favours, sexually coloured remarks, showing pornography, and any other unwelcome physical, verbal, or non-verbal conduct of a sexual nature.
- Complaint procedure with timelines:
- ICC composition: Name the Presiding Officer, confirm external member inclusion, and state that at least half the members must be women.
- Interim measures: Specify that the ICC may recommend transfer, leave, or modified reporting during the investigation to protect the complainant.
- Retaliation protection: Any form of retaliation against a complainant or witness triggers a separate investigation and disciplinary action.
Rollout tip: Run POSH awareness sessions quarterly, rather than annually. Use scenario-based workshops instead of slide decks. Make sure every employee knows the ICC members by name and how to reach them.
5. Employee Handbook
What it does: Serves as the single-source reference consolidating every policy, benefit, process, and expectation into one accessible document.
A common mistake: Many organisations treat the handbook as a one-time onboarding document, handing it over on day one and forgetting about it entirely. The best handbooks are living documents updated whenever a policy changes, with version control and re-acknowledgement workflows built in.
What your template should include:
- Company mission, vision, and values: Keep this to one page. It sets the tone but should stay concise enough to avoid dominating the document.
- Policy sections cross-referenced to standalone documents: The handbook summarises each policy; the full policy document is the authoritative source.
- Benefits and compensation overview: Salary structure, bonus criteria, health insurance, PF, gratuity, summarised with links to detailed documents.
- Digital acknowledgement and revision log: Every material update triggers re-acknowledgement. Maintain a revision history table at the front of the document showing date, version, section changed, and approver.
6. Non-Discrimination Policy
What it does: Reinforces equal opportunity commitments with specific protections across every stage of the employee lifecycle, providing a documented basis for employees to raise discrimination concerns.
What your template should include:
- Explicit protected classes: Mirror the equal opportunity list and include any emerging categories under India's evolving DEI framework.
- Lifecycle application: State explicitly that the policy covers recruitment, performance reviews, compensation adjustments, training access, promotion decisions, team assignments, and disciplinary proceedings.
- Reporting and investigation: Provide a confidential reporting channel, commit to completing investigations within [X] working days, and confirm protections against retaliation.
Employment Agreement Policies
These three policies form the legal backbone of the employer-employee relationship. I've seen enterprises lose termination disputes, often because their employment contract or exit policy was ambiguous rather than because the decision itself was wrong. Precision here saves litigation later.
7. Employee Contract
What it does: Establishes the legally binding terms of employment, covering role, compensation, obligations, and exit conditions.
What your template should include:
- Role and reporting: Designation, department, reporting manager, and primary location.
- Compensation structure: Fixed pay, variable pay, allowances, and benefits, broken down clearly.
- Working hours and leave: Standard hours, overtime expectations, and a reference to the Leave Policy.
- Confidentiality and IP assignment:
- Notice period and termination:
- Dispute resolution. Jurisdiction, governing law, and whether disputes go through arbitration or courts.
Suggested Read: Labour Law Compliance Checklist: What India's Four Codes Require
8. Employee Non-Disclosure Agreement (NDA)
What it does: Legally binds employees to protect confidential business information during and after employment.
What your template should include:
- Definition of confidential information: Be comprehensive and specific.
- Employee obligations: Refrain from disclosing, use information only for work purposes, return all materials (physical and digital) upon separation.
- Duration: Specify the NDA extends [2–5] years beyond the end of employment.
- Consequences: Breaches will be pursued through injunctive relief, financial damages, and any other legal remedies available.
9. Termination and Resignation Policy
What it does: Governs how both voluntary and involuntary exits happen, step by step, with full clarity on process.
What your template should include:
- Resignation process:
- Termination grounds: List specific, defensible grounds: gross misconduct, confirmed fraud or theft, persistent underperformance after documented performance improvement plans, illegal activity, or material breach of company policy.
- Termination procedure: The employee must be informed of the specific ground, given a documented opportunity to respond, and notified of the decision in writing. Include details on notice or pay in lieu, gratuity, leave encashment, and return of company assets.
- Exit interview: Make it standard for both resignations and employer-initiated exits. Track themes quarterly.
Leave and Flexibility Policies
These policies govern time away from work. In my experience, leave policy confusion generates more day-to-day HR tickets than almost anything else, especially in multi-state organisations where entitlements differ by location.
10. Leave Policy
What it does: Documents every leave type, its entitlement, and exactly how employees apply, get approval, and handle exceptions.
What your template should include:
- Leave types and entitlements: List each type with annual entitlements:
- Casual Leave (CL): [7–12] days for personal reasons
- Sick Leave (SL): [5–10] days for medical reasons (specify whether a medical certificate is required after [X] consecutive days)
- Earned/Privileged Leave (EL/PL): [as per applicable state act, typically 1 day per 20 days worked]
- Maternity Leave: 26 weeks paid leave for eligible employees
- Paternity Leave: [X] days (specify if applicable)
- Public Holidays: As per state calendar
- Application and approval process:
- Carry-forward and encashment rules:
- Unpaid leave: Eligibility, impact on benefits and payroll, approval requirements.
11. Work From Home Policy
What it does: Sets the rules for remote and hybrid work, covering eligibility, hours, communication, equipment, and data security.
Why you need this in 2026: We've worked with enterprises that operated hybrid models for three years without a written policy. When a data breach occurred through an unsecured home network, or when a manager denied WFH to one team member while allowing it for another, there was zero documented standard to reference.
The disputes that followed were entirely preventable.
What your template should include:
- Eligibility:
- Working hours and availability: Define core hours (e.g., 10 AM–4 PM) during which the employee must be reachable. Allow flexibility outside core hours.
- Communication standards: Specify mandatory tools (video for team meetings, messaging for daily check-ins, email for formal communication).
- Equipment and expenses: Clarify whether the company provides equipment (laptop, monitor, headset) and reimburses internet or co-working costs.
- Data security:
12. Sabbatical Policy
What it does: Offers long-tenured employees extended leave for personal or professional development, a retention tool that costs less than replacing experienced talent.
What your template should include:
- Eligibility: Minimum [5] years of continuous service. One sabbatical per [10]-year period.
- Duration and purpose: [4–12] weeks for education, research, volunteering, or personal well-being. Require the employee to submit a brief plan outlining the purpose and return date.
- Compensation and benefits:
- Return guarantee: Guarantee reinstatement to the same or a substantially equivalent role.
Rewards and Performance Policies
13. Rewards and Recognition Policy
What it does: Formalises how the organisation acknowledges outstanding work, so recognition is consistent and merit-based rather than dependent on whether an employee happens to have an attentive manager.
What your template should include:
- Categories: Performance awards (exceeding targets), values awards (demonstrating company values), milestone awards (tenure: 5, 10, 15 years), and peer recognition (nominations by colleagues).
- Nomination and selection: Define who can nominate (managers, peers, or self-nomination depending on the category), the review committee composition, and the selection criteria.
- Reward types: Cash bonuses, additional paid leave, gift cards, public recognition (town hall shout-outs, intranet features), or learning and development opportunities. Specify the monetary range for each category.
14. Attendance and Punctuality Guidelines
What it does: Sets clear expectations for showing up, on time, consistently, with a defined process for unplanned absences.
What your template should include:
- Standard expectations: Expected start times, grace period (if any), and the distinction between planned absence (applied in advance) and unplanned absence (reported on the day).
- Reporting process:
- Progressive consequences: Specify the escalation: verbal counselling, then written warning, then final warning, then suspension or termination. Include specific thresholds (e.g., [3] unplanned absences in a [30]-day period triggers the first formal step).
- Tracking method: State whether the organisation uses biometric, HCM-based, or manual attendance tracking and confirm records are auditable.
Safety and Compliance Policies
These three policies carry direct regulatory, financial, and reputational consequences. I've seen manufacturing clients face facility shutdowns and BFSI clients face board-level scrutiny because these policies existed on paper but lacked enforcement in practice.
15. Health and Safety Policy
What it does: Documents the organisation's commitment to a hazard-free workplace, with specific responsibilities and procedures.
What your template should include:
- Responsibilities, three tiers:
- Management: provide resources, maintain safe infrastructure, fund safety training and equipment.
- Employees: follow safety protocols, use PPE as required, report hazards immediately.
- Safety team/HR: conduct audits, investigate incidents, maintain training records.
- Hazard identification and reporting:
- Emergency procedures: Evacuation routes, assembly points, fire safety protocols, first aid locations, and emergency contact numbers.
- Training: New hire safety induction within [first week]. Annual refresher training for all employees. Role-specific training for high-risk roles (e.g., factory floor, lab, construction site).
- Annual review: Review the policy annually or immediately upon any workplace incident, regulatory change, or facility modification.
16. Drug and Alcohol Policy
What it does: Prohibits substance use in the workplace and defines consequences, especially critical for roles where impairment creates safety risks.
What your template should include:
- Prohibited conduct: Possession, use, distribution, or sale of illegal substances on company premises. Reporting to work under the influence of alcohol or drugs. Misuse of prescription medication affecting job performance or safety.
- Prescription medication disclosure:
- Testing: Specify whether the organisation conducts pre-employment, random, or post-incident testing, with reference to applicable legal constraints.
- Support and rehabilitation: Offer access to Employee Assistance Programmes (EAP). Employees who voluntarily seek help before an incident occurs will be supported and encouraged through the recovery process.
17. Fraud Policy
What it does: Defines what constitutes fraud, establishes prevention and detection mechanisms, and outlines the investigation-to-consequence process.
What your template should include:
- Definition:
- Responsibilities: Management sets the ethical tone and ensures controls exist. Employees report suspicious activity. The compliance team (or designated officer) investigates.
- Whistleblower protection: Provide a confidential channel (hotline, portal, designated email). Employees reporting in good faith are protected from retaliation. Anonymous reporting is permitted.
- Investigation and consequences: The compliance team gathers evidence, interviews involved parties, and documents findings. Confirmed fraud results in termination and may be referred to law enforcement. The organisation may pursue civil recovery.
Grievance and Dispute Resolution
18. Employee Grievance Redressal Policy
What it does: Gives employees a formal, documented path for raising workplace concerns and getting them resolved before they escalate to legal disputes.
What your template should include:
- Scope: A grievance is any concern about working conditions, interpersonal conflicts, policy application, compensation discrepancies, or any other matter affecting the employee's ability to perform their role.
- Four-stage process:
- Confidentiality and protection from retaliation. All grievances and related discussions are confidential. Retaliation in any form triggers separate disciplinary proceedings.
Travel and Expense Policy
19. Travel Policy
What it does: Standardises how business travel is authorised, booked, executed, and reimbursed, preventing both cost overruns and employee frustration.
What your template should include:
- Pre-approval: All business travel requires written approval from the reporting manager before booking. International travel requires [VP/CHRO]-level approval.
- Eligible expenses and limits: Transport (economy class for flights under [X] hours, business class for flights over [X] hours at [band level] and above), accommodation (specify per-night limits by city tier), meals (per diem rates or actuals with a daily cap), and incidentals (laundry, local transport).
- Booking process: Require use of [approved booking platform/travel desk]. Personal bookings are reimbursed only with prior approval.
- Expense submission:
- Consequences for policy violations: Late submissions, personal expenses charged to the company, or travel booked without approval may result in denied reimbursement and disciplinary action.
Hiring Policy
20. Hiring Policy
What it does: Governs every step of the recruitment lifecycle, from requisition to onboarding, ensuring fairness, consistency, and efficiency.
What your template should include:
- End-to-end process: Department submits a manpower requisition → HR posts the job description → sourcing and screening → shortlisting → structured interviews → selection → offer → background verification → onboarding.
- Roles and responsibilities: HR owns the pipeline, job posting, screening, and negotiation. Hiring managers own the job description, interview, and selection decision. Both sign off on the final offer.
- Bias prevention:
- Background verification: Mandate employment history, education, and criminal record verification as a condition of employment. Specify the verification is completed [before / within X days of] the start date.
- Anti-nepotism: Disclose and manage conflicts of interest when a candidate is related to an existing employee. Require approval from [HR Head / designated authority] before proceeding.
- Confidentiality: All candidate information is treated as confidential and shared only with individuals directly involved in the hiring decision.
How to Build Your Policy Framework: A Practical Playbook
The five-step process below is what I recommend to every CHRO building or overhauling their policy framework. It is based on what we've seen work in 1,200+ deployments: the sequence that actually gets policies written, approved, and enforced.
Step 1: Run a Policy Gap Analysis
Before writing anything, audit what you have. Map your existing policies against the 20-policy framework above. For each one, answer three questions: Does a written policy exist? When was it last updated? Is it actively enforced (tracked acknowledgements, documented violations, consistent application)?
You'll typically find three buckets: policies that exist and are current, policies that exist but are outdated or unenforced, and policies that simply lack documentation. The second bucket is the most dangerous — an outdated, unenforced policy is more harmful than a missing one in a legal dispute.
Step 2: Prioritise by Risk
Writing 20 policies simultaneously is impractical. Prioritise based on the risk of operating without the policy:
- Immediate (Month 1): POSH, Code of Conduct, Employee Contract, Leave Policy, Health & Safety. These carry direct legal liability.
- High priority (Months 2–3): Grievance Redressal, Termination, NDA, Equal Opportunity, WFH Policy. These are where disputes most commonly arise.
- Important (Months 3–6): Remaining policies: Attendance, Travel, Fraud, Hiring, Anti-Bullying, Rewards, Sabbatical, Drug & Alcohol, Non-Discrimination, Employee Handbook.
Step 3: Assemble the Right Drafting Team
Every policy needs three perspectives at the table:
- HR for operational practicality: will this actually work in day-to-day management?
- Legal for enforceability: does the language hold up under scrutiny?
- Operations/Business for feasibility: can the business actually implement this across all locations and shifts?
For specialised policies (POSH, Health & Safety, Data Protection), bring in subject matter experts.
Step 4: Write for Enforceability, Rather Than Elegance
I tell every policy writer the same thing: if a manager reading this policy at 9 PM during an incident struggles to figure out what to do, the policy has failed. Use plain language. Use numbered steps for procedures. Include sample language where judgment calls are involved. Reserve legal jargon for situations where a specific legal term is required for enforceability.
Every policy document should follow this structure:
- Title and version: Policy name, version number, effective date, next review date.
- Purpose: One paragraph explaining why this policy exists.
- Scope: Who it applies to, where, and when.
- Definitions: Define any term a reasonable employee might interpret differently.
- Policy statement: The core rules, expectations, and standards.
- Procedures: Step-by-step process for implementation, reporting, and escalation.
- Consequences: Specific outcomes for violations.
- Acknowledgement: Digital sign-off confirming the employee has read and understood the policy.
Step 5: Distribute, Track, and Enforce
A policy sitting in a shared drive is just a document, lacking any governance power. Distribution means every applicable employee receives the policy, is required to acknowledge it, and can access the current version at any time.
Tracking means you know who has acknowledged, who still needs to, and when acknowledgements are overdue. Enforcement means violations are investigated and consequences are applied consistently across locations, levels, and business units.
This is where manual processes collapse at scale. If you're managing 1,000+ employees across multiple locations, you need a platform that automates policy distribution, tracks acknowledgements in real time, sends escalations for overdue actions, and maintains an audit trail. It is the difference between having policies and governing with them.
.webp)
Turning Policies Into Enforceable Governance
Here's what I've learned from watching policy frameworks succeed and fail across hundreds of enterprises: the quality of the document matters, but the quality of the enforcement system matters more.
The best-written policy in India is ineffective if it sits in a PDF that was emailed once in 2022 and left untracked. The policies I've seen actually change organisational behaviour share three characteristics: employees can find them instantly, managers know how to apply them in real situations, and HR can prove (with data, rather than anecdotes) that they're being followed.
At ZingHR, this is the problem we built the platform to solve. Our Hire-to-Retire platform, powered by Ghrowth.ai , goes beyond storing policies. It automates the entire lifecycle.
Policies are distributed through the platform with version control, acknowledgements are tracked in real time, compliance gaps are surfaced on role-specific dashboards (CHRO, CFO, CEO, Board), and policy-driven rules flow natively into leave, attendance, payroll, and performance modules through ZingZeroTAP, our zero-touch payroll engine. One codebase, one database, zero middleware, zero contradictions between systems.
We've delivered this across 35+ modules, 12 industry verticals, and 2.8 million+ active users in India, MEA, and SEA. If you're ready to move from policy documents to policy governance, book a demo and we'll walk you through how it works on your specific framework.
Frequently asked questions (FAQs)
Start with the legally mandated ones: POSH policy, leave policy aligned with your state's requirements, health and safety policy, and employee contracts. Then prioritise by operational risk: Code of Conduct, Grievance Redressal, Work From Home, Termination, and Hiring. The full 20-policy framework in this guide covers every critical domain.
Define eligibility by role (rather than employee preference), set core availability hours, specify communication tools, clarify equipment and expense provisions, and mandate data security protocols (VPN, screen-lock, approved devices). Include the company's right to modify or revoke remote work arrangements with reasonable notice. See the Work From Home Policy section above for sample clauses.
At minimum, annually. In practice, trigger an immediate review whenever there's a relevant legislative change, a significant workplace incident, a change in organisational structure, or feedback from an audit or employee survey. In India, state-level amendments happen frequently enough that a "set it and forget it" approach creates real compliance risk.
Salary bands for each role or grade, the criteria for determining placement within a band, bonus and incentive calculation methodology, the frequency of pay equity audits, and a prohibition on asking candidates about salary history. The policy should name who is accountable for identifying and correcting pay disparities.
Free templates from sources like SHRM or AIHR are useful starting points, but every policy must be customised to your organisation's industry, state-specific requirements, internal governance standards, and operational realities. For enterprises managing 1,000+ employees across multiple locations, templates should be integrated into an HCM platform for version control and enforcement tracking.
What to do next?
See ZingHR in Action
Join the 1,200+ enterprises that have replaced fragmented HR with one intelligent, future-ready platform. See ZingHR in 30 minutes.
Build the Organization You Want
Great HR drives retention, capability, and culture. ZingHR takes care of the operational layer so your people team owns the strategy.






