Knowledge & Perspectives

AI in the Workplace and BRSR: What Automated Hiring, Monitoring, and Performance Systems Mean for Your Social Governance Obligations

Companies using AI for hiring, performance management, and workforce monitoring have social governance obligations that map directly to BRSR Principles 3 and 5. Most have not made that connection. This post explains which governance questions AI in the workplace creates under BRSR, what India’s DPDP Act adds, and what the governance architecture needs to look like for companies that want their social disclosures to hold up under assessment.
Table of Contents

Workforce and Labour Rights

There is a quiet assumption embedded in most conversations about AI and Indian business: that AI is primarily an efficiency tool, and that its governance implications sit mostly in data security and IT policy.

The BRSR framework does not see it that way. Neither do the buyers, investors, and assessors who are increasingly asking mid-sized Indian companies to show not just what their social policies say, but what their operational systems actually do.

Companies using AI for hiring, workforce monitoring, productivity tracking, or performance management have social governance obligations most have not yet thought through. Those obligations sit directly inside BRSR’s human rights and workforce principles. They affect what an assessor will look for. And they create a category of risk that the policy document on the company’s intranet is almost certainly not addressing.

This post is for HR heads, sustainability leads, and company secretaries at mid-sized listed companies who are starting to use AI tools in workforce management and have not yet mapped those tools to their BRSR obligations.

What AI in the Workplace Actually Looks Like in Indian Companies Today

Before connecting to BRSR, it is worth being specific about what “AI in the workplace” means in practice, because the term is broad enough to obscure the actual governance questions. Indian mid-sized companies are using AI-driven tools across four main categories:

Recruitment and hiring.

AI-powered applicant tracking systems that screen resumes, rank candidates, filter on keywords, and in some cases score video interview responses. These tools filter applicants before any human reviewer sees them. A candidate can be eliminated from consideration by an algorithm without any human ever evaluating their profile.

Workforce monitoring.

Productivity tracking tools that log keystrokes, capture periodic screenshots, track application usage, monitor login and logout times, and in some remote work contexts use webcam-based presence detection. These tools are more common than most sustainability teams realise, particularly in IT services, BPO, and manufacturing support functions.

Performance management.

Algorithmic performance scoring systems that aggregate data from multiple sources, sales figures, response times, error rates, output volumes, and use these to generate performance scores that influence appraisals, promotion decisions, and termination recommendations.

Workforce planning and deployment.

AI tools that assign shifts, allocate work, or schedule workers based on operational demand, often without direct human review of individual assignments.

Each of these categories produces a social governance question that maps directly to BRSR. The question is not whether companies should use these tools. The question is whether they have the governance architecture to use them in a way that is defensible under BRSR Principles 3 and 5, and increasingly under India’s Digital Personal Data Protection Act.

What BRSR Actually Requires on This

BRSR is built on the nine principles of the National Guidelines on Responsible Business Conduct. Three of those principles are directly engaged by AI in the workplace.

BRSR Principle 3 requires companies to respect and promote the wellbeing of all employees, whether permanent, contractual, or part-time. BRSR Core’s social and workforce attributes specifically cover workforce size and composition, use of contract labour, diversity, health and safety performance, training, wages, and access to social security benefits. (Source: ESG Market Advisory)

When an AI hiring system screens out candidates based on algorithmic criteria, and that system has not been audited for discriminatory outcomes, the company’s ability to demonstrate compliance with its diversity and inclusion commitments under Principle 3 becomes harder to establish. The number may be disclosed. The system that produced it may be producing biased outputs. That combination is a governance gap.

BRSR Principle 5 requires companies to respect and promote human rights. BRSR’s Principle 5 focus covers human rights due diligence, policies against discrimination and harassment, forced labour, and providing access to remedy for affected individuals. BRSR requires disclosures on human rights policies, training, and any reported instances of human rights violations. (Source: POLARIS Market Research)

Human rights due diligence under BRSR Principle 5 is not limited to supply chain relationships. It includes the company’s own workforce. A worker who is subject to algorithmic performance management that results in a warning, a demotion, or a termination recommendation, and who has no mechanism to understand or challenge that decision, is in a situation that implicates Principle 5 directly. The question is not theoretical. It is whether the company’s grievance mechanism, which BRSR also requires, is accessible and functional for workers who want to contest AI-driven decisions affecting their employment.

BRSR Principle 3 Essential Indicators specifically require disclosure of: number of complaints related to working conditions; access to and details of complaints mechanisms for workers; and details of any corrective actions taken. BRSR Principle 4 requires disclosure of human rights due diligence conducted and its scope, premises accessible to differently abled visitors, percentage of value chain partners assessed for rights issues, and actions taken to address rights risks. (Source: Research and Markets)

When AI systems are making or influencing consequential decisions about workers, human rights due diligence has to include those systems. A company that discloses it has conducted human rights due diligence but has not reviewed the AI tools that affect its workforce’s employment status is making a disclosure that an assessor will find difficult to verify.

The DPDP Act Adds Another Layer

India’s Digital Personal Data Protection Act, enacted in August 2023, adds a parallel set of obligations that interact directly with AI in the workplace.

The DPDP Act remains applicable to any processing of personal data through AI systems, if the other conditions of the law are met, given the broad definitions of processing and personal data. (Source: Mordor Intelligence)

With the recent uptick in employers using AI tools for recruitment, such as automatically screening job applicant resumes and matching applicants to new job opportunities, employers must ensure that the underlying data is accurate. (Source: Fortune Business Insights)

The DPDP Act’s requirements on notice, consent, and data accuracy apply to employee data processed through AI systems. Where AI makes a consequential decision using personal data, the data must be accurate, and employees have rights of correction. Correction, completion, and updating of personal data can be requested by the employee, but must also occur automatically when the personal data is likely to be used to make a decision that affects the principal. (Source: Mordor Intelligence)

One significant gap in the current framework is worth being honest about. Under Sections 11-12 of the DPDP Act, a worker can access or correct their data only if they previously provided consent. However, most workplace data processing occurs under the non-consent clause of Section 7(i). This effectively denies workers access to their data and recourse against algorithmic decisions, marking a significant gap in data governance for the Indian workforce. (Source: UnivDatos)

This gap does not eliminate the governance obligation. It makes it more important that companies build internal grievance mechanisms that give workers a meaningful channel to raise concerns about AI-driven decisions, because the regulatory framework alone does not guarantee that channel.

The Five Governance Questions AI in the Workplace Creates Under BRSR

These are not hypothetical. They are the questions a diligent BRSR Core assessor, a buyer ESG auditor, or a PE due diligence team will ask when they discover that a company uses AI in workforce decisions.

1. Has the company conducted human rights due diligence on its AI hiring tools?

BRSR Principle 5 requires disclosure of human rights due diligence conducted and its scope. If a company uses an AI-powered applicant tracking system, that system is part of the company’s human rights risk landscape. Vendors cap liability in standard agreements. An employer’s platform may scrape data from unknown sources, score candidates using opaque logic, and filter applicants before any human review, yet vendor agreements typically cap liability, disclaim compliance warranties, and restrict algorithmic audits. (Source: White & Case LLP)

A company that discloses it has conducted human rights due diligence but cannot show it has reviewed the AI tools making pre-screen hiring decisions is making an incomplete disclosure.

2. Can workers access a functioning grievance mechanism for decisions made by or influenced by AI?

BRSR requires companies to have a grievance mechanism accessible to workers, with documented intake, timelines, and closure records. If an AI performance system flags a worker for termination and that worker wants to understand or challenge the basis for that recommendation, the grievance mechanism must be able to receive, process, and resolve that challenge. Most grievance mechanisms at mid-sized companies were not designed with AI-driven decisions in mind. They were built for interpersonal disputes and safety complaints.

3. Are workforce diversity and inclusion disclosures accurate when AI hiring tools are in use?

AI that automatically filters out candidates with gaps in employment or specific keywords may inadvertently discriminate against protected groups or those with disabilities. (Source: CSDDD | Updates, Compliance) If a company’s AI hiring tool is systematically filtering out certain demographic groups, the diversity metrics the company discloses under BRSR Principle 3 may be accurate as stated but misleading in context. An assessor who understands the hiring process will identify this as a governance gap.

4. Is workforce monitoring proportionate, disclosed, and subject to a grievance pathway?

Productivity monitoring tools that track keystrokes, screen activity, or camera-based presence have implications for worker dignity and privacy. BRSR’s worker wellbeing disclosures and the DPDP Act’s data processing requirements both apply. Companies using these tools without a clear internal policy, worker notice, and a grievance pathway for concerns about monitoring have an exposure that their BRSR filing does not currently capture.

5. Does the company’s board receive visibility on AI workforce risks?

BRSR Principle 3 and the broader BRSR governance framework require board-level oversight of social matters. If AI tools are making or influencing decisions about hundreds or thousands of workers, those tools are a social governance risk that should appear somewhere in the company’s board reporting. In most mid-sized companies, they do not. The AI tools are implemented by IT or HR, used operationally, and never reach the sustainability committee or the board.

What Good Governance Looks Like Here

None of this argues against using AI in workforce management. The tools can be genuinely useful. The argument is about governance architecture: what needs to be in place for a company to use these tools in a way that is defensible under BRSR, honest in its disclosures, and fair to workers.

Four things every company using AI in workforce decisions should have in place:

An AI use register for workforce decisions. A documented inventory of which AI tools are used, what decisions they influence, what data they process, and who is responsible for their oversight. This does not need to be complex. It needs to exist.

Human rights due diligence that explicitly covers AI tools. The BRSR Principle 5 disclosure on human rights due diligence should name the AI tools used in workforce decisions as within scope. The due diligence should include at minimum: a review of how the vendor handles bias testing, what data sources the tool uses, and what appeal or override mechanism exists.

A grievance mechanism that explicitly covers AI-influenced decisions. Workers should be able to raise a concern about an AI-driven decision through the company’s existing grievance mechanism. The intake form, the workflow, and the escalation path should all be capable of handling this category of complaint. If they are not, the mechanism needs to be updated.

Board visibility on AI workforce risk. Twice a year at minimum, the sustainability committee or board should receive a summary of the AI tools used in workforce decisions, any concerns raised through the grievance mechanism about those tools, and any bias or accuracy issues identified through internal review.

Why This Will Become More Visible, Not Less

The regulatory direction globally is toward more scrutiny of AI in employment, not less. 83% of companies had planned to use AI to screen resumes in 2025, according to a survey by Resume Builder, yet state rules in the US demand audits, notices, and bias tests that vary widely. (Source: Normative)

India’s regulatory framework does not yet have dedicated AI employment law. But BRSR’s human rights due diligence requirements, the DPDP Act’s data processing obligations, and the direction of international investor scrutiny all point in the same direction. Companies that build the governance architecture now will be in a materially better position when assessors, buyers, and investors start asking these questions specifically.

The companies that will struggle are the ones that have implemented AI workforce tools operationally without connecting them to their social governance framework. When the BRSR disclosure says “human rights due diligence conducted” and the AI hiring tool has never been reviewed for discriminatory outcomes, that gap will eventually be visible.

Frequently Asked Questions about AI in the Workplace and BRSR

Does BRSR specifically mention AI or automated decision-making?

The current BRSR framework does not use the words “AI” or “automated decision-making” explicitly. However, BRSR Principles 3 and 5 require human rights due diligence, worker grievance mechanisms, and workforce wellbeing disclosures that apply to any organisational process affecting workers, including automated ones. The scope of these obligations does not change because a decision is made by an algorithm rather than a manager.

Is the DPDP Act in force for employee data in India?

The Digital Personal Data Protection Act was enacted in August 2023. Its rules were notified by the Indian government in November 2025 via G.S.R. 846(E). The Act applies to processing of digital personal data including employee data, with processing under employment-related purposes covered under Section 7(i) of the Act.

What is the governance risk if our AI hiring tool has not been audited for bias?

A company using an AI hiring tool that has not been reviewed for discriminatory outcomes has a gap in its human rights due diligence under BRSR Principle 5. If the tool’s outputs are producing demographic disparities in who gets screened through to interview, the company’s diversity disclosures under BRSR Principle 3 may be accurate as stated but misleading in context. An assessor who understands the hiring process may identify this. A buyer due diligence team almost certainly will.

Does a worker have a legal right to challenge an AI-driven employment decision in India?

Under the current DPDP Act framework, workers can request correction of personal data used in decisions affecting them, but this right is limited when processing occurs under the non-consent employment clause. There is currently no explicit statutory right to contest a solely automated employment decision in India, unlike under the EU GDPR. This makes internal grievance mechanisms that cover AI-driven decisions more important, not less.

What should a BRSR Principle 5 disclosure say about AI in the workplace?

At minimum, a complete BRSR Principle 5 human rights due diligence disclosure for a company using AI in workforce decisions should acknowledge that automated tools are within scope of the due diligence, identify the categories of decisions AI tools influence, describe how the company monitors for discriminatory or inaccurate outcomes, and note the grievance pathway available to affected workers. A disclosure that says human rights due diligence was conducted without any reference to AI tools is incomplete if those tools are in use.

Where does this fit in the SVEGA Framework?

AI workplace governance sits across two pillars of the SVEGA Framework. Pillar 2, Workforce Governance Architecture, covers the KPI ownership, monitoring, and evidence infrastructure that must extend to AI-influenced workforce decisions. Pillar 4, Grievance and Escalation Infrastructure, covers the mechanism design that must be capable of receiving and resolving worker concerns about automated decisions. A SVEGA Diagnostic will assess whether your current governance architecture covers AI workforce tools or has left them outside its scope.

What to Do Next

If your company uses AI tools in hiring, performance management, monitoring, or workforce planning, start with an honest internal audit of three things.

First, which tools are in use and what decisions do they influence. Second, whether those tools have been reviewed for accuracy and discriminatory outcomes, and what the vendor contractually provides in terms of transparency and auditability. Third, whether the company’s grievance mechanism can receive and process a worker complaint about an AI-driven decision.

If any of those three audits produces a gap, that gap is a BRSR governance exposure. It is also the kind of exposure that surfaces first in a buyer due diligence conversation or a BRSR Core assessment, not in an internal review.

Picture of Priyanka Bajiraj

Priyanka Bajiraj

Priyanka Bajiraj is a sustainability and social ESG professional with 10 years of experience across sustainability research, social governance advisory, UN exposure, and operational systems thinking.

Through SVEGA, Priyanka focuses on helping organisations move beyond ESG narratives and build practical governance systems that make social responsibility measurable, accountable, and operational.

WHAT'S INCLUDED

Build supplier systems that protect growth and market access.

Workforce and Labour Rights

A buyer’s social audit asks for POSH records, and a thirty-person factory with no HR team finds its committee does not meet the rule. The Internal Committee is mandatory at ten employees, the external member is not optional, and two 2025 additions now sit on top.

Regulatory Intelligence

The four labour codes came into force on 21 November 2025, repealing twenty-nine central labour laws, and the final central rules followed on 8 May 2026. For a factory of about a hundred people, several obligations are now settled and headcount-triggered: a new wage definition that lifts provident fund and gratuity costs, appointment letters for every worker, a grievance committee at twenty workers, a works committee at a hundred, and a creche at fifty.

Supplier Accountability

For a growing number of Indian manufacturers and exporters, a SMETA audit has become the compliance test that actually gates the order, ahead of anything SEBI requires. A buyer in Europe or the United States asks for one, and a factory that never had a BRSR obligation suddenly has an auditor at the gate. It matters here for one specific reason: SMETA measures a site against the ETI Base Code as well as Indian law, whichever protects the worker more, so a factory that is fully compliant with the labour codes can still receive findings. This post walks through what the auditor does on the day, and where mid-sized Indian factories most often lose ground.

Social Governance Fundamentals

Most social compliance advice in India is written for the top 1,000 listed companies. The unlisted manufacturers and exporters that carry the bulk of the country’s production sit below the BRSR line but still face buyer audits, the labour codes, and customer questionnaires. This post explains who the missing middle is and what social governance actually means for a company this size.

REACH US

If this resonates with the governance challenges you are navigating,

we welcome a focused conversation about where your organisation stands and what building the right systems would look like.