Certifications

The Quality Department at HTC proactively leads compliance and assurance initiatives through audits and assessments to strengthen governance, mitigate risks, and enhance operational excellence across our global delivery centers and services. HTC continues to maintain compliance with internationally recognized management system standards at the enterprise level, including ISO 9001 (Quality Management System), ISO/IEC 27001 (Information Security Management System), ISO 14001 (Environmental Management System), ISO 45001 (Occupational Health & Safety Management System), ISO/IEC 20000-1 (IT Service Management System), ISO 55001 (Asset Management System), and ISO/IEC 42001 (Artificial Intelligence Management System).

In FY2025, HTC successfully achieved CMMI Development Maturity Level 5 (ML5) under CMMI V3.0, demonstrating the organization’s commitment to process excellence, continuous improvement, and the delivery of high-quality software and engineering services. HTC has also achieved HITRUST Certification for applicable healthcare platforms and services, demonstrating adherence to the HITRUST Common Security Framework (CSF) and reinforcing the organization’s commitment to protecting sensitive healthcare information through comprehensive security, privacy, and regulatory compliance controls.

HTC also undergoes SSAE 18 SOC 2 Type II independent audits to validate the effectiveness of its security, availability, confidentiality, processing integrity, and privacy controls, providing assurance to customers regarding the robustness of its operational and information security practices.

HTC publishes its annual Environmental, Social, and Governance (ESG) Report in accordance with the Global Reporting Initiative (GRI) Standards, reflecting the organization’s commitment to transparent sustainability reporting and responsible business practices.

HTC actively participates in globally recognized sustainability assessments to benchmark and continuously improve its ESG performance. The company annually responds to the CDP (Carbon Disclosure Project) climate and environmental disclosure framework and undergoes EcoVadis sustainability assessments, demonstrating its commitment to responsible business practices, environmental stewardship, ethical governance, sustainable procurement, and social responsibility.

HTC has established a robust Health, Safety, and Environment Integrated Management System (HSEIMS) across its global operations to ensure compliance with applicable legal and regulatory requirements while promoting a safe, healthy, and environmentally responsible workplace. HTC’s ISO 14001 and ISO 45001 certifications cover its major delivery locations and business operations, with the certification scope expanding in line with business growth and operational requirements.

Recognizing that operational requirements vary across geographies, HTC implements a risk-based HSEIMS framework tailored to the nature and criticality of business activities at each location. Certified locations are subject to regular internal and external audits, while all remaining locations operate under HTC’s corporate HSE governance framework and comply with applicable environmental, health, and safety legislation.

Information security remains a fundamental pillar of HTC’s governance framework. HTC has implemented comprehensive information security policies, processes, and controls across its global workforce, business systems, and operations. The organization’s Information Security Management System (ISMS), certified to ISO/IEC 27001, covers its major delivery centers and critical business operations, ensuring the confidentiality, integrity, and availability of customer and organizational information.


 

List of certifications as on date

Certification Certificate / Report Location Certification Validity
ISO 9001:2015 25EQOV32 Chennai (MEPZ, Guindy) 19-Feb-2028
ISO 27001:2022 24EQNB69 Chennai (MEPZ, Guindy, Vandalur), Hyderabad 05-Aug-2027
ISO 9001:2015 23EQLX93/R1 Bengaluru 03-Nov-2026
ISO 27001:2022 23EQLC85/R1 Bengaluru 03-Nov-2026
ISO 20000-1:2018 23EITLM84/R1 Bengaluru 03-Nov-2026
ISO 55001:2014 22AAMS1001 Bengaluru 03-Nov-2026
ISO 14001:2015 23EELC79/R1 Troy 30-Oct-2026
ISO 45001:2018 23EOLJ72/R1 Troy 30-Oct-2026
CMMI DEV ML5 Appraisal #79797 Troy, Chennai, Hyderabad, Bengaluru 08-Dec-2028
HITRUST Chennai (MEPZ), Troy 10-Feb-2027
SSAE 18 / SOC 2 Type II Chennai (MEPZ, Guindy, Vandalur), Hyderabad, Bengaluru, Troy Compliance Verified Annually

Policies

QMS Policy

HTC will….

  • Deliver products, services and solutions right, the first time, every time.
  • Fulfil the requirements of our internal and external customers.
  • Deploy innovative processes by leveraging emerging technologies

ISMS Policy

HTC will ensure security in the organization by…

  • Protecting sensitive information / data assets from unauthorized access, disclosure, deletion, modification, and corruption through adequate physical, personnel, and logical security.
  • Preserving and protecting private information according to applicable laws, regulations, and contractual requirements.
  • Establishing adequate control for the security threats that are assessed.
  • Safeguarding the accuracy and completeness of information; ensuring the availability of information and associated services for business continuity.
  • Identifying adequate security-specific roles and responsibilities in the organization.
  • Leveraging emerging technologies to maintain the Confidentiality, Integrity, Availability, and Privacy of information assets belonging to business associates and customers, both internal and external.
  • Adhering to the Information Security Law in line with applicable IT-related Government Laws/Acts.
  • Establishing a Security Forum to establish, implement, monitor, and continually improve the ISMS.
  • Reporting security weaknesses/breaches and taking appropriate action as per the ISMS and applicable legal framework.
  • Providing adequate Information Security training and awareness to all employees and relevant third-party resources.
  • Involving all employees and relevant third parties to enforce the ISMS throughout the organization.

HSE IMS Policy

We, at HTC Global Services, are committed to bringing human expertise to technology to deliver purposeful solutions that amplify value by providing reliable services to achieve our stated goals through the following guidelines:

  • Establish, implement, maintain, and commit to comply with requirements, including legal and other requirements, to continually improve our HSE-Integrated Management System (HSE-IMS) to plan, develop, and provide reliable services that satisfy our interested parties’ requirements.
  • Plan, implement, and verify HSE-IMS-related training for the continual improvement of all our employees and contractors.
  • Deploy the HSE-IMS policy and develop suitable systems to achieve these objectives and targets.
  • Continually improve the Health, Safety and Environment Management System and enhance HSE-IMS performance through periodic reviews and assessments.
  • Commit to protecting the environment and preventing, eliminating, or minimising pollution-generating situations and potential risks that could harm the environment, including climate change and environmental sustainability.
  • Prevent work-related injury and ill health associated with psychosocial risks while promoting the well-being of our employees and contractors.
  • Commit to complying with applicable HSE-IMS legislation, regulations, and standards for all activities carried out by our employees and contractors.
  • Evaluate workplace safety and manage psychosocial risks to ensure hazards are eliminated or controlled to the extent reasonably practicable.
  • Promote and enhance a work environment based on dignity, mutual respect, confidentiality, cooperation, and trust within the HSE-IMS.
  • Conduct periodic assessments and reviews of our own and our contractors’ performance to ensure the continual improvement of our HSE-IMS.
  • Ensure that our HSE-IMS Policy is communicated, understood, applied, implemented, and maintained by everyone working for and on behalf of our company, and that it is displayed prominently for visitors, interested parties, and the public.

ESG Policy

HTC Global Services is committed to conducting business in a sustainable, ethical, and responsible manner. We integrate Environmental, Social, and Governance (ESG) principles into our operations, decision-making, and stakeholder relationships to create long-term value.

HTC Will:

Environmental (E):

  • Comply with all applicable environmental laws and regulations and strive to exceed regulatory requirements.
  • Minimise environmental impact by reducing waste, promoting reuse and recycling, and optimising the efficient use of natural resources.
  • Encourage the adoption of renewable energy sources and implement energy-efficient practices across operations.
  • Measure, monitor, and report greenhouse gas emissions (Scope 1, Scope 2, and Scope 3) in alignment with Science Based Targets initiative (SBTi) commitments.
  • Promote virtual collaboration and sustainable practices to reduce business travel and associated carbon emissions.
  • Continuously improve environmental performance through an effective Environmental Management System (EMS).

Social (S):

  • Provide a safe, healthy, and inclusive work environment for all employees.
  • Uphold and respect human rights by prohibiting child labour, forced labour, and all forms of discrimination.
  • Ensure fair wages, benefits, and safe and healthy working conditions for all employees.
  • Promote diversity, equity, and inclusion (DEI) across the workplace.
  • Support employee development through training, learning, and career advancement opportunities.
  • Encourage employee well-being, engagement, and work-life balance.
  • Promote community engagement and drive social responsibility initiatives.
  • Maintain transparent communication and provide effective channels for employee feedback and grievance redressal.

Governance (G):

  • Maintain the highest standards of business ethics, integrity, and transparency in all operations.
  • Prevent conflicts of interest, corruption, and bribery through robust policies and internal controls.
  • Ensure compliance with all applicable laws, regulations, and organisational policies.
  • Promote accountability and responsible decision-making at all levels of the organisation.
  • Safeguard confidential information and ensure data privacy and information security.

Privacy Policy

HTC is committed to protecting the privacy of personal information and ensuring its responsible processing in compliance with applicable legal, regulatory, and contractual requirements.

To achieve this, HTC shall:

  • Process personal information lawfully, fairly, transparently, and only for legitimate business, legal, and regulatory purposes.
  • Collect and process only the minimum personal information necessary for the specified and authorised purpose.
  • Provide individuals with appropriate information regarding how their personal information is collected, used, shared, retained, and protected.
  • Implement appropriate safeguards to protect personal information, including additional measures for children’s information where applicable.
  • Comply with applicable privacy laws, regulations, contractual obligations, and customer requirements across all jurisdictions in which HTC operates.
  • Establish and maintain appropriate technical, organisational, and administrative controls to safeguard personal information against unauthorised access, disclosure, alteration, loss, or misuse.
  • Provide privacy awareness and data protection training to employees, contractors, third parties, and vendors to promote the responsible handling of personal information.
  • Define, monitor, and periodically review privacy objectives, and continually improve the effectiveness of HTC’s Privacy Information Management practices.

AI Policy

HTC Shall,

  • Ensure the development, deployment, and use of Artificial Intelligence (AI) in a lawful, ethical, secure, and responsible manner aligned with HTC’s values and business objectives.
  • Adopt a risk-based approach to identify, assess, mitigate, monitor, and manage AI-related risks throughout the AI system lifecycle.
  • Promote fairness and prevent unlawful bias and discrimination through appropriate testing, validation, monitoring, and continual evaluation of AI systems.
  • Maintain transparency and provide appropriate explainability of AI systems, commensurate with their intended purpose, risk, and impact.
  • Establish meaningful human oversight for AI-supported decision-making, enabling appropriate monitoring, intervention, and accountability.
  • Protect personal and sensitive information by implementing appropriate privacy, security, and data governance controls in accordance with applicable legal, regulatory, and contractual requirements.
  • Ensure AI systems are designed, developed, deployed, and operated securely, reliably, and resiliently in accordance with secure development lifecycle practices.
  • Establish clear governance, roles, responsibilities, and accountability for the effective management and oversight of AI systems.
  • Manage AI-related incidents and monitor AI system performance to ensure continued effectiveness, reliability, and compliance.
  • Provide appropriate education, training, and awareness to employees and relevant third parties to promote the responsible development and use of AI.
  • Continually improve the effectiveness of the Artificial Intelligence Management System (AIMS) through defined objectives, performance monitoring, audits, management reviews, corrective actions, and the incorporation of lessons learned.
  • Comply with all applicable legal, regulatory, statutory, contractual, and customer requirements relating to AI, including, where applicable, the EU AI Act, applicable U.S. AI and privacy laws, and India’s Digital Personal Data Protection Act, 2023.

Risk Management

HTC adopts an enterprise-wide, risk-based approach to identify, assess, mitigate, monitor, and continually improve the management of risks across its business operations. Our risk management framework is aligned with internationally recognized standards and integrates security, privacy, quality, environmental, health & safety, artificial intelligence, climate, and ESG considerations to support resilient, compliant, and sustainable business operations.

Quality Management System (QMS)

HTC is committed to delivering consistent, high-quality products and services through its Quality Management System (QMS), supported by disciplined engineering and process maturity practices.

Key focus areas include:

  • Delivering products and services that consistently meet customer expectations.
  • Preventing defects, process non-conformities, and service disruptions.
  • Improving process effectiveness, operational efficiency, and service quality.
  • Managing supplier and supply chain quality risks.
  • Complying with applicable statutory, regulatory, contractual, and customer requirements.
  • Driving continual improvement through quality objectives, metrics, and process maturity.

Information Security Management System (ISMS)

HTC is committed to protecting information assets through its Information Security Management System (ISMS), which adopts a risk-based approach to identify, assess, and manage information security risks.

Key focus areas include:

  • Protecting systems, networks, and information from unauthorized access.
  • Preventing cyber threats, ransomware, malware, and data breaches.
  • Maintaining the confidentiality, integrity, and availability of information.
  • Reducing risks arising from insider threats and human error.
  • Managing third-party and supply chain information security risks.
  • Continuously monitoring and improving information security controls.

Privacy Information Management

HTC is committed to protecting personal information through its Privacy Information Management System (PIMS), which adopts a risk-based approach to managing privacy risks.

Key focus areas include:

  • Ensuring lawful, fair, and transparent processing of personal information.
  • Protecting personal data from unauthorized access, disclosure, alteration, or misuse.
  • Complying with applicable privacy laws, regulations, and contractual obligations.
  • Protecting data subject rights and consent management.
  • Managing cross-border data transfers and third-party privacy risks.
  • Strengthening privacy governance through continual monitoring and improvement.

Artificial Intelligence Management System (AIMS)

HTC is committed to the responsible development, deployment, and use of Artificial Intelligence through its Artificial Intelligence Management System (AIMS), which adopts a risk-based approach throughout the AI lifecycle.

Key focus areas include:

  • Promoting fairness and minimizing bias in AI systems.
  • Ensuring transparency and appropriate explainability of AI outcomes.
  • Developing secure, reliable, and resilient AI systems.
  • Protecting privacy and information security within AI-enabled solutions.
  • Managing AI-related legal, regulatory, ethical, and societal risks.
  • Continuously monitoring AI performance and governance.

Environmental, Social and Governance (ESG)

HTC integrates Environmental, Social, and Governance (ESG) principles into its business strategy while proactively managing ESG-related risks and opportunities to create sustainable value.

Key focus areas include:

  • Upholding ethical business practices, anti-bribery and anti-corruption principles, and strong corporate governance.
  • Respecting human rights while promoting employee well-being, Diversity, Equity & Inclusion (DEI), equal opportunity, and anti-harassment practices.
  • Advancing environmental stewardship, climate action, and responsible resource management.
  • Engaging responsibly with customers, suppliers, communities, and other stakeholders.
  • Publishing ESG disclosures aligned with the Global Reporting Initiative (GRI) Standards and supporting initiatives such as EcoVadis, CDP, and the Science Based Targets initiative (SBTi).
  • Driving continual improvement in sustainability performance through measurable objectives and transparent reporting.

Climate Change

HTC integrates climate-related risks and opportunities into its business strategy and decision-making to strengthen organizational resilience and support long-term sustainability. Building resilience against physical climate-related impacts.

Key focus areas include:

  • Building resilience against physical climate-related impacts.
  • Managing transition risks associated with regulations, technology, and market expectations.
  • Improving energy efficiency and optimizing resource utilization.
  • Strengthening supply chain resilience to climate-related disruptions.
  • Supporting greenhouse gas reduction initiatives and science-based climate goals.
  • Enhancing climate governance, monitoring, and transparent reporting.

Environmental Management System (EMS)

HTC is committed to minimizing the environmental impact of its operations through its Environmental Management System (EMS), which adopts a risk-based approach to environmental management.

Key focus areas include:

  • Preventing pollution and minimizing environmental impacts.
  • Improving energy efficiency, water conservation, and responsible resource utilization.
  • Reducing waste and promoting circular economy practices.
  • Complying with applicable environmental laws and regulations.
  • Preventing environmental incidents and promoting continual environmental improvement.

Occupational Health & Safety Management System (OHSMS)

HTC is committed to providing a safe and healthy workplace through its Occupational Health and Safety Management System (OHSMS)

Key focus areas include:

  • Preventing workplace injuries and occupational illnesses.
  • Identifying hazards and implementing appropriate risk controls.
  • Promoting safe work practices and employee awareness.
  • Managing contractor, visitor, and workplace safety.
  • Complying with applicable occupational health and safety requirements.
  • Driving continual improvement in workplace health and safety performance.

Compliance

At HTC, compliance is an integral part of our governance framework and business operations. We are committed to conducting business ethically, responsibly, and in compliance with applicable laws, regulations, contractual obligations, and internationally recognized standards.

Our compliance program is designed to promote accountability, transparency, and operational excellence across all business functions. Through well-defined policies, standardized processes, regular assessments, and continuous monitoring, we help ensure that our services consistently meet regulatory, customer, and industry requirements.

Our compliance framework

HTC’s compliance framework encompasses:

  • Information Security & Privacy – Safeguarding information assets and personal data through robust security and privacy controls aligned with globally recognized standards including ISO/IEC 27001 and SOC 2 Type II. Our security framework supports industry-specific compliance requirements, including HITRUST for healthcare environments and PCI DSS for applicable payment card processing environments and dedicated Client Centric Units, enabling the secure handling of sensitive and regulated information.
  • Quality Management & Process Excellence – Delivering consistent, high-quality services through standardized processes, performance monitoring, continual improvement, and a robust Quality Management System aligned with ISO/IEC 9001, complemented by disciplined process maturity practices appraised at CMMI Maturity Level 5 to ensure predictable, efficient, and high-quality service delivery.
  • Artificial Intelligence Governance – Promoting the responsible, ethical, secure, and transparent development, deployment, and use of Artificial Intelligence through a governance framework aligned with ISO/IEC 42001, ensuring effective risk management, human oversight, transparency, accountability, and continual improvement across AI-enabled solutions.
  • Risk Management – Identifying, assessing, and mitigating strategic, operational, cybersecurity, financial, legal and regulatory, environmental, social, political, cultural, and IT asset risks through a structured enterprise risk management framework aligned with ISO 31000 and NIST SP 800-30. Our risk management approach enables informed decision-making, strengthens organizational resilience, supports business continuity, and helps ensure the effective management of emerging and evolving risks across the organization.
  • Environmental, Social & Governance (ESG) – Advancing sustainable business practices and responsible corporate citizenship through environmental stewardship, social responsibility, and ethical governance. Our ESG framework is aligned with internationally recognized standards, including ISO 14001 for Environmental Management and ISO 45001 for Occupational Health & Safety. We publish our ESG Report in alignment with the Global Reporting Initiative (GRI) Standards and demonstrate our sustainability commitment through participation in EcoVadis, CDP, and the Science Based Targets initiative (SBTi). We also promote an inclusive workplace through Diversity, Equity & Inclusion (DEI) initiatives, anti-harassment and equal opportunity practices, anti-bribery and anti-corruption measures, human rights, ethical business conduct, and responsible corporate governance.
  • Regulatory & Contractual Compliance – Ensuring adherence to applicable legal, regulatory, industry-specific, and customer contractual requirements across the countries and jurisdictions in which we operate.

Our governance structure establishes clear roles, responsibilities, and executive oversight to ensure compliance requirements are effectively integrated into business operations and decision-making processes.

Continuous Compliance Monitoring

Compliance is an ongoing commitment rather than a one-time activity. HTC continuously monitors compliance obligations through periodic internal reviews, independent assessments, control evaluations, and management reporting to ensure the effectiveness of its governance and compliance framework.

Executive leadership, including the Chief Executive Officer (CEO) Chief Information Officer (CIO), Chief Delivery Officer (CDO), Chief Financial Officer (CFO), business leaders, and functional heads, provides strategic oversight by reviewing compliance performance, risk posture, audit outcomes, and key governance metrics. Findings are tracked to closure through structured corrective and preventive action (CAPA) processes, ensuring accountability, strengthening operational resilience, and driving continual improvement across the organization.

Policy Governance

HTC maintains a comprehensive set of corporate policies, standards, and procedures that establish clear expectations for employees, contractors, and business partners. These policies are regularly reviewed and updated to address evolving regulatory requirements, emerging technologies, and industry best practices.

Employee Awareness and Ethical Culture

Compliance begins with our people. We foster a culture of integrity by providing regular awareness programs, mandatory compliance training, and role-based education on information security, privacy, quality, ethics, AI governance, and regulatory responsibilities. Every employee is expected to uphold HTC’s Code of Business Conduct and contribute to maintaining the highest standards of ethical behaviour.

Independent Assurance

HTC validates the effectiveness of its compliance program through regular internal audits, independent third-party assessments, and external certification audits. These evaluations provide objective assurance that our controls remain effective and continue to meet applicable regulatory, contractual, and industry requirements.

Customer Trust

Our customers trust us with their critical business processes and sensitive information. We support that trust by maintaining transparent governance practices, implementing effective controls, managing risks proactively, and demonstrating compliance through recognized certifications and independent assessments. This commitment enables us to deliver secure, reliable, and high-quality services while helping our customers meet their own compliance obligations.

HTC’s executive leadership and top management actively engage with customer representatives through regular governance reviews, strategic discussions, and performance evaluations to strengthen collaboration, address evolving business needs, and ensure customer satisfaction, confidence, and long-term trust.

At HTC, compliance is more than meeting regulatory obligations—it is a commitment to integrity, accountability, operational excellence, and building lasting trust with our customers, partners, employees, and stakeholders.