QUIZ
Is your TA transformation on track?
See how leading organizations are using AI to transform talent acquisition and drive real business impact
QUIZ
Is your TA transformation on track?
See how leading organizations are using AI to transform talent acquisition and drive real business impact
QUIZ
Is your TA transformation on track?
See how leading organizations are using AI to transform talent acquisition and drive real business impact
QUIZ
Is your TA transformation on track?
See how leading organizations are using AI to transform talent acquisition and drive real business impact
QUIZ
Is your TA transformation on track?
See how leading organizations are using AI to transform talent acquisition and drive real business impact
At AMS, we value our reputation for reliability, integrity, and ethical and legally compliant business practices in all countries we operate in. We have a responsibility to our clients, partners, communities, and ourselves to conduct our business with the highest level of integrity and ethics. That’s why the world’s leading brands trust AMS to help them advance their vision safely and securely.
AMS protects our clients’ confidential data against unauthorized access and unauthorized disclosure of information.
AMS as an organisation has dedicated InfoSec and Data Protection functions, with policies and guidelines that are aligned with best practices in the field and GDPR laws. This shows our dedication as an organization to ensure our staff is trained properly and the best practices in these fields are incorporated into our processes.
AMS carries out background screening checks on all staff before employment begins to protect AMS and our clients against unnecessary risks. We are committed to engaging honest and trustworthy people, and background screening is an essential measure to mitigate the risk of engaging an individual who could cause harm or loss to AMS or our clients through unlawful, malicious or negligent activity.
AMS has its own minimum criteria that all employees must meet. We also carry out enhanced screening where required to meet our clients’ contractual obligations. We partner with experts in this field to carry out these checks as efficiently as possible with minimal disruption to candidates and staff.
Local legislation and regulations vary, which affects the extent to which some checks can be carried out in each country. AMS personnel undergo a standard background check or equivalent. These checks adhere to the Baseline Personnel Security Standard (BPSS).
Background checks include, where local laws allow:
Regular, mandatory training is deployed to all AMS staff around information security policies and data security and protection, to increase awareness of the continuously evolving security threats and how to keep the work and home environment secure.
AMS uses Microsoft Azure as its primary hosting provider. Azure works with the best industry standards for data encryption both in transit and at rest, and it is FIPS 140-2 compliant. Azure Active Directory groups handle access controls, reducing the risk of unauthorized data access. The following controls are in place:
At a glance, AMS infrastructure, major security controls include:
AMS security controls are also aligned to CIS18 controls. An Information Security Management System ISMS is in place, as well as a managed Security Operations Center. AMS works with enterprise SOC2/3 compliant providers with focus on threat detection and prevention. The network security protocols include distributed denial-of-service protection, firewall capabilities and network segmentation. Microsoft Azure operates in line with industry best practices, providing due diligence and compliance with local regulations as well as Client requirements (ISO27001 and ISO27017 accredited and periodically audited via SOC 2 T2 reports). The AMS Cloud framework is aligned to the NCSC 14 cloud security principles.
Data is set in a separate, dedicated Azure SQL Database (AES-256 bit encrypted), which prevents unwanted mingling and ensuring the physical separation of data within the deployment. Any data extracted and stored for purposes beyond the recruitment process outsourcing, such as further analysis or reporting it is rendered anonymous and all personally identifiable information (PII) is removed. This extra measure reinforces the preservation of user privacy. Deployments run in an environment, separate from other accounts.
AMS has an MSSP security operations center that monitors and alerts on potential suspicious activity. Our 24/7 SOC is using various dashboards within the SIEM solution, and alerts have different severity levels assigned to allow prioritization. Suspicious events or correlated events are raised as incidents and investigated by the SOC. We store security logs for 12 months, where core applications are monitored and core logs are captured centrally via the SIEM. The SIEM automatically applies event correlation and alerts on use cases, leveraging the MITRE ATT&CK framework. This then follows our incident response process.
AMS has a continuous vulnerability management process in place. Internal scans run daily, external scans run monthly, and the results are presented in a Power BI dashboard. There are no live assets excluded from the scanning scope. The scan reports back on all OS and applications which are installed on the device. The vulnerabilities are prioritized based on severity (CVSS 3.1 scoring). SOC, IT Support and Information Security teams will analyze the report and assign problem tasks to fix, reconfigure, or otherwise mitigate reported vulnerabilities. The vulnerabilities are all categorized, prioritized based on severity and then managed up to closure (via workarounds, full solution remediation, etc.). The remediation process has specific time targets, based on criticality.
AMS conducts annual pen testing, which is performed by accredited suppliers. The scope of the pen testing includes AMS locations, cloud environments and critical applications or web services.
AMS follows the ISO27001 SDLC methodology, as well as taking into account the OWASP top 10 recommendations. Separate environments exist for development, testing and production with key approval gateways between environments. Key gating, initial contact, project initiation, project setup, sprint planning, BA, Dev, Test, Demo lessons learnt, solution release, support preparation, support, handover to support. Ongoing release management is handled by DevOps within our Azure environment – all releases go through this process and has business, tech, security approval.
AMS has a Change Management process in place for the control, commitment and authorization of Change Requests (CR) to deliver a Change in new or existing environments or services. This is managed and authorized through the Change Advisory Board (CAB). The Change Management process applies to requests for change to the systems, software, hardware and services identified – installs, moves, additions and changes to the infrastructure and any software changes, across the whole service lifecycle. Changes are tested prior to Go Live to ensure there will not be an impact on the business.
In the unlikely event of a data breach, AMS has a cyber incident response plan in place. This plan outlines the communication strategy, investigation procedure, and mitigation measures to be taken in such scenarios.
As part of our ISO 27001, we get annually audited on our physical security. In a normal year in the office, we do random spot checks in the office (e.g., adhering to the clear desk policy, disposing of confidential information properly, printer papers, visitors escorted, etc.). Our offices are access controlled with the use of proximity access cards and centralized access control system that is managed by AMS or the landlord of the building; this would vary depending on the location. LAN cables are not available within the hot desk or reception parts of the office. The building security is monitored 24/7 and includes security guards, CCTV system, alarms, etc. depending on the location. Access to comms room or other secure areas is limited to authorized personnel only. Comms rooms would include lockable racks that would be managed and accessed by IT support or office management team only.
In the unlikely event of a disaster, AMS has a crisis management plan in place.
Backup procedures and failover strategies have also been implemented to ensure the application’s continuous operation and rapid recovery (e.g. our hosting data centers have a 6 minute failover time). These mechanisms are part of AMS’s comprehensive disaster recovery and business continuity strategy.
AMS has committed to a global risk management program, aligned to ISO 31000, that involves:
At AMS, we are committed to respecting and protecting the integrity, security and privacy of all individuals we work with, including our colleagues, clients, candidates, suppliers and everyone else who interacts with AMS. Our Privacy Office ensures a comprehensive and robust approach to global data protection and privacy, acting as a trusted advisor for AMS and its clients.
The AMS Privacy Office is dedicated to:
To achieve our privacy objectives, AMS has developed a range of policies, procedures and internal rules, including:
AMS applies a variety of controls to deliver privacy compliance, including:
By implementing these policies, procedures and controls, AMS is committed to delivering market-leading privacy management and ensuring the protection of personal data for all our stakeholders.
We are committed to ensuring the responsible, ethical and compliant use of artificial intelligence across AMS. Our AI Risk Governance Framework provides structured, organization-wide oversight to identify, assess and mitigate AI-related risks. It ensures that all AI solutions are developed, procured and deployed in alignment with legal and regulatory requirements, client expectations and internationally recognized standards including alignment with ISO 42001. This framework reinforces our commitment to trustworthy, human-centric AI and supports the safe, transparent and well-controlled use of AI throughout its lifecycle.
The AMS AI Risk Governance Office ensures that AI is used responsibly, safely and in alignment with client and regulatory expectations. Our key objectives are to:
To deliver effective AI risk governance, AMS has established a comprehensive set of policies, procedures and safeguards. These include:
AMS applies a variety of governance controls to ensure safe, compliant and transparent AI use:
By embedding these controls into our operations, AMS ensures our AI governance not only meets — but exceeds industry and client expectations.
AMS has convened a group of independent experts from business, academia and the not-for-profit sector to guide the ethical use of AI in talent acquisition. This board provides thought leadership, strengthens accountability and has helped develop an industry-first Ethical AI Charter for Talent, setting clear expectations for responsible AI across the recruitment ecosystem.
AMS operates a resilience strategy that aligns with ISO 22301 and industry best practice. We are ISO 22301 certified for our London Head Office, with our remaining locations operating in alignment with this standard. We conduct risk assessments across our operations and ensure we put in place relevant disaster recovery plans and procedures to recover services in the event of unforeseen incidents. We provide training to our teams to ensure best practices are adopted throughout the business. We conduct an ongoing cycle of business continuity tests to reinforce our plans and procedures with our teams. This is supported through location-based emergency management teams with a crisis management team providing global oversight. We aim for zero business disruption and protecting your data is our priority. At AMS, we implement robust recovery protocols following with documented recovery objectives. Our multi-tiered approach provides rapid business resilience during any critical event.
AMS Disaster Recovery Policy and Plan are available to our clients upon request.
AMS has a strong history of corporate social responsibility and continues to enable business success and progress future careers. We value our reputation for reliable, integral, ethical and legally compliant business practices in all countries we operate in, along with the importance of protecting our people and our planet. We have a responsibility to our clients, partners, communities and ourselves to conduct our business with the highest level of diligence. We hold ourselves accountable to our progress, delivering updates to our key stakeholders.
Across AMS, we focus our activities on the six United Nations Sustainable Development Goals where we believe we can have the most impact: gender equality; reduced inequalities; decent work and economic growth; good health and well-being; affordable and clean energy; and climate action.
We recognize that through our recruitment programs we are in a unique position to support our clients with delivering on their own social value priorities. We greatly value the importance of providing opportunities for our people and understand the influence we, via our team of 8,000 colleagues, can have on our clients, candidates and suppliers.
Enabling our teams’ personal development is critical to AMS. We support volunteering opportunities, social mobility initiatives and frequently engage our people to understand programs that are most important to them and their local communities.
AMS recognises that as a global company, our activities have an impact on the environment. Our efforts to protect the planet are deeply interconnected with the well-being of our people, as we recognise that a sustainable environment is the foundation of a thriving, resilient workforce.
At AMS, we value our reputation for reliability, integrity and ethical and legally compliant business practices in all countries we operate in. We have a responsibility to our clients, partners, communities and ourselves to conduct our business with the highest level of integrity and ethics. To support these commitments, AMS operates a range of policies that guide all employees to better understand our values, behaviors, responsibilities and standards of ethical business conduct that all AMS employees are expected to demonstrate in their roles both at work and in any situation where they act as representatives of AMS. They are designed to provide a reference of standards in delivering our services to clients and to ensure compliance with applicable legislative and regulatory requirements.
At AMS, we value our reputation for reliability, integrity and ethical and legally compliant business practices in all countries we operate in. We recognize that over and above any financial damage suffered, fraud, bribery and corruption may reflect adversely on our reputation and run counter to our values and corporate culture. As such, the fight against any acts of fraud, bribery and corruption is endorsed and supported at the most senior level within AMS.
We have a zero-tolerance attitude to criminal breaches of business practices within our business and our supply chain and will report them to the appropriate law enforcement authorities.
We are committed to maintaining the highest level of ethical standards in the conduct of our business affairs by establishing and promoting a corporate culture where we prevent, detect and report all acts of fraud, bribery and corruption. We have established relevant policies and procedures and training for our employees to follow
AMS operates a responsible procurement approach when engaging with Third Parties, in line with AMS Procurement Policy and Third-Party Assurance Policy. We are committed to partnering with strategic suppliers that align with our sustainability goals and have established sustainability programmes in place. AMS is committed to creating a level playing field for all suppliers and recognises the importance of supplier diversity in promoting economic growth, innovation and social responsibility. We will strive to include diverse suppliers in our procurement processes and actively seek out opportunities to do so.
AMS’ have established a Third-Party Assurance framework which enables AMS to apply necessary due diligence for the suppliers we wish to engage with, with a view to mitigating risk to AMS and AMS Clients.
AMS recognise that relationships with our third parties are fundamental to our ability to maintain operations and offer products and services to our employees and clients. AMS 3rd Party Assurance Policy formally defines this framework, roles and responsibilities, and scope of our 3rd Party Risk Management program.
AMS’ Supplier Code of Conduct sets out values, behaviours, responsibilities, and standards of ethical business conduct that all suppliers working with AMS are expected to follow. It applies to all suppliers providing products and services to AMS and their own supply chains.
See how Next Gen Talent Acquisition can drive speed, quality and business outcomes.