HR & Workforce Compliance
Replace fragmented spreadsheets and manual forms with a single, compliance-engineered HR platform. TMES helps regulated enterprises across Southeast Asia run the entire employee lifecycle — recruitment to off-boarding — with attendance that stands up to scrutiny, statutory Thai payroll, and audit evidence auditors can pull themselves.
Compliant HR. Evidenced by Design.
Most HR data is only as good as the record underneath it. A leave balance sits in a spreadsheet, an approval lives in a chat thread, a training certificate is a PDF in someone’s inbox — and a clock-in is a GPS pin any browser can fake in ten seconds. When an ISO or PDPA assessor asks you to prove something, the honest answer is usually a screenshot.
TMES delivers HR & Workforce Compliance as a managed solution on our Sentinel HR platform: one employee master for HR, Finance, Managers and Employees, bilingual Thai/English end to end, every action written to an immutable audit log — and every number traceable back to the person it came from. Attendance is verified against the site network, not just a coordinate. Payroll files in Revenue Department and Social Security formats. Assessors get their own read-only role instead of a folder of exports.
Business Benefits
What the Solution Delivers
Full Employee Lifecycle
Careers portal, AI CV screener, interview scorecards, offer letters accepted by link, and four employment-contract types (full-time, part-time, fixed-term, contractor / service agreement) e-signed with OTP — the signed PDF carrying the full bilingual contract body, with HR-editable templates behind a draft → approval → publish workflow. Then applicant self-onboarding, Azure/M365 accounts provisioned automatically, probation, goals and KPIs, merit and bonus cycles, succession planning — through to off-boarding with clearance and the Azure licence reclaimed. AI features run on Anthropic Claude or AWS Bedrock, configurable per feature, with automatic failover.
Verifiable Attendance
A browser can fake a GPS pin — so we do not trust one. Site network/IP binding, a server-side IP-to-GPS agreement check, impossible-travel detection, and a rotating six-digit on-site code (TOTP, refreshed every 60 seconds) that a spoofed coordinate cannot produce. Plus geofenced customer sites, shift rosters and WFH/off-site as approved request types. Scheduled attendance PDFs are private by design — each line manager receives their own team only, enforced by a hard rule that a recipient can never see rows for people they do not manage.
Thai Payroll & Statutory Engine
PND.1, PND.1 Kor, SSO Sor Por Sor 1-10 and 50 Tawi generated in Revenue Department / Social Security e-filing column order; bank payout files for KTB, BBL, SCB and KBank; overtime at Labour Protection Act multipliers pulled straight from attendance; manager-approved shift allowance and per diem (region- and level-based rates, non-taxable by default); provident fund with vesting; Social Security and Student Loan Fund; withholding that stays correct across the whole year with a per-employee year-end tax position; and a configurable multi-stage approval chain before anyone is paid.
Audit-Ready ISO Evidence
A genuine read-only Audit role built for external ISO and PDPA assessors — hand over access instead of screenshots. Immutable audit log, an RBAC matrix down to feature, action and data scope, ISO 27001 / 27701 / 29110 / 20000-1 training question banks with assessments, certificates and an expiring-certification dashboard.
PDPA Compliance Suite
Consent ledger, data-subject-rights requests from employees and a public intake channel for non-employees (including authorised-representative identity and ID-card upload), a DPO fulfilment queue, and a breach register running the mandatory 72-hour regulator clock under Section 37(4).
Workforce Analytics & Daily Briefing
Demographics, attrition, compensation, leave and overtime — with drill-down that reconciles: click any bar and see the exact employees behind the number, because the chart and the list share one model. Operational analytics for lateness, WFH adoption and site occupancy, Excel/PDF export, and a personalised daily briefing scoped to each user’s role.

The HR Platform Auditors Trust
Run the entire employee lifecycle on one platform where every action is captured in an immutable audit log — so ISO and PDPA auditors pull their own evidence.
- ISO 27001 / 27701 / 29110 / 20000-1 evidence
- PDPA 72-hour breach clock built in
- Bilingual Thai / English throughout
Built for Regulated Enterprises
ISO 27001 / 27701 Certified Organisations
Give assessors a read-only Audit role and let them pull their own evidence — training records, access matrix, approvals, audit trail. No parallel evidence binder, no audit-week scramble.
Thai Enterprises Under PDPA Scrutiny
Consent ledger, a DSR channel open to employees and the public alike, DPO fulfilment queue and the 72-hour breach clock — personal-data obligations handled in-system, bilingually.
Retail, F&B & Multi-Site Operators
Geofenced customer sites plus network binding and a rotating on-site code mean a shift can only be clocked from the site itself. Shift rosters, OT extracted from real punches, managers approving from their phone.
Financial Services & Insurance
RBAC to feature, action and data scope; confidential payroll figures gated per approval stage; every view and change written to an immutable log — built for operational-risk review.
Sentinel HR — The Platform Behind the Solution
Our HR & Workforce Compliance solution is delivered on Sentinel HR, the TMES enterprise HRMS purpose-built for ISO and PDPA-ready organisations in Thailand. Explore the full platform, its modules and the latest release.
The TMES Advantage
Why TMES for HR & Workforce Compliance
Generic global HR suites treat Thai compliance as a localisation add-on and treat a GPS coordinate as proof. Our solution is engineered for Thai regulated enterprises from the data model up.
Frequently Asked Questions
Q.Can employees fake their GPS location to clock in?
A browser can fake a coordinate, so Sentinel HR does not rely on one. Four layers defend the punch: the site’s network/IP range (a punch from outside it is refused regardless of GPS), a server-side check that the IP’s location agrees with the reported GPS, impossible-travel detection between consecutive punches, and a rotating six-digit on-site code (TOTP, refreshed every 60 seconds) that only someone physically at the site can read. Every punch stores its IP, GPS accuracy and any flags; high-confidence spoofs are blocked, softer signals are flagged for HR and surface in the daily briefing and the scheduled attendance report. Each layer is configurable — off, flag-only, or block.
Q.Can we go live mid-tax-year, or do we have to wait for 1 January?
You can go live mid-year. The migration toolkit imports employees in bulk along with year-to-date leave balances and month-by-month payroll history (with a bonus column), so the first in-system payroll run computes withholding tax against the tax already withheld earlier that year and employees get real payslips, badged as migrated, back to January. The importers accept any spreadsheet — fuzzy plus AI-assisted column mapping, an editable in-browser grid and duplicate detection — so a messy client file migrates fast. No 1 January cutover, no parallel run to keep the numbers honest.
Q.Can we run part-time, fixed-term or contractor agreements — and can HR edit the wording?
Yes to both. The solution ships four employment-contract types — full-time, part-time, fixed-term and a contractor / service agreement — each with its own clause set, term and scope of work (a per-position default, editable per hire). Contracts are e-signed with OTP and the signed PDF carries the full bilingual contract body, Thai authoritative. HR edits every clause of every template, Thai and English, in Settings behind a draft → approval → publish workflow (a second admin approves each new version), with full version history — while contracts already signed stay immutable.
Q.Do employees get a surprise tax bill at year end?
No. The Thai PIT engine withholds the right amount across the whole year rather than a flat estimate, so the figures reconcile at filing. Every employee can see their own year-end tax position — projected annual tax, withheld to date and the estimated balance — and an employee election governs how any catch-up is handled. Manager-approved per diem is non-taxable by default, so it does not distort those figures.
Q.Does it handle Thai payroll and statutory filings?
Yes. The engine produces PND.1 (ภ.ง.ด.1), PND.1 Kor (ภ.ง.ด.1ก), SSO Sor Por Sor 1-10 (สปส.1-10) and 50 Tawi (50 ทวิ) in Revenue Department / Social Security e-filing column order, plus bank payout files for KTB, BBL, SCB and KBank. It covers Social Security, provident fund with vesting, Student Loan Fund (กยศ.), shift allowance, severance, two withholding methods (progressive YTD-computed or fixed), and overtime at Labour Protection Act multipliers extracted automatically from attendance.
Q.Can auditors access evidence without risk to live data?
Yes — that is what the read-only Audit role is for. External ISO and PDPA assessors sign in themselves and pull training records, the access matrix, approvals and the immutable audit trail, with no ability to change anything. You hand over access instead of a folder of screenshots.
Q.How does the solution help with PDPA?
A consent ledger, data-subject-rights requests raised by employees and by the public through an external intake channel (with authorised-representative identity and ID-card upload), a DPO fulfilment queue, and a breach register running the mandatory 72-hour regulator clock under Section 37(4) — all bilingual, all in the audit log.
Q.Do the analytics reconcile with the underlying records?
Yes. Workforce Analytics covers demographics, attrition, compensation, leave and overtime, and every chart drills down: click a bar and you see the exact employees behind that number, because the chart and the list are built from one model. Results export to Excel and PDF.
Q.Which ISO standards are mapped?
ISO 27001 (information security), ISO 27701 (privacy / PIMS), ISO 29110 (VSE software engineering) and ISO 20000-1 (IT service management) — each with training question banks, assessments, certificates and an expiring-certification dashboard.
Q.Is the solution bilingual in Thai and English?
Yes, end to end — interface, notification emails, employment contracts, payslips and reports all exist in both Thai and English, built from the database up rather than bolted on as a translation layer.
Q.Is this a product or a managed service?
Both. The solution is delivered on the Sentinel HR platform as a managed engagement — implementation, data migration, change management, role configuration, ISO evidence walkthroughs and ongoing support from one accountable partner.
Q.How much of the employee lifecycle does it actually cover?
Roughly 30 integrated modules and 86 distinct features on one employee master and one audit trail — recruitment and AI CV screening, offers, e-signed contracts, self-onboarding, Azure/M365 provisioning, attendance and shift rosters, leave, WFH and off-site, overtime, expenses with receipt OCR, payroll, performance and KPIs, merit and bonus, succession planning, learning, employee relations, PDPA and off-boarding.
Compliance Is No Longer Optional
Why regulated enterprises are modernising HR.
Bring Your HR Into ISO & PDPA Compliance — Without Waiting for January
Talk to a TMES compliance architect about attendance you can prove, payroll that files itself in the right format, and evidence your auditors can pull without you.
