Welcome to HRTech Cube, Girish. We’re delighted to have you. To start, could you share a brief overview of your professional journey and what led you to focus on compliance automation and risk management at Sprinto?
When I was building RecruiterBox, a cloud-based applicant tracking system (ATS) designed to streamline the recruitment process, we spent six months and tens of thousands of dollars trying to get SOC 2 compliant. That experience changed how I think about compliance.
My engineering team could ship product updates in a matter of days. But for compliance, we were told to slow down, hire consultants, collect screenshots, and prepare for a point-in-time audit that took hundreds of hours and did very little to improve our actual security posture.
It felt broken. The process was manual, reactive, and disconnected from how modern SaaS companies operate.
After exiting RecruiterBox, I kept coming back to that inefficiency. Enterprise deals were stalling at the security review. Founders were treating compliance as a tax on growth. I believed there had to be a way to make compliance continuous, automated, and aligned with real security practices.
That belief became Sprinto. Our focus is simple: help companies achieve compliance much faster, continuously monitor controls, and turn what used to be a sales blocker into a growth lever.
You’ve spoken about the growing “residual risk gap” caused by slow offboarding and access-control failures. Can you explain what this gap looks like in practice and why it’s becoming a serious concern for HR and security teams?
The residual risk gap is the delay between a risk event and the control response.
In simple terms, someone leaves the company but still has access to systems for days or weeks. In SaaS-heavy environments, that can mean access to cloud infrastructure, HR systems, financial tools, or customer data.
This used to be treated as an operational oversight. Today, it is a governance failure.
Regulators no longer accept access reviews that happen once a quarter in a spreadsheet. They expect companies to know, at any point in time, who has access to what.
If removing access depends on someone sending an email or manually following up, things get missed. Former employees can retain access longer than they should, and no one notices until much later.
The fix is straightforward. When HR marks someone as exited, systems should automatically trigger access removal and flag anything that fails. Risk should be addressed the moment it appears, not weeks later during an audit.
Traditionally, onboarding and offboarding have been viewed as administrative processes. Why do you believe they must now be treated as legal events, and what are the implications for HR leaders?
Because onboarding and offboarding directly change who can see and use sensitive data. When someone joins a company, they are given access to systems that hold employee records, financial data, and company IP.
When they leave, that access needs to be removed quickly, and there has to be evidence. Not eventually. Not when someone remembers. Immediately, with a clear record that it was done.
Trust inside a company cannot be assumed anymore. It has to be demonstrable. Regulators, customers, and partners increasingly expect what I call queryable trust. If asked, you should be able to show exactly who had access to what, when that access was granted, and when it was removed.
From a legal standpoint, these moments shift responsibility. If access is not handled properly, the company carries the consequences.
For HR leaders, this means these processes cannot operate in a silo. A joining or exit event should automatically trigger access updates, checks, and documentation. HR is no longer just managing people’s workflows. It is managing moments that directly affect the company’s risk.
The concept of “training as testimony” is gaining traction. How is employee training evolving into a form of legal defense, and what should HR teams do to strengthen this layer of protection?
In the event of a breach or compliance failure, one of the first questions regulators ask is whether employees were trained. Training records become evidence. They show whether the organization took reasonable preventive steps.
That changes how we should think about training. It is not a yearly awareness exercise. It is part of the company’s legal defensibility. HR teams should connect training to real company policies and real risks. It should be easy to track who completed it, update it regularly, and tie it to the company’s standards.
When training is built into how the company actually runs compliance and updated whenever policies change, it becomes real protection. Not just something people rush through once a year.
As HR increasingly handles sensitive employee data, what does it truly mean for HR to operate as a Data Controller under GDPR and similar regulations?
Under GDPR, being a Data Controller means you are accountable for employee data. HR decides what data is collected, why it is collected, how long it is kept, and who gets access to it. That responsibility cannot sit loosely across teams.
You should be able to answer simple questions at any time. Where is our employee data? Who can access it? Why are we keeping it? For how long? If those answers are unclear, that is a risk.
HR today is running a regulated data environment. That requires visibility and discipline every day, not just when an auditor asks for it.
Organizations face a growing tension between data-erasure rights and mandatory data-retention requirements. How can HR teams navigate this conflict without exposing the company to regulatory risk?
The tension is real. An employee may request erasure of personal data, while the company may be legally required to retain certain records, such as payroll or tax documentation. This is not just a compliance challenge. It is a trust issue.
Trust between an organization and its employees is built on transparency. People should know what data is being retained, for how long, and why. When retention policies are clearly communicated upfront, conflicts reduce and confidence increases.
The practical solution is structured data classification and clear retention schedules. HR, legal, and compliance must define what is mandatory to retain and what can be erased. Automation can then enforce timelines and flag when data becomes eligible for deletion. Clarity builds trust. Documentation protects it. Ambiguity creates risk.
Many HR leaders worry that stronger compliance means more manual work. How can organizations build audit-ready documentation and automated controls without adding operational complexity?
That concern comes from how compliance used to work. Traditional approaches relied on manual evidence collection and separate trackers. That naturally increases workload.
Modern compliance systems flip that model with AI-powered automation. Controls are connected directly to the tools teams already use, such as HR systems, access management tools, and ticketing platforms. Evidence is captured automatically as part of normal operations. Monitoring runs quietly in the background.
Compliance becomes embedded in daily workflows rather than layered on top of them. HR teams should not have to maintain separate spreadsheets to prove what systems can continuously validate. If implemented correctly, stronger compliance reduces operational drag instead of increasing it.
We’re seeing a shift from static paper policies to “living systems” that prove compliance in real time. What does this transformation look like, and how should HR teams prepare for it?
Historically, compliance meant documented intent. Policies were written, signed, and stored. Today, auditors increasingly look for operational proof. If your policy says least privilege access, the system should continuously validate that this is actually enforced. A “living system” means your policies are tied to what is actually happening inside your tools. If something changes or goes wrong, you see it quickly instead of discovering it months later.
For HR teams, this means moving beyond just owning policies. You need visibility into whether those policies are being followed in practice.
Compliance is no longer about having the right documents. It is about proving, at any time, that the rules are working.
From a leadership standpoint, what personal strategy has guided you in helping organizations move from reactive compliance to proactive risk management?
I try to change how leadership thinks about compliance. Most teams see it as a tax on growth. Something that slows deals down, adds process, and shows up once a year as an audit fire drill.
If you treat compliance as an annual event, you will always be reactive. You scramble before audits, patch gaps temporarily, and repeat the cycle the following year. So, the first shift is mindset. Compliance is not a project. It is an operating capability that runs continuously and reduces more than just risk. Always-on compliance builds durable trust with customers, regulators, and your own teams.
The second is ownership. Risk decisions should not be outsourced to consultants or buried in spreadsheets. Leadership has to define risk appetite clearly. What are we comfortable with? What are we not? That clarity aligns the entire organization.
The third is how we use automation. I strongly believe in human-in-the-loop systems. Technology should surface gaps and give you visibility. It should not decide what level of risk you are willing to take. That remains a leadership call. When compliance runs continuously and leaders stay accountable for their judgment, it stops being a tax on growth and becomes part of how you manage risk responsibly.
As we wrap up, what final thoughts would you like to share with HR and compliance leaders who are rethinking their approach to risk, data governance, and workforce systems?
I would leave HR and compliance leaders with this thought. Trust today cannot be claimed. It has to be queryable.
It is not enough to say we take data protection seriously. You should be able to answer, at any point in time, simple questions about access, retention, training, and controls. Not because an audit is coming, but because that visibility exists by design. That is what I mean by making trust verifiable.
HR sits at the center of people’s data and access decisions. That puts you in a unique position to help the organization move from policy-based trust to proof-based trust. The goal is not to build more processes. It is to build systems where, if someone asks, you can show how things work. When trust becomes queryable, compliance stops being defensive. It becomes a real competitive advantage.
Girish Redekar, CEO of Sprinto
Girish Redekar is the co founder and CEO of Sprinto, a leading security compliance automation platform used by fast growing companies around the world. He is a repeat entrepreneur passionate about helping organizations build trust, streamline audits, and scale securely without slowing down innovation.

