Co-employment is a shared employment relationship in which both the hiring organisation and a staffing partner may exercise control over the same worker. It matters because shared control can create legal exposure around pay, benefits, injury claims, and disciplinary authority. Security and GRC teams must define responsibilities clearly to avoid confusion during incidents.
Expanded Definition
Co-employment describes a shared employment arrangement where two entities can each exercise some degree of control over the same worker. In practice, that usually means the hiring organisation manages day-to-day work, while a staffing firm or employer of record handles payroll, benefits administration, or certain legal obligations. The concept is not a cybersecurity term on its own, but it becomes security-relevant when responsibility for access, supervision, incident response, and offboarding is split across parties.
Definitions vary across jurisdictions and contract models, so NHI Management Group treats co-employment as an operational risk condition rather than a single fixed legal status. For security and GRC teams, the important question is not only who pays the worker, but who can approve access, revoke credentials, investigate misconduct, and attest to compliance. That matters for identity lifecycle control, privileged access, and accountability during investigations, especially when the worker uses shared systems or remotely administered accounts. The NIST Cybersecurity Framework 2.0 is useful here because it emphasizes governance, roles, and accountability even when labour relationships are distributed across organisations.
The most common misapplication is treating co-employment as a human resources-only issue, which occurs when access ownership and disciplinary authority are left undefined during onboarding and offboarding.
Examples and Use Cases
Implementing co-employment rigorously often introduces coordination overhead, requiring organisations to balance operational flexibility against clearer control boundaries and more disciplined recordkeeping.
- A contractor arrives through a staffing partner, but the client organisation assigns tasks, approves system access, and directs daily work. Security teams must know which party validates identity documents, role changes, and termination notices.
- An employer of record handles payroll for a distributed workforce while the client retains management authority. This creates a split responsibility model for joiner, mover, leaver events and can complicate access reviews if the two parties do not share timely status updates.
- A temporary worker is added to a cloud engineering team and receives access to production tools. The staffing partner may hold employment records, but the client organisation must still enforce least privilege, session monitoring, and immediate deprovisioning when the assignment ends.
- A workplace incident involves alleged misconduct by a shared worker. Legal, HR, and security teams need a pre-agreed process for evidence preservation, account suspension, and notification sequencing so the response is not delayed by uncertainty over authority.
- In regulated environments, co-employment can affect how background checks, policy acknowledgements, and security training are documented. Teams often use the NIST Cybersecurity Framework 2.0 governance language to assign responsibilities across parties without assuming a single employer controls every control point.
Why It Matters for Security Teams
Co-employment matters because ambiguous authority creates gaps in identity governance, access administration, and incident response. If security teams cannot tell who is responsible for approving access, revoking credentials, or escalating concerns, privileged accounts can stay active longer than intended and investigations can stall. That risk increases when workers use SaaS platforms, admin consoles, or sensitive datasets that require tight onboarding and offboarding discipline.
For NHI and identity teams, the practical concern is that a shared worker may accumulate multiple identities across payroll systems, collaboration tools, and cloud services, each with different owners and retention rules. That makes policy mapping essential: one party may own employment terms while another owns application access decisions. The same governance discipline reflected in NIST Cybersecurity Framework 2.0 should be extended to personnel workflows so responsibilities are explicit before an incident exposes the gap.
Organisations typically encounter the consequences only after a termination, fraud allegation, or access misuse event, at which point co-employment becomes operationally unavoidable to resolve.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 address the attack surface, NIST CSF 2.0, NIST SP 800-53 Rev 5 and NIST SP 800-63 set the technical controls, and ISO/IEC 27001:2022 define the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | GV.RM-02 | CSF 2.0 governance emphasizes roles, responsibilities, and risk ownership across shared operations. |
| NIST SP 800-53 Rev 5 | PS-4 | Personnel termination controls govern removal of access and return of assets when employment ends. |
| NIST SP 800-63 | Digital identity assurance matters when a shared worker is enrolled across multiple systems. | |
| ISO/IEC 27001:2022 | A.5.10 | Acceptable use and access accountability rely on clear assignment of responsibilities. |
| OWASP Non-Human Identity Top 10 | Shared workers can inherit multiple non-human and human identities that need governance. |
Ensure identity proofing and authenticator issuance remain attributable to the correct sponsor.
Related resources from NHI Mgmt Group
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on August 24, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org