If you wanted to harm the company, you wouldn’t have given them notice.
Obviously, if you had malicious intent, you would have ample opportunity to act before giving notice.
They just want to make sure they did what they could in case you should in fact have malicious intent. 'Oh, we escorted him off the premises within the hour; this one is not on us...'
Many very serious meetings were then held to ensure this could never ever happen again, regardless of the cost-benefit tradeoff, because inconvenient procedures don't make headlines.
It's not about stopping targeted harm (which is covered by other security procedures) but to limit the time where the employee is at increased risk of leaking data or doing things that they normally wouldn't because the main consequence of losing their job is removed. Someone knowing they'll be gone soon can also have a negative impact on team productivity and morale.
The same usual problems with false positives and false negatives.
(also 99.9% of employees are not leaving, considering them all a risk can be expensive)
All this means is that people take all the customer data before you submit your notice.
Different story if someone's fired for cause, of course.
I know it feels good to say that, but isn't it more likely they are just rational human beings making decisions by weighing a wide array of facts - most of which we aren't even aware exist?
I guess if it's a small startup with 5 people it doesn't matter, but please don't assume that everyone at all these major companies is a "bozo".
Effectiveness or actual purpose isn't on the radar, and improving security through these processes does happen but is basically a side-effect or an accident. Some of these things probably are based in some real need (at whichever business started the ball rolling) and tend to be useful for that reason, but I guarantee a lot are just doing things for the sake of being able to say something was done after an incident, get that in place at a couple bigcos and pretty soon it's a standard industry practice, even if it's not sensible at many places implementing it. This smells very much like one of those.
For example: a salesperson wont work on new deals and may even sabotage existing deals that they know they can pick up at a new company. Sometimes it's as innocuous as copying their contacts or browsing through new deal flow which they don't need to know about if they're going to a competitor. A manager might stop getting reports from their team or put off other tasks. Sure it may all go well but there are still hundreds of reasons to avoid all this potential risk.
HR departments aren't stupid or useless. They exist to manage the most complicated part of any business: the people. If you haven't ever worked in these sectors or departments, I'd recommend against assuming they have no value.
[EDIT] to provide some context, I've come to see a huge portion of decisions about policies, procedures, tools, and more as basically personal and departmental risk mitigation and blame-deflection rather than anything aimed at helping a business function. At a high level that's the goal, but in the details it becomes about making sure there's always something or someone to point a finger at. Conveniently these things don't always need to be directly relevant or useful, so long as something's being done and can be put on a powerpoint slide when the C-suite or someone at some company yours is courting asks a question. As long as "what are we doing about X?" can be answered with "Y and Z, both of which are standard industry practices, see this HBR article about how IBM does it" you're good.
Where has that been true? JPMorgan has policies on notice depending on your position (engineer II has a different notice window than a IV).
During the ISO9000 heyday, it was SHOCKING to see how random HR exit policies were between hundreds of companies, with a bias toward traditional 2 week notice. The norm is that smart people aren't in HR, because smaller companies outnumber smaller ones.
This is why I won't give extended notice.
What is that?