ISO/IEC 27001

⌘K
  1. Home
  2. Docs
  3. ISO/IEC 27001
  4. Other Doc
  5. Employee Screening Policy

Employee Screening Policy

1. Purpose

The Employee Screening Policy establishes requirements for conducting appropriate pre-employment and, where necessary, ongoing screening of employees, contractors, interns, and other personnel who may have access to organizational information, systems, facilities, or customer information.

The objective is to ensure that screening is:

  • Appropriate to the role
  • Proportionate to information-security risk
  • Consistent with applicable law
  • Performed before access is granted where required
  • Properly documented
  • Privacy-conscious
  • Consistently applied
  • Reviewed when circumstances or role requirements change

Core Principle

Define Role Risk → Determine Screening → Obtain Authorization → Screen → Verify → Record → Decide → Monitor


2. Scope

This policy applies to personnel who may have access to:

  • Organizational information
  • Confidential or Restricted information
  • Personal data
  • Customer information
  • Production systems
  • Cloud infrastructure
  • Source code
  • Security systems
  • Privileged accounts
  • Physical facilities
  • Critical business processes

It may apply to:

☐ Employees
☐ Contractors
☐ Consultants
☐ Interns
☐ Temporary workers
☐ Privileged administrators
☐ Remote personnel
☐ Third-party personnel

The exact scope should be determined by the organization’s risk assessment and applicable requirements.


3. Policy Statement

The organization shall perform appropriate personnel screening before granting access to information, systems, or facilities where screening is necessary based on:

  • Role responsibilities
  • Information classification
  • Level of system access
  • Privileged access
  • Business criticality
  • Legal requirements
  • Regulatory requirements
  • Customer requirements
  • Contractual requirements
  • Security risk

Screening shall be conducted fairly, consistently, and in accordance with applicable privacy and employment laws.


4. Screening Principles

The organization shall apply the following principles:

Risk-Based

Screening requirements should reflect the risk associated with the role.

Proportionate

The organization should not collect more personal information than necessary.

Lawful

Screening must comply with applicable employment, privacy, data-protection, and other legal requirements.

Consistent

Comparable roles should generally be subject to comparable screening requirements unless a documented reason exists for different treatment.

Confidential

Screening information must be protected against unauthorized access or disclosure.

Evidence-Based

Screening results should be appropriately documented.

Need-to-Know

Only authorized personnel should have access to screening information.


5. Roles and Responsibilities

RoleResponsibility
HRCoordinates screening process
Hiring ManagerDefines role requirements
Information SecurityDefines security-related screening requirements
Legal/PrivacyAdvises on legal/privacy requirements where necessary
Background Screening ProviderPerforms authorized checks where applicable
Hiring AuthorityMakes employment decision
EmployeeProvides required information and authorization
IT/SecurityControls access based on onboarding requirements

6. Role Risk Assessment

Before determining screening requirements, assess the role.

Consider:

☐ Access to Confidential information
☐ Access to Restricted information
☐ Customer data
☐ Personal data
☐ Financial information
☐ Source code
☐ Production systems
☐ Privileged access
☐ Security administration
☐ Cloud administration
☐ Physical access to secure areas
☐ Critical business processes
☐ Regulatory responsibilities
☐ Customer contractual requirements

Role Risk

☐ Low
☐ Medium
☐ High
☐ Critical

Rationale


7. Screening Levels

The organization may establish screening levels.

LevelTypical Role CharacteristicsScreening
BasicLimited information/system accessIdentity and employment verification as appropriate
StandardAccess to internal or confidential informationBasic checks plus role-appropriate verification
EnhancedSensitive information or significant system accessAdditional lawful checks appropriate to the role
CriticalPrivileged/critical systems or highly sensitive informationEnhanced screening subject to legal and contractual requirements

These levels are examples. The organization should define its own screening methodology.


8. Identity Verification

Where legally and operationally appropriate, verify:

☐ Identity
☐ Name
☐ Date of birth where legally permitted/required
☐ Address where relevant
☐ Right-to-work/employment eligibility where applicable
☐ Identity documentation

Only information necessary for the purpose should be collected and retained.


9. Employment Verification

Where appropriate:

☐ Previous employer
☐ Employment dates
☐ Job title
☐ Role/responsibilities
☐ Employment status

Verification should be performed using lawful and appropriate sources.


10. Education and Qualification Verification

Where qualifications are relevant to the role:

☐ Qualification verified
☐ Certification verified
☐ Professional license verified where applicable
☐ Relevant professional membership verified

For security-sensitive roles, relevant certifications or qualifications may be verified where they form part of the role requirements.


11. Professional Reference Checks

Where appropriate:

☐ References requested
☐ Reference source verified
☐ Reference obtained
☐ Relevant role information confirmed
☐ Evidence retained appropriately

Reference checks should be conducted consistently and in accordance with applicable employment requirements.


12. Criminal Record Checks

Criminal record or similar checks may be performed only where:

  • Legally permitted
  • Relevant to the role
  • Proportionate to the risk
  • Properly authorized
  • Consistent with applicable employment and privacy requirements

The organization should not automatically require criminal-record screening for every role.

Assessment


13. Financial Checks

Financial or credit checks should only be considered where:

  • Legally permitted
  • Relevant to the role
  • Proportionate to the risk
  • Required by applicable regulation or contract
  • Appropriately authorized

Examples may include certain roles with significant financial responsibility.


14. Sanctions or Regulatory Screening

Where legally and operationally required, screening may include relevant:

  • Sanctions lists
  • Regulatory restrictions
  • Professional restrictions
  • Licensing requirements

The organization should identify the specific legal or contractual requirement before performing such checks.


15. Screening for Privileged Roles

Enhanced screening may be appropriate for personnel with:

  • Cloud administrator access
  • Production administrator access
  • Database administrator access
  • Security administrator access
  • Identity administrator access
  • Source-code administration
  • Cryptographic key management
  • Security monitoring responsibilities

The screening level should be based on the organization’s risk assessment.


16. Screening for Remote Employees

Remote work does not automatically eliminate screening requirements.

Where applicable, assess:

☐ Identity verification
☐ Employment verification
☐ Role risk
☐ Information access
☐ System access
☐ Customer requirements
☐ Legal requirements


17. Contractor Screening

Contractors should be subject to appropriate screening based on:

  • Role
  • Access
  • Information classification
  • Contract requirements
  • Customer requirements
  • Duration
  • Privilege level

Where the contractor is supplied through an agency or supplier, the organization should determine whether screening is performed by the supplier and what evidence is required.


18. Third-Party Personnel

For third-party personnel with organizational access:

☐ Screening requirement defined
☐ Supplier responsibility defined
☐ Screening requirement included in contract where appropriate
☐ Evidence requirement defined
☐ Access restrictions implemented
☐ Security requirements communicated

The organization should not automatically require copies of sensitive background-check reports where confirmation of completion is sufficient.


19. Intern and Temporary Worker Screening

Screening for interns and temporary workers should be proportionate to:

  • Role
  • Age/legal status where relevant
  • Access
  • Information handled
  • System privileges
  • Duration of engagement

Where applicable, appropriate authorization and documentation should be obtained.


20. Screening Authorization

Before conducting checks that require personal information or consent:

☐ Purpose explained
☐ Required authorization obtained
☐ Applicable legal basis identified where required
☐ Information collection minimized
☐ Screening provider authorized
☐ Privacy notice provided where required


21. Privacy and Data Protection

Screening information must be handled securely.

The organization should consider:

  • Purpose limitation
  • Data minimization
  • Accuracy
  • Access restriction
  • Retention
  • Secure storage
  • Secure disposal
  • Lawful processing
  • Individual rights where applicable

Screening information should not be stored in general personnel folders unless appropriate access restrictions are applied.


22. Screening Records

Record only information necessary to demonstrate that required screening was completed.

Possible records:

☐ Screening status
☐ Screening date
☐ Screening level
☐ Check type
☐ Verification result
☐ Reviewer
☐ Exceptions
☐ Approval

Where possible, record “verified” rather than retaining unnecessary copies of sensitive source documents.


23. Screening Result

Possible outcomes:

☐ Satisfactory
☐ Satisfactory with documented consideration
☐ Additional information required
☐ Unable to verify
☐ Escalation required
☐ Not cleared for specified role/access

The decision should follow applicable employment, privacy, and legal requirements.


24. Screening Exceptions

An exception may occur where:

  • A required document cannot be obtained
  • A verification source is unavailable
  • Screening cannot be completed before joining
  • A legal limitation applies
  • A customer requirement cannot be immediately satisfied

Exceptions should be:

☐ Documented
☐ Risk assessed
☐ Approved
☐ Time-bound where appropriate
☐ Subject to compensating controls


25. Access Before Screening Completion

Where screening is incomplete but business requirements require the individual to start:

Consider:

☐ Restricted access
☐ No privileged access
☐ No production access
☐ No access to sensitive information
☐ Supervised activity
☐ Temporary controls
☐ Completion deadline

Access should be aligned with the organization’s risk decision.


26. Screening and Onboarding

Before granting normal access, verify:

☐ Required screening completed
☐ Employment/contract relationship confirmed
☐ Confidentiality requirements completed
☐ Security responsibilities communicated
☐ Required agreements completed
☐ Appropriate access approved
☐ Security training assigned


27. Ongoing Screening

Ongoing or periodic screening should only be performed where justified by:

  • Law
  • Regulation
  • Contract
  • Role risk
  • Security requirements
  • Significant change in responsibilities

Periodic screening should not automatically be applied to every employee.


28. Role Change

When an employee moves to a different role:

☐ New role assessed
☐ Screening requirements reassessed
☐ Additional screening performed where required
☐ Access reviewed
☐ Privileges adjusted
☐ Previous access removed where no longer required


29. Security-Sensitive Role Change

If a person moves into a privileged or security-sensitive role:

Consider:

  • Enhanced screening
  • Additional confidentiality requirements
  • Security training
  • Access review
  • Management approval

Assessment


30. Screening Provider

Where an external screening provider is used:

☐ Provider approved
☐ Contract reviewed
☐ Privacy requirements reviewed
☐ Security requirements defined
☐ Data location understood
☐ Retention requirements understood
☐ Subprocessors considered
☐ Access to screening information restricted


31. Screening Evidence Review

Where screening evidence is reviewed:

☐ Source identified
☐ Evidence appears authentic
☐ Information matches the individual
☐ Required check completed
☐ Date is appropriate
☐ Exceptions documented
☐ Evidence securely stored


32. Confidentiality

Screening information is confidential.

Access should be limited to authorized personnel such as:

  • HR
  • Authorized management
  • Legal/Privacy
  • Authorized security personnel

Screening information should not be unnecessarily shared with:

  • General employees
  • Project teams
  • Customers
  • Suppliers
  • Other departments

33. Retention

Define retention based on:

  • Applicable law
  • Employment requirements
  • Privacy requirements
  • Contractual requirements
  • Business need

Retention Period

Screening Record: __________________

Retention Basis: __________________

Secure Disposal Method: __________________


34. Secure Disposal

When screening information is no longer required:

☐ Retention period verified
☐ Record securely deleted/destroyed
☐ Electronic copies removed where appropriate
☐ Physical copies securely destroyed
☐ Disposal recorded where required


35. Screening Incidents

A screening-related security or privacy incident may include:

  • Unauthorized disclosure
  • Incorrect screening result
  • Loss of screening records
  • Unauthorized access
  • Data breach
  • Improper retention
  • Unauthorized screening

Such incidents should be handled through the organization’s Incident Management Procedure and applicable privacy process.


36. Monitoring and Compliance

The organization may periodically review:

☐ Required screening completed
☐ Screening completed before required access
☐ Exceptions documented
☐ Records protected
☐ Retention followed
☐ Third-party screening requirements followed
☐ Screening providers comply with requirements


37. Metrics

Possible metrics include:

MetricResult
Personnel requiring screening
Screening completed
Screening pending
Screening exceptions
Privileged roles screened
Third-party personnel screened
Overdue screening
Screening-related findings

38. Roles and Access Relationship

Screening should be considered together with access requirements.

Example:

Role → Information → Access → Privilege → Risk → Screening Requirement

A role requiring production administrator access may warrant more extensive screening than a role with access only to public information.


39. Employee Screening Review

Review this policy periodically and when there are:

☐ Legal changes
☐ Regulatory changes
☐ Customer requirements
☐ Contract changes
☐ Significant security incidents
☐ Organizational changes
☐ Changes in role types
☐ New privileged roles
☐ New countries of operation
☐ Changes to privacy requirements


40. AWS SaaS Startup Example

A SaaS startup has the following roles:

RoleAccessExample Screening
Marketing ExecutivePublic/Internal informationBasic role-appropriate verification
Software DeveloperSource codeStandard verification
DevOps EngineerCloud/production systemsEnhanced screening where justified
Security AdministratorSecurity systems/privileged accessEnhanced screening where justified
Finance AdministratorFinancial informationRole-appropriate enhanced checks where lawful
ContractorDepends on scopeRisk-based screening

Example

A new DevOps engineer will receive access to:

  • AWS production
  • IAM
  • CI/CD
  • Infrastructure-as-Code
  • Monitoring
  • Production logs

The organization assesses the role as High Risk because of privileged production access.

The organization therefore defines appropriate screening requirements before granting the intended level of access.

Audit Trail

Role Definition → Risk Assessment → Screening Requirement → Authorization → Screening → Verification → Approval → Access Provisioning → Record


41. Startup-Friendly Screening Model

A startup can avoid applying the same screening package to every employee.

Low-Risk Role

Focus on:

  • Identity
  • Employment relationship
  • Role requirements
  • Applicable legal requirements

Medium-Risk Role

Add appropriate:

  • Employment verification
  • Qualification verification
  • References
  • Other lawful role-specific checks

High/Critical Role

Consider enhanced checks appropriate to:

  • Privileged access
  • Sensitive information
  • Customer requirements
  • Regulatory obligations
  • Legal requirements

The objective is risk-based screening, not maximum screening for every employee.


42. Common Mistakes

Avoid:

  • Applying identical screening to every role without considering risk.
  • Performing checks without a lawful basis or required authorization.
  • Collecting unnecessary personal information.
  • Keeping full background reports when verification status is sufficient.
  • Storing screening records without access restrictions.
  • Granting privileged access before required screening is completed.
  • Ignoring contractor and third-party personnel.
  • Failing to document screening exceptions.
  • Using outdated screening information without considering role changes.
  • Assuming screening alone makes privileged access secure.
  • Allowing HR screening records to be broadly accessible.
  • Retaining screening records indefinitely.
  • Failing to consider applicable local employment and privacy requirements.

43. Relationship With Other ISMS Documents

DocumentRelationship
Information Security PolicyProvides overall security direction
Human Resources Security ProcedureDefines personnel lifecycle requirements
Recruitment ProcedureDefines hiring process
Onboarding ProcedureEstablishes personnel before access
Access Management ProcedureControls system access
Privileged Access ProcedureControls privileged access
Security Awareness ProcedureProvides security training
Employee Offboarding ProcedureRemoves access at termination
Supplier Security RequirementsAddresses third-party personnel
Data Protection PolicyGoverns personal-data handling
Incident Response ProcedureHandles screening-related incidents
Risk AssessmentDetermines role-related security risk

44. ISO/IEC 27001 Connection

Employee screening supports personnel-security controls by helping the organization establish appropriate trust and security requirements before personnel are given access to information or systems.

The organization’s screening approach should be based on:

  • Applicable laws
  • Employment requirements
  • Role responsibilities
  • Information classification
  • Access privileges
  • Risk assessment
  • Customer requirements
  • Contractual requirements
  • Regulatory requirements

The Employee Screening Policy is not itself a universally prescribed ISO/IEC 27001 document. The organization should determine the appropriate screening activities and documented evidence based on its risks and applicable requirements.


45. Audit Evidence Checklist

An auditor should be able to verify:

☐ Screening policy approved
☐ Role-risk criteria defined
☐ Screening requirements documented
☐ Appropriate authorization obtained
☐ Required screening completed
☐ Screening exceptions documented
☐ Privileged roles assessed
☐ Contractor requirements addressed
☐ Third-party personnel requirements addressed
☐ Screening records protected
☐ Retention requirements defined
☐ Access restricted
☐ Screening requirements reviewed periodically
☐ Applicable legal/privacy requirements considered


46. Final Employee Screening Audit Trail

For each role requiring screening, the organization should be able to demonstrate:

What is the role?

What information and systems can the person access?

What is the security risk of the role?

What screening is required?

Why is that screening appropriate?

Was the required authorization obtained?

Was the screening completed?

Were any exceptions identified?

Who reviewed the result?

Was access granted at the appropriate level?

How is screening information protected?

How long is it retained?

What happens when the role changes?

Final Principle

Employee screening should establish an appropriate level of assurance for the role without becoming an unnecessary collection of personal information. The objective is to apply lawful, proportionate, risk-based screening before granting access appropriate to the individual’s responsibilities.