1. Purpose
The Employee Screening Policy establishes requirements for conducting appropriate pre-employment and, where necessary, ongoing screening of employees, contractors, interns, and other personnel who may have access to organizational information, systems, facilities, or customer information.
The objective is to ensure that screening is:
- Appropriate to the role
- Proportionate to information-security risk
- Consistent with applicable law
- Performed before access is granted where required
- Properly documented
- Privacy-conscious
- Consistently applied
- Reviewed when circumstances or role requirements change
Core Principle
Define Role Risk → Determine Screening → Obtain Authorization → Screen → Verify → Record → Decide → Monitor
2. Scope
This policy applies to personnel who may have access to:
- Organizational information
- Confidential or Restricted information
- Personal data
- Customer information
- Production systems
- Cloud infrastructure
- Source code
- Security systems
- Privileged accounts
- Physical facilities
- Critical business processes
It may apply to:
☐ Employees
☐ Contractors
☐ Consultants
☐ Interns
☐ Temporary workers
☐ Privileged administrators
☐ Remote personnel
☐ Third-party personnel
The exact scope should be determined by the organization’s risk assessment and applicable requirements.
3. Policy Statement
The organization shall perform appropriate personnel screening before granting access to information, systems, or facilities where screening is necessary based on:
- Role responsibilities
- Information classification
- Level of system access
- Privileged access
- Business criticality
- Legal requirements
- Regulatory requirements
- Customer requirements
- Contractual requirements
- Security risk
Screening shall be conducted fairly, consistently, and in accordance with applicable privacy and employment laws.
4. Screening Principles
The organization shall apply the following principles:
Risk-Based
Screening requirements should reflect the risk associated with the role.
Proportionate
The organization should not collect more personal information than necessary.
Lawful
Screening must comply with applicable employment, privacy, data-protection, and other legal requirements.
Consistent
Comparable roles should generally be subject to comparable screening requirements unless a documented reason exists for different treatment.
Confidential
Screening information must be protected against unauthorized access or disclosure.
Evidence-Based
Screening results should be appropriately documented.
Need-to-Know
Only authorized personnel should have access to screening information.
5. Roles and Responsibilities
| Role | Responsibility |
|---|---|
| HR | Coordinates screening process |
| Hiring Manager | Defines role requirements |
| Information Security | Defines security-related screening requirements |
| Legal/Privacy | Advises on legal/privacy requirements where necessary |
| Background Screening Provider | Performs authorized checks where applicable |
| Hiring Authority | Makes employment decision |
| Employee | Provides required information and authorization |
| IT/Security | Controls access based on onboarding requirements |
6. Role Risk Assessment
Before determining screening requirements, assess the role.
Consider:
☐ Access to Confidential information
☐ Access to Restricted information
☐ Customer data
☐ Personal data
☐ Financial information
☐ Source code
☐ Production systems
☐ Privileged access
☐ Security administration
☐ Cloud administration
☐ Physical access to secure areas
☐ Critical business processes
☐ Regulatory responsibilities
☐ Customer contractual requirements
Role Risk
☐ Low
☐ Medium
☐ High
☐ Critical
Rationale
7. Screening Levels
The organization may establish screening levels.
| Level | Typical Role Characteristics | Screening |
|---|---|---|
| Basic | Limited information/system access | Identity and employment verification as appropriate |
| Standard | Access to internal or confidential information | Basic checks plus role-appropriate verification |
| Enhanced | Sensitive information or significant system access | Additional lawful checks appropriate to the role |
| Critical | Privileged/critical systems or highly sensitive information | Enhanced screening subject to legal and contractual requirements |
These levels are examples. The organization should define its own screening methodology.
8. Identity Verification
Where legally and operationally appropriate, verify:
☐ Identity
☐ Name
☐ Date of birth where legally permitted/required
☐ Address where relevant
☐ Right-to-work/employment eligibility where applicable
☐ Identity documentation
Only information necessary for the purpose should be collected and retained.
9. Employment Verification
Where appropriate:
☐ Previous employer
☐ Employment dates
☐ Job title
☐ Role/responsibilities
☐ Employment status
Verification should be performed using lawful and appropriate sources.
10. Education and Qualification Verification
Where qualifications are relevant to the role:
☐ Qualification verified
☐ Certification verified
☐ Professional license verified where applicable
☐ Relevant professional membership verified
For security-sensitive roles, relevant certifications or qualifications may be verified where they form part of the role requirements.
11. Professional Reference Checks
Where appropriate:
☐ References requested
☐ Reference source verified
☐ Reference obtained
☐ Relevant role information confirmed
☐ Evidence retained appropriately
Reference checks should be conducted consistently and in accordance with applicable employment requirements.
12. Criminal Record Checks
Criminal record or similar checks may be performed only where:
- Legally permitted
- Relevant to the role
- Proportionate to the risk
- Properly authorized
- Consistent with applicable employment and privacy requirements
The organization should not automatically require criminal-record screening for every role.
Assessment
13. Financial Checks
Financial or credit checks should only be considered where:
- Legally permitted
- Relevant to the role
- Proportionate to the risk
- Required by applicable regulation or contract
- Appropriately authorized
Examples may include certain roles with significant financial responsibility.
14. Sanctions or Regulatory Screening
Where legally and operationally required, screening may include relevant:
- Sanctions lists
- Regulatory restrictions
- Professional restrictions
- Licensing requirements
The organization should identify the specific legal or contractual requirement before performing such checks.
15. Screening for Privileged Roles
Enhanced screening may be appropriate for personnel with:
- Cloud administrator access
- Production administrator access
- Database administrator access
- Security administrator access
- Identity administrator access
- Source-code administration
- Cryptographic key management
- Security monitoring responsibilities
The screening level should be based on the organization’s risk assessment.
16. Screening for Remote Employees
Remote work does not automatically eliminate screening requirements.
Where applicable, assess:
☐ Identity verification
☐ Employment verification
☐ Role risk
☐ Information access
☐ System access
☐ Customer requirements
☐ Legal requirements
17. Contractor Screening
Contractors should be subject to appropriate screening based on:
- Role
- Access
- Information classification
- Contract requirements
- Customer requirements
- Duration
- Privilege level
Where the contractor is supplied through an agency or supplier, the organization should determine whether screening is performed by the supplier and what evidence is required.
18. Third-Party Personnel
For third-party personnel with organizational access:
☐ Screening requirement defined
☐ Supplier responsibility defined
☐ Screening requirement included in contract where appropriate
☐ Evidence requirement defined
☐ Access restrictions implemented
☐ Security requirements communicated
The organization should not automatically require copies of sensitive background-check reports where confirmation of completion is sufficient.
19. Intern and Temporary Worker Screening
Screening for interns and temporary workers should be proportionate to:
- Role
- Age/legal status where relevant
- Access
- Information handled
- System privileges
- Duration of engagement
Where applicable, appropriate authorization and documentation should be obtained.
20. Screening Authorization
Before conducting checks that require personal information or consent:
☐ Purpose explained
☐ Required authorization obtained
☐ Applicable legal basis identified where required
☐ Information collection minimized
☐ Screening provider authorized
☐ Privacy notice provided where required
21. Privacy and Data Protection
Screening information must be handled securely.
The organization should consider:
- Purpose limitation
- Data minimization
- Accuracy
- Access restriction
- Retention
- Secure storage
- Secure disposal
- Lawful processing
- Individual rights where applicable
Screening information should not be stored in general personnel folders unless appropriate access restrictions are applied.
22. Screening Records
Record only information necessary to demonstrate that required screening was completed.
Possible records:
☐ Screening status
☐ Screening date
☐ Screening level
☐ Check type
☐ Verification result
☐ Reviewer
☐ Exceptions
☐ Approval
Where possible, record “verified” rather than retaining unnecessary copies of sensitive source documents.
23. Screening Result
Possible outcomes:
☐ Satisfactory
☐ Satisfactory with documented consideration
☐ Additional information required
☐ Unable to verify
☐ Escalation required
☐ Not cleared for specified role/access
The decision should follow applicable employment, privacy, and legal requirements.
24. Screening Exceptions
An exception may occur where:
- A required document cannot be obtained
- A verification source is unavailable
- Screening cannot be completed before joining
- A legal limitation applies
- A customer requirement cannot be immediately satisfied
Exceptions should be:
☐ Documented
☐ Risk assessed
☐ Approved
☐ Time-bound where appropriate
☐ Subject to compensating controls
25. Access Before Screening Completion
Where screening is incomplete but business requirements require the individual to start:
Consider:
☐ Restricted access
☐ No privileged access
☐ No production access
☐ No access to sensitive information
☐ Supervised activity
☐ Temporary controls
☐ Completion deadline
Access should be aligned with the organization’s risk decision.
26. Screening and Onboarding
Before granting normal access, verify:
☐ Required screening completed
☐ Employment/contract relationship confirmed
☐ Confidentiality requirements completed
☐ Security responsibilities communicated
☐ Required agreements completed
☐ Appropriate access approved
☐ Security training assigned
27. Ongoing Screening
Ongoing or periodic screening should only be performed where justified by:
- Law
- Regulation
- Contract
- Role risk
- Security requirements
- Significant change in responsibilities
Periodic screening should not automatically be applied to every employee.
28. Role Change
When an employee moves to a different role:
☐ New role assessed
☐ Screening requirements reassessed
☐ Additional screening performed where required
☐ Access reviewed
☐ Privileges adjusted
☐ Previous access removed where no longer required
29. Security-Sensitive Role Change
If a person moves into a privileged or security-sensitive role:
Consider:
- Enhanced screening
- Additional confidentiality requirements
- Security training
- Access review
- Management approval
Assessment
30. Screening Provider
Where an external screening provider is used:
☐ Provider approved
☐ Contract reviewed
☐ Privacy requirements reviewed
☐ Security requirements defined
☐ Data location understood
☐ Retention requirements understood
☐ Subprocessors considered
☐ Access to screening information restricted
31. Screening Evidence Review
Where screening evidence is reviewed:
☐ Source identified
☐ Evidence appears authentic
☐ Information matches the individual
☐ Required check completed
☐ Date is appropriate
☐ Exceptions documented
☐ Evidence securely stored
32. Confidentiality
Screening information is confidential.
Access should be limited to authorized personnel such as:
- HR
- Authorized management
- Legal/Privacy
- Authorized security personnel
Screening information should not be unnecessarily shared with:
- General employees
- Project teams
- Customers
- Suppliers
- Other departments
33. Retention
Define retention based on:
- Applicable law
- Employment requirements
- Privacy requirements
- Contractual requirements
- Business need
Retention Period
Screening Record: __________________
Retention Basis: __________________
Secure Disposal Method: __________________
34. Secure Disposal
When screening information is no longer required:
☐ Retention period verified
☐ Record securely deleted/destroyed
☐ Electronic copies removed where appropriate
☐ Physical copies securely destroyed
☐ Disposal recorded where required
35. Screening Incidents
A screening-related security or privacy incident may include:
- Unauthorized disclosure
- Incorrect screening result
- Loss of screening records
- Unauthorized access
- Data breach
- Improper retention
- Unauthorized screening
Such incidents should be handled through the organization’s Incident Management Procedure and applicable privacy process.
36. Monitoring and Compliance
The organization may periodically review:
☐ Required screening completed
☐ Screening completed before required access
☐ Exceptions documented
☐ Records protected
☐ Retention followed
☐ Third-party screening requirements followed
☐ Screening providers comply with requirements
37. Metrics
Possible metrics include:
| Metric | Result |
|---|---|
| Personnel requiring screening | |
| Screening completed | |
| Screening pending | |
| Screening exceptions | |
| Privileged roles screened | |
| Third-party personnel screened | |
| Overdue screening | |
| Screening-related findings |
38. Roles and Access Relationship
Screening should be considered together with access requirements.
Example:
Role → Information → Access → Privilege → Risk → Screening Requirement
A role requiring production administrator access may warrant more extensive screening than a role with access only to public information.
39. Employee Screening Review
Review this policy periodically and when there are:
☐ Legal changes
☐ Regulatory changes
☐ Customer requirements
☐ Contract changes
☐ Significant security incidents
☐ Organizational changes
☐ Changes in role types
☐ New privileged roles
☐ New countries of operation
☐ Changes to privacy requirements
40. AWS SaaS Startup Example
A SaaS startup has the following roles:
| Role | Access | Example Screening |
|---|---|---|
| Marketing Executive | Public/Internal information | Basic role-appropriate verification |
| Software Developer | Source code | Standard verification |
| DevOps Engineer | Cloud/production systems | Enhanced screening where justified |
| Security Administrator | Security systems/privileged access | Enhanced screening where justified |
| Finance Administrator | Financial information | Role-appropriate enhanced checks where lawful |
| Contractor | Depends on scope | Risk-based screening |
Example
A new DevOps engineer will receive access to:
- AWS production
- IAM
- CI/CD
- Infrastructure-as-Code
- Monitoring
- Production logs
The organization assesses the role as High Risk because of privileged production access.
The organization therefore defines appropriate screening requirements before granting the intended level of access.
Audit Trail
Role Definition → Risk Assessment → Screening Requirement → Authorization → Screening → Verification → Approval → Access Provisioning → Record
41. Startup-Friendly Screening Model
A startup can avoid applying the same screening package to every employee.
Low-Risk Role
Focus on:
- Identity
- Employment relationship
- Role requirements
- Applicable legal requirements
Medium-Risk Role
Add appropriate:
- Employment verification
- Qualification verification
- References
- Other lawful role-specific checks
High/Critical Role
Consider enhanced checks appropriate to:
- Privileged access
- Sensitive information
- Customer requirements
- Regulatory obligations
- Legal requirements
The objective is risk-based screening, not maximum screening for every employee.
42. Common Mistakes
Avoid:
- Applying identical screening to every role without considering risk.
- Performing checks without a lawful basis or required authorization.
- Collecting unnecessary personal information.
- Keeping full background reports when verification status is sufficient.
- Storing screening records without access restrictions.
- Granting privileged access before required screening is completed.
- Ignoring contractor and third-party personnel.
- Failing to document screening exceptions.
- Using outdated screening information without considering role changes.
- Assuming screening alone makes privileged access secure.
- Allowing HR screening records to be broadly accessible.
- Retaining screening records indefinitely.
- Failing to consider applicable local employment and privacy requirements.
43. Relationship With Other ISMS Documents
| Document | Relationship |
|---|---|
| Information Security Policy | Provides overall security direction |
| Human Resources Security Procedure | Defines personnel lifecycle requirements |
| Recruitment Procedure | Defines hiring process |
| Onboarding Procedure | Establishes personnel before access |
| Access Management Procedure | Controls system access |
| Privileged Access Procedure | Controls privileged access |
| Security Awareness Procedure | Provides security training |
| Employee Offboarding Procedure | Removes access at termination |
| Supplier Security Requirements | Addresses third-party personnel |
| Data Protection Policy | Governs personal-data handling |
| Incident Response Procedure | Handles screening-related incidents |
| Risk Assessment | Determines role-related security risk |
44. ISO/IEC 27001 Connection
Employee screening supports personnel-security controls by helping the organization establish appropriate trust and security requirements before personnel are given access to information or systems.
The organization’s screening approach should be based on:
- Applicable laws
- Employment requirements
- Role responsibilities
- Information classification
- Access privileges
- Risk assessment
- Customer requirements
- Contractual requirements
- Regulatory requirements
The Employee Screening Policy is not itself a universally prescribed ISO/IEC 27001 document. The organization should determine the appropriate screening activities and documented evidence based on its risks and applicable requirements.
45. Audit Evidence Checklist
An auditor should be able to verify:
☐ Screening policy approved
☐ Role-risk criteria defined
☐ Screening requirements documented
☐ Appropriate authorization obtained
☐ Required screening completed
☐ Screening exceptions documented
☐ Privileged roles assessed
☐ Contractor requirements addressed
☐ Third-party personnel requirements addressed
☐ Screening records protected
☐ Retention requirements defined
☐ Access restricted
☐ Screening requirements reviewed periodically
☐ Applicable legal/privacy requirements considered
46. Final Employee Screening Audit Trail
For each role requiring screening, the organization should be able to demonstrate:
What is the role?
What information and systems can the person access?
What is the security risk of the role?
What screening is required?
Why is that screening appropriate?
Was the required authorization obtained?
Was the screening completed?
Were any exceptions identified?
Who reviewed the result?
Was access granted at the appropriate level?
How is screening information protected?
How long is it retained?
What happens when the role changes?
Final Principle
Employee screening should establish an appropriate level of assurance for the role without becoming an unnecessary collection of personal information. The objective is to apply lawful, proportionate, risk-based screening before granting access appropriate to the individual’s responsibilities.
