1. Purpose
The Background Verification Procedure defines how the organization performs, documents, reviews, and manages background verification for employees, contractors, interns, temporary workers, and other personnel where verification is required.
The objective is to ensure that background verification:
- Is appropriate to the role and associated risks
- Is performed lawfully and proportionately
- Supports information-security requirements
- Helps verify relevant identity, employment, education, and professional information
- Protects personal and sensitive information
- Is completed before granting access where required
- Produces appropriate evidence for audit purposes
- Provides a consistent process for exceptions and adverse results
Core Principle
Define Role Risk → Determine Checks → Obtain Authorization → Verify → Review → Decide → Record → Protect → Monitor
2. Scope
This procedure applies to:
- Permanent employees
- Temporary employees
- Contractors
- Consultants
- Interns
- Apprentices
- Outsourced personnel
- Third-party personnel where required
- Personnel assigned to security-sensitive roles
The procedure applies during:
- Pre-employment
- Pre-engagement
- Role changes
- Transfers to sensitive roles
- Periodic re-verification where justified
- Investigation of material discrepancies where appropriate
3. Background Verification Information
| Field | Details |
|---|---|
| Verification ID | |
| Candidate/Personnel ID | |
| Name | |
| Position | |
| Department | |
| Employment Type | |
| Role Risk Level | |
| Verification Level | |
| Verification Provider | |
| Request Date | |
| Authorization Date | |
| Verification Start Date | |
| Verification Completion Date | |
| HR Owner | |
| Security Review Required | |
| Status |
4. Roles and Responsibilities
HR
Responsible for:
- Initiating verification
- Obtaining required authorization
- Coordinating verification
- Reviewing results
- Maintaining records
- Communicating relevant outcomes
Hiring Manager
Responsible for:
- Defining the role
- Identifying role-specific risks
- Confirming required verification level
- Supporting decisions regarding discrepancies
Information Security
Where applicable:
- Advises on security-sensitive roles
- Reviews verification requirements for privileged positions
- Assesses information-security implications
- Supports risk decisions
Legal/Privacy
Where required:
- Advises on applicable legal and privacy requirements
- Reviews sensitive or complex verification activities
- Advises on permissible checks
Management
Responsible for:
- Approving significant exceptions or risk acceptance where required
- Ensuring appropriate resources and governance
5. Role Risk Assessment
Background verification should be proportionate to the role.
Consider:
☐ Access to confidential information
☐ Access to personal data
☐ Access to financial information
☐ Production-system access
☐ Privileged access
☐ Cloud administration
☐ Source-code access
☐ Security administration
☐ Customer-facing responsibility
☐ Regulatory responsibility
☐ Financial responsibility
☐ Physical facility access
☐ Business-critical responsibility
Role Risk
☐ Low
☐ Medium
☐ High
☐ Critical
Risk Rationale
6. Verification Levels
Example risk-based model:
| Level | Typical Checks |
|---|---|
| Basic | Identity and employment verification |
| Standard | Identity, employment, education/qualification and references where relevant |
| Enhanced | Standard checks plus additional lawful checks appropriate to the role |
| High-Risk | Enhanced verification appropriate to privileged, regulated, financial, or highly sensitive roles |
The organization should define its own verification levels based on applicable law, role requirements, and risk.
7. Verification Requirements
Determine which checks are required.
☐ Identity verification
☐ Address verification where relevant
☐ Employment verification
☐ Education verification
☐ Professional qualification verification
☐ Professional references
☐ Professional registration verification
☐ Criminal-record check where lawful and relevant
☐ Sanctions/regulatory screening where applicable
☐ Financial checks where lawful and role-relevant
☐ Conflict-of-interest declaration
☐ Right-to-work verification where applicable
☐ Other: ______________________
Not every individual requires every check.
8. Candidate Authorization
Before conducting checks:
☐ Verification requirement communicated
☐ Required consent/authorization obtained
☐ Purpose explained
☐ Verification scope explained
☐ Applicable privacy information provided
☐ Verification provider authorized
☐ Legal requirements considered
Verification should not be performed outside the approved scope.
9. Identity Verification
Verify identity using appropriate and lawful sources.
Possible evidence may include:
- Government-issued identification
- Authorized identity-verification service
- Other legally acceptable evidence
Verify, where appropriate:
☐ Name
☐ Date of birth
☐ Identity document validity
☐ Identity consistency
☐ Other required information
Result
☐ Verified
☐ Partially Verified
☐ Unable to Verify
☐ Discrepancy Identified
10. Employment Verification
Where employment history is relevant:
☐ Previous employer identified
☐ Employment dates verified
☐ Position verified
☐ Employment status verified
☐ Relevant responsibilities verified where appropriate
☐ Significant unexplained gaps identified
☐ Discrepancies documented
Verification should be limited to information relevant to the stated purpose and permitted by applicable requirements.
11. Education and Qualification Verification
Where qualifications are relevant:
☐ Institution verified
☐ Qualification verified
☐ Completion status verified
☐ Relevant professional certification verified
☐ Professional registration verified where applicable
☐ Discrepancies recorded
Result
12. Professional Reference Verification
Where references are required:
☐ Reference requirement defined
☐ Reference identity verified
☐ Reference obtained from appropriate source
☐ Relevant employment relationship confirmed
☐ Response recorded
☐ Material concerns escalated where appropriate
Do not request unnecessary personal information from referees.
13. Criminal Record Checks
Criminal-record checks should only be performed where:
- Legally permissible
- Relevant to the role
- Proportionate to the risk
- Appropriately authorized
Consider:
☐ Legal requirements
☐ Jurisdiction
☐ Role sensitivity
☐ Nature of the position
☐ Data protection requirements
☐ Accuracy of the information
☐ Opportunity to challenge inaccurate information
A criminal-record result should not automatically be treated as a reason for rejection without considering applicable law, organizational policy, role relevance, and the circumstances.
14. Financial Checks
Financial checks should only be conducted where legally permitted and relevant to the role.
Potentially relevant roles may include:
- Financial control
- Treasury
- Payment administration
- Certain regulated roles
- Roles with significant financial authority
Consider:
☐ Legal basis
☐ Role relevance
☐ Proportionality
☐ Candidate notification/authorization
☐ Data protection
☐ Secure handling
15. Sanctions and Regulatory Screening
Where applicable:
☐ Sanctions screening completed
☐ Regulatory registration verified
☐ Professional license verified
☐ Required regulatory status confirmed
☐ Potential match investigated
☐ False positives resolved
☐ Evidence retained
Screening should use appropriate and reliable sources.
16. Security-Sensitive Roles
Enhanced verification may be appropriate for roles involving:
- Production administration
- Cloud administration
- Security operations
- Information-security management
- Database administration
- Source-code administration
- Financial systems
- Customer-sensitive information
- Cryptographic key management
- Privileged infrastructure
For such roles:
☐ Role risk assessed
☐ Enhanced checks identified
☐ Verification completed before privileged access where practical
☐ Exceptions documented
☐ Additional approval obtained where required
17. Contractor Verification
Before assigning contractors to security-sensitive activities:
☐ Contractor identity verified
☐ Contracting organization identified
☐ Required background checks confirmed
☐ Confidentiality requirements established
☐ Security responsibilities defined
☐ Access requirements identified
☐ Verification evidence reviewed where appropriate
18. Third-Party Personnel
Where suppliers provide personnel with organizational access:
☐ Supplier screening requirements defined
☐ Supplier verification responsibility defined
☐ Required checks communicated contractually
☐ Evidence/attestation requirements defined
☐ High-risk personnel subject to additional review where appropriate
☐ Access restricted until required verification is complete
19. Interns and Temporary Personnel
Verification requirements should be proportionate to:
- Role
- Access
- Information handled
- Duration
- Business risk
Do not assume that temporary personnel require no verification.
20. Verification Provider
If an external verification provider is used:
☐ Provider approved
☐ Provider identity verified
☐ Scope defined
☐ Privacy/security requirements reviewed
☐ Confidentiality requirements established
☐ Data-processing requirements addressed where applicable
☐ Data retention understood
☐ Subprocessors identified where relevant
☐ Secure information transfer established
21. Verification Evidence
Evidence may include:
- Verification report
- Confirmation from authorized source
- Qualification confirmation
- Employment confirmation
- Reference confirmation
- Screening result
- Provider attestation
Avoid retaining unnecessary copies of highly sensitive personal information.
Where possible, retain:
Verification performed → Result → Date → Reviewer → Decision
rather than unnecessary source documents.
22. Evidence Review
The reviewer should determine whether the evidence is:
☐ Relevant
☐ Reliable
☐ Current
☐ Complete enough for the purpose
☐ From an appropriate source
☐ Consistent with information provided by the individual
Evidence Assessment
23. Discrepancy Identification
Potential discrepancies may include:
- Incorrect employment dates
- Incorrect qualifications
- Unexplained information
- Identity mismatch
- Unverified professional credentials
- Material inconsistencies
- Potential screening match
Record:
| Discrepancy | Source | Impact | Action | Status |
|---|---|---|---|---|
24. Discrepancy Review
A discrepancy should be reviewed before making an employment or access decision.
Consider:
☐ Accuracy of information
☐ Source reliability
☐ Materiality
☐ Role relevance
☐ Legal requirements
☐ Candidate explanation
☐ Potential security impact
☐ Need for additional verification
The individual should be given an appropriate opportunity to clarify potentially inaccurate information where required.
25. Verification Result
Overall Result
☐ Satisfactory
☐ Satisfactory with Conditions
☐ Further Verification Required
☐ Discrepancy Under Review
☐ Not Satisfactory
☐ Unable to Complete
Reviewer Comments
26. Access Before Verification Completion
As a general principle, personnel should not receive access beyond the organization’s approved onboarding level until required verification is completed.
Where business requirements require access before completion:
☐ Business justification documented
☐ Risk assessed
☐ Access minimized
☐ MFA enabled where applicable
☐ Privileged access restricted
☐ Time limitation defined
☐ Management approval obtained
☐ Verification completion tracked
27. Verification and Onboarding
Before granting normal organizational access:
☐ Required verification completed
☐ Results reviewed
☐ Discrepancies resolved or formally addressed
☐ Employment/engagement approved
☐ Security requirements communicated
☐ Required confidentiality agreement completed
☐ Access request approved
28. Background Verification and Access Management
Verification should connect with access management.
Example
A developer requiring:
- GitHub access
- AWS development access
- CI/CD access
may require a different verification level from an employee with no system access.
A developer requiring AWS production administration may require enhanced verification based on organizational risk.
Audit Trail
Role → Risk → Verification → Approval → Access → Review
29. Periodic Re-Verification
Periodic re-verification should be risk-based and legally permissible.
Consider re-verification when:
☐ Role becomes significantly more sensitive
☐ Privileged access is granted
☐ Regulatory requirements change
☐ Contract requires re-verification
☐ Significant security concern arises
☐ Organizational policy requires periodic verification
Periodic checks should not become routine collection of unnecessary personal information.
30. Role Change
When an employee moves into a more sensitive role:
☐ New role assessed
☐ New verification requirements identified
☐ Additional checks completed where required
☐ Access requirements reassessed
☐ Existing verification reviewed
☐ Approval recorded
31. Privacy and Personal Data Protection
Background verification can involve sensitive personal information.
The organization should:
☐ Collect only necessary information
☐ Define the purpose of collection
☐ Use appropriate lawful processing mechanisms
☐ Restrict access
☐ Protect verification records
☐ Avoid unnecessary duplication
☐ Define retention periods
☐ Securely dispose of information
☐ Manage third-party verification providers appropriately
☐ Address international transfers where applicable
32. Access to Verification Records
Verification records should be accessible only to authorized personnel.
Potential access roles:
- HR
- Authorized management
- Legal/privacy personnel
- Information security where required
- Authorized verification administrators
Access should be:
☐ Role-based
☐ Least privilege
☐ Logged where appropriate
☐ Periodically reviewed
33. Confidentiality
Background verification information should be treated as confidential.
Personnel handling verification information must:
☐ Maintain confidentiality
☐ Use information only for authorized purposes
☐ Avoid unnecessary disclosure
☐ Secure physical and electronic records
☐ Report suspected unauthorized disclosure
34. Record Retention
Define retention based on:
- Legal requirements
- Employment requirements
- Contractual requirements
- Privacy requirements
- Litigation/claim requirements
- Organizational records policy
Retention Period
Do not retain verification information indefinitely without a defined purpose.
35. Secure Disposal
When retention expires:
☐ Record identified
☐ Retention requirement confirmed
☐ Disposal authorized
☐ Electronic information securely deleted
☐ Physical records securely destroyed
☐ Disposal evidence retained where appropriate
36. Exceptions
Exceptions may be required when verification cannot be completed within the normal timeframe.
Record:
- Reason
- Risk
- Missing verification
- Compensating controls
- Access restrictions
- Approval
- Expiry/review date
Exception Record
Exceptions should be time-bound and should not be used to permanently bypass required verification.
37. Verification Incidents
Security/privacy incidents involving verification information must be handled under the organization’s incident-management process.
Examples include:
- Unauthorized access
- Accidental disclosure
- Lost records
- Incorrect verification result
- Compromised verification provider
- Unauthorized transmission
- Data breach
38. Compliance Monitoring
Periodically verify:
☐ Required checks are completed
☐ Verification records are complete
☐ Exceptions are approved
☐ Sensitive records are protected
☐ Retention requirements are followed
☐ Verification providers comply with requirements
☐ High-risk personnel receive required verification
☐ Access is not granted contrary to defined requirements
39. Metrics
Useful metrics include:
| Metric | Result |
|---|---|
| Personnel requiring verification | |
| Verification completed | |
| Verification pending | |
| Verification overdue | |
| Discrepancies identified | |
| Discrepancies unresolved | |
| Exceptions | |
| High-risk roles verified | |
| Average completion time | |
| Provider issues |
Metrics should support process improvement rather than unnecessary collection of personal information.
40. Background Verification Register
Maintain an appropriate register.
| Verification ID | Personnel ID | Role | Risk | Verification Level | Status | Date | Reviewer |
|---|---|---|---|---|---|---|---|
The register should avoid storing unnecessary sensitive details.
41. Findings
If the review identifies weaknesses:
| Finding ID | Area | Finding | Risk | Action | Owner | Due Date | Status |
|---|---|---|---|---|---|---|---|
Examples:
- Verification not completed before privileged access
- Required authorization missing
- Verification evidence incomplete
- Sensitive records accessible to unauthorized personnel
- Expired verification provider arrangement
- Required re-verification not performed
42. Corrective Action
For significant findings:
☐ Root cause identified
☐ Immediate correction performed
☐ Corrective action defined
☐ Owner assigned
☐ Due date assigned
☐ Evidence required
☐ Effectiveness verification defined
☐ Residual risk assessed
Corrective Action
43. Risk Assessment
Where verification gaps create information-security risk, assess:
Threat → Vulnerability → Exposure → Impact → Risk → Treatment
Example:
A privileged administrator has not completed required background verification → organizational verification requirement is incomplete → privileged access creates increased personnel-related risk → risk assessed according to the organization’s methodology → temporary access restriction or additional verification may be applied.
44. Management Approval
Where required:
HR Owner: ______________________
Hiring Manager: ______________________
Information Security: ______________________
Legal/Privacy: ______________________
Risk Owner: ______________________
Approver: ______________________
Date: ______________________
45. Review Frequency
Review this procedure:
- At planned intervals
- Following legal or regulatory changes
- Following significant security incidents
- Following material changes to employment practices
- Following changes to verification providers
- Following significant audit findings
- When new categories of personnel or roles are introduced
Next Review Date
46. AWS SaaS Startup Example
Consider an AWS-based SaaS startup.
Employee A — Marketing
Access:
- Marketing SaaS applications
- Public website
- Internal collaboration tools
Risk: Low/Medium
Basic or standard verification may be appropriate according to organizational requirements.
Employee B — Software Developer
Access:
- Source code
- Development AWS environment
- CI/CD
Risk: Medium
Additional employment, education, qualification, or reference verification may be appropriate.
Employee C — Production Cloud Administrator
Access:
- AWS production
- IAM
- Security configurations
- Production infrastructure
Risk: High/Critical depending on the organization’s risk assessment.
Enhanced verification may be appropriate, together with:
- Strong authentication
- Privileged access controls
- Least privilege
- Logging
- Access review
- Approval
- Periodic reassessment
Audit Trail
Role Risk → Verification Requirement → Authorization → Verification → Review → Approval → Access → Monitoring
47. Startup-Friendly Background Verification Model
A startup can keep the process simple while maintaining appropriate control.
Low-Risk Personnel
Focus on:
- Identity
- Basic employment verification
- Role requirements
- Authorization
- Record
Medium-Risk Personnel
Add:
- Education/qualification verification where relevant
- References
- Additional employment verification
- Security-sensitive role assessment
High/Critical-Risk Personnel
Add, where lawful and relevant:
- Enhanced verification
- Additional professional checks
- Regulatory screening
- Additional approval
- Pre-access verification
- Periodic reassessment
The objective is not to perform the maximum number of checks. It is to perform the appropriate checks for the role and risk.
48. Common Mistakes
Avoid:
- Performing the same checks for every role without considering risk
- Performing checks without appropriate authorization
- Collecting unnecessary personal information
- Retaining complete sensitive reports indefinitely
- Granting privileged access before required verification is complete
- Treating a verification report as automatically accurate
- Ignoring discrepancies
- Failing to document decisions
- Using unapproved verification providers
- Ignoring privacy requirements
- Failing to protect verification records
- Performing unlawful or irrelevant checks
- Failing to reassess requirements when a role changes
49. Relationship With Other ISMS Documents
| Document | Relationship |
|---|---|
| Employee Screening Policy | Defines overall screening requirements |
| Background Verification Procedure | Defines verification workflow |
| Employee Onboarding Procedure | Uses verification completion before onboarding/access |
| Employee Offboarding Procedure | Removes access when personnel leave |
| Access Management Procedure | Controls system access |
| Personnel Security Procedure | Defines personnel-security requirements |
| Security Awareness Procedure | Defines security training |
| Confidentiality/NDA | Protects organizational information |
| Supplier Security Requirements | Addresses third-party personnel |
| Incident Management Procedure | Handles verification-related incidents |
| Information Security Policy | Establishes overall security expectations |
| Risk Management Procedure | Assesses risks arising from verification gaps |
50. ISO/IEC 27001 Connection
Background verification supports the organization’s personnel-security controls and risk-management approach.
The organization should determine:
- Which personnel require verification
- What checks are appropriate
- When checks must be completed
- What evidence should be retained
- How sensitive information is protected
- How exceptions are managed
- Whether periodic re-verification is necessary
The Background Verification Procedure is not itself a universally prescribed ISO/IEC 27001 document. The specific process should be based on the organization’s ISMS scope, risk assessment, applicable controls, legal requirements, contractual requirements, customer expectations, and role sensitivity.
51. Audit Evidence Checklist
An auditor may request evidence such as:
☐ Background Verification Procedure
☐ Employee Screening Policy
☐ Role risk assessment
☐ Verification requirements
☐ Authorization/consent records where applicable
☐ Verification register
☐ Verification completion records
☐ Sample verification evidence
☐ Discrepancy records
☐ Exception records
☐ Approval records
☐ Verification provider assessment
☐ Privacy/retention requirements
☐ Access restrictions for verification records
☐ Corrective actions
☐ Periodic review evidence
Sensitive personal information should not be unnecessarily exposed during an audit.
52. Final Background Verification Audit Trail
For each applicable individual, the organization should be able to demonstrate:
Why is verification required?
What is the risk of the role?
What checks were required?
Was appropriate authorization obtained?
Who performed the verification?
What evidence was reviewed?
Were discrepancies identified?
How were discrepancies handled?
Who reviewed the result?
Was the engagement approved?
Was access restricted until required verification was complete?
How was verification information protected?
How long will the information be retained?
What happens when retention expires?
Final Principle
Background verification is not simply a background-check exercise. It is a risk-based personnel-security process that connects the role, verification requirements, authorization, evidence, decision, access, privacy protection, and ongoing personnel-security controls into a defensible audit trail.
