ISO/IEC 27001

⌘K
  1. Home
  2. Docs
  3. ISO/IEC 27001
  4. Other Doc
  5. Employee Screening Checklist

Employee Screening Checklist

1. Purpose

The Employee Screening Checklist provides a structured method for verifying that required employee screening has been appropriately planned, authorized, completed, reviewed, and documented.

The checklist supports a risk-based approach to personnel security and helps ensure that screening requirements are applied consistently according to the individual’s role, responsibilities, information exposure, and access.

Core Principle

Identify Role → Assess Risk → Define Screening → Authorize → Verify → Review → Decide → Record → Protect


2. When to Use

Use this checklist:

  • Before employment where screening is required
  • Before granting sensitive or privileged access
  • For contractors and temporary personnel where applicable
  • When personnel move to security-sensitive roles
  • During periodic re-verification where required
  • When contractual or regulatory requirements apply
  • When a material discrepancy requires additional verification

3. Employee Screening Information

FieldDetails
Screening ID
Employee/Personnel ID
Name
Position
Department
Employment Type
Hiring Manager
HR Owner
Role Risk
Screening Level
Screening Provider
Screening Start Date
Screening Completion Date
Reviewer
Status

4. Screening Status

☐ Not Started
☐ In Progress
☐ Pending Information
☐ Pending Verification
☐ Discrepancy Under Review
☐ Completed
☐ Completed With Conditions
☐ Exception Approved
☐ Closed

Comments


5. Role and Risk Assessment

Before screening, confirm:

☐ Job description reviewed
☐ Responsibilities identified
☐ Information accessed identified
☐ Systems accessed identified
☐ Privileged access identified
☐ Production access identified
☐ Customer information identified
☐ Personal data access identified
☐ Financial responsibility identified
☐ Regulatory responsibility identified
☐ Role risk assessed
☐ Screening level selected

Role Risk

☐ Low
☐ Medium
☐ High
☐ Critical


6. Screening Level

☐ Level 1 – Basic
☐ Level 2 – Standard
☐ Level 3 – Enhanced
☐ Level 4 – High Risk

Reason for Selected Level


7. Authorization and Privacy

Before starting screening:

☐ Screening requirement communicated
☐ Purpose explained
☐ Appropriate authorization/consent obtained where required
☐ Privacy information provided where applicable
☐ Scope of screening defined
☐ Applicable legal requirements considered
☐ Jurisdiction identified
☐ Verification provider authorized
☐ Data-handling requirements defined


8. Identity Verification

☐ Identity verification required
☐ Identity verified
☐ Identification source appropriate
☐ Name verified
☐ Identity information consistent
☐ Verification date recorded
☐ Result reviewed

Result

☐ Verified
☐ Partially Verified
☐ Unable to Verify
☐ Discrepancy


9. Address Verification

Where relevant:

☐ Address verification required
☐ Address verified
☐ Source appropriate
☐ Verification completed
☐ Discrepancy identified/reviewed

Address verification should only be performed where relevant and legally appropriate.


10. Employment Verification

☐ Employment verification required
☐ Previous employer information provided
☐ Employment dates verified
☐ Position verified
☐ Relevant responsibilities verified where appropriate
☐ Significant gaps reviewed
☐ Discrepancies documented
☐ Verification completed

Result


11. Education and Qualification Verification

Where relevant:

☐ Qualification requirement identified
☐ Institution verified
☐ Qualification verified
☐ Completion status verified
☐ Professional certification verified
☐ License/registration verified
☐ Expiry checked where applicable
☐ Discrepancies reviewed


12. Professional References

Where applicable:

☐ References required
☐ Reference identity verified
☐ Reference obtained from appropriate source
☐ Relevant employment relationship confirmed
☐ Response documented
☐ Material concern identified/reviewed
☐ Reference verification completed


13. Criminal Record Check

Where lawful and relevant:

☐ Check required
☐ Appropriate authorization obtained
☐ Appropriate source/provider used
☐ Check completed
☐ Result reviewed
☐ Potential match investigated
☐ Candidate clarification obtained where appropriate
☐ Decision documented

A criminal-record check should not be performed merely because it is available; it should be relevant, proportionate, and legally permissible.


14. Financial Check

Where lawful and relevant to the role:

☐ Financial check required
☐ Legal requirements considered
☐ Authorization obtained
☐ Check completed
☐ Result reviewed
☐ Material issue assessed
☐ Decision documented

Financial checks should generally be limited to roles where financial responsibility or applicable requirements make them relevant.


15. Sanctions and Regulatory Screening

Where applicable:

☐ Sanctions screening required
☐ Regulatory screening required
☐ Professional registration checked
☐ License verified
☐ Screening completed
☐ Potential match reviewed
☐ False positive resolved
☐ Result recorded


16. Conflict-of-Interest Check

Where relevant:

☐ Conflict-of-interest declaration required
☐ Declaration completed
☐ Potential conflict identified
☐ Conflict reviewed
☐ Mitigation defined
☐ Approval obtained
☐ Review date established


17. Right-to-Work Verification

Where applicable:

☐ Right-to-work requirement identified
☐ Required evidence verified
☐ Verification completed
☐ Expiry date recorded where applicable
☐ Follow-up requirement established


18. Security-Sensitive Role Review

For security-sensitive positions:

☐ Role classified as security-sensitive
☐ Security responsibilities identified
☐ Privileged access identified
☐ Production access identified
☐ Restricted information identified
☐ Enhanced screening requirements reviewed
☐ Security approval obtained where required


19. Privileged Access Screening

If the employee will receive privileged access:

☐ Privileged access requirement documented
☐ Business justification documented
☐ Required screening completed
☐ Identity verified
☐ Relevant employment verification completed
☐ Relevant qualification verification completed
☐ Additional checks completed where required
☐ Security review completed
☐ Management approval obtained
☐ Access restrictions defined


20. Production Access Screening

If production access is required:

☐ Production access identified
☐ Role risk assessed
☐ Screening requirement reviewed
☐ Required verification completed
☐ Security approval obtained
☐ Access scope defined
☐ MFA required
☐ Privileged access controls established
☐ Access review scheduled


21. AWS / Cloud Administrator Screening

For cloud administrators:

☐ Cloud administration responsibility identified
☐ AWS/Azure/GCP access identified
☐ Production access identified
☐ IAM administration identified
☐ Privileged access identified
☐ Enhanced screening assessed
☐ Required verification completed
☐ Security approval obtained
☐ Access restrictions defined


22. Developer Screening

For developers:

☐ Source-code access identified
☐ Repository access identified
☐ CI/CD access identified
☐ Development environment identified
☐ Production access identified
☐ Screening level assessed
☐ Employment verification completed
☐ Qualification verification completed where relevant
☐ References completed where required
☐ Privileged access separately assessed


23. Finance Employee Screening

For finance personnel:

☐ Financial responsibilities identified
☐ Payment authority identified
☐ Financial-system access identified
☐ Sensitive information identified
☐ Role risk assessed
☐ Qualification verification completed where relevant
☐ Employment verification completed
☐ References completed where required
☐ Financial screening assessed where lawful/relevant
☐ Conflict-of-interest review completed


24. HR Employee Screening

For HR personnel:

☐ Employee-data access identified
☐ Sensitive personal data identified
☐ HR systems access identified
☐ Role risk assessed
☐ Employment verification completed
☐ Qualification verification completed where relevant
☐ References completed where required
☐ Confidentiality requirements established
☐ Access restrictions defined


25. Contractor Screening

For contractors:

☐ Contractor status identified
☐ Contracting organization identified
☐ Screening responsibility defined
☐ Required screening confirmed
☐ Verification completed
☐ NDA/confidentiality requirement completed
☐ Access scope defined
☐ Access expiry defined
☐ Supplier requirements reviewed where applicable


26. Third-Party Personnel Screening

Where personnel are supplied by a third party:

☐ Supplier screening requirement defined
☐ Contractual requirement established
☐ Supplier responsibility identified
☐ Screening evidence/attestation obtained where appropriate
☐ High-risk personnel separately assessed
☐ Access restricted until required verification is completed


27. Screening Evidence Review

For each completed check:

☐ Evidence received
☐ Evidence source identified
☐ Evidence date recorded
☐ Evidence relevant
☐ Evidence sufficiently reliable
☐ Result consistent with information provided
☐ Reviewer identified
☐ Review completed

Avoid storing unnecessary copies of sensitive personal documents.


28. Discrepancy Review

If a discrepancy is identified:

☐ Discrepancy recorded
☐ Source identified
☐ Materiality assessed
☐ Role relevance assessed
☐ Candidate/personnel explanation obtained where appropriate
☐ Additional verification performed where required
☐ Security impact assessed
☐ Legal/privacy considerations reviewed
☐ Decision documented

Discrepancy

Resolution


29. Screening Decision

Overall Result

☐ Satisfactory
☐ Satisfactory With Conditions
☐ Further Verification Required
☐ Discrepancy Under Review
☐ Exception Required
☐ Unable to Complete

Decision Rationale


30. Access Before Screening Completion

If required screening is incomplete:

☐ Access withheld
☐ Access restricted
☐ Temporary access approved
☐ Business justification documented
☐ Risk assessed
☐ Compensating controls established
☐ Expiry date established
☐ Approval obtained
☐ Completion tracked


31. Screening Exception

If an exception is required:

FieldDetails
Exception ID
Missing Check
Reason
Risk
Compensating Control
Approver
Expiry Date
Status

Exceptions should be time-bound and reviewed before expiry.


32. Screening Completion

Before marking screening complete:

☐ Required checks completed
☐ Results reviewed
☐ Discrepancies resolved or addressed
☐ Exceptions approved
☐ Screening decision documented
☐ Required approvals obtained
☐ Records protected
☐ Screening register updated
☐ Access decision communicated to relevant stakeholders


33. Onboarding Dependency

Before normal access is granted, confirm:

☐ Screening requirements satisfied
☐ Employment/engagement approved
☐ Confidentiality requirements completed
☐ Security responsibilities communicated
☐ Security awareness requirements identified
☐ Access request approved
☐ MFA configured where required
☐ Least privilege applied


34. Periodic Re-Screening

Where applicable:

☐ Re-screening requirement defined
☐ Re-screening frequency defined
☐ Role risk reviewed
☐ Regulatory requirements reviewed
☐ Contractual requirements reviewed
☐ Re-verification completed
☐ Results reviewed
☐ Records updated

Re-screening should be based on risk and applicable requirements rather than automatically collecting unnecessary information.


35. Role Change

When an employee changes role:

☐ New role reviewed
☐ New access identified
☐ Risk reassessed
☐ Screening level reassessed
☐ Additional screening identified
☐ Additional verification completed where required
☐ Existing screening reviewed
☐ Access reviewed
☐ Approval recorded


36. Privacy and Record Protection

Verify:

☐ Screening information classified appropriately
☐ Access restricted
☐ Records securely stored
☐ Transmission protected
☐ Sensitive information minimized
☐ Retention period defined
☐ Disposal requirement defined
☐ Unauthorized disclosure controls established


37. Screening Provider Review

If an external provider is used:

☐ Provider approved
☐ Provider security reviewed
☐ Confidentiality requirements established
☐ Privacy requirements reviewed
☐ Data-processing requirements addressed where applicable
☐ Subprocessors identified where relevant
☐ Data retention understood
☐ Secure transfer method established


38. Screening Register

Record the screening status without unnecessarily storing sensitive personal information.

Screening IDPersonnel IDRoleRiskLevelStatusCompletion DateReviewer

39. Findings

Record process weaknesses:

Finding IDAreaFindingRiskActionOwnerDue DateStatus

Typical findings include:

  • Screening not completed
  • Required authorization missing
  • Verification evidence incomplete
  • Privileged access granted before required screening
  • Expired professional qualification
  • Unresolved discrepancy
  • Inappropriate access to screening records
  • Screening exception expired

40. Corrective Action

For significant findings:

☐ Root cause identified
☐ Immediate correction performed
☐ Corrective action defined
☐ Owner assigned
☐ Due date assigned
☐ Evidence requirement defined
☐ Effectiveness verification defined
☐ Residual risk assessed
☐ Closure approved


41. Final Screening Review

Reviewer Confirmation

I confirm that the applicable screening requirements have been reviewed and that the available evidence supports the recorded screening result.

Reviewer: __________________________

Role: ______________________________

Date: ______________________________

Signature/Approval: __________________


42. Management Approval

Where required:

HR Owner: __________________________

Hiring Manager: _____________________

Information Security: ________________

Legal/Privacy: _______________________

Risk Owner: _________________________

Approver: ___________________________

Date: ______________________________


43. Review Frequency

This checklist should be reviewed when:

☐ Screening requirements change
☐ Role requirements change
☐ New regulations apply
☐ New customer requirements apply
☐ Security incidents identify personnel-related risks
☐ Audit findings identify weaknesses
☐ Verification provider changes
☐ The screening matrix is updated


44. AWS SaaS Startup Example

Consider a startup operating a SaaS platform on AWS.

Developer

Access:

  • GitHub
  • Development AWS
  • CI/CD

Checklist should confirm:

☐ Identity verified
☐ Employment verified
☐ Qualification verified where relevant
☐ References completed where required
☐ Source-code access identified
☐ CI/CD access identified
☐ Production access separately assessed

AWS Production Administrator

Access:

  • AWS production
  • IAM
  • Security configuration
  • Infrastructure

Additional checks may include:

☐ Enhanced role screening
☐ Employment verification
☐ Relevant qualifications
☐ Professional references
☐ Additional lawful checks where relevant
☐ Security approval
☐ Privileged access approval

Audit Trail

Role → Risk → Screening Level → Verification → Review → Approval → Access


45. Startup-Friendly Screening Model

Low Risk

Checklist focuses on:

  • Identity
  • Basic employment verification
  • Role assessment
  • Authorization
  • Record

Medium Risk

Add:

  • Education/qualification
  • Employment history
  • References
  • Access review
  • Security-sensitive assessment

High/Critical Risk

Add, where lawful and relevant:

  • Enhanced verification
  • Professional credentials
  • Regulatory checks
  • Additional approval
  • Privileged-access review
  • Periodic reassessment

The objective is to maintain appropriate screening without creating unnecessary administrative or privacy burden.


46. Common Mistakes

Avoid:

  • Treating every employee the same
  • Ignoring actual system access
  • Granting privileged access before required screening
  • Performing checks without appropriate authorization
  • Collecting excessive personal information
  • Retaining sensitive screening documents indefinitely
  • Ignoring discrepancies
  • Failing to document screening decisions
  • Using unapproved screening providers
  • Ignoring contractor and third-party personnel
  • Failing to reassess screening when roles change
  • Treating screening completion as proof that all personnel-security risks have been eliminated

47. Relationship With Other ISMS Documents

DocumentRelationship
Employee Screening PolicyDefines screening requirements
Background Verification ProcedureDefines verification workflow
Role-Based Screening MatrixDetermines screening level by role
Employee Onboarding ProcedureUses screening completion as an onboarding dependency
Employee Offboarding ProcedureControls personnel exit
Access Management ProcedureControls system access
Privileged Access ProcedureControls privileged access
Personnel Security ProcedureDefines personnel-security controls
Security Awareness ProcedureDefines security training
Risk AssessmentAssesses role and personnel risk
Exception RegisterRecords approved screening exceptions
Supplier Security RequirementsCovers third-party personnel

48. ISO/IEC 27001 Connection

Employee screening supports personnel-security risk management and the organization’s implementation of applicable information-security controls.

The organization should determine:

  • Which roles require screening
  • What checks are appropriate
  • When checks must be completed
  • How screening evidence is protected
  • How exceptions are managed
  • Whether re-screening is required
  • How screening connects with access management

The Employee Screening Checklist is not itself a universally prescribed ISO/IEC 27001 form. The organization’s screening requirements should be determined through its ISMS scope, risk assessment, applicable controls, legal requirements, contractual requirements, customer requirements, and role sensitivity.


49. Audit Evidence Checklist

Maintain appropriate evidence such as:

☐ Employee Screening Policy
☐ Background Verification Procedure
☐ Role-Based Screening Matrix
☐ Completed screening checklist
☐ Screening register
☐ Authorization/consent records where applicable
☐ Verification results
☐ Qualification verification
☐ Employment verification
☐ Reference verification
☐ Regulatory screening where applicable
☐ Discrepancy records
☐ Exception records
☐ Approval records
☐ Screening provider assessment
☐ Periodic review evidence
☐ Corrective action records

Sensitive personal information should be minimized and securely protected.


50. Final Employee Screening Audit Trail

For every applicable employee or personnel member, the organization should be able to demonstrate:

What is the person’s role?
What risk does the role present?
What screening level applies?
Which checks were required?
Was appropriate authorization obtained?
Were the checks completed?
What evidence supports the results?
Were discrepancies identified?
How were discrepancies addressed?
Who reviewed the results?
Who approved the outcome?
Was access restricted until required screening was complete?
How were screening records protected?
When will the screening requirement be reviewed again?

Final Principle

Employee screening is not simply a background-check form. It is a risk-based control connecting the employee’s role, access, information exposure, verification requirements, evidence, decision, privacy protection, and ongoing personnel-security responsibilities into one defensible audit trail.