ISO/IEC 27001

⌘K
  1. Home
  2. Docs
  3. ISO/IEC 27001
  4. Other Doc
  5. Screening Exception Form

Screening Exception Form

1. Purpose

The Screening Exception Form is used when an approved personnel screening requirement cannot be completed, cannot be completed within the required timeframe, or requires a temporary deviation from the organization’s established screening requirements.

The form ensures that the exception is:

  • Clearly documented
  • Business justified
  • Risk assessed
  • Time-bound
  • Approved by an appropriate authority
  • Supported by compensating controls where necessary
  • Monitored until resolved
  • Formally closed

Core Principle

Identify Exception → Justify → Assess Risk → Define Controls → Approve → Monitor → Resolve → Close


2. Important Principle

A screening exception should not automatically mean that the screening requirement is cancelled.

The organization should determine whether:

  • The screening can be completed later
  • An alternative verification method is available
  • Access should be restricted temporarily
  • Compensating controls are required
  • The requirement can legally be deferred
  • The residual risk can be accepted

Exceptions should normally have a defined expiry or review date.


3. Exception Information

FieldDetails
Exception ID
Date Raised
Personnel ID
Personnel Name/Reference
Employee / Contractor
Role
Department
Hiring/Business Owner
Screening Level
Exception Status
Requested Start Date
Exception Expiry Date
Reviewer

Status

☐ Draft
☐ Under Review
☐ Approved
☐ Approved With Conditions
☐ Rejected
☐ Expired
☐ Resolved
☐ Closed


4. Personnel and Role Information

Role: ______________________________

Employment Type:

☐ Employee
☐ Contractor
☐ Consultant
☐ Intern
☐ Temporary Worker
☐ Third-Party Personnel
☐ Other: __________________

Business Owner: ____________________

Manager: ___________________________

Engagement Start Date: ______________

Expected End Date: __________________


5. Role Risk Assessment

Role Risk

☐ Low
☐ Medium
☐ High
☐ Critical

Consider:

☐ Confidential information
☐ Restricted information
☐ Personal data
☐ Customer data
☐ Financial information
☐ Source code
☐ Production access
☐ Cloud access
☐ Privileged access
☐ Security administration
☐ Regulatory responsibility
☐ Critical business process

Risk Rationale


6. Screening Requirement

Identify the screening requirement that cannot currently be completed.

Required Screening Level

☐ Level 1 – Basic
☐ Level 2 – Standard
☐ Level 3 – Enhanced
☐ Level 4 – High Risk

Required Check

☐ Identity verification
☐ Address verification
☐ Employment verification
☐ Education/qualification verification
☐ Professional reference
☐ Professional certification/license
☐ Criminal-record check where lawful/relevant
☐ Financial check where lawful/relevant
☐ Sanctions/regulatory screening
☐ Right-to-work verification
☐ Conflict-of-interest declaration
☐ Other: ______________________________


7. Exception Description

Describe exactly what requirement cannot be completed.

Exception

Requirement That Cannot Be Met

Current Status


8. Reason for Exception

Select the applicable reason:

☐ Verification provider delay
☐ Information unavailable
☐ Third-party dependency
☐ Candidate/contractor documentation unavailable
☐ Jurisdictional limitation
☐ Legal restriction
☐ Technical issue
☐ Business urgency
☐ Emergency engagement
☐ International verification delay
☐ Role changed unexpectedly
☐ Other: ______________________________

Detailed Business Justification


9. Why Normal Screening Cannot Be Completed

Explain why the normal screening process cannot be followed.

Expected Resolution


10. Alternative Verification

Determine whether an alternative method can reduce the exception.

☐ Alternative identity verification
☐ Alternative employment verification
☐ Professional reference
☐ Certification verification
☐ Supplier attestation
☐ Previous screening evidence
☐ Additional management verification
☐ Other independent evidence
☐ No alternative available

Alternative Verification Performed

Result


11. Business Impact

If the screening requirement is not completed, assess the business impact.

Potential impacts:

☐ Hiring delay
☐ Project delay
☐ Customer commitment affected
☐ Critical skill unavailable
☐ Business continuity impact
☐ Security operations impact
☐ Production support impact
☐ Regulatory impact
☐ Other: ______________________________

Business Impact Assessment


12. Security Risk Assessment

Assess the security risk created by the exception.

Threat

Vulnerability

Exposure

Potential Impact

Risk


13. Risk Rating

Use the organization’s approved risk methodology.

Risk FactorRating
Likelihood
Impact
Inherent Risk
Existing Controls
Residual Risk

Residual Risk

☐ Low
☐ Medium
☐ High
☐ Critical

Risk Rationale


14. Access Impact

Determine whether the exception affects system or information access.

☐ No system access
☐ Internal application access
☐ Confidential information access
☐ Restricted information access
☐ Customer-data access
☐ Source-code access
☐ Cloud access
☐ Production access
☐ Privileged access
☐ Security administration access

Access Impact


15. Temporary Access Restrictions

Where appropriate, apply temporary restrictions.

☐ No privileged access
☐ No production access
☐ No customer-data access
☐ No restricted-information access
☐ Development access only
☐ Read-only access
☐ Limited application access
☐ Temporary account
☐ Time-limited access
☐ Additional approval required
☐ Enhanced monitoring

Access Restrictions


16. Compensating Controls

Identify controls that reduce the risk while the exception remains open.

Possible controls:

☐ Limited access
☐ Least privilege
☐ MFA
☐ Temporary account
☐ Expiring access
☐ Enhanced logging
☐ Additional management review
☐ Additional supervision
☐ Restricted production access
☐ Dual approval
☐ Additional reference verification
☐ Additional identity verification
☐ Increased access review frequency
☐ Additional security monitoring

Compensating Controls

ControlOwnerStart DateReview DateStatus

17. Control Effectiveness

Assess whether the compensating controls adequately reduce the risk.

☐ Effective
☐ Partially Effective
☐ Not Effective
☐ Requires Additional Control

Assessment


18. Exception Duration

Exception Start Date: __________________

Exception Expiry Date: _________________

Expected Screening Completion Date: ______

Maximum Duration

Exceptions should not remain open indefinitely without formal review.


19. Remediation Plan

Define the action required to resolve the exception.

ActionOwnerTarget DateEvidence RequiredStatus

Completion Criteria

The exception may be closed when:

☐ Required screening completed
☐ Evidence reviewed
☐ Discrepancy resolved
☐ Temporary controls removed or updated
☐ Access restrictions reviewed
☐ Residual risk reassessed
☐ Closure approved


20. Screening Completion Tracking

RequirementStatusExpected DateActual DateEvidence

21. Legal and Privacy Review

Where applicable:

☐ Legal requirements reviewed
☐ Privacy requirements reviewed
☐ Screening limitation is legally permissible
☐ Alternative verification considered
☐ Personal-data handling reviewed
☐ International transfer requirements reviewed
☐ Regulatory requirements considered


22. Customer and Contractual Requirements

Determine whether the exception affects:

☐ Customer contract
☐ Security questionnaire commitment
☐ Data-processing requirement
☐ Regulatory commitment
☐ Supplier requirement
☐ Customer personnel-screening requirement
☐ Other contractual obligation

Impact


23. Third-Party Contractor Exception

If the exception applies to contractor or supplier personnel:

Supplier: ____________________________

Contract/Agreement: __________________

Supplier Screening Responsibility: _____

☐ Supplier notified
☐ Supplier approval obtained where required
☐ Supplier attestation obtained
☐ Contractual requirement reviewed
☐ Replacement personnel considered
☐ Access restrictions applied

Supplier Comments


24. Emergency Screening Exception

Emergency exceptions may be required when immediate personnel engagement is necessary.

Examples:

  • Critical incident
  • Business continuity event
  • Urgent production recovery
  • Critical skill requirement
  • Immediate security response

Before approving emergency access:

☐ Business emergency confirmed
☐ Risk assessed
☐ Minimum access defined
☐ MFA enabled
☐ Temporary access established
☐ Monitoring enabled
☐ Approval obtained
☐ Screening completion deadline established

Emergency Justification


25. Approval

Business Owner

Name: ______________________________

Role: _______________________________

Decision:

☐ Approve
☐ Approve With Conditions
☐ Reject

Comments:

Signature/Approval: __________________

Date: ______________________________


26. Information Security Approval

Required where the exception affects information-security risk or privileged access.

Reviewer: ___________________________

Risk Assessment Reviewed: ☐ Yes ☐ No

Compensating Controls Reviewed: ☐ Yes ☐ No

Decision:

☐ Approve
☐ Approve With Conditions
☐ Reject

Comments

Approval: ___________________________

Date: ______________________________


27. HR / People Approval

Reviewer: ___________________________

☐ Screening requirement reviewed
☐ Exception justified
☐ Verification plan established
☐ Retention/privacy requirements considered

Decision

☐ Approve
☐ Approve With Conditions
☐ Reject

Comments:


28. Legal / Privacy Approval

Required where the exception involves legal, privacy, regulatory, or jurisdictional restrictions.

Reviewer: ___________________________

☐ Legal implications reviewed
☐ Privacy implications reviewed
☐ Alternative process considered
☐ Exception is appropriately documented

Decision

☐ Approve
☐ Approve With Conditions
☐ Reject
☐ Not Required

Comments:


29. Risk Acceptance

Where residual risk exceeds the organization’s normal tolerance:

Risk Owner: _________________________

Residual Risk: _______________________

Risk Treatment:

☐ Reduce
☐ Avoid
☐ Share/Transfer
☐ Accept

Risk Acceptance Statement

Risk Owner Approval: ________________

Date: ______________________________


30. Exception Monitoring

While the exception remains open:

☐ Screening progress monitored
☐ Compensating controls monitored
☐ Access monitored
☐ Expiry date monitored
☐ Risk reassessed where necessary
☐ Status reported to owner
☐ Escalation triggered if overdue

Monitoring Frequency

☐ Weekly
☐ Monthly
☐ Quarterly
☐ Other: __________________


31. Exception Review

Review the exception when:

☐ Screening status changes
☐ Risk changes
☐ Role changes
☐ Access changes
☐ Compensating control fails
☐ Security incident occurs
☐ Contract changes
☐ Regulatory requirements change
☐ Exception approaches expiry

Review Record

Review DateReviewerRiskStatusAction

32. Exception Extension

Extensions should not occur automatically.

If an extension is required:

Original Expiry Date: __________________

New Expiry Date: ______________________

Reason for Extension:

Updated Risk Assessment: ☐ Completed

Updated Controls: ☐ Required ☐ Not Required

Approval: _____________________________


33. Exception Closure

The exception may be closed when the underlying screening requirement has been resolved or otherwise formally addressed.

☐ Required screening completed
☐ Verification evidence reviewed
☐ Outstanding discrepancy resolved
☐ Risk reassessed
☐ Compensating controls reviewed
☐ Temporary access restrictions reviewed
☐ Exception no longer required
☐ Register updated
☐ Closure approved

Closure Date

Closure Comments


34. Closure Approval

HR/People Owner: _____________________

Information Security: _________________

Risk Owner: __________________________

Business Owner: ______________________

Closure Date: _________________________


35. Expired Exception

If the exception reaches its expiry date without resolution:

☐ Escalate to owner
☐ Restrict applicable access
☐ Suspend access where appropriate
☐ Reassess risk
☐ Extend with approval
☐ Complete screening
☐ Convert to formal risk treatment/acceptance where appropriate

An expired exception should not simply remain open without review.


36. Screening Exception Register

Maintain a central register.

Exception IDPersonnelRoleRiskRequirementStartExpiryOwnerStatus

37. Exception Metrics

Useful management metrics include:

MetricResult
Open screening exceptions
High-risk exceptions
Critical exceptions
Expired exceptions
Exceptions nearing expiry
Average exception duration
Exceptions by reason
Exceptions by department
Exceptions by employee/contractor type
Exceptions with access restrictions
Exceptions overdue for review
Exceptions successfully closed

38. Exception Trend Analysis

Review trends such as:

  • Repeated verification-provider delays
  • Frequent documentation gaps
  • Recurring exceptions for the same role
  • Excessive screening delays
  • Repeated access-before-screening requests
  • Contractor screening weaknesses
  • Jurisdiction-specific challenges

Recurring exceptions may indicate that the underlying screening process requires improvement.


39. Findings and Corrective Action

If exception analysis identifies a systemic weakness:

☐ Finding raised
☐ Root cause assessed
☐ Corrective action defined
☐ Process owner assigned
☐ Target date established
☐ Effectiveness review defined
☐ Management escalation completed where necessary


40. AWS SaaS Startup Example

A SaaS startup urgently needs an experienced AWS engineer to support a production incident.

The organization’s normal process requires enhanced screening before production administrative access.

Exception

The engineer’s employment and identity verification can be completed immediately, but one additional verification check is delayed because the external provider requires additional time.

Temporary Controls

☐ Identity verified
☐ Employment verified
☐ NDA completed
☐ AWS named account created
☐ MFA enabled
☐ Temporary privileged access
☐ Access limited to incident scope
☐ Session/activity logging enabled
☐ Access expiry defined
☐ Security owner assigned
☐ Outstanding verification tracked

Exception

Enhanced screening is temporarily incomplete due to verification-provider delay.

Risk Treatment

Restrict access to the minimum production resources required for incident recovery and require security-owner approval for privileged actions.

Closure

The exception is closed once the outstanding verification is completed, evidence is reviewed, and residual risk is reassessed.

Audit Trail

Emergency Need → Screening Gap → Risk Assessment → Temporary Controls → Approval → Limited Access → Verification Completion → Risk Reassessment → Closure


41. Startup-Friendly Exception Model

A startup can use a simple four-step process:

1. Identify

What screening requirement cannot be completed?

2. Assess

What risk does the delay create?

3. Control

Can access or responsibilities be restricted until screening is completed?

4. Approve and Track

Obtain the appropriate approval, define an expiry date, and track the exception to closure.

This prevents exceptions from becoming informal workarounds.


42. Common Mistakes

Avoid:

  • Treating an exception as permanent permission
  • Approving exceptions without risk assessment
  • Allowing unlimited privileged access during an exception
  • Failing to define an expiry date
  • Not assigning an owner
  • Not tracking outstanding screening
  • Repeatedly extending exceptions without addressing the root cause
  • Failing to document compensating controls
  • Ignoring privacy/legal requirements
  • Allowing expired exceptions to remain active
  • Using exceptions to bypass mandatory legal or regulatory requirements
  • Treating screening exceptions as routine administrative approvals

43. Relationship With Other ISMS Documents

DocumentRelationship
Employee Screening PolicyDefines screening requirements
Background Verification ProcedureDefines verification activities
Role-Based Screening MatrixDetermines screening level
Employee Screening ChecklistRecords completion of screening
Contractor Screening ProcedureDefines contractor screening
Access Management ProcedureControls access during exceptions
Privileged Access ProcedureControls privileged access
Risk Management ProcedureAssesses exception risk
Information Security Exception RegisterRecords the exception
Employee Onboarding ProcedureControls onboarding dependencies
Supplier Security RequirementsAddresses supplier personnel
Incident Management ProcedureHandles security incidents

44. ISO/IEC 27001 Connection

A screening exception process supports risk-based management of personnel-security requirements.

The organization should ensure that exceptions are:

  • Identified
  • Justified
  • Risk assessed
  • Appropriately controlled
  • Approved by authorized personnel
  • Time-bound
  • Monitored
  • Reviewed
  • Resolved or formally risk-accepted

The Screening Exception Form is not itself a universally prescribed ISO/IEC 27001 document. The organization’s exception process should be aligned with its ISMS risk methodology, applicable controls, legal requirements, contractual requirements, and personnel-security requirements.

An internal screening exception should not be treated as authorization to disregard a mandatory legal or regulatory requirement.


45. Audit Evidence Checklist

Maintain appropriate evidence such as:

☐ Completed Screening Exception Form
☐ Screening requirement
☐ Role risk assessment
☐ Business justification
☐ Alternative verification assessment
☐ Risk assessment
☐ Compensating controls
☐ Access restrictions
☐ Approval records
☐ Risk acceptance where applicable
☐ Screening completion evidence
☐ Exception monitoring records
☐ Extension approvals
☐ Closure evidence
☐ Exception Register
☐ Corrective actions

Sensitive personal information should be minimized and protected.


46. Final Screening Exception Audit Trail

For every screening exception, the organization should be able to demonstrate:

What screening requirement could not be completed?
Why could it not be completed?
Why is the exception necessary?
What risk does the exception create?
What alternative verification was considered?
What compensating controls were implemented?
Who approved the exception?
When does the exception expire?
How is the exception monitored?
What happens if it is not resolved by the expiry date?
Was the required screening eventually completed?
Was residual risk reassessed?
Who approved closure?

Final Principle

A screening exception is a controlled, temporary deviation—not a permanent bypass of personnel-security requirements. Every exception should have a documented reason, risk assessment, appropriate controls, accountable owner, expiry/review date, and clear path to resolution or formal risk acceptance.