ISO/IEC 27001

⌘K
  1. Home
  2. Docs
  3. ISO/IEC 27001
  4. Other Doc
  5. Employee Onboarding Checklist

Employee Onboarding Checklist

1. Purpose

The Employee Onboarding Checklist provides a structured process for securely onboarding new employees and ensuring that required employment, information-security, access, confidentiality, training, and asset-management activities are completed before the employee begins normal work.

The objective is to ensure that a new employee:

  • Is properly identified and authorized
  • Has completed required pre-employment checks
  • Understands security responsibilities
  • Receives only the access required for their role
  • Uses approved systems and devices
  • Completes required security training
  • Acknowledges applicable policies
  • Protects organizational and customer information
  • Has appropriate security controls from the start of employment
  • Has a complete and traceable onboarding record

Core Principle

Hire → Verify → Define Role → Communicate → Train → Approve → Provision → Validate → Record → Monitor


2. Scope

This checklist applies to:

  • Permanent employees
  • Temporary employees
  • Interns
  • Employees working remotely
  • Employees with privileged access
  • Employees with production access
  • Employees handling confidential or restricted information

Contractors and third-party personnel should be handled through the applicable contractor or supplier onboarding process.


3. Employee Onboarding Information

FieldDetails
Employee Name
Employee ID
Job Title
Department
Manager
Employment Type
Joining Date
Work Location
Remote/Office/Hybrid
HR Owner
IT Owner
Security Owner
Business Owner
Onboarding Completion Date

4. Pre-Onboarding Requirements

Complete applicable activities before the employee receives organizational access.

☐ Employment offer/contract completed

☐ Employment terms reviewed

☐ Confidentiality requirements established

☐ Information-security responsibilities defined

☐ Required background verification completed

☐ Right-to-work verification completed where applicable

☐ Role identified

☐ Reporting manager identified

☐ Department identified

☐ Role risk assessed

☐ Required access identified

☐ Sensitive information access identified

☐ Privileged access requirement identified

☐ Production access requirement identified

☐ Required equipment identified

☐ Required software identified


5. Role and Responsibility Definition

Document the employee’s role before provisioning access.

Role Information

Role: __________________________

Department: __________________________

Manager: __________________________

Business Function: __________________________

Primary Responsibilities: __________________________

Security Responsibilities

☐ Role-specific security responsibilities identified

☐ Information handled by the role identified

☐ Systems used by the role identified

☐ Security-sensitive responsibilities identified

☐ Regulatory/customer requirements identified where applicable


6. Role Risk Assessment

Assess whether the employee’s role presents elevated security risk.

Consider:

☐ Access to personal data

☐ Access to customer data

☐ Access to confidential information

☐ Access to restricted information

☐ Production access

☐ Privileged access

☐ AWS/cloud administration

☐ Database administration

☐ Source-code access

☐ CI/CD access

☐ Financial systems

☐ Security systems

☐ Critical business processes

Role Risk

☐ Low

☐ Medium

☐ High

☐ Critical

Rationale: __________________________


7. Background Verification

Where required:

☐ Identity verified

☐ Address verified where applicable

☐ Employment history verified

☐ Education/qualification verified where applicable

☐ References checked where applicable

☐ Criminal record check where lawful and relevant

☐ Financial check where lawful and relevant

☐ Regulatory/sanctions screening where applicable

☐ Security-sensitive role assessment completed

☐ Verification discrepancies reviewed

☐ Screening result recorded

☐ Screening exception approved where required

Sensitive screening information should be minimized and protected.


8. Employment and Security Documentation

Complete applicable documentation.

☐ Employment agreement

☐ Confidentiality/NDA agreement

☐ Information-security responsibilities

☐ Acceptable-use requirements

☐ Intellectual-property requirements

☐ Privacy/data-protection requirements

☐ Remote-working requirements

☐ AI/Generative AI requirements

☐ Customer-specific security requirements where applicable

☐ Role-specific security requirements


9. Security Policy Distribution

Provide the employee with applicable policies and procedures.

☐ Information Security Policy

☐ Acceptable Use Policy

☐ Access Control Policy

☐ Data Classification Policy

☐ Password/MFA requirements

☐ Incident Management Procedure

☐ Remote Working Policy

☐ Employee Security Responsibilities

☐ Privacy/Data Protection requirements

☐ AI/Generative AI Policy or requirements

☐ Business Continuity responsibilities

☐ Other applicable policies

Evidence

Policy Distribution Location: __________________________


10. Employee Security Acknowledgement

The employee should acknowledge applicable security requirements.

☐ Policies received

☐ Policies reviewed

☐ Security responsibilities reviewed

☐ Confidentiality requirements reviewed

☐ Incident reporting process reviewed

☐ Access responsibilities reviewed

☐ Employee acknowledgement completed

☐ Evidence retained

Acknowledgement Record

PolicyVersionDate IssuedDate AcknowledgedStatus

11. Security Awareness Training

Assign required security awareness training.

☐ General security awareness

☐ Phishing awareness

☐ Password and MFA security

☐ Information classification

☐ Data protection

☐ Incident reporting

☐ Remote working security

☐ Device security

☐ Social engineering

☐ AI security requirements

☐ Role-specific security training

Training Record

Training: __________________________

Completion Date: __________________________

Evidence: __________________________


12. Access Requirements

Identify all systems the employee requires.

SystemEnvironmentAccess RequiredPrivilegedApprovalExpiry

Access should be based on:

  • Business need
  • Role
  • Least privilege
  • Segregation of duties
  • Information sensitivity
  • Risk
  • Approved authorization

13. User Account Creation

Before creating accounts:

☐ Employee identity verified

☐ Employee ID assigned

☐ Manager confirmed

☐ Role confirmed

☐ Access approved

☐ Account owner identified

☐ Required systems identified

☐ Naming standard followed

☐ Individual account created

☐ Shared account avoided unless specifically justified


14. Authentication and MFA

☐ Initial password securely provided

☐ Password changed where applicable

☐ MFA enabled

☐ MFA enrollment verified

☐ Recovery methods configured securely

☐ Authentication requirements communicated

☐ Password manager provided where applicable

☐ Authentication evidence recorded


15. Email and Collaboration Access

☐ Corporate email created

☐ Email MFA enabled

☐ Collaboration platform access created

☐ Approved communication channels communicated

☐ External sharing restrictions communicated

☐ Email security requirements communicated


16. SaaS Application Access

Identify approved SaaS applications.

☐ HR system

☐ Ticketing system

☐ Collaboration platform

☐ Project management

☐ Source-code platform

☐ Documentation platform

☐ Security platform

☐ Finance system

☐ CRM

☐ Other: __________________________

For each application:

☐ Business need confirmed

☐ Manager approval obtained

☐ Appropriate role assigned

☐ MFA enabled where applicable

☐ Access recorded


17. Cloud Access

Where cloud access is required:

☐ Cloud account identified

☐ Business need documented

☐ IAM role identified

☐ Least privilege applied

☐ MFA enabled

☐ Privileged access separately controlled

☐ Production access separately approved

☐ Logging enabled where appropriate

☐ Access expiry defined where appropriate


18. AWS Access

For AWS environments:

☐ Individual AWS identity created

☐ SSO/federated access configured where applicable

☐ MFA enabled

☐ Appropriate IAM role assigned

☐ Least privilege reviewed

☐ Production access separately approved

☐ Administrative access separately approved

☐ AWS root account access not assigned for routine work

☐ Access logging enabled where applicable

☐ AWS access recorded


19. Privileged Access

If privileged access is required:

☐ Business justification documented

☐ Security approval obtained

☐ Named privileged account used

☐ MFA enabled

☐ Administrative permissions defined

☐ Production permissions defined

☐ Logging enabled

☐ Temporary access used where practical

☐ Access expiry defined where appropriate

☐ Privileged access review scheduled


20. Production Access

If production access is required:

☐ Business requirement documented

☐ Manager approval obtained

☐ System owner approval obtained

☐ Security requirements reviewed

☐ MFA enabled

☐ Least privilege applied

☐ Access limited to required systems

☐ Production activity logging enabled where appropriate

☐ Emergency access requirements communicated

☐ Access review date defined


21. Source-Code Access

For developers and technical personnel:

☐ Source-code repository identified

☐ Repository access approved

☐ Appropriate repository permissions assigned

☐ MFA enabled

☐ Branch protection requirements communicated

☐ Secrets protection requirements communicated

☐ Code-review requirements communicated

☐ Production deployment permissions separately controlled

☐ CI/CD permissions separately assessed


22. Database Access

Where applicable:

☐ Database identified

☐ Business need documented

☐ Access approved

☐ Appropriate role assigned

☐ Production database access separately approved

☐ Privileged access controlled

☐ Credentials securely managed

☐ Database activity logging enabled where appropriate


23. CI/CD Access

For engineering or DevOps roles:

☐ CI/CD platform identified

☐ Access approved

☐ Repository permissions reviewed

☐ Deployment permissions reviewed

☐ Production deployment permissions separately approved

☐ Secrets access restricted

☐ Administrative permissions restricted

☐ MFA enabled


24. Endpoint Assignment

If a company device is provided:

☐ Device assigned

☐ Asset ID recorded

☐ Device ownership recorded

☐ Device encryption enabled

☐ Endpoint protection enabled

☐ Security configuration applied

☐ Supported operating system confirmed

☐ Security updates enabled

☐ Device management enabled where applicable

☐ Screen-lock requirement configured


25. Company Asset Handover

AssetAsset IDConditionEmployee SignatureDate
Laptop
Mobile
Security Token
Other

The employee should be informed of their responsibility to protect company assets.


26. Remote Working Setup

For remote employees:

☐ Approved device provided

☐ Secure authentication configured

☐ MFA configured

☐ Secure connectivity configured where required

☐ Remote-working policy communicated

☐ Device security requirements communicated

☐ Information protection requirements communicated

☐ Public/shared environment risks explained

☐ Incident reporting requirements explained


27. Physical Access

Where applicable:

☐ Office access requested

☐ Access approved

☐ Access badge issued

☐ Physical access recorded

☐ Visitor requirements communicated

☐ Secure-area restrictions communicated

☐ Badge protection requirements communicated


28. Information Classification

The employee should understand applicable classifications.

☐ Public

☐ Internal

☐ Confidential

☐ Restricted

The employee should understand:

  • What information they can access
  • Where it may be stored
  • How it may be shared
  • How it should be protected
  • How it should be disposed of

29. Customer Information

Where the role involves customer information:

☐ Customer information identified

☐ Customer-specific requirements communicated

☐ Access restricted

☐ Data handling requirements communicated

☐ Information transfer requirements communicated

☐ Retention requirements communicated

☐ Incident reporting requirements communicated


30. Personal Data

Where personal data is handled:

☐ Personal data categories identified

☐ Authorized purpose communicated

☐ Access restricted

☐ Data minimization requirements communicated

☐ Secure handling communicated

☐ Data-sharing requirements communicated

☐ Incident/breach reporting communicated

☐ Retention/deletion requirements communicated


31. AI and Generative AI

Where AI tools are used:

☐ Approved AI tools identified

☐ Restricted information requirements communicated

☐ Customer-data restrictions communicated

☐ Personal-data restrictions communicated

☐ Source-code restrictions communicated

☐ AI output review requirements communicated

☐ Approved-use requirements acknowledged


32. Incident Reporting

The employee must know how to report:

☐ Security incidents

☐ Phishing

☐ Malware

☐ Lost/stolen device

☐ Credential compromise

☐ Unauthorized access

☐ Data leakage

☐ Suspicious activity

☐ Security weaknesses

Reporting Contact

Security Email: __________________________

Incident Portal: __________________________

Emergency Contact: __________________________


33. Vulnerability and Security Weakness Reporting

Employees should understand that suspected security weaknesses should be reported rather than independently exploited.

☐ Reporting channel provided

☐ Security contact provided

☐ Escalation process communicated

☐ Unauthorized security testing prohibited


34. Acceptable Use

Employee confirms understanding of acceptable use requirements.

☐ Approved business use

☐ Prohibited activities

☐ Unauthorized software

☐ Unauthorized cloud services

☐ Unauthorized data sharing

☐ Credential sharing

☐ Security-control bypass

☐ Unauthorized testing

☐ Misuse of organizational resources


35. Role-Specific Security Requirements

Developers

☐ Secure coding

☐ Source-code protection

☐ Secrets management

☐ Code review

☐ Secure deployment

DevOps / Cloud Administrators

☐ Privileged access

☐ AWS/cloud security

☐ Infrastructure changes

☐ Logging

☐ Emergency access

Finance

☐ Financial information protection

☐ Payment information

☐ Segregation of duties

☐ Fraud awareness

HR

☐ Employee personal data

☐ Confidentiality

☐ Privacy requirements

☐ Restricted access

Security Personnel

☐ Security monitoring

☐ Incident handling

☐ Security testing

☐ Evidence protection


36. Manager Confirmation

The manager confirms that:

☐ Employee role has been defined

☐ Business responsibilities are understood

☐ Required systems have been identified

☐ Access requirements are appropriate

☐ Privileged access requirements have been considered

☐ Sensitive information access has been considered

☐ Role-specific security requirements have been identified

Manager Name: __________________________

Signature/Electronic Approval: __________________________

Date: __________________________


37. IT Confirmation

IT confirms:

☐ Required accounts created

☐ MFA enabled

☐ Required access provisioned

☐ Device assigned

☐ Endpoint security configured

☐ SaaS access provisioned

☐ Cloud access configured where applicable

☐ Access recorded

☐ Security validation completed

IT Owner: __________________________

Date: __________________________


38. Security Confirmation

Information Security confirms where applicable:

☐ Security responsibilities communicated

☐ Required training assigned

☐ Privileged access reviewed

☐ Production access reviewed

☐ Sensitive information access reviewed

☐ Security exceptions identified

☐ Security requirements completed

Security Reviewer: __________________________

Date: __________________________


39. HR Confirmation

HR confirms:

☐ Employment documentation completed

☐ Screening completed where required

☐ Confidentiality requirements completed

☐ Required policy acknowledgement completed

☐ Employee records established

☐ Onboarding evidence retained

HR Owner: __________________________

Date: __________________________


40. Onboarding Exceptions

Document incomplete requirements.

RequirementReasonRiskCompensating ControlOwnerDue Date

Access should not be granted beyond approved requirements merely because onboarding activities are incomplete.


41. Onboarding Completion

Before marking onboarding complete:

☐ Employment requirements completed

☐ Screening requirements completed

☐ Security responsibilities communicated

☐ Required policies distributed

☐ Security acknowledgement completed

☐ Security training completed or assigned according to policy

☐ Access approved

☐ Accounts created

☐ MFA enabled

☐ Device secured

☐ Required SaaS access provisioned

☐ Cloud access secured where applicable

☐ Privileged access reviewed

☐ Production access reviewed

☐ Incident reporting communicated

☐ Asset handover completed

☐ Exceptions documented

☐ Evidence retained


42. Onboarding Approval

Employee: __________________________

Manager: __________________________

HR: __________________________

IT: __________________________

Security: __________________________

Onboarding Status:

☐ Complete

☐ Complete with Conditions

☐ Pending

☐ Exception Approved

Completion Date: __________________________


43. Post-Onboarding Review

Within an appropriate period after joining:

☐ Access still matches role

☐ Excess access identified

☐ Required training completed

☐ Security policies understood

☐ Device compliant

☐ Security issues identified

☐ Privileged access reviewed where applicable

☐ Production access reviewed where applicable

☐ Onboarding issues closed

Review Date



44. Joiner-Mover-Leaver Integration

Employee onboarding should connect with the organization’s Joiner-Mover-Leaver process.

Joiner

Hire → Verify → Approve → Provision → Train → Acknowledge → Monitor

Mover

Role Change → Reassess Access → Remove Old Access → Approve New Access → Update Responsibilities

Leaver

Notify → Disable → Revoke → Recover Assets → Return/Delete Information → Verify → Record


45. Onboarding Evidence

Maintain appropriate evidence such as:

  • Employment documentation
  • Screening completion
  • Confidentiality agreement
  • Policy acknowledgement
  • Training records
  • Access approvals
  • Account creation records
  • MFA enrollment
  • Device assignment
  • Asset acknowledgement
  • Privileged-access approval
  • Production-access approval
  • Manager confirmation
  • HR confirmation
  • IT confirmation
  • Security confirmation
  • Exception records
  • Completion record

Evidence should be protected from unauthorized access and modification.


46. Onboarding Register

EmployeeRoleJoin DateScreeningTrainingAccessMFAAssetsAcknowledgementStatus

47. Onboarding Metrics

Management may monitor:

  • New employees onboarded
  • Onboarding completion rate
  • Delayed onboarding
  • Access provisioning time
  • MFA completion
  • Security training completion
  • Policy acknowledgement completion
  • Screening completion
  • Onboarding exceptions
  • Privileged-access onboarding
  • Production-access onboarding
  • Post-onboarding access findings

48. AWS SaaS Startup Example

An AWS-based SaaS startup hires a new DevOps engineer.

Before Joining

HR completes employment documentation and required screening.

The manager identifies that the role requires:

  • AWS access
  • GitHub/source-code access
  • CI/CD access
  • Production access
  • Monitoring access

Security Review

The security requirements identify:

  • MFA
  • Individual accounts
  • Least privilege
  • Temporary/limited production access where practical
  • Privileged-access controls
  • Logging
  • Secure credential management

Onboarding

The employee:

  1. Signs confidentiality requirements.
  2. Reviews security policies.
  3. Completes security awareness training.
  4. Acknowledges security responsibilities.
  5. Receives a managed company laptop.
  6. Enrolls in MFA.
  7. Receives approved AWS IAM/SSO access.
  8. Receives approved source-code access.
  9. Receives separately approved production access.
  10. Is informed of incident-reporting requirements.

Evidence

Employee → Role → Screening → Security Responsibilities → Training → Approval → Access → MFA → Asset → Acknowledgement → Validation → Record


49. Startup-Friendly Onboarding Model

A startup can keep onboarding lightweight while maintaining appropriate security.

Day 0 — Before Joining

  • Employment documentation
  • Screening where required
  • Role definition
  • Access requirements
  • Equipment preparation

Day 1

  • Security policies
  • Confidentiality
  • MFA
  • Device security
  • Account setup
  • Incident reporting

First Week

  • Security awareness training
  • Role-specific training
  • Access validation
  • Policy acknowledgement
  • Required SaaS/cloud access

First 30 Days

  • Review access
  • Review onboarding exceptions
  • Confirm training completion
  • Verify security requirements

For privileged or production roles, additional controls may be required before access is granted.


50. Common Mistakes

Avoid:

  • Creating accounts before verifying the employee.
  • Giving access based only on job title.
  • Giving broad access “for convenience.”
  • Delaying MFA.
  • Giving production access without separate justification.
  • Forgetting source-code or cloud access.
  • Treating onboarding as an HR-only process.
  • Failing to communicate incident-reporting requirements.
  • Failing to collect policy acknowledgement.
  • Giving employees access before required screening where the role requires completed screening.
  • Not recording asset handover.
  • Not reviewing access after onboarding.
  • Ignoring onboarding exceptions.
  • Creating shared accounts instead of individual accounts.
  • Treating completion of a checklist as proof that security controls are actually effective.

51. Relationship With Other ISMS Documents

DocumentRelationship
Human Resources Security PolicyDefines personnel-security requirements
Employee Screening PolicyDefines screening requirements
Background Verification ProcedurePerforms verification
Employment Security ClauseEstablishes contractual security obligations
Employee Security ResponsibilitiesDefines employee responsibilities
Employee Security AcknowledgementRecords acknowledgement
Security Awareness ProcedureDefines security training
Access Management ProcedureControls access provisioning
Joiner-Mover-Leaver ProcedureManages lifecycle access
Asset Management ProcedureManages assigned assets
Employee Offboarding ProcedureControls employee exit
Confidentiality AgreementProtects confidential information

52. ISO/IEC 27001 Connection

Employee onboarding supports the organization’s management of personnel security, information-security responsibilities, access control, awareness, and protection of information.

However, an Employee Onboarding Checklist is not itself a universally prescribed ISO/IEC 27001 document or form.

The organization should determine onboarding activities based on:

  • ISMS scope
  • Information-security risks
  • Employee role
  • Information accessed
  • System access
  • Privileged access
  • Applicable controls
  • Legal and regulatory requirements
  • Customer and contractual requirements

The organization should retain sufficient evidence to demonstrate that required onboarding activities were completed.


53. Audit Evidence Checklist

☐ Employee identification

☐ Employment documentation

☐ Role definition

☐ Role-risk assessment

☐ Background verification evidence/status

☐ Confidentiality agreement

☐ Security responsibilities

☐ Policy distribution

☐ Policy acknowledgement

☐ Security training

☐ Access approval

☐ Account creation

☐ MFA evidence

☐ Privileged-access approval

☐ Production-access approval

☐ Device assignment

☐ Asset acknowledgement

☐ Cloud access approval

☐ Source-code access approval

☐ Manager confirmation

☐ HR confirmation

☐ IT confirmation

☐ Security confirmation

☐ Exceptions

☐ Post-onboarding review

☐ Final completion record


54. Final Employee Onboarding Audit Trail

For every employee, the organization should be able to demonstrate:

Who is the employee?
What role were they hired for?
What information will they access?
What systems will they access?
What security risk does the role present?
Were required screening checks completed?
What security responsibilities were communicated?
Which policies were provided?
Was security training completed?
What access was requested?
Who approved the access?
Was MFA enabled?
Was privileged or production access separately controlled?
What assets were assigned?
Did the employee acknowledge applicable requirements?
Were exceptions documented?
Was onboarding independently validated where appropriate?

Final Principle

Secure onboarding starts before the employee receives access.

A strong onboarding process connects HR verification, role definition, security responsibilities, training, confidentiality, access authorization, MFA, asset management, and evidence into one controlled lifecycle.