1. Purpose
The Employee Onboarding Checklist provides a structured process for securely onboarding new employees and ensuring that required employment, information-security, access, confidentiality, training, and asset-management activities are completed before the employee begins normal work.
The objective is to ensure that a new employee:
- Is properly identified and authorized
- Has completed required pre-employment checks
- Understands security responsibilities
- Receives only the access required for their role
- Uses approved systems and devices
- Completes required security training
- Acknowledges applicable policies
- Protects organizational and customer information
- Has appropriate security controls from the start of employment
- Has a complete and traceable onboarding record
Core Principle
Hire → Verify → Define Role → Communicate → Train → Approve → Provision → Validate → Record → Monitor
2. Scope
This checklist applies to:
- Permanent employees
- Temporary employees
- Interns
- Employees working remotely
- Employees with privileged access
- Employees with production access
- Employees handling confidential or restricted information
Contractors and third-party personnel should be handled through the applicable contractor or supplier onboarding process.
3. Employee Onboarding Information
| Field | Details |
|---|---|
| Employee Name | |
| Employee ID | |
| Job Title | |
| Department | |
| Manager | |
| Employment Type | |
| Joining Date | |
| Work Location | |
| Remote/Office/Hybrid | |
| HR Owner | |
| IT Owner | |
| Security Owner | |
| Business Owner | |
| Onboarding Completion Date |
4. Pre-Onboarding Requirements
Complete applicable activities before the employee receives organizational access.
☐ Employment offer/contract completed
☐ Employment terms reviewed
☐ Confidentiality requirements established
☐ Information-security responsibilities defined
☐ Required background verification completed
☐ Right-to-work verification completed where applicable
☐ Role identified
☐ Reporting manager identified
☐ Department identified
☐ Role risk assessed
☐ Required access identified
☐ Sensitive information access identified
☐ Privileged access requirement identified
☐ Production access requirement identified
☐ Required equipment identified
☐ Required software identified
5. Role and Responsibility Definition
Document the employee’s role before provisioning access.
Role Information
Role: __________________________
Department: __________________________
Manager: __________________________
Business Function: __________________________
Primary Responsibilities: __________________________
Security Responsibilities
☐ Role-specific security responsibilities identified
☐ Information handled by the role identified
☐ Systems used by the role identified
☐ Security-sensitive responsibilities identified
☐ Regulatory/customer requirements identified where applicable
6. Role Risk Assessment
Assess whether the employee’s role presents elevated security risk.
Consider:
☐ Access to personal data
☐ Access to customer data
☐ Access to confidential information
☐ Access to restricted information
☐ Production access
☐ Privileged access
☐ AWS/cloud administration
☐ Database administration
☐ Source-code access
☐ CI/CD access
☐ Financial systems
☐ Security systems
☐ Critical business processes
Role Risk
☐ Low
☐ Medium
☐ High
☐ Critical
Rationale: __________________________
7. Background Verification
Where required:
☐ Identity verified
☐ Address verified where applicable
☐ Employment history verified
☐ Education/qualification verified where applicable
☐ References checked where applicable
☐ Criminal record check where lawful and relevant
☐ Financial check where lawful and relevant
☐ Regulatory/sanctions screening where applicable
☐ Security-sensitive role assessment completed
☐ Verification discrepancies reviewed
☐ Screening result recorded
☐ Screening exception approved where required
Sensitive screening information should be minimized and protected.
8. Employment and Security Documentation
Complete applicable documentation.
☐ Employment agreement
☐ Confidentiality/NDA agreement
☐ Information-security responsibilities
☐ Acceptable-use requirements
☐ Intellectual-property requirements
☐ Privacy/data-protection requirements
☐ Remote-working requirements
☐ AI/Generative AI requirements
☐ Customer-specific security requirements where applicable
☐ Role-specific security requirements
9. Security Policy Distribution
Provide the employee with applicable policies and procedures.
☐ Information Security Policy
☐ Acceptable Use Policy
☐ Access Control Policy
☐ Data Classification Policy
☐ Password/MFA requirements
☐ Incident Management Procedure
☐ Remote Working Policy
☐ Employee Security Responsibilities
☐ Privacy/Data Protection requirements
☐ AI/Generative AI Policy or requirements
☐ Business Continuity responsibilities
☐ Other applicable policies
Evidence
Policy Distribution Location: __________________________
10. Employee Security Acknowledgement
The employee should acknowledge applicable security requirements.
☐ Policies received
☐ Policies reviewed
☐ Security responsibilities reviewed
☐ Confidentiality requirements reviewed
☐ Incident reporting process reviewed
☐ Access responsibilities reviewed
☐ Employee acknowledgement completed
☐ Evidence retained
Acknowledgement Record
| Policy | Version | Date Issued | Date Acknowledged | Status |
|---|---|---|---|---|
11. Security Awareness Training
Assign required security awareness training.
☐ General security awareness
☐ Phishing awareness
☐ Password and MFA security
☐ Information classification
☐ Data protection
☐ Incident reporting
☐ Remote working security
☐ Device security
☐ Social engineering
☐ AI security requirements
☐ Role-specific security training
Training Record
Training: __________________________
Completion Date: __________________________
Evidence: __________________________
12. Access Requirements
Identify all systems the employee requires.
| System | Environment | Access Required | Privileged | Approval | Expiry |
|---|---|---|---|---|---|
Access should be based on:
- Business need
- Role
- Least privilege
- Segregation of duties
- Information sensitivity
- Risk
- Approved authorization
13. User Account Creation
Before creating accounts:
☐ Employee identity verified
☐ Employee ID assigned
☐ Manager confirmed
☐ Role confirmed
☐ Access approved
☐ Account owner identified
☐ Required systems identified
☐ Naming standard followed
☐ Individual account created
☐ Shared account avoided unless specifically justified
14. Authentication and MFA
☐ Initial password securely provided
☐ Password changed where applicable
☐ MFA enabled
☐ MFA enrollment verified
☐ Recovery methods configured securely
☐ Authentication requirements communicated
☐ Password manager provided where applicable
☐ Authentication evidence recorded
15. Email and Collaboration Access
☐ Corporate email created
☐ Email MFA enabled
☐ Collaboration platform access created
☐ Approved communication channels communicated
☐ External sharing restrictions communicated
☐ Email security requirements communicated
16. SaaS Application Access
Identify approved SaaS applications.
☐ HR system
☐ Ticketing system
☐ Collaboration platform
☐ Project management
☐ Source-code platform
☐ Documentation platform
☐ Security platform
☐ Finance system
☐ CRM
☐ Other: __________________________
For each application:
☐ Business need confirmed
☐ Manager approval obtained
☐ Appropriate role assigned
☐ MFA enabled where applicable
☐ Access recorded
17. Cloud Access
Where cloud access is required:
☐ Cloud account identified
☐ Business need documented
☐ IAM role identified
☐ Least privilege applied
☐ MFA enabled
☐ Privileged access separately controlled
☐ Production access separately approved
☐ Logging enabled where appropriate
☐ Access expiry defined where appropriate
18. AWS Access
For AWS environments:
☐ Individual AWS identity created
☐ SSO/federated access configured where applicable
☐ MFA enabled
☐ Appropriate IAM role assigned
☐ Least privilege reviewed
☐ Production access separately approved
☐ Administrative access separately approved
☐ AWS root account access not assigned for routine work
☐ Access logging enabled where applicable
☐ AWS access recorded
19. Privileged Access
If privileged access is required:
☐ Business justification documented
☐ Security approval obtained
☐ Named privileged account used
☐ MFA enabled
☐ Administrative permissions defined
☐ Production permissions defined
☐ Logging enabled
☐ Temporary access used where practical
☐ Access expiry defined where appropriate
☐ Privileged access review scheduled
20. Production Access
If production access is required:
☐ Business requirement documented
☐ Manager approval obtained
☐ System owner approval obtained
☐ Security requirements reviewed
☐ MFA enabled
☐ Least privilege applied
☐ Access limited to required systems
☐ Production activity logging enabled where appropriate
☐ Emergency access requirements communicated
☐ Access review date defined
21. Source-Code Access
For developers and technical personnel:
☐ Source-code repository identified
☐ Repository access approved
☐ Appropriate repository permissions assigned
☐ MFA enabled
☐ Branch protection requirements communicated
☐ Secrets protection requirements communicated
☐ Code-review requirements communicated
☐ Production deployment permissions separately controlled
☐ CI/CD permissions separately assessed
22. Database Access
Where applicable:
☐ Database identified
☐ Business need documented
☐ Access approved
☐ Appropriate role assigned
☐ Production database access separately approved
☐ Privileged access controlled
☐ Credentials securely managed
☐ Database activity logging enabled where appropriate
23. CI/CD Access
For engineering or DevOps roles:
☐ CI/CD platform identified
☐ Access approved
☐ Repository permissions reviewed
☐ Deployment permissions reviewed
☐ Production deployment permissions separately approved
☐ Secrets access restricted
☐ Administrative permissions restricted
☐ MFA enabled
24. Endpoint Assignment
If a company device is provided:
☐ Device assigned
☐ Asset ID recorded
☐ Device ownership recorded
☐ Device encryption enabled
☐ Endpoint protection enabled
☐ Security configuration applied
☐ Supported operating system confirmed
☐ Security updates enabled
☐ Device management enabled where applicable
☐ Screen-lock requirement configured
25. Company Asset Handover
| Asset | Asset ID | Condition | Employee Signature | Date |
|---|---|---|---|---|
| Laptop | ||||
| Mobile | ||||
| Security Token | ||||
| Other |
The employee should be informed of their responsibility to protect company assets.
26. Remote Working Setup
For remote employees:
☐ Approved device provided
☐ Secure authentication configured
☐ MFA configured
☐ Secure connectivity configured where required
☐ Remote-working policy communicated
☐ Device security requirements communicated
☐ Information protection requirements communicated
☐ Public/shared environment risks explained
☐ Incident reporting requirements explained
27. Physical Access
Where applicable:
☐ Office access requested
☐ Access approved
☐ Access badge issued
☐ Physical access recorded
☐ Visitor requirements communicated
☐ Secure-area restrictions communicated
☐ Badge protection requirements communicated
28. Information Classification
The employee should understand applicable classifications.
☐ Public
☐ Internal
☐ Confidential
☐ Restricted
The employee should understand:
- What information they can access
- Where it may be stored
- How it may be shared
- How it should be protected
- How it should be disposed of
29. Customer Information
Where the role involves customer information:
☐ Customer information identified
☐ Customer-specific requirements communicated
☐ Access restricted
☐ Data handling requirements communicated
☐ Information transfer requirements communicated
☐ Retention requirements communicated
☐ Incident reporting requirements communicated
30. Personal Data
Where personal data is handled:
☐ Personal data categories identified
☐ Authorized purpose communicated
☐ Access restricted
☐ Data minimization requirements communicated
☐ Secure handling communicated
☐ Data-sharing requirements communicated
☐ Incident/breach reporting communicated
☐ Retention/deletion requirements communicated
31. AI and Generative AI
Where AI tools are used:
☐ Approved AI tools identified
☐ Restricted information requirements communicated
☐ Customer-data restrictions communicated
☐ Personal-data restrictions communicated
☐ Source-code restrictions communicated
☐ AI output review requirements communicated
☐ Approved-use requirements acknowledged
32. Incident Reporting
The employee must know how to report:
☐ Security incidents
☐ Phishing
☐ Malware
☐ Lost/stolen device
☐ Credential compromise
☐ Unauthorized access
☐ Data leakage
☐ Suspicious activity
☐ Security weaknesses
Reporting Contact
Security Email: __________________________
Incident Portal: __________________________
Emergency Contact: __________________________
33. Vulnerability and Security Weakness Reporting
Employees should understand that suspected security weaknesses should be reported rather than independently exploited.
☐ Reporting channel provided
☐ Security contact provided
☐ Escalation process communicated
☐ Unauthorized security testing prohibited
34. Acceptable Use
Employee confirms understanding of acceptable use requirements.
☐ Approved business use
☐ Prohibited activities
☐ Unauthorized software
☐ Unauthorized cloud services
☐ Unauthorized data sharing
☐ Credential sharing
☐ Security-control bypass
☐ Unauthorized testing
☐ Misuse of organizational resources
35. Role-Specific Security Requirements
Developers
☐ Secure coding
☐ Source-code protection
☐ Secrets management
☐ Code review
☐ Secure deployment
DevOps / Cloud Administrators
☐ Privileged access
☐ AWS/cloud security
☐ Infrastructure changes
☐ Logging
☐ Emergency access
Finance
☐ Financial information protection
☐ Payment information
☐ Segregation of duties
☐ Fraud awareness
HR
☐ Employee personal data
☐ Confidentiality
☐ Privacy requirements
☐ Restricted access
Security Personnel
☐ Security monitoring
☐ Incident handling
☐ Security testing
☐ Evidence protection
36. Manager Confirmation
The manager confirms that:
☐ Employee role has been defined
☐ Business responsibilities are understood
☐ Required systems have been identified
☐ Access requirements are appropriate
☐ Privileged access requirements have been considered
☐ Sensitive information access has been considered
☐ Role-specific security requirements have been identified
Manager Name: __________________________
Signature/Electronic Approval: __________________________
Date: __________________________
37. IT Confirmation
IT confirms:
☐ Required accounts created
☐ MFA enabled
☐ Required access provisioned
☐ Device assigned
☐ Endpoint security configured
☐ SaaS access provisioned
☐ Cloud access configured where applicable
☐ Access recorded
☐ Security validation completed
IT Owner: __________________________
Date: __________________________
38. Security Confirmation
Information Security confirms where applicable:
☐ Security responsibilities communicated
☐ Required training assigned
☐ Privileged access reviewed
☐ Production access reviewed
☐ Sensitive information access reviewed
☐ Security exceptions identified
☐ Security requirements completed
Security Reviewer: __________________________
Date: __________________________
39. HR Confirmation
HR confirms:
☐ Employment documentation completed
☐ Screening completed where required
☐ Confidentiality requirements completed
☐ Required policy acknowledgement completed
☐ Employee records established
☐ Onboarding evidence retained
HR Owner: __________________________
Date: __________________________
40. Onboarding Exceptions
Document incomplete requirements.
| Requirement | Reason | Risk | Compensating Control | Owner | Due Date |
|---|---|---|---|---|---|
Access should not be granted beyond approved requirements merely because onboarding activities are incomplete.
41. Onboarding Completion
Before marking onboarding complete:
☐ Employment requirements completed
☐ Screening requirements completed
☐ Security responsibilities communicated
☐ Required policies distributed
☐ Security acknowledgement completed
☐ Security training completed or assigned according to policy
☐ Access approved
☐ Accounts created
☐ MFA enabled
☐ Device secured
☐ Required SaaS access provisioned
☐ Cloud access secured where applicable
☐ Privileged access reviewed
☐ Production access reviewed
☐ Incident reporting communicated
☐ Asset handover completed
☐ Exceptions documented
☐ Evidence retained
42. Onboarding Approval
Employee: __________________________
Manager: __________________________
HR: __________________________
IT: __________________________
Security: __________________________
Onboarding Status:
☐ Complete
☐ Complete with Conditions
☐ Pending
☐ Exception Approved
Completion Date: __________________________
43. Post-Onboarding Review
Within an appropriate period after joining:
☐ Access still matches role
☐ Excess access identified
☐ Required training completed
☐ Security policies understood
☐ Device compliant
☐ Security issues identified
☐ Privileged access reviewed where applicable
☐ Production access reviewed where applicable
☐ Onboarding issues closed
Review Date
44. Joiner-Mover-Leaver Integration
Employee onboarding should connect with the organization’s Joiner-Mover-Leaver process.
Joiner
Hire → Verify → Approve → Provision → Train → Acknowledge → Monitor
Mover
Role Change → Reassess Access → Remove Old Access → Approve New Access → Update Responsibilities
Leaver
Notify → Disable → Revoke → Recover Assets → Return/Delete Information → Verify → Record
45. Onboarding Evidence
Maintain appropriate evidence such as:
- Employment documentation
- Screening completion
- Confidentiality agreement
- Policy acknowledgement
- Training records
- Access approvals
- Account creation records
- MFA enrollment
- Device assignment
- Asset acknowledgement
- Privileged-access approval
- Production-access approval
- Manager confirmation
- HR confirmation
- IT confirmation
- Security confirmation
- Exception records
- Completion record
Evidence should be protected from unauthorized access and modification.
46. Onboarding Register
| Employee | Role | Join Date | Screening | Training | Access | MFA | Assets | Acknowledgement | Status |
|---|---|---|---|---|---|---|---|---|---|
47. Onboarding Metrics
Management may monitor:
- New employees onboarded
- Onboarding completion rate
- Delayed onboarding
- Access provisioning time
- MFA completion
- Security training completion
- Policy acknowledgement completion
- Screening completion
- Onboarding exceptions
- Privileged-access onboarding
- Production-access onboarding
- Post-onboarding access findings
48. AWS SaaS Startup Example
An AWS-based SaaS startup hires a new DevOps engineer.
Before Joining
HR completes employment documentation and required screening.
The manager identifies that the role requires:
- AWS access
- GitHub/source-code access
- CI/CD access
- Production access
- Monitoring access
Security Review
The security requirements identify:
- MFA
- Individual accounts
- Least privilege
- Temporary/limited production access where practical
- Privileged-access controls
- Logging
- Secure credential management
Onboarding
The employee:
- Signs confidentiality requirements.
- Reviews security policies.
- Completes security awareness training.
- Acknowledges security responsibilities.
- Receives a managed company laptop.
- Enrolls in MFA.
- Receives approved AWS IAM/SSO access.
- Receives approved source-code access.
- Receives separately approved production access.
- Is informed of incident-reporting requirements.
Evidence
Employee → Role → Screening → Security Responsibilities → Training → Approval → Access → MFA → Asset → Acknowledgement → Validation → Record
49. Startup-Friendly Onboarding Model
A startup can keep onboarding lightweight while maintaining appropriate security.
Day 0 — Before Joining
- Employment documentation
- Screening where required
- Role definition
- Access requirements
- Equipment preparation
Day 1
- Security policies
- Confidentiality
- MFA
- Device security
- Account setup
- Incident reporting
First Week
- Security awareness training
- Role-specific training
- Access validation
- Policy acknowledgement
- Required SaaS/cloud access
First 30 Days
- Review access
- Review onboarding exceptions
- Confirm training completion
- Verify security requirements
For privileged or production roles, additional controls may be required before access is granted.
50. Common Mistakes
Avoid:
- Creating accounts before verifying the employee.
- Giving access based only on job title.
- Giving broad access “for convenience.”
- Delaying MFA.
- Giving production access without separate justification.
- Forgetting source-code or cloud access.
- Treating onboarding as an HR-only process.
- Failing to communicate incident-reporting requirements.
- Failing to collect policy acknowledgement.
- Giving employees access before required screening where the role requires completed screening.
- Not recording asset handover.
- Not reviewing access after onboarding.
- Ignoring onboarding exceptions.
- Creating shared accounts instead of individual accounts.
- Treating completion of a checklist as proof that security controls are actually effective.
51. Relationship With Other ISMS Documents
| Document | Relationship |
|---|---|
| Human Resources Security Policy | Defines personnel-security requirements |
| Employee Screening Policy | Defines screening requirements |
| Background Verification Procedure | Performs verification |
| Employment Security Clause | Establishes contractual security obligations |
| Employee Security Responsibilities | Defines employee responsibilities |
| Employee Security Acknowledgement | Records acknowledgement |
| Security Awareness Procedure | Defines security training |
| Access Management Procedure | Controls access provisioning |
| Joiner-Mover-Leaver Procedure | Manages lifecycle access |
| Asset Management Procedure | Manages assigned assets |
| Employee Offboarding Procedure | Controls employee exit |
| Confidentiality Agreement | Protects confidential information |
52. ISO/IEC 27001 Connection
Employee onboarding supports the organization’s management of personnel security, information-security responsibilities, access control, awareness, and protection of information.
However, an Employee Onboarding Checklist is not itself a universally prescribed ISO/IEC 27001 document or form.
The organization should determine onboarding activities based on:
- ISMS scope
- Information-security risks
- Employee role
- Information accessed
- System access
- Privileged access
- Applicable controls
- Legal and regulatory requirements
- Customer and contractual requirements
The organization should retain sufficient evidence to demonstrate that required onboarding activities were completed.
53. Audit Evidence Checklist
☐ Employee identification
☐ Employment documentation
☐ Role definition
☐ Role-risk assessment
☐ Background verification evidence/status
☐ Confidentiality agreement
☐ Security responsibilities
☐ Policy distribution
☐ Policy acknowledgement
☐ Security training
☐ Access approval
☐ Account creation
☐ MFA evidence
☐ Privileged-access approval
☐ Production-access approval
☐ Device assignment
☐ Asset acknowledgement
☐ Cloud access approval
☐ Source-code access approval
☐ Manager confirmation
☐ HR confirmation
☐ IT confirmation
☐ Security confirmation
☐ Exceptions
☐ Post-onboarding review
☐ Final completion record
54. Final Employee Onboarding Audit Trail
For every employee, the organization should be able to demonstrate:
Who is the employee?
What role were they hired for?
What information will they access?
What systems will they access?
What security risk does the role present?
Were required screening checks completed?
What security responsibilities were communicated?
Which policies were provided?
Was security training completed?
What access was requested?
Who approved the access?
Was MFA enabled?
Was privileged or production access separately controlled?
What assets were assigned?
Did the employee acknowledge applicable requirements?
Were exceptions documented?
Was onboarding independently validated where appropriate?
Final Principle
Secure onboarding starts before the employee receives access.
A strong onboarding process connects HR verification, role definition, security responsibilities, training, confidentiality, access authorization, MFA, asset management, and evidence into one controlled lifecycle.
