1. Purpose
The Personnel Security Audit Checklist provides a structured process for assessing whether personnel-security controls are properly designed, implemented, and operating effectively.
The checklist covers the personnel lifecycle from onboarding through role changes and offboarding, including:
- Screening
- Employment/engagement terms
- Confidentiality
- Security responsibilities
- Security awareness
- Access management
- Role changes
- Privileged access
- Contractor security
- Remote working
- Disciplinary processes
- Offboarding
- Asset return
- Confidentiality after exit
- Security records and evidence
Core Principle
Verify → Authorize → Train → Protect → Monitor → Review → Revoke → Verify → Improve
2. Scope
This checklist may be applied to:
☐ Employees
☐ Contractors
☐ Consultants
☐ Interns
☐ Temporary workers
☐ Agency personnel
☐ Outsourced personnel
☐ Privileged users
☐ Remote workers
☐ Third-party personnel
☐ Other: ______________________
The audit scope should identify the departments, locations, systems, personnel population, and review period covered.
3. Audit Information
| Field | Details |
|---|---|
| Audit ID | |
| Audit Date | |
| Audit Period | |
| Business Unit | |
| Location | |
| Auditor | |
| Security Reviewer | |
| HR Owner | |
| Scope | |
| Sample Size | |
| Methodology | |
| Previous Audit Date | |
| Overall Result |
4. Audit Objective
The audit should determine whether:
☐ Personnel-security requirements are defined
☐ Personnel understand their security responsibilities
☐ Screening is performed where required
☐ Confidentiality obligations are established
☐ Security training is completed
☐ Access is authorized appropriately
☐ Access matches job responsibilities
☐ Role changes trigger access review
☐ Privileged access is controlled
☐ Contractors are appropriately managed
☐ Security violations are addressed
☐ Offboarding is performed promptly
☐ Assets are recovered
☐ Confidentiality continues after exit
☐ Evidence is maintained
☐ Identified gaps are remediated
5. Audit Criteria
Define the criteria used for the audit.
☐ Information Security Policy
☐ Personnel Security Policy
☐ Employee Screening Policy
☐ Background Verification Procedure
☐ Employment agreements
☐ Contractor agreements
☐ NDA/confidentiality requirements
☐ Security Awareness Policy
☐ Access Management Procedure
☐ Privileged Access Procedure
☐ Employee Onboarding Checklist
☐ Role Change Checklist
☐ Employee Offboarding Policy
☐ Contractor Offboarding Procedure
☐ Asset Return Checklist
☐ Disciplinary Policy
☐ Incident Management Procedure
☐ Applicable laws/regulations
☐ Customer contractual requirements
☐ ISO 27001 requirements
☐ SOC 2 requirements where applicable
☐ Other: ______________________
6. Personnel Population
Obtain an understanding of the personnel population.
| Category | Total | Sampled | Exceptions |
|---|---|---|---|
| Employees | |||
| Contractors | |||
| Consultants | |||
| Interns | |||
| Temporary Workers | |||
| Privileged Users | |||
| Remote Workers |
7. Personnel Lifecycle Review
Confirm that security controls exist throughout the lifecycle.
☐ Pre-employment/engagement
☐ Onboarding
☐ Employment/engagement
☐ Security awareness
☐ Role change
☐ Access review
☐ Privileged access
☐ Disciplinary process
☐ Termination/offboarding
☐ Asset return
☐ Access revocation
☐ Continuing confidentiality
8. Personnel Screening
Determine whether appropriate screening is performed.
☐ Screening requirements defined
☐ Screening based on role/risk
☐ Identity verification
☐ Employment verification
☐ Qualification verification
☐ Reference checks where required
☐ Background checks where legally permitted and appropriate
☐ Screening evidence retained
☐ Screening exceptions documented
☐ Screening completed before access where required
Sample Testing
| Person | Role | Screening Required | Completed | Evidence | Exception |
|---|---|---|---|---|---|
9. Screening Exceptions
Review exceptions.
☐ Exceptions identified
☐ Business justification documented
☐ Risk assessed
☐ Compensating controls identified
☐ Appropriate approval obtained
☐ Exception expiry defined
☐ Follow-up completed
10. Employment and Engagement Terms
Verify that personnel terms include applicable security responsibilities.
☐ Employment/engagement agreement exists
☐ Security responsibilities defined
☐ Confidentiality obligations defined
☐ Acceptable-use requirements addressed
☐ Information-protection obligations addressed
☐ Intellectual-property requirements addressed
☐ Incident-reporting responsibilities addressed
☐ Continuing confidentiality addressed
☐ Offboarding obligations addressed
11. Confidentiality and NDA
Verify confidentiality requirements.
☐ NDA required where appropriate
☐ NDA completed
☐ Employee confidentiality acknowledgement completed
☐ Contractor confidentiality agreement completed
☐ Supplier personnel confidentiality requirements addressed
☐ Confidentiality scope appropriate
☐ Customer confidentiality addressed
☐ Source-code confidentiality addressed
☐ Security-information confidentiality addressed
☐ Post-termination confidentiality addressed
Sample Testing
| Person | NDA Required | NDA Present | Valid | Evidence |
|---|---|---|---|---|
12. Security Responsibilities
Determine whether personnel understand their responsibilities.
☐ Security policy provided
☐ Role responsibilities documented
☐ Acceptable-use requirements communicated
☐ Information-classification responsibilities communicated
☐ Access responsibilities communicated
☐ Credential responsibilities communicated
☐ Incident-reporting responsibilities communicated
☐ Confidentiality requirements communicated
☐ Remote-working requirements communicated where applicable
13. Security Awareness Training
Verify completion of required training.
☐ Security awareness training defined
☐ New-joiner training completed
☐ Periodic training completed
☐ Phishing awareness completed
☐ Password/MFA awareness completed
☐ Incident reporting training completed
☐ Data-protection training completed where applicable
☐ Role-specific training completed
☐ Training effectiveness assessed where appropriate
Training Sample
| Person | Training Required | Completed | Date | Evidence |
|---|---|---|---|---|
14. Role-Based Security Training
For sensitive roles:
☐ Developers
☐ DevOps
☐ System administrators
☐ Security personnel
☐ Database administrators
☐ Finance personnel
☐ HR personnel
☐ Privacy personnel
☐ Customer support
☐ Managers
☐ Privileged users
Verify that training reflects the risks associated with the role.
15. Personnel Onboarding
Sample newly onboarded personnel.
Verify:
☐ Identity verified
☐ Employment/engagement approved
☐ Screening completed where required
☐ Contract completed
☐ NDA completed
☐ Security policies provided
☐ Security training completed
☐ Role defined
☐ Access approved
☐ MFA enabled
☐ Required assets assigned
☐ Access expiry defined for contractors
☐ Onboarding evidence retained
16. Access Authorization
Verify that personnel access is formally approved.
☐ Business need documented
☐ Role identified
☐ System owner approval obtained
☐ Manager approval obtained
☐ Security approval obtained where required
☐ Access level defined
☐ Least privilege applied
☐ Need-to-know applied
☐ Individual account used
☐ Access evidence retained
17. Access Rights Review
Sample personnel and compare actual access with job responsibilities.
| Person | Role | System | Access | Required? | Excess Access? | Action |
|---|---|---|---|---|---|---|
Verify:
☐ Access matches role
☐ Unnecessary access removed
☐ Privileged access separately reviewed
☐ Production access justified
☐ Customer access justified
☐ Access expiry enforced where required
18. Privileged User Review
Identify privileged users.
☐ Privileged users identified
☐ Business justification documented
☐ Named accounts used
☐ MFA enabled
☐ Administrative access restricted
☐ Privileged activity logged
☐ Access reviewed periodically
☐ Temporary access used where appropriate
☐ Emergency access controlled
☐ Privileged access revoked when no longer required
19. Cloud and AWS Access
For cloud-enabled organizations:
☐ Cloud users identified
☐ AWS/Azure/GCP access identified
☐ IAM roles reviewed
☐ MFA verified
☐ Privileged cloud access reviewed
☐ Production cloud access reviewed
☐ Access keys controlled
☐ SSO assignments reviewed
☐ Cloud activity logging available
☐ Access removal tested for departed users
AWS Sample
| User | AWS Account | Role | Privileged | MFA | Required | Action |
|---|---|---|---|---|---|---|
20. Source-Code Access
For development personnel:
☐ Repository access identified
☐ Repository access appropriate
☐ MFA enabled
☐ Organization membership reviewed
☐ Branch permissions reviewed
☐ Production deployment rights reviewed
☐ Personal access tokens controlled
☐ SSH keys controlled
☐ Source-code access removed after exit
21. Customer-System Access
Where personnel access customer environments:
☐ Customer access authorized
☐ Customer-specific requirements documented
☐ Named accounts used
☐ MFA enabled
☐ Access limited
☐ Access reviewed
☐ Customer access removed when no longer required
☐ Customer requirements included in offboarding
22. Contractor and Third-Party Personnel
Verify:
☐ Contractors identified
☐ Supplier personnel identified
☐ Contractor agreements completed
☐ NDA completed
☐ Screening performed where required
☐ Security training completed
☐ Access separately approved
☐ End date recorded
☐ Access expiry defined
☐ Periodic access review performed
☐ Supplier coordinates personnel changes
☐ Offboarding requirements defined
23. Remote Worker Security
For remote personnel:
☐ Remote-working requirements defined
☐ Device security requirements defined
☐ MFA enabled
☐ VPN used where required
☐ Encryption enabled where required
☐ Screen-lock requirements followed
☐ Confidential information protected
☐ Public Wi-Fi risks addressed
☐ Personal-device requirements addressed
24. BYOD Security
Where personal devices are permitted:
☐ BYOD policy exists
☐ Security requirements defined
☐ Approved applications identified
☐ Company data restrictions defined
☐ Device security requirements defined
☐ Corporate account controls implemented
☐ Company data removal process defined
☐ Offboarding process addresses BYOD
25. Personnel Changes
Sample recent role changes.
☐ Role change formally recorded
☐ New responsibilities documented
☐ Existing access reviewed
☐ Unnecessary access removed
☐ New access approved
☐ Privileged access reassessed
☐ Training updated
☐ Confidentiality requirements reviewed
☐ Evidence retained
26. Joiner-Mover-Leaver Testing
Select a sample from each category:
Joiners
☐ New employee
☐ New contractor
☐ New privileged user
Movers
☐ Department change
☐ Role change
☐ Privilege change
Leavers
☐ Resignation
☐ Termination
☐ Contractor completion
For each sample, verify that the expected security lifecycle was completed.
27. Offboarding
Sample personnel who left during the audit period.
Verify:
☐ Exit notification received
☐ Access inventory completed
☐ Corporate identity disabled
☐ Email access removed
☐ Cloud access removed
☐ Source-code access removed
☐ Production access removed
☐ Customer access removed
☐ SaaS access removed
☐ Privileged access removed
☐ Shared access reviewed
☐ Credentials/secrets addressed
☐ Assets returned
☐ Confidential information addressed
☐ Exit confidentiality confirmed
☐ Evidence retained
28. Access Revocation Timeliness
Test whether access was removed within the organization’s defined timeframe.
| Person | Exit Date | Access Revoked | Time Difference | Requirement Met? |
|---|---|---|---|---|
Investigate:
- Delayed notification
- Manual process failures
- Weekend/holiday delays
- Supplier communication failures
- Shared accounts
- Cloud accounts
- Customer systems
29. Asset Return
Verify that departing personnel returned organizational assets.
☐ Laptop
☐ Desktop
☐ Mobile
☐ Tablet
☐ Security keys
☐ Access cards
☐ Removable media
☐ Other equipment
Verify:
☐ Asset register updated
☐ Asset recovered
☐ Condition recorded
☐ Data protection requirements addressed
☐ Device wipe/reuse performed where appropriate
☐ Legal/investigation hold considered before wiping
30. Confidentiality After Exit
Verify that continuing obligations are addressed.
☐ NDA continues after exit
☐ Exit acknowledgement completed where required
☐ Confidential information return/deletion addressed
☐ Source-code copies addressed
☐ Customer information addressed
☐ Personal-data copies addressed
☐ Company documents addressed
☐ Credentials addressed
☐ Continuing legal/contractual obligations communicated
31. Disciplinary Process
Review whether security violations are addressed consistently.
☐ Disciplinary policy exists
☐ Security violations defined
☐ Investigation process defined
☐ HR involvement defined
☐ Security involvement defined
☐ Appropriate escalation defined
☐ Evidence maintained
☐ Corrective action documented
☐ Confidentiality maintained during investigation
32. Security Violations
Review a sample of security violations.
☐ Violation recorded
☐ Severity assessed
☐ Investigation completed
☐ Evidence preserved
☐ Root cause considered
☐ Corrective action assigned
☐ Disciplinary action documented where applicable
☐ Lessons learned considered
☐ Repeat issues monitored
33. Security Incident Reporting
Verify personnel know how to report:
- Phishing
- Malware
- Lost devices
- Credential compromise
- Unauthorized access
- Data disclosure
- Suspicious activity
- Security policy violations
☐ Reporting mechanism available
☐ Security contact identified
☐ Reporting timeframe defined
☐ Training provided
☐ Reports tracked
34. Personnel Security Records
Review whether records are complete and appropriately protected.
☐ Employee records
☐ Screening records
☐ NDA records
☐ Training records
☐ Access approvals
☐ Role-change records
☐ Offboarding records
☐ Asset records
☐ Disciplinary records
☐ Security acknowledgements
Personnel records should only be accessible to authorized individuals.
35. Privacy and Personnel Records
Where personnel data is processed:
☐ Purpose identified
☐ Access restricted
☐ Retention defined
☐ Privacy requirements addressed
☐ Sensitive information protected
☐ Legal retention requirements considered
☐ Secure disposal defined
Do not collect or retain personnel information that is unnecessary for the stated purpose.
36. Personnel Security Metrics
Review relevant metrics.
| Metric | Target | Actual | Status |
|---|---|---|---|
| Security Training Completion | |||
| Screening Completion | |||
| MFA Coverage | |||
| Access Review Completion | |||
| Timely Access Revocation | |||
| NDA Completion | |||
| Offboarding Completion | |||
| Security Incidents |
37. Evidence Sampling
Select evidence using a risk-based sample.
Possible evidence:
☐ HR records
☐ Screening evidence
☐ NDA records
☐ Training records
☐ IAM records
☐ SSO records
☐ MFA configuration
☐ Cloud IAM records
☐ Access approvals
☐ Access review records
☐ Offboarding records
☐ Asset-return records
☐ Security incident records
☐ Disciplinary records
☐ Supplier records
Evidence should be sufficient to demonstrate that the control operated without unnecessarily exposing personal or sensitive information.
38. Evidence Quality
For each sample, determine whether evidence is:
☐ Complete
☐ Accurate
☐ Current
☐ Traceable
☐ Approved
☐ Dated
☐ Attributable
☐ Protected from unauthorized modification
Avoid retaining unnecessary passwords, credentials, private keys, or other authentication secrets as audit evidence.
39. Personnel Security Findings
Record audit findings.
| Finding ID | Area | Requirement | Finding | Risk | Owner | Due Date |
|---|---|---|---|---|---|---|
Classify findings according to the organization’s methodology.
Example:
☐ Critical
☐ High
☐ Medium
☐ Low
☐ Observation
☐ Opportunity for Improvement
40. Root Cause Analysis
For significant findings:
☐ Root cause identified
☐ Contributing factors identified
☐ Process weakness identified
☐ Technology weakness identified
☐ Training weakness identified
☐ Ownership weakness identified
☐ Corrective action defined
☐ Preventive action considered
Root Cause
41. Corrective Action Plan
| Finding | Corrective Action | Owner | Due Date | Status | Evidence |
|---|---|---|---|---|---|
Corrective actions should address the underlying cause rather than simply correcting an individual record.
42. Follow-Up Verification
For closed findings:
☐ Corrective action completed
☐ Evidence reviewed
☐ Control tested again
☐ Finding effectively addressed
☐ Residual risk assessed
☐ Finding closed
☐ Lessons learned recorded
43. Overall Audit Assessment
Control Effectiveness
☐ Effective
☐ Partially Effective
☐ Ineffective
☐ Not Applicable
Overall Personnel Security Result
☐ Satisfactory
☐ Satisfactory with Improvements
☐ Remediation Required
☐ Significant Risk Identified
☐ Further Investigation Required
Summary
44. Management Response
Management Comments
Management Action
Risk Acceptance
☐ Not Required
☐ Required and Approved
☐ Required but Pending
Risk Owner: ______________________
Approval Date: ______________________
45. Audit Approval
Auditor
Name: ______________________
Signature/Approval: ______________________
Date: ______________________
Security Owner
Name: ______________________
Approval: ______________________
Date: ______________________
Management
Name: ______________________
Approval: ______________________
Date: ______________________
46. AWS SaaS Startup Example
Scenario
An AWS SaaS startup has:
- 20 employees
- 5 contractors
- 3 developers with production access
- 2 DevOps administrators
- Remote employees
- GitHub source-code repositories
- AWS production environment
- Customer data
A personnel security audit samples:
- 3 new joiners
- 2 role changes
- 2 contractors
- 2 privileged users
- 3 leavers
Audit Tests
Joiners
Verify:
Screening → NDA → Training → Access Approval → MFA
Movers
Verify:
Role Change → Existing Access Review → Remove Old Access → Approve New Access
Privileged Users
Verify:
Business Need → Named Account → MFA → Least Privilege → Logging → Periodic Review
Leavers
Verify:
Exit Notification → Access Revocation → Credential Review → Asset Return → Confidentiality → Evidence
Example Finding
A contractor’s GitHub access remained active for five days after the project ended.
Risk: Unauthorized access to source code.
Corrective Action: Implement mandatory contractor end dates and automated access expiry.
47. Startup-Friendly Personnel Security Audit Model
A startup does not need to audit every personnel record individually.
Use a risk-based sample.
Minimum Annual Sample
Consider sampling:
- New employees
- New contractors
- Recent role changes
- Privileged users
- Production users
- Recent leavers
- High-risk contractors
- Security incidents involving personnel
Higher-Risk Areas
Prioritize:
- AWS/cloud administrators
- Developers with production access
- Database administrators
- Security administrators
- Finance personnel
- Personnel handling customer data
- Personnel handling Restricted information
- Remote privileged users
48. Common Mistakes
Avoid:
- Auditing only HR records without testing system access.
- Assuming an NDA means personnel security is complete.
- Checking whether training exists without checking completion.
- Failing to sample contractors.
- Ignoring privileged users.
- Ignoring cloud access.
- Ignoring source-code access.
- Checking leaver records without testing actual access revocation.
- Failing to compare HR termination dates with IAM disablement dates.
- Ignoring personal-device risks.
- Failing to review role changes.
- Keeping excessive personnel data as audit evidence.
- Closing findings without testing corrective actions.
- Treating personnel security as only an HR responsibility.
49. Relationship With Other ISMS Documents
| Document | Relationship |
|---|---|
| Employee Screening Policy | Defines screening requirements |
| Background Verification Procedure | Defines screening execution |
| Employee Security Responsibilities | Defines personnel obligations |
| Employment Security Clause Template | Establishes contractual requirements |
| Confidentiality and NDA Policy | Protects confidential information |
| Employee Security Acknowledgement | Records acceptance of security responsibilities |
| Security Awareness Policy | Defines awareness requirements |
| Security Awareness Training Procedure | Defines training process |
| Employee Onboarding Checklist | Controls secure onboarding |
| Employee Role Change Checklist | Controls access during role changes |
| Employee Offboarding Policy | Controls secure employee exit |
| Access Management Procedure | Controls logical access |
| Access Revocation Checklist | Removes access |
| Privileged User Offboarding Checklist | Handles privileged-user exits |
| Asset Return Checklist | Recovers organizational assets |
| Disciplinary Policy | Handles security violations |
| Incident Response Procedure | Handles personnel-related security incidents |
| Supplier/Contractor Security Procedures | Controls external personnel |
| Risk Register | Tracks significant personnel-security risks |
50. ISO 27001 / SOC 2 Connection
Personnel security auditing supports the organization’s risk-based management of people who have access to information and systems.
Relevant areas may include:
- Personnel screening
- Terms and conditions of employment/engagement
- Information-security awareness
- Confidentiality
- Access control
- Identity management
- Access rights
- Supplier/contractor security
- Incident reporting
- Disciplinary processes
- Offboarding
- Asset management
- Information protection
For SOC 2, personnel-security audit evidence can support controls relating to:
- Logical access
- User lifecycle management
- Security awareness
- Confidentiality
- Protection of customer information
- Vendor/contractor management
- Security incident management
The organization should determine the specific controls and audit evidence based on its ISMS scope, risk assessment, contractual requirements, and Statement of Applicability.
51. Quick Audit Checklist
☐ Personnel population identified
☐ Audit scope defined
☐ Screening requirements reviewed
☐ Screening sample tested
☐ Employment/contract terms reviewed
☐ NDA/confidentiality reviewed
☐ Security responsibilities reviewed
☐ Security training reviewed
☐ New joiners sampled
☐ Role changes sampled
☐ Access approvals sampled
☐ Least privilege tested
☐ Privileged access tested
☐ Cloud access tested
☐ Source-code access tested
☐ Customer access tested
☐ Contractor controls tested
☐ Remote-working controls tested
☐ Offboarding sampled
☐ Access-revocation timeliness tested
☐ Asset return tested
☐ Continuing confidentiality tested
☐ Security violations reviewed
☐ Personnel incidents reviewed
☐ Records protected
☐ Findings documented
☐ Root cause assessed
☐ Corrective actions assigned
☐ Follow-up completed
☐ Management response obtained
☐ Audit evidence retained
52. Document Control
| Field | Details |
|---|---|
| Document Name | Personnel Security Audit Checklist |
| Document Owner | |
| Security Owner | |
| Version | |
| Effective Date | |
| Audit Frequency | |
| Classification | Internal |
| Approved By | |
| Next Review Date |
53. Final Audit Trail
For every personnel-security audit, the organization should be able to demonstrate:
Who was included in the audit scope?
What personnel-security requirements were tested?
Were screening requirements followed?
Were confidentiality obligations established?
Did personnel receive security training?
Was access properly authorized?
Does access match the person’s current role?
Were privileged users appropriately controlled?
Were contractors and third-party personnel included?
Were role changes tested?
Were leaver access revocations tested?
Were assets recovered?
Were continuing confidentiality obligations addressed?
What findings were identified?
Who owns corrective actions?
Was remediation independently verified?
Final Principle
Personnel security is not an HR-only process. It connects people, contracts, confidentiality, training, identity, access, information, technology, and offboarding into one security lifecycle.
The complete audit lifecycle should be:
Scope → Sample → Verify → Test → Identify Gaps → Assess Risk → Correct → Verify → Report → Improve
