ISO/IEC 27001

⌘K
  1. Home
  2. Docs
  3. ISO/IEC 27001
  4. Other Doc
  5. Background Verification Procedure

Background Verification Procedure

1. Purpose

The Background Verification Procedure defines how the organization performs, documents, reviews, and manages background verification for employees, contractors, interns, temporary workers, and other personnel where verification is required.

The objective is to ensure that background verification:

  • Is appropriate to the role and associated risks
  • Is performed lawfully and proportionately
  • Supports information-security requirements
  • Helps verify relevant identity, employment, education, and professional information
  • Protects personal and sensitive information
  • Is completed before granting access where required
  • Produces appropriate evidence for audit purposes
  • Provides a consistent process for exceptions and adverse results

Core Principle

Define Role Risk → Determine Checks → Obtain Authorization → Verify → Review → Decide → Record → Protect → Monitor


2. Scope

This procedure applies to:

  • Permanent employees
  • Temporary employees
  • Contractors
  • Consultants
  • Interns
  • Apprentices
  • Outsourced personnel
  • Third-party personnel where required
  • Personnel assigned to security-sensitive roles

The procedure applies during:

  • Pre-employment
  • Pre-engagement
  • Role changes
  • Transfers to sensitive roles
  • Periodic re-verification where justified
  • Investigation of material discrepancies where appropriate

3. Background Verification Information

FieldDetails
Verification ID
Candidate/Personnel ID
Name
Position
Department
Employment Type
Role Risk Level
Verification Level
Verification Provider
Request Date
Authorization Date
Verification Start Date
Verification Completion Date
HR Owner
Security Review Required
Status

4. Roles and Responsibilities

HR

Responsible for:

  • Initiating verification
  • Obtaining required authorization
  • Coordinating verification
  • Reviewing results
  • Maintaining records
  • Communicating relevant outcomes

Hiring Manager

Responsible for:

  • Defining the role
  • Identifying role-specific risks
  • Confirming required verification level
  • Supporting decisions regarding discrepancies

Information Security

Where applicable:

  • Advises on security-sensitive roles
  • Reviews verification requirements for privileged positions
  • Assesses information-security implications
  • Supports risk decisions

Where required:

  • Advises on applicable legal and privacy requirements
  • Reviews sensitive or complex verification activities
  • Advises on permissible checks

Management

Responsible for:

  • Approving significant exceptions or risk acceptance where required
  • Ensuring appropriate resources and governance

5. Role Risk Assessment

Background verification should be proportionate to the role.

Consider:

☐ Access to confidential information
☐ Access to personal data
☐ Access to financial information
☐ Production-system access
☐ Privileged access
☐ Cloud administration
☐ Source-code access
☐ Security administration
☐ Customer-facing responsibility
☐ Regulatory responsibility
☐ Financial responsibility
☐ Physical facility access
☐ Business-critical responsibility

Role Risk

☐ Low
☐ Medium
☐ High
☐ Critical

Risk Rationale


6. Verification Levels

Example risk-based model:

LevelTypical Checks
BasicIdentity and employment verification
StandardIdentity, employment, education/qualification and references where relevant
EnhancedStandard checks plus additional lawful checks appropriate to the role
High-RiskEnhanced verification appropriate to privileged, regulated, financial, or highly sensitive roles

The organization should define its own verification levels based on applicable law, role requirements, and risk.


7. Verification Requirements

Determine which checks are required.

☐ Identity verification
☐ Address verification where relevant
☐ Employment verification
☐ Education verification
☐ Professional qualification verification
☐ Professional references
☐ Professional registration verification
☐ Criminal-record check where lawful and relevant
☐ Sanctions/regulatory screening where applicable
☐ Financial checks where lawful and role-relevant
☐ Conflict-of-interest declaration
☐ Right-to-work verification where applicable
☐ Other: ______________________

Not every individual requires every check.


8. Candidate Authorization

Before conducting checks:

☐ Verification requirement communicated
☐ Required consent/authorization obtained
☐ Purpose explained
☐ Verification scope explained
☐ Applicable privacy information provided
☐ Verification provider authorized
☐ Legal requirements considered

Verification should not be performed outside the approved scope.


9. Identity Verification

Verify identity using appropriate and lawful sources.

Possible evidence may include:

  • Government-issued identification
  • Authorized identity-verification service
  • Other legally acceptable evidence

Verify, where appropriate:

☐ Name
☐ Date of birth
☐ Identity document validity
☐ Identity consistency
☐ Other required information

Result

☐ Verified
☐ Partially Verified
☐ Unable to Verify
☐ Discrepancy Identified


10. Employment Verification

Where employment history is relevant:

☐ Previous employer identified
☐ Employment dates verified
☐ Position verified
☐ Employment status verified
☐ Relevant responsibilities verified where appropriate
☐ Significant unexplained gaps identified
☐ Discrepancies documented

Verification should be limited to information relevant to the stated purpose and permitted by applicable requirements.


11. Education and Qualification Verification

Where qualifications are relevant:

☐ Institution verified
☐ Qualification verified
☐ Completion status verified
☐ Relevant professional certification verified
☐ Professional registration verified where applicable
☐ Discrepancies recorded

Result


12. Professional Reference Verification

Where references are required:

☐ Reference requirement defined
☐ Reference identity verified
☐ Reference obtained from appropriate source
☐ Relevant employment relationship confirmed
☐ Response recorded
☐ Material concerns escalated where appropriate

Do not request unnecessary personal information from referees.


13. Criminal Record Checks

Criminal-record checks should only be performed where:

  • Legally permissible
  • Relevant to the role
  • Proportionate to the risk
  • Appropriately authorized

Consider:

☐ Legal requirements
☐ Jurisdiction
☐ Role sensitivity
☐ Nature of the position
☐ Data protection requirements
☐ Accuracy of the information
☐ Opportunity to challenge inaccurate information

A criminal-record result should not automatically be treated as a reason for rejection without considering applicable law, organizational policy, role relevance, and the circumstances.


14. Financial Checks

Financial checks should only be conducted where legally permitted and relevant to the role.

Potentially relevant roles may include:

  • Financial control
  • Treasury
  • Payment administration
  • Certain regulated roles
  • Roles with significant financial authority

Consider:

☐ Legal basis
☐ Role relevance
☐ Proportionality
☐ Candidate notification/authorization
☐ Data protection
☐ Secure handling


15. Sanctions and Regulatory Screening

Where applicable:

☐ Sanctions screening completed
☐ Regulatory registration verified
☐ Professional license verified
☐ Required regulatory status confirmed
☐ Potential match investigated
☐ False positives resolved
☐ Evidence retained

Screening should use appropriate and reliable sources.


16. Security-Sensitive Roles

Enhanced verification may be appropriate for roles involving:

  • Production administration
  • Cloud administration
  • Security operations
  • Information-security management
  • Database administration
  • Source-code administration
  • Financial systems
  • Customer-sensitive information
  • Cryptographic key management
  • Privileged infrastructure

For such roles:

☐ Role risk assessed
☐ Enhanced checks identified
☐ Verification completed before privileged access where practical
☐ Exceptions documented
☐ Additional approval obtained where required


17. Contractor Verification

Before assigning contractors to security-sensitive activities:

☐ Contractor identity verified
☐ Contracting organization identified
☐ Required background checks confirmed
☐ Confidentiality requirements established
☐ Security responsibilities defined
☐ Access requirements identified
☐ Verification evidence reviewed where appropriate


18. Third-Party Personnel

Where suppliers provide personnel with organizational access:

☐ Supplier screening requirements defined
☐ Supplier verification responsibility defined
☐ Required checks communicated contractually
☐ Evidence/attestation requirements defined
☐ High-risk personnel subject to additional review where appropriate
☐ Access restricted until required verification is complete


19. Interns and Temporary Personnel

Verification requirements should be proportionate to:

  • Role
  • Access
  • Information handled
  • Duration
  • Business risk

Do not assume that temporary personnel require no verification.


20. Verification Provider

If an external verification provider is used:

☐ Provider approved
☐ Provider identity verified
☐ Scope defined
☐ Privacy/security requirements reviewed
☐ Confidentiality requirements established
☐ Data-processing requirements addressed where applicable
☐ Data retention understood
☐ Subprocessors identified where relevant
☐ Secure information transfer established


21. Verification Evidence

Evidence may include:

  • Verification report
  • Confirmation from authorized source
  • Qualification confirmation
  • Employment confirmation
  • Reference confirmation
  • Screening result
  • Provider attestation

Avoid retaining unnecessary copies of highly sensitive personal information.

Where possible, retain:

Verification performed → Result → Date → Reviewer → Decision

rather than unnecessary source documents.


22. Evidence Review

The reviewer should determine whether the evidence is:

☐ Relevant
☐ Reliable
☐ Current
☐ Complete enough for the purpose
☐ From an appropriate source
☐ Consistent with information provided by the individual

Evidence Assessment


23. Discrepancy Identification

Potential discrepancies may include:

  • Incorrect employment dates
  • Incorrect qualifications
  • Unexplained information
  • Identity mismatch
  • Unverified professional credentials
  • Material inconsistencies
  • Potential screening match

Record:

DiscrepancySourceImpactActionStatus

24. Discrepancy Review

A discrepancy should be reviewed before making an employment or access decision.

Consider:

☐ Accuracy of information
☐ Source reliability
☐ Materiality
☐ Role relevance
☐ Legal requirements
☐ Candidate explanation
☐ Potential security impact
☐ Need for additional verification

The individual should be given an appropriate opportunity to clarify potentially inaccurate information where required.


25. Verification Result

Overall Result

☐ Satisfactory
☐ Satisfactory with Conditions
☐ Further Verification Required
☐ Discrepancy Under Review
☐ Not Satisfactory
☐ Unable to Complete

Reviewer Comments


26. Access Before Verification Completion

As a general principle, personnel should not receive access beyond the organization’s approved onboarding level until required verification is completed.

Where business requirements require access before completion:

☐ Business justification documented
☐ Risk assessed
☐ Access minimized
☐ MFA enabled where applicable
☐ Privileged access restricted
☐ Time limitation defined
☐ Management approval obtained
☐ Verification completion tracked


27. Verification and Onboarding

Before granting normal organizational access:

☐ Required verification completed
☐ Results reviewed
☐ Discrepancies resolved or formally addressed
☐ Employment/engagement approved
☐ Security requirements communicated
☐ Required confidentiality agreement completed
☐ Access request approved


28. Background Verification and Access Management

Verification should connect with access management.

Example

A developer requiring:

  • GitHub access
  • AWS development access
  • CI/CD access

may require a different verification level from an employee with no system access.

A developer requiring AWS production administration may require enhanced verification based on organizational risk.

Audit Trail

Role → Risk → Verification → Approval → Access → Review


29. Periodic Re-Verification

Periodic re-verification should be risk-based and legally permissible.

Consider re-verification when:

☐ Role becomes significantly more sensitive
☐ Privileged access is granted
☐ Regulatory requirements change
☐ Contract requires re-verification
☐ Significant security concern arises
☐ Organizational policy requires periodic verification

Periodic checks should not become routine collection of unnecessary personal information.


30. Role Change

When an employee moves into a more sensitive role:

☐ New role assessed
☐ New verification requirements identified
☐ Additional checks completed where required
☐ Access requirements reassessed
☐ Existing verification reviewed
☐ Approval recorded


31. Privacy and Personal Data Protection

Background verification can involve sensitive personal information.

The organization should:

☐ Collect only necessary information
☐ Define the purpose of collection
☐ Use appropriate lawful processing mechanisms
☐ Restrict access
☐ Protect verification records
☐ Avoid unnecessary duplication
☐ Define retention periods
☐ Securely dispose of information
☐ Manage third-party verification providers appropriately
☐ Address international transfers where applicable


32. Access to Verification Records

Verification records should be accessible only to authorized personnel.

Potential access roles:

  • HR
  • Authorized management
  • Legal/privacy personnel
  • Information security where required
  • Authorized verification administrators

Access should be:

☐ Role-based
☐ Least privilege
☐ Logged where appropriate
☐ Periodically reviewed


33. Confidentiality

Background verification information should be treated as confidential.

Personnel handling verification information must:

☐ Maintain confidentiality
☐ Use information only for authorized purposes
☐ Avoid unnecessary disclosure
☐ Secure physical and electronic records
☐ Report suspected unauthorized disclosure


34. Record Retention

Define retention based on:

  • Legal requirements
  • Employment requirements
  • Contractual requirements
  • Privacy requirements
  • Litigation/claim requirements
  • Organizational records policy

Retention Period

Do not retain verification information indefinitely without a defined purpose.


35. Secure Disposal

When retention expires:

☐ Record identified
☐ Retention requirement confirmed
☐ Disposal authorized
☐ Electronic information securely deleted
☐ Physical records securely destroyed
☐ Disposal evidence retained where appropriate


36. Exceptions

Exceptions may be required when verification cannot be completed within the normal timeframe.

Record:

  • Reason
  • Risk
  • Missing verification
  • Compensating controls
  • Access restrictions
  • Approval
  • Expiry/review date

Exception Record

Exceptions should be time-bound and should not be used to permanently bypass required verification.


37. Verification Incidents

Security/privacy incidents involving verification information must be handled under the organization’s incident-management process.

Examples include:

  • Unauthorized access
  • Accidental disclosure
  • Lost records
  • Incorrect verification result
  • Compromised verification provider
  • Unauthorized transmission
  • Data breach

38. Compliance Monitoring

Periodically verify:

☐ Required checks are completed
☐ Verification records are complete
☐ Exceptions are approved
☐ Sensitive records are protected
☐ Retention requirements are followed
☐ Verification providers comply with requirements
☐ High-risk personnel receive required verification
☐ Access is not granted contrary to defined requirements


39. Metrics

Useful metrics include:

MetricResult
Personnel requiring verification
Verification completed
Verification pending
Verification overdue
Discrepancies identified
Discrepancies unresolved
Exceptions
High-risk roles verified
Average completion time
Provider issues

Metrics should support process improvement rather than unnecessary collection of personal information.


40. Background Verification Register

Maintain an appropriate register.

Verification IDPersonnel IDRoleRiskVerification LevelStatusDateReviewer

The register should avoid storing unnecessary sensitive details.


41. Findings

If the review identifies weaknesses:

Finding IDAreaFindingRiskActionOwnerDue DateStatus

Examples:

  • Verification not completed before privileged access
  • Required authorization missing
  • Verification evidence incomplete
  • Sensitive records accessible to unauthorized personnel
  • Expired verification provider arrangement
  • Required re-verification not performed

42. Corrective Action

For significant findings:

☐ Root cause identified
☐ Immediate correction performed
☐ Corrective action defined
☐ Owner assigned
☐ Due date assigned
☐ Evidence required
☐ Effectiveness verification defined
☐ Residual risk assessed

Corrective Action


43. Risk Assessment

Where verification gaps create information-security risk, assess:

Threat → Vulnerability → Exposure → Impact → Risk → Treatment

Example:

A privileged administrator has not completed required background verification → organizational verification requirement is incomplete → privileged access creates increased personnel-related risk → risk assessed according to the organization’s methodology → temporary access restriction or additional verification may be applied.


44. Management Approval

Where required:

HR Owner: ______________________

Hiring Manager: ______________________

Information Security: ______________________

Legal/Privacy: ______________________

Risk Owner: ______________________

Approver: ______________________

Date: ______________________


45. Review Frequency

Review this procedure:

  • At planned intervals
  • Following legal or regulatory changes
  • Following significant security incidents
  • Following material changes to employment practices
  • Following changes to verification providers
  • Following significant audit findings
  • When new categories of personnel or roles are introduced

Next Review Date


46. AWS SaaS Startup Example

Consider an AWS-based SaaS startup.

Employee A — Marketing

Access:

  • Marketing SaaS applications
  • Public website
  • Internal collaboration tools

Risk: Low/Medium

Basic or standard verification may be appropriate according to organizational requirements.

Employee B — Software Developer

Access:

  • Source code
  • Development AWS environment
  • CI/CD

Risk: Medium

Additional employment, education, qualification, or reference verification may be appropriate.

Employee C — Production Cloud Administrator

Access:

  • AWS production
  • IAM
  • Security configurations
  • Production infrastructure

Risk: High/Critical depending on the organization’s risk assessment.

Enhanced verification may be appropriate, together with:

  • Strong authentication
  • Privileged access controls
  • Least privilege
  • Logging
  • Access review
  • Approval
  • Periodic reassessment

Audit Trail

Role Risk → Verification Requirement → Authorization → Verification → Review → Approval → Access → Monitoring


47. Startup-Friendly Background Verification Model

A startup can keep the process simple while maintaining appropriate control.

Low-Risk Personnel

Focus on:

  • Identity
  • Basic employment verification
  • Role requirements
  • Authorization
  • Record

Medium-Risk Personnel

Add:

  • Education/qualification verification where relevant
  • References
  • Additional employment verification
  • Security-sensitive role assessment

High/Critical-Risk Personnel

Add, where lawful and relevant:

  • Enhanced verification
  • Additional professional checks
  • Regulatory screening
  • Additional approval
  • Pre-access verification
  • Periodic reassessment

The objective is not to perform the maximum number of checks. It is to perform the appropriate checks for the role and risk.


48. Common Mistakes

Avoid:

  • Performing the same checks for every role without considering risk
  • Performing checks without appropriate authorization
  • Collecting unnecessary personal information
  • Retaining complete sensitive reports indefinitely
  • Granting privileged access before required verification is complete
  • Treating a verification report as automatically accurate
  • Ignoring discrepancies
  • Failing to document decisions
  • Using unapproved verification providers
  • Ignoring privacy requirements
  • Failing to protect verification records
  • Performing unlawful or irrelevant checks
  • Failing to reassess requirements when a role changes

49. Relationship With Other ISMS Documents

DocumentRelationship
Employee Screening PolicyDefines overall screening requirements
Background Verification ProcedureDefines verification workflow
Employee Onboarding ProcedureUses verification completion before onboarding/access
Employee Offboarding ProcedureRemoves access when personnel leave
Access Management ProcedureControls system access
Personnel Security ProcedureDefines personnel-security requirements
Security Awareness ProcedureDefines security training
Confidentiality/NDAProtects organizational information
Supplier Security RequirementsAddresses third-party personnel
Incident Management ProcedureHandles verification-related incidents
Information Security PolicyEstablishes overall security expectations
Risk Management ProcedureAssesses risks arising from verification gaps

50. ISO/IEC 27001 Connection

Background verification supports the organization’s personnel-security controls and risk-management approach.

The organization should determine:

  • Which personnel require verification
  • What checks are appropriate
  • When checks must be completed
  • What evidence should be retained
  • How sensitive information is protected
  • How exceptions are managed
  • Whether periodic re-verification is necessary

The Background Verification Procedure is not itself a universally prescribed ISO/IEC 27001 document. The specific process should be based on the organization’s ISMS scope, risk assessment, applicable controls, legal requirements, contractual requirements, customer expectations, and role sensitivity.


51. Audit Evidence Checklist

An auditor may request evidence such as:

☐ Background Verification Procedure
☐ Employee Screening Policy
☐ Role risk assessment
☐ Verification requirements
☐ Authorization/consent records where applicable
☐ Verification register
☐ Verification completion records
☐ Sample verification evidence
☐ Discrepancy records
☐ Exception records
☐ Approval records
☐ Verification provider assessment
☐ Privacy/retention requirements
☐ Access restrictions for verification records
☐ Corrective actions
☐ Periodic review evidence

Sensitive personal information should not be unnecessarily exposed during an audit.


52. Final Background Verification Audit Trail

For each applicable individual, the organization should be able to demonstrate:

Why is verification required?
What is the risk of the role?
What checks were required?
Was appropriate authorization obtained?
Who performed the verification?
What evidence was reviewed?
Were discrepancies identified?
How were discrepancies handled?
Who reviewed the result?
Was the engagement approved?
Was access restricted until required verification was complete?
How was verification information protected?
How long will the information be retained?
What happens when retention expires?

Final Principle

Background verification is not simply a background-check exercise. It is a risk-based personnel-security process that connects the role, verification requirements, authorization, evidence, decision, access, privacy protection, and ongoing personnel-security controls into a defensible audit trail.