1. Purpose
The Background Verification Register provides a centralized record of background verification activities performed for employees, contractors, consultants, interns, temporary workers, and other personnel where screening is required.
The register helps the organization demonstrate that:
- Appropriate screening requirements were identified
- Screening was completed for applicable personnel
- Verification results were reviewed
- Exceptions were documented
- Outstanding checks were tracked
- Screening records are protected
- Re-verification requirements are monitored
- Screening decisions can be demonstrated during an audit
Core Principle
Identify → Assess → Screen → Verify → Review → Record → Monitor → Reassess
2. Scope
The register may include:
- Employees
- Contractors
- Consultants
- Freelancers
- Interns
- Temporary workers
- Agency personnel
- Third-party personnel
- Security-sensitive personnel
- Privileged users
- Personnel requiring enhanced screening
The register should contain only the information necessary to manage the screening process.
3. Register Ownership
Register Owner: __________________________
HR/People Owner: _________________________
Information Security Owner: _______________
Risk Owner: _______________________________
Register Location/System: _________________
Review Frequency: _________________________
4. Master Background Verification Register
| Verification ID | Personnel ID | Personnel Type | Role | Department | Risk | Screening Level | Status | Completion Date | Next Review |
|---|---|---|---|---|---|---|---|---|---|
Personnel Type
- Employee
- Contractor
- Consultant
- Intern
- Temporary Worker
- Third-Party Personnel
Risk
- Low
- Medium
- High
- Critical
Screening Level
- Level 1 – Basic
- Level 2 – Standard
- Level 3 – Enhanced
- Level 4 – High Risk
5. Personnel Information
| Field | Details |
|---|---|
| Verification ID | |
| Personnel ID | |
| Name/Reference | |
| Personnel Type | |
| Role | |
| Department | |
| Manager | |
| Business Owner | |
| Employment/Engagement Start | |
| Employment/Engagement End | |
| Location/Jurisdiction | |
| Role Risk | |
| Screening Level |
Avoid storing unnecessary sensitive personal information in the register.
6. Screening Requirement Register
Record what screening is required for each person.
| Verification ID | ID | EMP | EDU | REF | PROF | CR* | REG* | FIN* | COI | RTW | Other |
|---|---|---|---|---|---|---|---|---|---|---|---|
Use:
- Required
- Completed
- Not Required
- Pending
- Exception
* Only where lawful, relevant, and proportionate.
7. Screening Status
Use standardized statuses:
☐ Not Started
☐ Initiated
☐ In Progress
☐ Pending Information
☐ Pending Provider
☐ Pending Review
☐ Discrepancy Identified
☐ Exception Approved
☐ Completed
☐ Completed With Conditions
☐ Re-Screening Required
☐ Closed
8. Identity Verification Register
| Verification ID | Identity Required | Source/Provider | Date Completed | Result | Reviewer |
|---|---|---|---|---|---|
Possible results:
- Verified
- Partially Verified
- Unable to Verify
- Discrepancy
Do not unnecessarily store copies of identity documents in the register.
9. Employment Verification Register
| Verification ID | Employer/Engagement | Period Verified | Role Verified | Result | Date | Reviewer |
|---|---|---|---|---|---|---|
Record only information necessary to demonstrate completion and result.
10. Education and Qualification Register
| Verification ID | Qualification | Institution | Verification Date | Result | Reviewer |
|---|---|---|---|---|---|
For professional certifications:
| Verification ID | Certification | Issuing Body | Valid Until | Verified | Reviewer |
|---|---|---|---|---|---|
11. Professional Reference Register
| Verification ID | Reference Type | Reference Verified | Date | Result | Reviewer |
|---|---|---|---|---|---|
Avoid recording unnecessary personal information about referees.
12. Criminal Record Check Register
Where legally permitted and relevant:
| Verification ID | Required | Provider/Source | Date | Result | Review Status |
|---|---|---|---|---|---|
Use controlled result categories rather than storing unnecessary detailed criminal-record information.
Example:
- Completed – No Relevant Result
- Completed – Requires Review
- Not Required
- Pending
- Exception
13. Financial Screening Register
Where lawful and relevant:
| Verification ID | Required | Provider | Date | Result | Reviewer |
|---|---|---|---|---|---|
Avoid storing detailed financial information unless there is a documented requirement to retain it.
14. Regulatory and Sanctions Screening Register
| Verification ID | Screening Type | Source | Date | Result | Reviewer |
|---|---|---|---|---|---|
Examples:
- Sanctions screening
- Regulatory registration
- Professional license
- Industry authorization
15. Right-to-Work Register
Where applicable:
| Verification ID | Required | Verified | Expiry | Follow-Up Date | Status |
|---|---|---|---|---|---|
16. Conflict-of-Interest Register
Where applicable:
| Verification ID | Declaration Required | Completed | Conflict Identified | Action | Status |
|---|---|---|---|---|---|
17. Security-Sensitive Role Register
Identify personnel with heightened security responsibilities.
| Verification ID | Role | Production Access | Privileged Access | Restricted Data | Screening Level | Status |
|---|---|---|---|---|---|---|
Examples:
- AWS Administrator
- System Administrator
- Database Administrator
- Security Engineer
- SOC Analyst
- VAPT Consultant
- CISO
- Source-Code Administrator
18. Privileged User Screening Register
| Verification ID | User | Privileged Role | System | Screening Complete | Approval | Review Date |
|---|---|---|---|---|---|---|
The register should support correlation between personnel screening and privileged access.
19. Contractor Screening Register
| Contractor ID | Contractor | Supplier | Role | Risk | Screening Level | Status | Access Expiry |
|---|---|---|---|---|---|---|---|
Where suppliers perform screening, record:
☐ Supplier responsible
☐ Attestation received
☐ Evidence reviewed where required
☐ Contractual requirement confirmed
20. Third-Party Personnel Register
| Personnel ID | Supplier | Role | Access | Screening Responsibility | Status | Review Date |
|---|---|---|---|---|---|---|
21. Screening Provider Register
Where external providers are used:
| Provider | Service | Approved | Security Review | Privacy Review | Contract | Status |
|---|---|---|---|---|---|---|
Consider:
- Provider security
- Confidentiality
- Privacy
- Data location
- Retention
- Subprocessors
- International transfers
- Data disposal
22. Authorization Register
Track required authorization.
| Verification ID | Authorization Required | Obtained | Date | Method | Reviewer |
|---|---|---|---|---|---|
Authorization should be obtained before performing checks where required.
23. Screening Evidence Register
| Verification ID | Evidence Type | Source | Date | Reviewed | Reviewer | Location |
|---|---|---|---|---|---|---|
Examples:
- Employment confirmation
- Qualification confirmation
- Professional certification
- Reference confirmation
- Screening-provider result
- Regulatory registration
Do not store passwords, authentication secrets, or other unnecessary sensitive information as screening evidence.
24. Discrepancy Register
Record material discrepancies separately where appropriate.
| Discrepancy ID | Verification ID | Area | Description | Risk | Status | Resolution |
|---|---|---|---|---|---|---|
Potential areas:
- Identity
- Employment
- Qualification
- Professional certification
- Regulatory screening
- Other relevant information
25. Discrepancy Review
For each material discrepancy:
☐ Source verified
☐ Accuracy assessed
☐ Materiality assessed
☐ Role relevance assessed
☐ Explanation obtained where appropriate
☐ Additional verification performed
☐ Security impact assessed
☐ Legal/privacy considerations reviewed
☐ Decision documented
26. Screening Exception Register
| Exception ID | Verification ID | Missing Check | Reason | Risk | Compensating Control | Expiry | Status |
|---|---|---|---|---|---|---|---|
Track:
- Exception reason
- Risk
- Approval
- Compensating controls
- Expiry
- Resolution
27. Screening Exception Status
☐ Open
☐ Under Review
☐ Approved
☐ Approved With Conditions
☐ Expiring Soon
☐ Expired
☐ Resolved
☐ Closed
Expired exceptions should be escalated and reviewed.
28. Screening Decision Register
| Verification ID | Result | Conditions | Decision Maker | Decision Date | Status |
|---|---|---|---|---|---|
Possible results:
- Satisfactory
- Satisfactory With Conditions
- Further Verification Required
- Exception Required
- Not Approved
- Unable to Complete
29. Access Dependency
Where screening is a prerequisite for access:
| Verification ID | System | Access Type | Screening Complete | Access Approved | Access Date |
|---|---|---|---|---|---|
This helps demonstrate that required screening was considered before sensitive access was granted.
30. Screening Before Privileged Access
For privileged users:
☐ Screening requirement identified
☐ Required verification completed
☐ Results reviewed
☐ Security approval obtained
☐ Privileged access approved
☐ MFA enabled
☐ Least privilege applied
☐ Access review scheduled
31. Pending Screening Register
Track incomplete screening.
| Verification ID | Personnel | Role | Missing Requirement | Reason | Owner | Due Date | Status |
|---|---|---|---|---|---|---|---|
This should be reviewed regularly.
32. Overdue Screening Register
| Verification ID | Personnel | Role | Requirement | Due Date | Days Overdue | Risk | Action |
|---|---|---|---|---|---|---|---|
High-risk overdue screening should be escalated according to the organization’s risk process.
33. Re-Screening Register
Where periodic or event-driven re-screening applies:
| Verification ID | Personnel | Role | Trigger | Required Date | Completed | Result | Next Review |
|---|---|---|---|---|---|---|---|
Possible triggers:
- Periodic review
- Role change
- Privileged access
- Regulatory requirement
- Customer requirement
- Security concern
- Contract extension
34. Role Change Screening
| Personnel ID | Previous Role | New Role | Risk Change | Additional Screening | Completion | Approval |
|---|---|---|---|---|---|---|
The organization should reassess screening when role responsibilities or access materially change.
35. Screening Completion Dashboard
Track:
| Metric | Count |
|---|---|
| Total Personnel Requiring Screening | |
| Completed | |
| In Progress | |
| Pending | |
| Overdue | |
| Exceptions | |
| High-Risk Personnel | |
| High-Risk Screening Completed | |
| Re-Screening Due | |
| Re-Screening Overdue | |
| Discrepancies | |
| Open Discrepancies |
36. Screening Coverage
Calculate:
Screening Coverage % = Completed Required Screenings ÷ Total Required Screenings × 100
Result
__________ %
For high-risk personnel, consider maintaining a separate coverage metric.
High-Risk Screening Coverage
__________ %
37. Screening Timeliness
Track:
- Average screening completion time
- Average time by screening provider
- Average time by screening level
- Number of overdue screenings
- Number of provider-related delays
Metrics
| Metric | Result |
|---|---|
| Average completion time | |
| Median completion time | |
| Overdue screening count | |
| Longest open screening | |
| Provider delay count |
38. Screening Exceptions Dashboard
| Metric | Result |
|---|---|
| Open Exceptions | |
| High-Risk Exceptions | |
| Critical Exceptions | |
| Expiring Within 30 Days | |
| Expired Exceptions | |
| Average Exception Duration | |
| Exceptions Closed | |
| Repeated Exceptions |
39. Screening Discrepancy Dashboard
| Metric | Result |
|---|---|
| Total Discrepancies | |
| Open Discrepancies | |
| High-Risk Discrepancies | |
| Discrepancies by Category | |
| Average Resolution Time | |
| Repeated Discrepancies |
The purpose is process and risk monitoring, not unnecessary profiling of individuals.
40. Access and Screening Monitoring
Where appropriate, compare screening records against access records.
Check:
☐ Personnel with privileged access have required screening
☐ Production users have required screening
☐ Contractors with sensitive access are appropriately screened
☐ Screening exceptions have corresponding access controls
☐ Departed personnel are removed
☐ Role changes trigger screening reassessment
41. Background Verification Review
Periodically review the register for:
☐ Missing records
☐ Incomplete screening
☐ Expired screening
☐ Overdue screening
☐ Open exceptions
☐ Unresolved discrepancies
☐ High-risk personnel
☐ Privileged personnel
☐ Contractor personnel
☐ Third-party personnel
☐ Re-screening requirements
☐ Data-retention requirements
42. Record Protection
The register itself should be protected.
☐ Restricted access
☐ Role-based permissions
☐ Appropriate classification
☐ Secure storage
☐ Secure transmission
☐ Access logging where appropriate
☐ Backup
☐ Retention period defined
☐ Secure disposal
☐ Privacy requirements addressed
The register should generally contain verification status and management information rather than complete sensitive background reports.
43. Retention
Define retention based on:
- Applicable law
- Employment requirements
- Contractual requirements
- Privacy requirements
- Legal claims/litigation requirements
- Organizational records policy
Retention Period: ______________________
Disposal Requirement
44. Register Change Control
Changes to the register should be traceable where appropriate.
Record:
| Date | Change | Changed By | Reason | Approved By |
|---|---|---|---|---|
Examples:
- New personnel added
- Screening completed
- Exception added
- Result changed
- Role changed
- Re-screening completed
- Record closed
45. Data Quality Review
Periodically confirm:
☐ Personnel IDs are correct
☐ Roles are current
☐ Screening levels are current
☐ Status is accurate
☐ Completion dates are recorded
☐ Exceptions have expiry dates
☐ Review dates are current
☐ Departed personnel are appropriately closed
☐ Duplicate records removed
☐ Unnecessary sensitive data removed
46. Findings
Register process findings where necessary.
| Finding ID | Area | Finding | Risk | Action | Owner | Due Date | Status |
|---|---|---|---|---|---|---|---|
Examples:
- Required screening not recorded
- Screening status inaccurate
- High-risk screening overdue
- Exception expired
- Re-screening not performed
- Register not updated following role change
- Unauthorized access to register
47. Corrective Action
For significant findings:
☐ Root cause identified
☐ Immediate correction performed
☐ Corrective action defined
☐ Owner assigned
☐ Due date established
☐ Evidence requirement defined
☐ Effectiveness review defined
☐ Residual risk assessed
☐ Closure approved
48. Management Reporting
The register can provide management with:
- Screening coverage
- High-risk screening status
- Overdue screening
- Exceptions
- Discrepancies
- Re-screening status
- Contractor screening
- Privileged personnel screening
- Provider performance
- Trends
Management reporting should use aggregated information wherever individual-level detail is unnecessary.
49. AWS SaaS Startup Example
A SaaS startup has:
- 15 employees
- 5 contractors
- 2 AWS administrators
- 3 developers
- 1 security consultant
The register may contain:
| Personnel Type | Role | Risk | Screening | Status |
|---|---|---|---|---|
| Employee | Marketing | Low | Level 1 | Complete |
| Employee | Developer | Medium | Level 2–3 | Complete |
| Employee | AWS Administrator | High | Level 4 | Complete |
| Employee | Security Engineer | High | Level 3–4 | Complete |
| Contractor | VAPT Consultant | High | Level 3–4 | Complete |
| Contractor | Designer | Low | Level 1 | Complete |
The register does not need to contain complete copies of every background-check document.
Instead, it can demonstrate:
Person → Role → Risk → Required Screening → Completion → Result → Approval → Review
50. Startup-Friendly Register Model
For a small organization, start with one master spreadsheet or controlled system containing:
| ID | Person | Type | Role | Risk | Screening Level | Status | Completion | Exception | Next Review |
|---|---|---|---|---|---|---|---|---|---|
Use additional sheets/registers only when needed for:
- Exceptions
- Discrepancies
- Re-screening
- High-risk personnel
- Screening providers
This keeps the process manageable while preserving audit evidence.
51. Common Mistakes
Avoid:
- Treating the register as a storage location for complete background reports
- Storing unnecessary personal information
- Failing to record screening requirements
- Recording only completed screenings and ignoring pending cases
- Not tracking expiry dates
- Not tracking exceptions
- Failing to identify high-risk personnel
- Not linking screening requirements to role risk
- Failing to update the register after role changes
- Ignoring contractor and third-party personnel
- Allowing departed personnel to remain active
- Giving unrestricted access to the register
- Failing to reconcile screening with privileged access
52. Relationship With Other ISMS Documents
| Document | Relationship |
|---|---|
| Employee Screening Policy | Defines screening principles |
| Background Verification Procedure | Defines verification process |
| Role-Based Screening Matrix | Defines screening level by role |
| Employee Screening Checklist | Provides individual screening checklist |
| Contractor Screening Procedure | Defines contractor screening |
| Screening Exception Form | Documents deviations |
| Personnel Security Procedure | Defines personnel-security controls |
| Access Management Procedure | Controls system access |
| Privileged Access Procedure | Controls privileged access |
| Employee Onboarding Procedure | Connects screening to onboarding |
| Employee Offboarding Procedure | Connects screening records to personnel exit |
| Risk Register | Tracks significant personnel-related risks |
53. ISO/IEC 27001 Connection
A Background Verification Register supports the organization’s ability to demonstrate that applicable personnel-screening requirements are identified, performed, reviewed, and monitored.
The organization should determine:
- What screening records are necessary
- Which personnel require screening
- How screening status is monitored
- How exceptions are tracked
- How re-screening is managed
- How sensitive information is protected
- How long records are retained
The Background Verification Register is not itself a universally prescribed ISO/IEC 27001 document. Its design and level of detail should be based on the organization’s ISMS scope, risk assessment, applicable controls, legal requirements, contractual requirements, and personnel-security practices.
54. Audit Evidence Checklist
The organization should be able to provide appropriate evidence such as:
☐ Background Verification Register
☐ Role-Based Screening Matrix
☐ Background Verification Procedure
☐ Employee Screening Policy
☐ Contractor Screening Procedure
☐ Sample completed screening records
☐ Screening requirements
☐ Verification results
☐ Screening approvals
☐ Exception records
☐ Discrepancy records
☐ Re-screening records
☐ Privileged-role screening records
☐ Contractor screening records
☐ Periodic register review
☐ Corrective actions
Sensitive personal information should be minimized and appropriately protected during audits.
55. Final Background Verification Audit Trail
The register should enable the organization to answer:
Who requires screening?
Why is screening required?
What role does the person perform?
What risk level applies?
What screening level applies?
Which checks were required?
Were the checks completed?
Were results reviewed?
Were discrepancies identified?
Were exceptions approved?
Does the person have privileged or sensitive access?
Is re-screening required?
When is the next review due?
Are screening records appropriately protected?
Final Principle
The Background Verification Register is the control point between the organization’s screening requirements and actual personnel records. It should provide enough evidence to demonstrate that the right people were screened at the right level, exceptions were controlled, outstanding actions were tracked, and sensitive screening information was appropriately protected—without becoming an unnecessary repository of personal data.
