ISO/IEC 27001

⌘K
  1. Home
  2. Docs
  3. ISO/IEC 27001
  4. Other Doc
  5. Background Verification Register

Background Verification Register

1. Purpose

The Background Verification Register provides a centralized record of background verification activities performed for employees, contractors, consultants, interns, temporary workers, and other personnel where screening is required.

The register helps the organization demonstrate that:

  • Appropriate screening requirements were identified
  • Screening was completed for applicable personnel
  • Verification results were reviewed
  • Exceptions were documented
  • Outstanding checks were tracked
  • Screening records are protected
  • Re-verification requirements are monitored
  • Screening decisions can be demonstrated during an audit

Core Principle

Identify → Assess → Screen → Verify → Review → Record → Monitor → Reassess


2. Scope

The register may include:

  • Employees
  • Contractors
  • Consultants
  • Freelancers
  • Interns
  • Temporary workers
  • Agency personnel
  • Third-party personnel
  • Security-sensitive personnel
  • Privileged users
  • Personnel requiring enhanced screening

The register should contain only the information necessary to manage the screening process.


3. Register Ownership

Register Owner: __________________________

HR/People Owner: _________________________

Information Security Owner: _______________

Risk Owner: _______________________________

Register Location/System: _________________

Review Frequency: _________________________


4. Master Background Verification Register

Verification IDPersonnel IDPersonnel TypeRoleDepartmentRiskScreening LevelStatusCompletion DateNext Review

Personnel Type

  • Employee
  • Contractor
  • Consultant
  • Intern
  • Temporary Worker
  • Third-Party Personnel

Risk

  • Low
  • Medium
  • High
  • Critical

Screening Level

  • Level 1 – Basic
  • Level 2 – Standard
  • Level 3 – Enhanced
  • Level 4 – High Risk

5. Personnel Information

FieldDetails
Verification ID
Personnel ID
Name/Reference
Personnel Type
Role
Department
Manager
Business Owner
Employment/Engagement Start
Employment/Engagement End
Location/Jurisdiction
Role Risk
Screening Level

Avoid storing unnecessary sensitive personal information in the register.


6. Screening Requirement Register

Record what screening is required for each person.

Verification IDIDEMPEDUREFPROFCR*REG*FIN*COIRTWOther

Use:

  • Required
  • Completed
  • Not Required
  • Pending
  • Exception

* Only where lawful, relevant, and proportionate.


7. Screening Status

Use standardized statuses:

☐ Not Started
☐ Initiated
☐ In Progress
☐ Pending Information
☐ Pending Provider
☐ Pending Review
☐ Discrepancy Identified
☐ Exception Approved
☐ Completed
☐ Completed With Conditions
☐ Re-Screening Required
☐ Closed


8. Identity Verification Register

Verification IDIdentity RequiredSource/ProviderDate CompletedResultReviewer

Possible results:

  • Verified
  • Partially Verified
  • Unable to Verify
  • Discrepancy

Do not unnecessarily store copies of identity documents in the register.


9. Employment Verification Register

Verification IDEmployer/EngagementPeriod VerifiedRole VerifiedResultDateReviewer

Record only information necessary to demonstrate completion and result.


10. Education and Qualification Register

Verification IDQualificationInstitutionVerification DateResultReviewer

For professional certifications:

Verification IDCertificationIssuing BodyValid UntilVerifiedReviewer

11. Professional Reference Register

Verification IDReference TypeReference VerifiedDateResultReviewer

Avoid recording unnecessary personal information about referees.


12. Criminal Record Check Register

Where legally permitted and relevant:

Verification IDRequiredProvider/SourceDateResultReview Status

Use controlled result categories rather than storing unnecessary detailed criminal-record information.

Example:

  • Completed – No Relevant Result
  • Completed – Requires Review
  • Not Required
  • Pending
  • Exception

13. Financial Screening Register

Where lawful and relevant:

Verification IDRequiredProviderDateResultReviewer

Avoid storing detailed financial information unless there is a documented requirement to retain it.


14. Regulatory and Sanctions Screening Register

Verification IDScreening TypeSourceDateResultReviewer

Examples:

  • Sanctions screening
  • Regulatory registration
  • Professional license
  • Industry authorization

15. Right-to-Work Register

Where applicable:

Verification IDRequiredVerifiedExpiryFollow-Up DateStatus

16. Conflict-of-Interest Register

Where applicable:

Verification IDDeclaration RequiredCompletedConflict IdentifiedActionStatus

17. Security-Sensitive Role Register

Identify personnel with heightened security responsibilities.

Verification IDRoleProduction AccessPrivileged AccessRestricted DataScreening LevelStatus

Examples:

  • AWS Administrator
  • System Administrator
  • Database Administrator
  • Security Engineer
  • SOC Analyst
  • VAPT Consultant
  • CISO
  • Source-Code Administrator

18. Privileged User Screening Register

Verification IDUserPrivileged RoleSystemScreening CompleteApprovalReview Date

The register should support correlation between personnel screening and privileged access.


19. Contractor Screening Register

Contractor IDContractorSupplierRoleRiskScreening LevelStatusAccess Expiry

Where suppliers perform screening, record:

☐ Supplier responsible
☐ Attestation received
☐ Evidence reviewed where required
☐ Contractual requirement confirmed


20. Third-Party Personnel Register

Personnel IDSupplierRoleAccessScreening ResponsibilityStatusReview Date

21. Screening Provider Register

Where external providers are used:

ProviderServiceApprovedSecurity ReviewPrivacy ReviewContractStatus

Consider:

  • Provider security
  • Confidentiality
  • Privacy
  • Data location
  • Retention
  • Subprocessors
  • International transfers
  • Data disposal

22. Authorization Register

Track required authorization.

Verification IDAuthorization RequiredObtainedDateMethodReviewer

Authorization should be obtained before performing checks where required.


23. Screening Evidence Register

Verification IDEvidence TypeSourceDateReviewedReviewerLocation

Examples:

  • Employment confirmation
  • Qualification confirmation
  • Professional certification
  • Reference confirmation
  • Screening-provider result
  • Regulatory registration

Do not store passwords, authentication secrets, or other unnecessary sensitive information as screening evidence.


24. Discrepancy Register

Record material discrepancies separately where appropriate.

Discrepancy IDVerification IDAreaDescriptionRiskStatusResolution

Potential areas:

  • Identity
  • Employment
  • Qualification
  • Professional certification
  • Regulatory screening
  • Other relevant information

25. Discrepancy Review

For each material discrepancy:

☐ Source verified
☐ Accuracy assessed
☐ Materiality assessed
☐ Role relevance assessed
☐ Explanation obtained where appropriate
☐ Additional verification performed
☐ Security impact assessed
☐ Legal/privacy considerations reviewed
☐ Decision documented


26. Screening Exception Register

Exception IDVerification IDMissing CheckReasonRiskCompensating ControlExpiryStatus

Track:

  • Exception reason
  • Risk
  • Approval
  • Compensating controls
  • Expiry
  • Resolution

27. Screening Exception Status

☐ Open
☐ Under Review
☐ Approved
☐ Approved With Conditions
☐ Expiring Soon
☐ Expired
☐ Resolved
☐ Closed

Expired exceptions should be escalated and reviewed.


28. Screening Decision Register

Verification IDResultConditionsDecision MakerDecision DateStatus

Possible results:

  • Satisfactory
  • Satisfactory With Conditions
  • Further Verification Required
  • Exception Required
  • Not Approved
  • Unable to Complete

29. Access Dependency

Where screening is a prerequisite for access:

Verification IDSystemAccess TypeScreening CompleteAccess ApprovedAccess Date

This helps demonstrate that required screening was considered before sensitive access was granted.


30. Screening Before Privileged Access

For privileged users:

☐ Screening requirement identified
☐ Required verification completed
☐ Results reviewed
☐ Security approval obtained
☐ Privileged access approved
☐ MFA enabled
☐ Least privilege applied
☐ Access review scheduled


31. Pending Screening Register

Track incomplete screening.

Verification IDPersonnelRoleMissing RequirementReasonOwnerDue DateStatus

This should be reviewed regularly.


32. Overdue Screening Register

Verification IDPersonnelRoleRequirementDue DateDays OverdueRiskAction

High-risk overdue screening should be escalated according to the organization’s risk process.


33. Re-Screening Register

Where periodic or event-driven re-screening applies:

Verification IDPersonnelRoleTriggerRequired DateCompletedResultNext Review

Possible triggers:

  • Periodic review
  • Role change
  • Privileged access
  • Regulatory requirement
  • Customer requirement
  • Security concern
  • Contract extension

34. Role Change Screening

Personnel IDPrevious RoleNew RoleRisk ChangeAdditional ScreeningCompletionApproval

The organization should reassess screening when role responsibilities or access materially change.


35. Screening Completion Dashboard

Track:

MetricCount
Total Personnel Requiring Screening
Completed
In Progress
Pending
Overdue
Exceptions
High-Risk Personnel
High-Risk Screening Completed
Re-Screening Due
Re-Screening Overdue
Discrepancies
Open Discrepancies

36. Screening Coverage

Calculate:

Screening Coverage % = Completed Required Screenings ÷ Total Required Screenings × 100

Result

__________ %

For high-risk personnel, consider maintaining a separate coverage metric.

High-Risk Screening Coverage

__________ %


37. Screening Timeliness

Track:

  • Average screening completion time
  • Average time by screening provider
  • Average time by screening level
  • Number of overdue screenings
  • Number of provider-related delays

Metrics

MetricResult
Average completion time
Median completion time
Overdue screening count
Longest open screening
Provider delay count

38. Screening Exceptions Dashboard

MetricResult
Open Exceptions
High-Risk Exceptions
Critical Exceptions
Expiring Within 30 Days
Expired Exceptions
Average Exception Duration
Exceptions Closed
Repeated Exceptions

39. Screening Discrepancy Dashboard

MetricResult
Total Discrepancies
Open Discrepancies
High-Risk Discrepancies
Discrepancies by Category
Average Resolution Time
Repeated Discrepancies

The purpose is process and risk monitoring, not unnecessary profiling of individuals.


40. Access and Screening Monitoring

Where appropriate, compare screening records against access records.

Check:

☐ Personnel with privileged access have required screening
☐ Production users have required screening
☐ Contractors with sensitive access are appropriately screened
☐ Screening exceptions have corresponding access controls
☐ Departed personnel are removed
☐ Role changes trigger screening reassessment


41. Background Verification Review

Periodically review the register for:

☐ Missing records
☐ Incomplete screening
☐ Expired screening
☐ Overdue screening
☐ Open exceptions
☐ Unresolved discrepancies
☐ High-risk personnel
☐ Privileged personnel
☐ Contractor personnel
☐ Third-party personnel
☐ Re-screening requirements
☐ Data-retention requirements


42. Record Protection

The register itself should be protected.

☐ Restricted access
☐ Role-based permissions
☐ Appropriate classification
☐ Secure storage
☐ Secure transmission
☐ Access logging where appropriate
☐ Backup
☐ Retention period defined
☐ Secure disposal
☐ Privacy requirements addressed

The register should generally contain verification status and management information rather than complete sensitive background reports.


43. Retention

Define retention based on:

  • Applicable law
  • Employment requirements
  • Contractual requirements
  • Privacy requirements
  • Legal claims/litigation requirements
  • Organizational records policy

Retention Period: ______________________

Disposal Requirement


44. Register Change Control

Changes to the register should be traceable where appropriate.

Record:

DateChangeChanged ByReasonApproved By

Examples:

  • New personnel added
  • Screening completed
  • Exception added
  • Result changed
  • Role changed
  • Re-screening completed
  • Record closed

45. Data Quality Review

Periodically confirm:

☐ Personnel IDs are correct
☐ Roles are current
☐ Screening levels are current
☐ Status is accurate
☐ Completion dates are recorded
☐ Exceptions have expiry dates
☐ Review dates are current
☐ Departed personnel are appropriately closed
☐ Duplicate records removed
☐ Unnecessary sensitive data removed


46. Findings

Register process findings where necessary.

Finding IDAreaFindingRiskActionOwnerDue DateStatus

Examples:

  • Required screening not recorded
  • Screening status inaccurate
  • High-risk screening overdue
  • Exception expired
  • Re-screening not performed
  • Register not updated following role change
  • Unauthorized access to register

47. Corrective Action

For significant findings:

☐ Root cause identified
☐ Immediate correction performed
☐ Corrective action defined
☐ Owner assigned
☐ Due date established
☐ Evidence requirement defined
☐ Effectiveness review defined
☐ Residual risk assessed
☐ Closure approved


48. Management Reporting

The register can provide management with:

  • Screening coverage
  • High-risk screening status
  • Overdue screening
  • Exceptions
  • Discrepancies
  • Re-screening status
  • Contractor screening
  • Privileged personnel screening
  • Provider performance
  • Trends

Management reporting should use aggregated information wherever individual-level detail is unnecessary.


49. AWS SaaS Startup Example

A SaaS startup has:

  • 15 employees
  • 5 contractors
  • 2 AWS administrators
  • 3 developers
  • 1 security consultant

The register may contain:

Personnel TypeRoleRiskScreeningStatus
EmployeeMarketingLowLevel 1Complete
EmployeeDeveloperMediumLevel 2–3Complete
EmployeeAWS AdministratorHighLevel 4Complete
EmployeeSecurity EngineerHighLevel 3–4Complete
ContractorVAPT ConsultantHighLevel 3–4Complete
ContractorDesignerLowLevel 1Complete

The register does not need to contain complete copies of every background-check document.

Instead, it can demonstrate:

Person → Role → Risk → Required Screening → Completion → Result → Approval → Review


50. Startup-Friendly Register Model

For a small organization, start with one master spreadsheet or controlled system containing:

IDPersonTypeRoleRiskScreening LevelStatusCompletionExceptionNext Review

Use additional sheets/registers only when needed for:

  • Exceptions
  • Discrepancies
  • Re-screening
  • High-risk personnel
  • Screening providers

This keeps the process manageable while preserving audit evidence.


51. Common Mistakes

Avoid:

  • Treating the register as a storage location for complete background reports
  • Storing unnecessary personal information
  • Failing to record screening requirements
  • Recording only completed screenings and ignoring pending cases
  • Not tracking expiry dates
  • Not tracking exceptions
  • Failing to identify high-risk personnel
  • Not linking screening requirements to role risk
  • Failing to update the register after role changes
  • Ignoring contractor and third-party personnel
  • Allowing departed personnel to remain active
  • Giving unrestricted access to the register
  • Failing to reconcile screening with privileged access

52. Relationship With Other ISMS Documents

DocumentRelationship
Employee Screening PolicyDefines screening principles
Background Verification ProcedureDefines verification process
Role-Based Screening MatrixDefines screening level by role
Employee Screening ChecklistProvides individual screening checklist
Contractor Screening ProcedureDefines contractor screening
Screening Exception FormDocuments deviations
Personnel Security ProcedureDefines personnel-security controls
Access Management ProcedureControls system access
Privileged Access ProcedureControls privileged access
Employee Onboarding ProcedureConnects screening to onboarding
Employee Offboarding ProcedureConnects screening records to personnel exit
Risk RegisterTracks significant personnel-related risks

53. ISO/IEC 27001 Connection

A Background Verification Register supports the organization’s ability to demonstrate that applicable personnel-screening requirements are identified, performed, reviewed, and monitored.

The organization should determine:

  • What screening records are necessary
  • Which personnel require screening
  • How screening status is monitored
  • How exceptions are tracked
  • How re-screening is managed
  • How sensitive information is protected
  • How long records are retained

The Background Verification Register is not itself a universally prescribed ISO/IEC 27001 document. Its design and level of detail should be based on the organization’s ISMS scope, risk assessment, applicable controls, legal requirements, contractual requirements, and personnel-security practices.


54. Audit Evidence Checklist

The organization should be able to provide appropriate evidence such as:

☐ Background Verification Register
☐ Role-Based Screening Matrix
☐ Background Verification Procedure
☐ Employee Screening Policy
☐ Contractor Screening Procedure
☐ Sample completed screening records
☐ Screening requirements
☐ Verification results
☐ Screening approvals
☐ Exception records
☐ Discrepancy records
☐ Re-screening records
☐ Privileged-role screening records
☐ Contractor screening records
☐ Periodic register review
☐ Corrective actions

Sensitive personal information should be minimized and appropriately protected during audits.


55. Final Background Verification Audit Trail

The register should enable the organization to answer:

Who requires screening?
Why is screening required?
What role does the person perform?
What risk level applies?
What screening level applies?
Which checks were required?
Were the checks completed?
Were results reviewed?
Were discrepancies identified?
Were exceptions approved?
Does the person have privileged or sensitive access?
Is re-screening required?
When is the next review due?
Are screening records appropriately protected?

Final Principle

The Background Verification Register is the control point between the organization’s screening requirements and actual personnel records. It should provide enough evidence to demonstrate that the right people were screened at the right level, exceptions were controlled, outstanding actions were tracked, and sensitive screening information was appropriately protected—without becoming an unnecessary repository of personal data.