1. Purpose
The Contractor Screening Procedure defines how the organization identifies, assesses, performs, reviews, and records background screening for contractors and other non-employee personnel who may perform services on behalf of the organization.
The objective is to ensure that contractors:
- Are appropriately identified and verified
- Receive screening proportionate to their role and risk
- Meet applicable contractual and security requirements
- Are appropriately screened before receiving sensitive access where required
- Have their information handled securely
- Have screening results reviewed and documented
- Are subject to appropriate controls throughout the engagement
- Are appropriately reassessed when their role or access changes
Core Principle
Identify Contractor → Assess Role Risk → Define Screening → Verify → Review → Approve → Grant Access → Monitor → Reassess → Offboard
2. Scope
This procedure applies to:
- Independent contractors
- Consultants
- Freelancers
- Temporary workers
- Contract employees
- Agency personnel
- Professional service providers
- Security consultants
- VAPT personnel
- vCISO personnel
- Outsourced IT personnel
- Managed service personnel
- Third-party personnel with organizational access
It applies whether the contractor works:
- Remotely
- On-site
- From a supplier location
- From another country
- Through a contracting agency
3. Contractor Screening Information
| Field | Details |
|---|---|
| Contractor ID | |
| Name | |
| Contracting Company | |
| Role | |
| Department | |
| Business Owner | |
| Supplier Owner | |
| Contract Start Date | |
| Contract End Date | |
| Role Risk | |
| Screening Level | |
| Screening Provider | |
| Screening Completed | |
| Access Required | |
| Privileged Access | |
| Reviewer | |
| Approval Status |
4. Contractor Classification
Classify the contractor:
☐ Independent Contractor
☐ Consultant
☐ Freelancer
☐ Agency Worker
☐ Temporary Worker
☐ Contract Employee
☐ Managed Service Personnel
☐ Security Consultant
☐ VAPT Consultant
☐ Other: ______________________
5. Contractor Role Assessment
Before screening, determine:
☐ Services to be provided
☐ Responsibilities
☐ Business process supported
☐ Information accessed
☐ Systems accessed
☐ Customer information accessed
☐ Personal data accessed
☐ Source-code access
☐ Production access
☐ Privileged access
☐ Cloud access
☐ Security responsibilities
☐ Physical access
☐ Regulatory responsibilities
Business Purpose
6. Contractor Risk Assessment
Assess the contractor based on:
Information Risk
☐ Public
☐ Internal
☐ Confidential
☐ Restricted
Access Risk
☐ No system access
☐ Standard user access
☐ Sensitive application access
☐ Source-code access
☐ Production access
☐ Privileged access
Business Risk
☐ Non-critical service
☐ Important business service
☐ Critical business service
☐ Customer-facing activity
Risk Level
☐ Low
☐ Medium
☐ High
☐ Critical
Risk Rationale
7. Screening Level
Example:
| Level | Typical Requirement |
|---|---|
| Level 1 – Basic | Identity and basic verification |
| Level 2 – Standard | Identity, employment/engagement, qualification and references where relevant |
| Level 3 – Enhanced | Standard checks plus role-specific checks |
| Level 4 – High Risk | Enhanced verification plus additional review and approval |
The organization should determine the final screening level using its own risk methodology and applicable requirements.
8. Contractor Identity Verification
Before engagement:
☐ Identity verified
☐ Identity document/source appropriate
☐ Name verified
☐ Contact information verified
☐ Contracting organization verified where applicable
☐ Verification date recorded
☐ Discrepancies reviewed
9. Contractor Employment/Engagement Verification
Where relevant:
☐ Current employer/agency verified
☐ Previous engagement verified
☐ Relevant experience verified
☐ Engagement dates verified
☐ Role/responsibilities verified
☐ Significant discrepancies reviewed
For independent contractors, verify relevant professional or business information instead of relying on traditional employment verification.
10. Qualification Verification
Where relevant:
☐ Required qualification identified
☐ Certification verified
☐ Professional license verified
☐ Registration verified
☐ Certification validity checked
☐ Relevant experience verified
☐ Evidence reviewed
This is particularly relevant for:
- Security consultants
- Auditors
- VAPT testers
- Cloud specialists
- Regulated professionals
- Technical specialists
11. Professional References
Where appropriate:
☐ Reference requirement established
☐ Reference identity verified
☐ Relevant professional relationship confirmed
☐ Reference obtained
☐ Response reviewed
☐ Material concerns documented
☐ Result recorded
12. Criminal Record Checks
Where lawful and relevant:
☐ Requirement assessed
☐ Legal requirements reviewed
☐ Authorization obtained where required
☐ Appropriate provider/source used
☐ Check completed
☐ Result reviewed
☐ Potential match investigated
☐ Decision documented
Criminal-record checks should be role-based, proportionate, and legally permissible.
13. Financial Checks
Where legally permissible and relevant:
☐ Financial responsibility identified
☐ Requirement assessed
☐ Authorization obtained
☐ Check completed
☐ Result reviewed
☐ Material issue assessed
☐ Decision documented
Financial checks should not be automatically applied to all contractors.
14. Regulatory and Sanctions Screening
Where applicable:
☐ Regulatory requirement identified
☐ Sanctions screening completed
☐ Professional registration checked
☐ License checked
☐ Regulatory status verified
☐ Potential match investigated
☐ False positive resolved
☐ Evidence recorded
15. Security-Sensitive Contractors
Enhanced screening may be appropriate for contractors who:
- Administer production systems
- Manage cloud infrastructure
- Perform security operations
- Conduct VAPT
- Manage source code
- Access customer information
- Access restricted information
- Manage security infrastructure
- Manage cryptographic keys
- Perform security audits
- Provide vCISO services
For such contractors:
☐ Role risk assessed
☐ Screening level approved
☐ Required verification completed
☐ Security responsibilities documented
☐ NDA/confidentiality requirements completed
☐ Access requirements defined
☐ Security approval obtained
16. VAPT Contractor Screening
Before providing testing access:
☐ Contractor identity verified
☐ Organization verified
☐ Relevant experience verified
☐ Relevant certifications verified where required
☐ Professional references considered
☐ NDA completed
☐ Statement of Work approved
☐ Testing scope approved
☐ Testing window defined
☐ Temporary accounts created
☐ MFA enabled
☐ Access expiry defined
☐ Testing credentials restricted
☐ Report handling requirements defined
17. Cloud/Production Contractor Screening
For contractors requiring production or cloud access:
☐ Production requirement documented
☐ Business justification documented
☐ Risk assessment completed
☐ Required screening completed
☐ Security approval obtained
☐ Named account required
☐ MFA enabled
☐ Least privilege applied
☐ Privileged access separately approved
☐ Session/activity logging enabled where appropriate
☐ Access expiry established
☐ Periodic review scheduled
18. Contractor Personnel Supplied by a Vendor
Where a supplier provides personnel:
☐ Supplier screening responsibility defined
☐ Screening requirements included in contract
☐ Supplier confirms required screening
☐ Evidence/attestation obtained where appropriate
☐ High-risk personnel separately assessed
☐ Personnel changes communicated
☐ Replacement personnel screened
☐ Access revoked for departing personnel
The organization should not assume that supplier personnel have been screened merely because the supplier states that screening is part of its general HR process.
19. Contractor Screening Responsibility
Define who performs the screening.
| Screening Activity | Organization | Supplier | Contractor | Other |
|---|---|---|---|---|
| Identity verification | ||||
| Employment verification | ||||
| Qualification verification | ||||
| Reference check | ||||
| Regulatory check | ||||
| Security review | ||||
| Final approval |
Responsibilities should be clearly defined before access is granted.
20. Evidence and Attestation
Where the supplier performs screening:
☐ Screening requirements documented
☐ Supplier attestation obtained where appropriate
☐ Scope of screening confirmed
☐ Screening completion date confirmed
☐ Exceptions disclosed
☐ Re-screening requirements defined
☐ Evidence requirements agreed
Avoid collecting unnecessary copies of sensitive personal records.
21. Contractor Authorization
Before screening:
☐ Purpose defined
☐ Required checks defined
☐ Appropriate authorization/consent obtained where required
☐ Privacy information provided where applicable
☐ Screening scope communicated
☐ Provider approved
☐ Applicable legal requirements considered
22. Privacy and Personal Data
Contractor screening may involve sensitive personal information.
Ensure:
☐ Minimum necessary information collected
☐ Purpose defined
☐ Appropriate lawful processing mechanism identified
☐ Access restricted
☐ Information securely stored
☐ Information securely transmitted
☐ Retention period defined
☐ Secure disposal defined
☐ Third-party processing addressed where applicable
☐ International transfers assessed where applicable
23. Screening Evidence Review
The reviewer should confirm:
☐ Evidence relates to the correct contractor
☐ Evidence is from an appropriate source
☐ Evidence is sufficiently reliable
☐ Evidence is current
☐ Required checks are complete
☐ Material discrepancies are addressed
☐ Result supports the screening decision
Evidence Review
24. Contractor Screening Result
Result
☐ Satisfactory
☐ Satisfactory With Conditions
☐ Further Verification Required
☐ Discrepancy Under Review
☐ Exception Required
☐ Not Approved
☐ Unable to Complete
Reviewer Comments
25. Contractor Access Before Screening Completion
As a general principle, required screening should be completed before granting sensitive or privileged access.
If business requirements require early access:
☐ Business justification documented
☐ Risk assessed
☐ Access minimized
☐ Temporary access used
☐ MFA enabled
☐ Privileged access restricted
☐ Expiry established
☐ Compensating controls defined
☐ Approval obtained
☐ Screening completion tracked
26. Contractor Access Management
After screening approval:
☐ Access request approved
☐ Named account created
☐ Shared accounts prohibited unless specifically justified
☐ MFA enabled
☐ Least privilege applied
☐ Access scope documented
☐ Production access separately approved
☐ Privileged access separately approved
☐ Access expiry recorded
☐ Monitoring established where appropriate
27. Temporary Contractor Access
Where access is temporary:
| System | Access | Start | Expiry | Approver | Status |
|---|---|---|---|---|---|
Temporary access should have a defined end date wherever practical.
28. Contractor Access Review
Periodically verify:
☐ Contractor still engaged
☐ Business need still exists
☐ Access still required
☐ Access remains appropriate
☐ Privileged access still justified
☐ Expiry dates remain valid
☐ Contractor role has not changed
☐ Screening remains appropriate
29. Contractor Role Change
When responsibilities change:
☐ New role assessed
☐ Information access reassessed
☐ System access reassessed
☐ Risk reassessed
☐ Screening requirements reassessed
☐ Additional screening completed where required
☐ New access approved
☐ Previous access removed where no longer required
30. Replacement Contractor
When a contractor is replaced:
☐ Previous contractor identified
☐ Previous access scheduled for removal
☐ New contractor screened
☐ New contractor approved
☐ New accounts created
☐ Old accounts disabled
☐ Credentials/tokens rotated where required
☐ Handover completed securely
Never transfer a contractor’s personal account to another individual.
31. Contractor Screening Exceptions
If required screening cannot be completed:
☐ Reason documented
☐ Missing check identified
☐ Risk assessed
☐ Compensating controls defined
☐ Access restrictions established
☐ Approver identified
☐ Expiry/review date defined
☐ Exception recorded
Exceptions should be temporary and monitored.
32. Contractor Security Responsibilities
Before access is provided, communicate applicable requirements:
☐ Information-security policy
☐ Acceptable use requirements
☐ Confidentiality requirements
☐ Access requirements
☐ MFA requirements
☐ Data-handling requirements
☐ Incident-reporting requirements
☐ Remote-working requirements
☐ Secure development requirements where applicable
☐ Customer-data handling requirements
☐ Security testing restrictions where applicable
33. Contractor Confidentiality
Where required:
☐ NDA executed
☐ Confidential information defined
☐ Permitted use defined
☐ Disclosure restrictions defined
☐ Return/deletion requirements defined
☐ Confidentiality survives termination where applicable
34. Contractor Security Incidents
Contractors must report security incidents according to the organization’s incident-management requirements.
Examples:
- Lost device
- Credential compromise
- Unauthorized access
- Data leakage
- Malware infection
- Phishing
- Security testing outside approved scope
- Accidental disclosure
- Suspected customer-data exposure
☐ Incident reporting requirement communicated
☐ Security contact provided
☐ Escalation process defined
☐ Evidence preservation requirements communicated
35. Contractor Offboarding
At the end of the engagement:
☐ Contract end confirmed
☐ Business owner notified
☐ Access inventory reviewed
☐ User accounts disabled
☐ Privileged access revoked
☐ Cloud access removed
☐ VPN access removed
☐ Source-code access removed
☐ CI/CD access removed
☐ API tokens revoked
☐ SSH keys addressed
☐ Certificates addressed
☐ Assets returned
☐ Information returned/deleted where required
☐ Supplier notified where applicable
☐ Secrets rotated where necessary
☐ Offboarding evidence retained
Exit Principle
Revoke → Return/Delete → Verify → Record → Close
36. Contractor Screening Register
Maintain an appropriate register.
| Contractor ID | Contractor | Role | Risk | Level | Screening Status | Access Status | Review Date |
|---|---|---|---|---|---|---|---|
The register should not contain unnecessary sensitive personal information.
37. Findings
Record screening or contractor-security findings.
| Finding ID | Area | Finding | Risk | Action | Owner | Due Date | Status |
|---|---|---|---|---|---|---|---|
Examples:
- Contractor granted access before required screening
- Screening evidence unavailable
- Supplier screening responsibility unclear
- Contractor access not expired
- Privileged access not separately approved
- Departed contractor account still active
38. Corrective Action
For significant findings:
☐ Root cause identified
☐ Immediate correction performed
☐ Corrective action defined
☐ Owner assigned
☐ Due date assigned
☐ Remediation evidence required
☐ Effectiveness verification defined
☐ Residual risk assessed
☐ Closure approved
39. Contractor Risk Review
Assess the complete relationship:
Contractor → Service → Information → Access → Dependency → Threat → Vulnerability → Impact → Risk → Controls → Residual Risk
Risk Assessment
Risk Treatment
40. Management Approval
Where required:
Business Owner: ______________________
Supplier Owner: ______________________
HR/People Owner: _____________________
Information Security: _________________
Legal/Privacy: ________________________
Risk Owner: __________________________
Approver: ____________________________
Date: ________________________________
41. Periodic Review
Review contractor screening requirements based on:
☐ Contract duration
☐ Role risk
☐ Information sensitivity
☐ Access level
☐ Privileged access
☐ Customer requirements
☐ Regulatory requirements
☐ Security incidents
☐ Role changes
☐ Supplier changes
☐ Re-screening requirements
42. Re-Screening Triggers
Reassessment may be required following:
☐ Significant role change
☐ New privileged access
☐ New production access
☐ New sensitive information
☐ Contract extension
☐ Regulatory requirement
☐ Customer requirement
☐ Security incident
☐ Significant concern regarding contractor suitability
☐ Change in contracting organization
☐ Long-term engagement requiring periodic review
43. AWS SaaS Startup Example
Consider an AWS SaaS startup engaging an external DevOps contractor.
Contractor Responsibilities
- AWS infrastructure
- CI/CD
- Infrastructure-as-Code
- Production deployments
- Monitoring
Risk
High because the contractor may have:
- Production access
- Cloud administrative access
- Source-code access
- CI/CD access
- Infrastructure access
Required Controls
☐ Identity verification
☐ Relevant employment/engagement verification
☐ Technical qualification verification where relevant
☐ Professional references
☐ Additional lawful screening where appropriate
☐ NDA
☐ Defined Statement of Work
☐ Named AWS account
☐ MFA
☐ Least privilege
☐ Temporary/expiring access
☐ Privileged-access approval
☐ Logging
☐ Periodic access review
☐ Offboarding plan
Audit Trail
Business Need → Contractor Risk → Screening → Approval → Contract → Access → Monitoring → Review → Offboarding
44. Startup-Friendly Contractor Screening Model
Low-Risk Contractor
Examples:
- Graphic designer
- Content writer
- General administrative support
Focus on:
- Identity
- Engagement verification
- Confidentiality
- Basic access controls
Medium-Risk Contractor
Examples:
- Developer
- HR consultant
- Finance consultant
- Customer-support contractor
Add:
- Employment/engagement verification
- Qualifications where relevant
- References
- Information-security requirements
- Access review
High/Critical-Risk Contractor
Examples:
- AWS administrator
- Security consultant
- VAPT provider
- Production engineer
- Database administrator
Add:
- Enhanced screening
- Relevant professional verification
- Additional lawful checks where appropriate
- Security approval
- Privileged-access controls
- Temporary access
- Strong authentication
- Periodic review
- Formal offboarding
45. Common Mistakes
Avoid:
- Assuming contractors do not require screening
- Treating supplier employment checks as sufficient without defining requirements
- Granting access before required verification
- Giving contractors employee-level access by default
- Using shared accounts
- Allowing permanent contractor access
- Failing to define screening responsibility
- Failing to screen replacement personnel
- Ignoring subcontractors
- Failing to revoke access at contract termination
- Failing to rotate credentials after privileged contractor access
- Collecting excessive personal information
- Retaining sensitive screening information indefinitely
- Performing unlawful or irrelevant checks
46. Relationship With Other ISMS Documents
| Document | Relationship |
|---|---|
| Employee Screening Policy | Establishes general screening principles |
| Background Verification Procedure | Defines verification activities |
| Role-Based Screening Matrix | Determines screening requirements by role |
| Supplier Security Requirements | Defines third-party security requirements |
| Supplier Due Diligence Checklist | Assesses the supplier organization |
| Supplier Security Addendum | Establishes contractual requirements |
| Contractor Access Procedure | Controls contractor access |
| Access Management Procedure | Controls system access |
| Privileged Access Procedure | Controls privileged access |
| Supplier Offboarding Checklist | Supports supplier/contractor exit |
| Incident Management Procedure | Handles contractor security incidents |
| Information Security Exception Register | Records approved exceptions |
| Risk Assessment | Assesses contractor-related risk |
47. ISO/IEC 27001 Connection
Contractor screening supports the organization’s personnel-security and supplier-security risk management.
The organization should determine:
- Which contractors require screening
- What level of screening is appropriate
- Who is responsible for performing the checks
- What evidence is required
- When screening must be completed
- What access restrictions apply
- How contractor changes are handled
- When re-screening is required
- How contractor offboarding is performed
The Contractor Screening Procedure is not itself a universally prescribed ISO/IEC 27001 document. The organization’s requirements should be based on its ISMS scope, risk assessment, applicable controls, contractual requirements, legal requirements, customer requirements, and the contractor’s actual responsibilities and access.
48. Audit Evidence Checklist
Maintain appropriate evidence such as:
☐ Contractor Screening Procedure
☐ Contractor screening requirements
☐ Role-Based Screening Matrix
☐ Contractor risk assessment
☐ Screening records
☐ Supplier screening attestation where applicable
☐ Verification evidence
☐ NDA/confidentiality agreement
☐ Contract/SOW
☐ Access approvals
☐ Privileged access approvals
☐ Access review records
☐ Exceptions
☐ Security training/acknowledgement
☐ Contractor incident records
☐ Offboarding evidence
☐ Credential/token revocation evidence
☐ Periodic review records
Avoid exposing unnecessary personal or confidential information during audits.
49. Final Contractor Screening Audit Trail
For each security-relevant contractor, the organization should be able to demonstrate:
Why is the contractor required?
What service will they provide?
What information will they access?
What systems will they access?
Will they have privileged or production access?
What is the contractor’s risk level?
What screening is required?
Who is responsible for performing the screening?
Was the screening completed before sensitive access?
What evidence supports the result?
Who approved the contractor?
How is contractor access monitored?
What happens when the contractor’s role changes?
What happens when the contract ends?
Final Principle
Contractor screening is not simply an HR background check. It is a risk-based security process connecting the contractor’s business need, responsibilities, information exposure, access, screening, contractual requirements, approval, monitoring, and secure offboarding into one defensible audit trail.
