ISO/IEC 27001

⌘K
  1. Home
  2. Docs
  3. ISO/IEC 27001
  4. Other Doc
  5. Contractor Screening Procedure

Contractor Screening Procedure

1. Purpose

The Contractor Screening Procedure defines how the organization identifies, assesses, performs, reviews, and records background screening for contractors and other non-employee personnel who may perform services on behalf of the organization.

The objective is to ensure that contractors:

  • Are appropriately identified and verified
  • Receive screening proportionate to their role and risk
  • Meet applicable contractual and security requirements
  • Are appropriately screened before receiving sensitive access where required
  • Have their information handled securely
  • Have screening results reviewed and documented
  • Are subject to appropriate controls throughout the engagement
  • Are appropriately reassessed when their role or access changes

Core Principle

Identify Contractor → Assess Role Risk → Define Screening → Verify → Review → Approve → Grant Access → Monitor → Reassess → Offboard


2. Scope

This procedure applies to:

  • Independent contractors
  • Consultants
  • Freelancers
  • Temporary workers
  • Contract employees
  • Agency personnel
  • Professional service providers
  • Security consultants
  • VAPT personnel
  • vCISO personnel
  • Outsourced IT personnel
  • Managed service personnel
  • Third-party personnel with organizational access

It applies whether the contractor works:

  • Remotely
  • On-site
  • From a supplier location
  • From another country
  • Through a contracting agency

3. Contractor Screening Information

FieldDetails
Contractor ID
Name
Contracting Company
Role
Department
Business Owner
Supplier Owner
Contract Start Date
Contract End Date
Role Risk
Screening Level
Screening Provider
Screening Completed
Access Required
Privileged Access
Reviewer
Approval Status

4. Contractor Classification

Classify the contractor:

☐ Independent Contractor
☐ Consultant
☐ Freelancer
☐ Agency Worker
☐ Temporary Worker
☐ Contract Employee
☐ Managed Service Personnel
☐ Security Consultant
☐ VAPT Consultant
☐ Other: ______________________


5. Contractor Role Assessment

Before screening, determine:

☐ Services to be provided
☐ Responsibilities
☐ Business process supported
☐ Information accessed
☐ Systems accessed
☐ Customer information accessed
☐ Personal data accessed
☐ Source-code access
☐ Production access
☐ Privileged access
☐ Cloud access
☐ Security responsibilities
☐ Physical access
☐ Regulatory responsibilities

Business Purpose


6. Contractor Risk Assessment

Assess the contractor based on:

Information Risk

☐ Public
☐ Internal
☐ Confidential
☐ Restricted

Access Risk

☐ No system access
☐ Standard user access
☐ Sensitive application access
☐ Source-code access
☐ Production access
☐ Privileged access

Business Risk

☐ Non-critical service
☐ Important business service
☐ Critical business service
☐ Customer-facing activity

Risk Level

☐ Low
☐ Medium
☐ High
☐ Critical

Risk Rationale


7. Screening Level

Example:

LevelTypical Requirement
Level 1 – BasicIdentity and basic verification
Level 2 – StandardIdentity, employment/engagement, qualification and references where relevant
Level 3 – EnhancedStandard checks plus role-specific checks
Level 4 – High RiskEnhanced verification plus additional review and approval

The organization should determine the final screening level using its own risk methodology and applicable requirements.


8. Contractor Identity Verification

Before engagement:

☐ Identity verified
☐ Identity document/source appropriate
☐ Name verified
☐ Contact information verified
☐ Contracting organization verified where applicable
☐ Verification date recorded
☐ Discrepancies reviewed


9. Contractor Employment/Engagement Verification

Where relevant:

☐ Current employer/agency verified
☐ Previous engagement verified
☐ Relevant experience verified
☐ Engagement dates verified
☐ Role/responsibilities verified
☐ Significant discrepancies reviewed

For independent contractors, verify relevant professional or business information instead of relying on traditional employment verification.


10. Qualification Verification

Where relevant:

☐ Required qualification identified
☐ Certification verified
☐ Professional license verified
☐ Registration verified
☐ Certification validity checked
☐ Relevant experience verified
☐ Evidence reviewed

This is particularly relevant for:

  • Security consultants
  • Auditors
  • VAPT testers
  • Cloud specialists
  • Regulated professionals
  • Technical specialists

11. Professional References

Where appropriate:

☐ Reference requirement established
☐ Reference identity verified
☐ Relevant professional relationship confirmed
☐ Reference obtained
☐ Response reviewed
☐ Material concerns documented
☐ Result recorded


12. Criminal Record Checks

Where lawful and relevant:

☐ Requirement assessed
☐ Legal requirements reviewed
☐ Authorization obtained where required
☐ Appropriate provider/source used
☐ Check completed
☐ Result reviewed
☐ Potential match investigated
☐ Decision documented

Criminal-record checks should be role-based, proportionate, and legally permissible.


13. Financial Checks

Where legally permissible and relevant:

☐ Financial responsibility identified
☐ Requirement assessed
☐ Authorization obtained
☐ Check completed
☐ Result reviewed
☐ Material issue assessed
☐ Decision documented

Financial checks should not be automatically applied to all contractors.


14. Regulatory and Sanctions Screening

Where applicable:

☐ Regulatory requirement identified
☐ Sanctions screening completed
☐ Professional registration checked
☐ License checked
☐ Regulatory status verified
☐ Potential match investigated
☐ False positive resolved
☐ Evidence recorded


15. Security-Sensitive Contractors

Enhanced screening may be appropriate for contractors who:

  • Administer production systems
  • Manage cloud infrastructure
  • Perform security operations
  • Conduct VAPT
  • Manage source code
  • Access customer information
  • Access restricted information
  • Manage security infrastructure
  • Manage cryptographic keys
  • Perform security audits
  • Provide vCISO services

For such contractors:

☐ Role risk assessed
☐ Screening level approved
☐ Required verification completed
☐ Security responsibilities documented
☐ NDA/confidentiality requirements completed
☐ Access requirements defined
☐ Security approval obtained


16. VAPT Contractor Screening

Before providing testing access:

☐ Contractor identity verified
☐ Organization verified
☐ Relevant experience verified
☐ Relevant certifications verified where required
☐ Professional references considered
☐ NDA completed
☐ Statement of Work approved
☐ Testing scope approved
☐ Testing window defined
☐ Temporary accounts created
☐ MFA enabled
☐ Access expiry defined
☐ Testing credentials restricted
☐ Report handling requirements defined


17. Cloud/Production Contractor Screening

For contractors requiring production or cloud access:

☐ Production requirement documented
☐ Business justification documented
☐ Risk assessment completed
☐ Required screening completed
☐ Security approval obtained
☐ Named account required
☐ MFA enabled
☐ Least privilege applied
☐ Privileged access separately approved
☐ Session/activity logging enabled where appropriate
☐ Access expiry established
☐ Periodic review scheduled


18. Contractor Personnel Supplied by a Vendor

Where a supplier provides personnel:

☐ Supplier screening responsibility defined
☐ Screening requirements included in contract
☐ Supplier confirms required screening
☐ Evidence/attestation obtained where appropriate
☐ High-risk personnel separately assessed
☐ Personnel changes communicated
☐ Replacement personnel screened
☐ Access revoked for departing personnel

The organization should not assume that supplier personnel have been screened merely because the supplier states that screening is part of its general HR process.


19. Contractor Screening Responsibility

Define who performs the screening.

Screening ActivityOrganizationSupplierContractorOther
Identity verification
Employment verification
Qualification verification
Reference check
Regulatory check
Security review
Final approval

Responsibilities should be clearly defined before access is granted.


20. Evidence and Attestation

Where the supplier performs screening:

☐ Screening requirements documented
☐ Supplier attestation obtained where appropriate
☐ Scope of screening confirmed
☐ Screening completion date confirmed
☐ Exceptions disclosed
☐ Re-screening requirements defined
☐ Evidence requirements agreed

Avoid collecting unnecessary copies of sensitive personal records.


21. Contractor Authorization

Before screening:

☐ Purpose defined
☐ Required checks defined
☐ Appropriate authorization/consent obtained where required
☐ Privacy information provided where applicable
☐ Screening scope communicated
☐ Provider approved
☐ Applicable legal requirements considered


22. Privacy and Personal Data

Contractor screening may involve sensitive personal information.

Ensure:

☐ Minimum necessary information collected
☐ Purpose defined
☐ Appropriate lawful processing mechanism identified
☐ Access restricted
☐ Information securely stored
☐ Information securely transmitted
☐ Retention period defined
☐ Secure disposal defined
☐ Third-party processing addressed where applicable
☐ International transfers assessed where applicable


23. Screening Evidence Review

The reviewer should confirm:

☐ Evidence relates to the correct contractor
☐ Evidence is from an appropriate source
☐ Evidence is sufficiently reliable
☐ Evidence is current
☐ Required checks are complete
☐ Material discrepancies are addressed
☐ Result supports the screening decision

Evidence Review


24. Contractor Screening Result

Result

☐ Satisfactory
☐ Satisfactory With Conditions
☐ Further Verification Required
☐ Discrepancy Under Review
☐ Exception Required
☐ Not Approved
☐ Unable to Complete

Reviewer Comments


25. Contractor Access Before Screening Completion

As a general principle, required screening should be completed before granting sensitive or privileged access.

If business requirements require early access:

☐ Business justification documented
☐ Risk assessed
☐ Access minimized
☐ Temporary access used
☐ MFA enabled
☐ Privileged access restricted
☐ Expiry established
☐ Compensating controls defined
☐ Approval obtained
☐ Screening completion tracked


26. Contractor Access Management

After screening approval:

☐ Access request approved
☐ Named account created
☐ Shared accounts prohibited unless specifically justified
☐ MFA enabled
☐ Least privilege applied
☐ Access scope documented
☐ Production access separately approved
☐ Privileged access separately approved
☐ Access expiry recorded
☐ Monitoring established where appropriate


27. Temporary Contractor Access

Where access is temporary:

SystemAccessStartExpiryApproverStatus

Temporary access should have a defined end date wherever practical.


28. Contractor Access Review

Periodically verify:

☐ Contractor still engaged
☐ Business need still exists
☐ Access still required
☐ Access remains appropriate
☐ Privileged access still justified
☐ Expiry dates remain valid
☐ Contractor role has not changed
☐ Screening remains appropriate


29. Contractor Role Change

When responsibilities change:

☐ New role assessed
☐ Information access reassessed
☐ System access reassessed
☐ Risk reassessed
☐ Screening requirements reassessed
☐ Additional screening completed where required
☐ New access approved
☐ Previous access removed where no longer required


30. Replacement Contractor

When a contractor is replaced:

☐ Previous contractor identified
☐ Previous access scheduled for removal
☐ New contractor screened
☐ New contractor approved
☐ New accounts created
☐ Old accounts disabled
☐ Credentials/tokens rotated where required
☐ Handover completed securely

Never transfer a contractor’s personal account to another individual.


31. Contractor Screening Exceptions

If required screening cannot be completed:

☐ Reason documented
☐ Missing check identified
☐ Risk assessed
☐ Compensating controls defined
☐ Access restrictions established
☐ Approver identified
☐ Expiry/review date defined
☐ Exception recorded

Exceptions should be temporary and monitored.


32. Contractor Security Responsibilities

Before access is provided, communicate applicable requirements:

☐ Information-security policy
☐ Acceptable use requirements
☐ Confidentiality requirements
☐ Access requirements
☐ MFA requirements
☐ Data-handling requirements
☐ Incident-reporting requirements
☐ Remote-working requirements
☐ Secure development requirements where applicable
☐ Customer-data handling requirements
☐ Security testing restrictions where applicable


33. Contractor Confidentiality

Where required:

☐ NDA executed
☐ Confidential information defined
☐ Permitted use defined
☐ Disclosure restrictions defined
☐ Return/deletion requirements defined
☐ Confidentiality survives termination where applicable


34. Contractor Security Incidents

Contractors must report security incidents according to the organization’s incident-management requirements.

Examples:

  • Lost device
  • Credential compromise
  • Unauthorized access
  • Data leakage
  • Malware infection
  • Phishing
  • Security testing outside approved scope
  • Accidental disclosure
  • Suspected customer-data exposure

☐ Incident reporting requirement communicated
☐ Security contact provided
☐ Escalation process defined
☐ Evidence preservation requirements communicated


35. Contractor Offboarding

At the end of the engagement:

☐ Contract end confirmed
☐ Business owner notified
☐ Access inventory reviewed
☐ User accounts disabled
☐ Privileged access revoked
☐ Cloud access removed
☐ VPN access removed
☐ Source-code access removed
☐ CI/CD access removed
☐ API tokens revoked
☐ SSH keys addressed
☐ Certificates addressed
☐ Assets returned
☐ Information returned/deleted where required
☐ Supplier notified where applicable
☐ Secrets rotated where necessary
☐ Offboarding evidence retained

Exit Principle

Revoke → Return/Delete → Verify → Record → Close


36. Contractor Screening Register

Maintain an appropriate register.

Contractor IDContractorRoleRiskLevelScreening StatusAccess StatusReview Date

The register should not contain unnecessary sensitive personal information.


37. Findings

Record screening or contractor-security findings.

Finding IDAreaFindingRiskActionOwnerDue DateStatus

Examples:

  • Contractor granted access before required screening
  • Screening evidence unavailable
  • Supplier screening responsibility unclear
  • Contractor access not expired
  • Privileged access not separately approved
  • Departed contractor account still active

38. Corrective Action

For significant findings:

☐ Root cause identified
☐ Immediate correction performed
☐ Corrective action defined
☐ Owner assigned
☐ Due date assigned
☐ Remediation evidence required
☐ Effectiveness verification defined
☐ Residual risk assessed
☐ Closure approved


39. Contractor Risk Review

Assess the complete relationship:

Contractor → Service → Information → Access → Dependency → Threat → Vulnerability → Impact → Risk → Controls → Residual Risk

Risk Assessment

Risk Treatment


40. Management Approval

Where required:

Business Owner: ______________________

Supplier Owner: ______________________

HR/People Owner: _____________________

Information Security: _________________

Legal/Privacy: ________________________

Risk Owner: __________________________

Approver: ____________________________

Date: ________________________________


41. Periodic Review

Review contractor screening requirements based on:

☐ Contract duration
☐ Role risk
☐ Information sensitivity
☐ Access level
☐ Privileged access
☐ Customer requirements
☐ Regulatory requirements
☐ Security incidents
☐ Role changes
☐ Supplier changes
☐ Re-screening requirements


42. Re-Screening Triggers

Reassessment may be required following:

☐ Significant role change
☐ New privileged access
☐ New production access
☐ New sensitive information
☐ Contract extension
☐ Regulatory requirement
☐ Customer requirement
☐ Security incident
☐ Significant concern regarding contractor suitability
☐ Change in contracting organization
☐ Long-term engagement requiring periodic review


43. AWS SaaS Startup Example

Consider an AWS SaaS startup engaging an external DevOps contractor.

Contractor Responsibilities

  • AWS infrastructure
  • CI/CD
  • Infrastructure-as-Code
  • Production deployments
  • Monitoring

Risk

High because the contractor may have:

  • Production access
  • Cloud administrative access
  • Source-code access
  • CI/CD access
  • Infrastructure access

Required Controls

☐ Identity verification
☐ Relevant employment/engagement verification
☐ Technical qualification verification where relevant
☐ Professional references
☐ Additional lawful screening where appropriate
☐ NDA
☐ Defined Statement of Work
☐ Named AWS account
☐ MFA
☐ Least privilege
☐ Temporary/expiring access
☐ Privileged-access approval
☐ Logging
☐ Periodic access review
☐ Offboarding plan

Audit Trail

Business Need → Contractor Risk → Screening → Approval → Contract → Access → Monitoring → Review → Offboarding


44. Startup-Friendly Contractor Screening Model

Low-Risk Contractor

Examples:

  • Graphic designer
  • Content writer
  • General administrative support

Focus on:

  • Identity
  • Engagement verification
  • Confidentiality
  • Basic access controls

Medium-Risk Contractor

Examples:

  • Developer
  • HR consultant
  • Finance consultant
  • Customer-support contractor

Add:

  • Employment/engagement verification
  • Qualifications where relevant
  • References
  • Information-security requirements
  • Access review

High/Critical-Risk Contractor

Examples:

  • AWS administrator
  • Security consultant
  • VAPT provider
  • Production engineer
  • Database administrator

Add:

  • Enhanced screening
  • Relevant professional verification
  • Additional lawful checks where appropriate
  • Security approval
  • Privileged-access controls
  • Temporary access
  • Strong authentication
  • Periodic review
  • Formal offboarding

45. Common Mistakes

Avoid:

  • Assuming contractors do not require screening
  • Treating supplier employment checks as sufficient without defining requirements
  • Granting access before required verification
  • Giving contractors employee-level access by default
  • Using shared accounts
  • Allowing permanent contractor access
  • Failing to define screening responsibility
  • Failing to screen replacement personnel
  • Ignoring subcontractors
  • Failing to revoke access at contract termination
  • Failing to rotate credentials after privileged contractor access
  • Collecting excessive personal information
  • Retaining sensitive screening information indefinitely
  • Performing unlawful or irrelevant checks

46. Relationship With Other ISMS Documents

DocumentRelationship
Employee Screening PolicyEstablishes general screening principles
Background Verification ProcedureDefines verification activities
Role-Based Screening MatrixDetermines screening requirements by role
Supplier Security RequirementsDefines third-party security requirements
Supplier Due Diligence ChecklistAssesses the supplier organization
Supplier Security AddendumEstablishes contractual requirements
Contractor Access ProcedureControls contractor access
Access Management ProcedureControls system access
Privileged Access ProcedureControls privileged access
Supplier Offboarding ChecklistSupports supplier/contractor exit
Incident Management ProcedureHandles contractor security incidents
Information Security Exception RegisterRecords approved exceptions
Risk AssessmentAssesses contractor-related risk

47. ISO/IEC 27001 Connection

Contractor screening supports the organization’s personnel-security and supplier-security risk management.

The organization should determine:

  • Which contractors require screening
  • What level of screening is appropriate
  • Who is responsible for performing the checks
  • What evidence is required
  • When screening must be completed
  • What access restrictions apply
  • How contractor changes are handled
  • When re-screening is required
  • How contractor offboarding is performed

The Contractor Screening Procedure is not itself a universally prescribed ISO/IEC 27001 document. The organization’s requirements should be based on its ISMS scope, risk assessment, applicable controls, contractual requirements, legal requirements, customer requirements, and the contractor’s actual responsibilities and access.


48. Audit Evidence Checklist

Maintain appropriate evidence such as:

☐ Contractor Screening Procedure
☐ Contractor screening requirements
☐ Role-Based Screening Matrix
☐ Contractor risk assessment
☐ Screening records
☐ Supplier screening attestation where applicable
☐ Verification evidence
☐ NDA/confidentiality agreement
☐ Contract/SOW
☐ Access approvals
☐ Privileged access approvals
☐ Access review records
☐ Exceptions
☐ Security training/acknowledgement
☐ Contractor incident records
☐ Offboarding evidence
☐ Credential/token revocation evidence
☐ Periodic review records

Avoid exposing unnecessary personal or confidential information during audits.


49. Final Contractor Screening Audit Trail

For each security-relevant contractor, the organization should be able to demonstrate:

Why is the contractor required?
What service will they provide?
What information will they access?
What systems will they access?
Will they have privileged or production access?
What is the contractor’s risk level?
What screening is required?
Who is responsible for performing the screening?
Was the screening completed before sensitive access?
What evidence supports the result?
Who approved the contractor?
How is contractor access monitored?
What happens when the contractor’s role changes?
What happens when the contract ends?

Final Principle

Contractor screening is not simply an HR background check. It is a risk-based security process connecting the contractor’s business need, responsibilities, information exposure, access, screening, contractual requirements, approval, monitoring, and secure offboarding into one defensible audit trail.