1. Purpose
The Employee Screening Checklist provides a structured method for verifying that required employee screening has been appropriately planned, authorized, completed, reviewed, and documented.
The checklist supports a risk-based approach to personnel security and helps ensure that screening requirements are applied consistently according to the individual’s role, responsibilities, information exposure, and access.
Core Principle
Identify Role → Assess Risk → Define Screening → Authorize → Verify → Review → Decide → Record → Protect
2. When to Use
Use this checklist:
- Before employment where screening is required
- Before granting sensitive or privileged access
- For contractors and temporary personnel where applicable
- When personnel move to security-sensitive roles
- During periodic re-verification where required
- When contractual or regulatory requirements apply
- When a material discrepancy requires additional verification
3. Employee Screening Information
| Field | Details |
|---|---|
| Screening ID | |
| Employee/Personnel ID | |
| Name | |
| Position | |
| Department | |
| Employment Type | |
| Hiring Manager | |
| HR Owner | |
| Role Risk | |
| Screening Level | |
| Screening Provider | |
| Screening Start Date | |
| Screening Completion Date | |
| Reviewer | |
| Status |
4. Screening Status
☐ Not Started
☐ In Progress
☐ Pending Information
☐ Pending Verification
☐ Discrepancy Under Review
☐ Completed
☐ Completed With Conditions
☐ Exception Approved
☐ Closed
Comments
5. Role and Risk Assessment
Before screening, confirm:
☐ Job description reviewed
☐ Responsibilities identified
☐ Information accessed identified
☐ Systems accessed identified
☐ Privileged access identified
☐ Production access identified
☐ Customer information identified
☐ Personal data access identified
☐ Financial responsibility identified
☐ Regulatory responsibility identified
☐ Role risk assessed
☐ Screening level selected
Role Risk
☐ Low
☐ Medium
☐ High
☐ Critical
6. Screening Level
☐ Level 1 – Basic
☐ Level 2 – Standard
☐ Level 3 – Enhanced
☐ Level 4 – High Risk
Reason for Selected Level
7. Authorization and Privacy
Before starting screening:
☐ Screening requirement communicated
☐ Purpose explained
☐ Appropriate authorization/consent obtained where required
☐ Privacy information provided where applicable
☐ Scope of screening defined
☐ Applicable legal requirements considered
☐ Jurisdiction identified
☐ Verification provider authorized
☐ Data-handling requirements defined
8. Identity Verification
☐ Identity verification required
☐ Identity verified
☐ Identification source appropriate
☐ Name verified
☐ Identity information consistent
☐ Verification date recorded
☐ Result reviewed
Result
☐ Verified
☐ Partially Verified
☐ Unable to Verify
☐ Discrepancy
9. Address Verification
Where relevant:
☐ Address verification required
☐ Address verified
☐ Source appropriate
☐ Verification completed
☐ Discrepancy identified/reviewed
Address verification should only be performed where relevant and legally appropriate.
10. Employment Verification
☐ Employment verification required
☐ Previous employer information provided
☐ Employment dates verified
☐ Position verified
☐ Relevant responsibilities verified where appropriate
☐ Significant gaps reviewed
☐ Discrepancies documented
☐ Verification completed
Result
11. Education and Qualification Verification
Where relevant:
☐ Qualification requirement identified
☐ Institution verified
☐ Qualification verified
☐ Completion status verified
☐ Professional certification verified
☐ License/registration verified
☐ Expiry checked where applicable
☐ Discrepancies reviewed
12. Professional References
Where applicable:
☐ References required
☐ Reference identity verified
☐ Reference obtained from appropriate source
☐ Relevant employment relationship confirmed
☐ Response documented
☐ Material concern identified/reviewed
☐ Reference verification completed
13. Criminal Record Check
Where lawful and relevant:
☐ Check required
☐ Appropriate authorization obtained
☐ Appropriate source/provider used
☐ Check completed
☐ Result reviewed
☐ Potential match investigated
☐ Candidate clarification obtained where appropriate
☐ Decision documented
A criminal-record check should not be performed merely because it is available; it should be relevant, proportionate, and legally permissible.
14. Financial Check
Where lawful and relevant to the role:
☐ Financial check required
☐ Legal requirements considered
☐ Authorization obtained
☐ Check completed
☐ Result reviewed
☐ Material issue assessed
☐ Decision documented
Financial checks should generally be limited to roles where financial responsibility or applicable requirements make them relevant.
15. Sanctions and Regulatory Screening
Where applicable:
☐ Sanctions screening required
☐ Regulatory screening required
☐ Professional registration checked
☐ License verified
☐ Screening completed
☐ Potential match reviewed
☐ False positive resolved
☐ Result recorded
16. Conflict-of-Interest Check
Where relevant:
☐ Conflict-of-interest declaration required
☐ Declaration completed
☐ Potential conflict identified
☐ Conflict reviewed
☐ Mitigation defined
☐ Approval obtained
☐ Review date established
17. Right-to-Work Verification
Where applicable:
☐ Right-to-work requirement identified
☐ Required evidence verified
☐ Verification completed
☐ Expiry date recorded where applicable
☐ Follow-up requirement established
18. Security-Sensitive Role Review
For security-sensitive positions:
☐ Role classified as security-sensitive
☐ Security responsibilities identified
☐ Privileged access identified
☐ Production access identified
☐ Restricted information identified
☐ Enhanced screening requirements reviewed
☐ Security approval obtained where required
19. Privileged Access Screening
If the employee will receive privileged access:
☐ Privileged access requirement documented
☐ Business justification documented
☐ Required screening completed
☐ Identity verified
☐ Relevant employment verification completed
☐ Relevant qualification verification completed
☐ Additional checks completed where required
☐ Security review completed
☐ Management approval obtained
☐ Access restrictions defined
20. Production Access Screening
If production access is required:
☐ Production access identified
☐ Role risk assessed
☐ Screening requirement reviewed
☐ Required verification completed
☐ Security approval obtained
☐ Access scope defined
☐ MFA required
☐ Privileged access controls established
☐ Access review scheduled
21. AWS / Cloud Administrator Screening
For cloud administrators:
☐ Cloud administration responsibility identified
☐ AWS/Azure/GCP access identified
☐ Production access identified
☐ IAM administration identified
☐ Privileged access identified
☐ Enhanced screening assessed
☐ Required verification completed
☐ Security approval obtained
☐ Access restrictions defined
22. Developer Screening
For developers:
☐ Source-code access identified
☐ Repository access identified
☐ CI/CD access identified
☐ Development environment identified
☐ Production access identified
☐ Screening level assessed
☐ Employment verification completed
☐ Qualification verification completed where relevant
☐ References completed where required
☐ Privileged access separately assessed
23. Finance Employee Screening
For finance personnel:
☐ Financial responsibilities identified
☐ Payment authority identified
☐ Financial-system access identified
☐ Sensitive information identified
☐ Role risk assessed
☐ Qualification verification completed where relevant
☐ Employment verification completed
☐ References completed where required
☐ Financial screening assessed where lawful/relevant
☐ Conflict-of-interest review completed
24. HR Employee Screening
For HR personnel:
☐ Employee-data access identified
☐ Sensitive personal data identified
☐ HR systems access identified
☐ Role risk assessed
☐ Employment verification completed
☐ Qualification verification completed where relevant
☐ References completed where required
☐ Confidentiality requirements established
☐ Access restrictions defined
25. Contractor Screening
For contractors:
☐ Contractor status identified
☐ Contracting organization identified
☐ Screening responsibility defined
☐ Required screening confirmed
☐ Verification completed
☐ NDA/confidentiality requirement completed
☐ Access scope defined
☐ Access expiry defined
☐ Supplier requirements reviewed where applicable
26. Third-Party Personnel Screening
Where personnel are supplied by a third party:
☐ Supplier screening requirement defined
☐ Contractual requirement established
☐ Supplier responsibility identified
☐ Screening evidence/attestation obtained where appropriate
☐ High-risk personnel separately assessed
☐ Access restricted until required verification is completed
27. Screening Evidence Review
For each completed check:
☐ Evidence received
☐ Evidence source identified
☐ Evidence date recorded
☐ Evidence relevant
☐ Evidence sufficiently reliable
☐ Result consistent with information provided
☐ Reviewer identified
☐ Review completed
Avoid storing unnecessary copies of sensitive personal documents.
28. Discrepancy Review
If a discrepancy is identified:
☐ Discrepancy recorded
☐ Source identified
☐ Materiality assessed
☐ Role relevance assessed
☐ Candidate/personnel explanation obtained where appropriate
☐ Additional verification performed where required
☐ Security impact assessed
☐ Legal/privacy considerations reviewed
☐ Decision documented
Discrepancy
Resolution
29. Screening Decision
Overall Result
☐ Satisfactory
☐ Satisfactory With Conditions
☐ Further Verification Required
☐ Discrepancy Under Review
☐ Exception Required
☐ Unable to Complete
Decision Rationale
30. Access Before Screening Completion
If required screening is incomplete:
☐ Access withheld
☐ Access restricted
☐ Temporary access approved
☐ Business justification documented
☐ Risk assessed
☐ Compensating controls established
☐ Expiry date established
☐ Approval obtained
☐ Completion tracked
31. Screening Exception
If an exception is required:
| Field | Details |
|---|---|
| Exception ID | |
| Missing Check | |
| Reason | |
| Risk | |
| Compensating Control | |
| Approver | |
| Expiry Date | |
| Status |
Exceptions should be time-bound and reviewed before expiry.
32. Screening Completion
Before marking screening complete:
☐ Required checks completed
☐ Results reviewed
☐ Discrepancies resolved or addressed
☐ Exceptions approved
☐ Screening decision documented
☐ Required approvals obtained
☐ Records protected
☐ Screening register updated
☐ Access decision communicated to relevant stakeholders
33. Onboarding Dependency
Before normal access is granted, confirm:
☐ Screening requirements satisfied
☐ Employment/engagement approved
☐ Confidentiality requirements completed
☐ Security responsibilities communicated
☐ Security awareness requirements identified
☐ Access request approved
☐ MFA configured where required
☐ Least privilege applied
34. Periodic Re-Screening
Where applicable:
☐ Re-screening requirement defined
☐ Re-screening frequency defined
☐ Role risk reviewed
☐ Regulatory requirements reviewed
☐ Contractual requirements reviewed
☐ Re-verification completed
☐ Results reviewed
☐ Records updated
Re-screening should be based on risk and applicable requirements rather than automatically collecting unnecessary information.
35. Role Change
When an employee changes role:
☐ New role reviewed
☐ New access identified
☐ Risk reassessed
☐ Screening level reassessed
☐ Additional screening identified
☐ Additional verification completed where required
☐ Existing screening reviewed
☐ Access reviewed
☐ Approval recorded
36. Privacy and Record Protection
Verify:
☐ Screening information classified appropriately
☐ Access restricted
☐ Records securely stored
☐ Transmission protected
☐ Sensitive information minimized
☐ Retention period defined
☐ Disposal requirement defined
☐ Unauthorized disclosure controls established
37. Screening Provider Review
If an external provider is used:
☐ Provider approved
☐ Provider security reviewed
☐ Confidentiality requirements established
☐ Privacy requirements reviewed
☐ Data-processing requirements addressed where applicable
☐ Subprocessors identified where relevant
☐ Data retention understood
☐ Secure transfer method established
38. Screening Register
Record the screening status without unnecessarily storing sensitive personal information.
| Screening ID | Personnel ID | Role | Risk | Level | Status | Completion Date | Reviewer |
|---|---|---|---|---|---|---|---|
39. Findings
Record process weaknesses:
| Finding ID | Area | Finding | Risk | Action | Owner | Due Date | Status |
|---|---|---|---|---|---|---|---|
Typical findings include:
- Screening not completed
- Required authorization missing
- Verification evidence incomplete
- Privileged access granted before required screening
- Expired professional qualification
- Unresolved discrepancy
- Inappropriate access to screening records
- Screening exception expired
40. Corrective Action
For significant findings:
☐ Root cause identified
☐ Immediate correction performed
☐ Corrective action defined
☐ Owner assigned
☐ Due date assigned
☐ Evidence requirement defined
☐ Effectiveness verification defined
☐ Residual risk assessed
☐ Closure approved
41. Final Screening Review
Reviewer Confirmation
I confirm that the applicable screening requirements have been reviewed and that the available evidence supports the recorded screening result.
Reviewer: __________________________
Role: ______________________________
Date: ______________________________
Signature/Approval: __________________
42. Management Approval
Where required:
HR Owner: __________________________
Hiring Manager: _____________________
Information Security: ________________
Legal/Privacy: _______________________
Risk Owner: _________________________
Approver: ___________________________
Date: ______________________________
43. Review Frequency
This checklist should be reviewed when:
☐ Screening requirements change
☐ Role requirements change
☐ New regulations apply
☐ New customer requirements apply
☐ Security incidents identify personnel-related risks
☐ Audit findings identify weaknesses
☐ Verification provider changes
☐ The screening matrix is updated
44. AWS SaaS Startup Example
Consider a startup operating a SaaS platform on AWS.
Developer
Access:
- GitHub
- Development AWS
- CI/CD
Checklist should confirm:
☐ Identity verified
☐ Employment verified
☐ Qualification verified where relevant
☐ References completed where required
☐ Source-code access identified
☐ CI/CD access identified
☐ Production access separately assessed
AWS Production Administrator
Access:
- AWS production
- IAM
- Security configuration
- Infrastructure
Additional checks may include:
☐ Enhanced role screening
☐ Employment verification
☐ Relevant qualifications
☐ Professional references
☐ Additional lawful checks where relevant
☐ Security approval
☐ Privileged access approval
Audit Trail
Role → Risk → Screening Level → Verification → Review → Approval → Access
45. Startup-Friendly Screening Model
Low Risk
Checklist focuses on:
- Identity
- Basic employment verification
- Role assessment
- Authorization
- Record
Medium Risk
Add:
- Education/qualification
- Employment history
- References
- Access review
- Security-sensitive assessment
High/Critical Risk
Add, where lawful and relevant:
- Enhanced verification
- Professional credentials
- Regulatory checks
- Additional approval
- Privileged-access review
- Periodic reassessment
The objective is to maintain appropriate screening without creating unnecessary administrative or privacy burden.
46. Common Mistakes
Avoid:
- Treating every employee the same
- Ignoring actual system access
- Granting privileged access before required screening
- Performing checks without appropriate authorization
- Collecting excessive personal information
- Retaining sensitive screening documents indefinitely
- Ignoring discrepancies
- Failing to document screening decisions
- Using unapproved screening providers
- Ignoring contractor and third-party personnel
- Failing to reassess screening when roles change
- Treating screening completion as proof that all personnel-security risks have been eliminated
47. Relationship With Other ISMS Documents
| Document | Relationship |
|---|---|
| Employee Screening Policy | Defines screening requirements |
| Background Verification Procedure | Defines verification workflow |
| Role-Based Screening Matrix | Determines screening level by role |
| Employee Onboarding Procedure | Uses screening completion as an onboarding dependency |
| Employee Offboarding Procedure | Controls personnel exit |
| Access Management Procedure | Controls system access |
| Privileged Access Procedure | Controls privileged access |
| Personnel Security Procedure | Defines personnel-security controls |
| Security Awareness Procedure | Defines security training |
| Risk Assessment | Assesses role and personnel risk |
| Exception Register | Records approved screening exceptions |
| Supplier Security Requirements | Covers third-party personnel |
48. ISO/IEC 27001 Connection
Employee screening supports personnel-security risk management and the organization’s implementation of applicable information-security controls.
The organization should determine:
- Which roles require screening
- What checks are appropriate
- When checks must be completed
- How screening evidence is protected
- How exceptions are managed
- Whether re-screening is required
- How screening connects with access management
The Employee Screening Checklist is not itself a universally prescribed ISO/IEC 27001 form. The organization’s screening requirements should be determined through its ISMS scope, risk assessment, applicable controls, legal requirements, contractual requirements, customer requirements, and role sensitivity.
49. Audit Evidence Checklist
Maintain appropriate evidence such as:
☐ Employee Screening Policy
☐ Background Verification Procedure
☐ Role-Based Screening Matrix
☐ Completed screening checklist
☐ Screening register
☐ Authorization/consent records where applicable
☐ Verification results
☐ Qualification verification
☐ Employment verification
☐ Reference verification
☐ Regulatory screening where applicable
☐ Discrepancy records
☐ Exception records
☐ Approval records
☐ Screening provider assessment
☐ Periodic review evidence
☐ Corrective action records
Sensitive personal information should be minimized and securely protected.
50. Final Employee Screening Audit Trail
For every applicable employee or personnel member, the organization should be able to demonstrate:
What is the person’s role?
What risk does the role present?
What screening level applies?
Which checks were required?
Was appropriate authorization obtained?
Were the checks completed?
What evidence supports the results?
Were discrepancies identified?
How were discrepancies addressed?
Who reviewed the results?
Who approved the outcome?
Was access restricted until required screening was complete?
How were screening records protected?
When will the screening requirement be reviewed again?
Final Principle
Employee screening is not simply a background-check form. It is a risk-based control connecting the employee’s role, access, information exposure, verification requirements, evidence, decision, privacy protection, and ongoing personnel-security responsibilities into one defensible audit trail.
