ISO/IEC 27001

⌘K
  1. Home
  2. Docs
  3. ISO/IEC 27001
  4. Other Doc
  5. HR Security Audit Checklist

HR Security Audit Checklist

1. Purpose

The HR Security Audit Checklist provides a structured method for assessing whether personnel-security requirements are defined, implemented, followed, and supported by evidence throughout the employee lifecycle.

The checklist covers:

  • Pre-employment screening
  • Employment terms and responsibilities
  • Onboarding
  • Security awareness
  • Access management
  • Role changes
  • Remote working
  • Contractors and third-party personnel
  • Disciplinary processes
  • Confidentiality
  • Offboarding
  • Re-screening
  • Personnel records
  • Security compliance
  • Evidence and auditability

Core Principle

Recruit → Screen → Define Responsibilities → Onboard → Train → Grant Access → Monitor → Review → Offboard


2. When to Use

Use this checklist:

  • During internal audits
  • During ISO/IEC 27001 readiness assessments
  • During periodic HR security reviews
  • During compliance monitoring
  • After significant HR/process changes
  • After security incidents involving personnel
  • During access-control reviews
  • During supplier/contractor reviews
  • Before external certification audits

3. Audit Information

FieldDetails
Audit ID
Audit Date
Audit Period
Auditor
HR Owner
Information Security Owner
Scope
Locations
Departments
Employee Population
Contractor Population
Criteria
Previous Audit
Overall Status

4. Audit Status

Use:

☐ Compliant
☐ Partially Compliant
☐ Non-Compliant
☐ Not Applicable
☐ Not Tested
☐ Improvement Opportunity


5. HR Security Governance

Verify:

☐ HR security responsibilities are defined
☐ Information-security responsibilities are assigned
☐ HR and Information Security responsibilities are coordinated
☐ Personnel-security requirements are documented
☐ HR security policies are approved
☐ Procedures are documented where necessary
☐ Roles and responsibilities are communicated
☐ HR security requirements are periodically reviewed
☐ Security requirements are incorporated into relevant HR processes

Evidence


6. Personnel Security Risk Assessment

Verify:

☐ Personnel-related security risks are identified
☐ Sensitive roles are identified
☐ Privileged roles are identified
☐ Production-access roles are identified
☐ Roles handling restricted information are identified
☐ Screening requirements are risk-based
☐ Security requirements reflect role responsibilities
☐ Personnel risks are included in the organization’s risk-management process where relevant


7. Sensitive Role Identification

Verify:

☐ Sensitive roles have been identified
☐ Role sensitivity is based on actual access/responsibility
☐ Privileged roles are identified
☐ Cloud administration roles are identified
☐ Production roles are identified
☐ Security roles are identified
☐ Financially sensitive roles are identified
☐ Customer-data-sensitive roles are identified
☐ Security-sensitive third-party roles are identified
☐ Sensitive role classifications are periodically reviewed


8. Background Verification

Verify:

☐ Background verification requirements are defined
☐ Screening is based on role risk
☐ Screening requirements are documented
☐ Appropriate authorization is obtained
☐ Identity verification is performed where required
☐ Employment verification is performed where required
☐ Qualification verification is performed where required
☐ Reference checks are performed where required
☐ Regulatory/sanctions checks are performed where relevant
☐ Criminal checks are performed only where lawful and relevant
☐ Financial checks are performed only where lawful and relevant
☐ Screening results are reviewed
☐ Discrepancies are investigated appropriately
☐ Screening exceptions are documented
☐ Screening completion is recorded


9. Background Verification Register

Verify:

☐ Register exists where needed
☐ Required personnel are recorded
☐ Screening level is recorded
☐ Screening status is current
☐ Completion date is recorded
☐ Exceptions are recorded
☐ Pending checks are tracked
☐ Overdue checks are tracked
☐ Re-screening requirements are tracked
☐ Access to the register is restricted
☐ Sensitive information is minimized


10. Employment Terms and Conditions

Verify that relevant employment/engagement terms address:

☐ Information-security responsibilities
☐ Confidentiality obligations
☐ Acceptable use requirements
☐ Information-handling requirements
☐ Intellectual-property requirements
☐ Security incident reporting
☐ Access responsibilities
☐ Compliance responsibilities
☐ Return of organizational assets
☐ Information return/deletion requirements where applicable
☐ Continuing confidentiality obligations where appropriate


11. Confidentiality and NDA

Verify:

☐ Confidentiality requirements are defined
☐ NDA requirements are identified
☐ NDA is executed where required
☐ Confidentiality obligations cover organizational information
☐ Customer information is addressed
☐ Personal data is addressed where appropriate
☐ Source code and intellectual property are addressed
☐ Security information is protected
☐ Continuing obligations after termination are defined where appropriate


12. Employee Onboarding

Verify:

☐ Identity verification completed
☐ Required screening completed
☐ Employment documentation completed
☐ Security responsibilities communicated
☐ Acceptable-use requirements communicated
☐ Confidentiality requirements communicated
☐ Security awareness completed
☐ Required policies communicated
☐ Access requests approved
☐ Access provisioned based on role
☐ MFA configured where required
☐ Privileged access separately approved
☐ Equipment issued securely
☐ Security contacts provided


13. Joiner Access

Verify:

☐ New-user access is formally requested
☐ Business need is documented
☐ Manager approval is obtained
☐ System owner approval is obtained where required
☐ Least privilege is applied
☐ Role-based access is used where appropriate
☐ Privileged access is separately controlled
☐ MFA is enabled
☐ Access provisioning is traceable
☐ Access is reviewed after onboarding


14. Security Awareness and Training

Verify:

☐ Security awareness program exists
☐ New personnel receive security awareness
☐ Training is appropriate to role
☐ Security policies are communicated
☐ Training completion is recorded
☐ Security responsibilities are understood
☐ Phishing/security awareness activities are performed where appropriate
☐ Role-specific training is provided where necessary
☐ Refresher training is performed
☐ Training exceptions are tracked


15. Policy Acknowledgement

Verify:

☐ Applicable policies are communicated
☐ Personnel can access current policies
☐ Required acknowledgement is recorded where applicable
☐ New joiners complete required acknowledgement
☐ Material policy changes are communicated
☐ Overdue acknowledgements are tracked
☐ Policy acknowledgement records are protected

Important:

Policy acknowledgement demonstrates receipt/review; it does not by itself demonstrate actual compliance.


16. Personnel Responsibilities

Verify personnel understand responsibilities relating to:

☐ Information protection
☐ Passwords/authentication
☐ MFA
☐ Device security
☐ Remote working
☐ Data handling
☐ Customer information
☐ Personal data
☐ Security incidents
☐ Phishing/social engineering
☐ Acceptable use
☐ Software installation
☐ Cloud usage
☐ Confidentiality


17. Access Management

Verify:

☐ User identities are unique
☐ Access is based on business need
☐ Least privilege is applied
☐ Role-based access is used where appropriate
☐ Access approval is documented
☐ Access is reviewed periodically
☐ Dormant accounts are identified
☐ Excess access is removed
☐ Privileged access is separately controlled
☐ Access is revoked when no longer required


18. Joiner-Mover-Leaver Process

Verify:

Joiner

☐ New personnel trigger access workflow
☐ Screening requirements are considered
☐ Security training is completed
☐ Appropriate access is provisioned

Mover

☐ Role changes trigger access review
☐ Old access is removed
☐ New access is approved
☐ Screening requirements are reassessed where necessary

Leaver

☐ Exit triggers access revocation
☐ Assets are recovered
☐ Organizational information is protected
☐ Accounts are disabled
☐ Privileged access is removed
☐ Tokens/keys are addressed where required


19. Privileged User Security

Verify:

☐ Privileged roles are identified
☐ Privileged access is justified
☐ Appropriate screening is completed
☐ Management approval exists
☐ MFA is enabled
☐ Individual accounts are used
☐ Shared privileged accounts are avoided or controlled
☐ Privileged activity is logged where appropriate
☐ Access is periodically reviewed
☐ Emergency privileged access is controlled
☐ Privileged access is revoked when no longer required


20. Production Access Personnel

For personnel with production access:

☐ Role sensitivity assessed
☐ Screening requirement assessed
☐ Business justification documented
☐ Access approved
☐ MFA enabled
☐ Least privilege applied
☐ Production access logged where appropriate
☐ Access reviewed periodically
☐ Emergency access controlled
☐ Access revoked when no longer required


21. Remote Working

Verify:

☐ Remote-working requirements are defined
☐ Remote access is authorized
☐ MFA is used
☐ Approved devices are used
☐ Device security is implemented
☐ Sensitive information is protected
☐ Public/untrusted networks are appropriately controlled
☐ VPN/secure access is used where required
☐ Remote access is monitored where appropriate
☐ Personnel understand remote-working security requirements


22. Mobile Device Security

Where applicable:

☐ Mobile-device requirements are defined
☐ Device encryption is enabled
☐ Screen lock is enabled
☐ Approved applications are used
☐ Device management is implemented where required
☐ Lost/stolen device reporting is defined
☐ Remote wipe is available where appropriate
☐ Corporate data is protected


23. Acceptable Use

Verify personnel understand requirements relating to:

☐ Corporate systems
☐ Email
☐ Internet
☐ Cloud services
☐ SaaS applications
☐ Company devices
☐ Personal devices
☐ Software installation
☐ Removable media
☐ Social media
☐ AI/generative AI tools
☐ Confidential information


24. AI and Generative AI Usage

Where applicable, verify:

☐ AI usage requirements are defined
☐ Personnel know what information may be entered into AI tools
☐ Restricted/customer information is protected
☐ Personal data restrictions are communicated
☐ Approved AI tools are identified where necessary
☐ Confidential source code restrictions are defined
☐ AI-generated content review requirements are defined where applicable
☐ Security risks are communicated


25. Contractor Security

Verify:

☐ Contractors are identified
☐ Contractor roles are risk-assessed
☐ Screening requirements are defined
☐ Confidentiality requirements apply
☐ Security responsibilities are documented
☐ Access is approved
☐ Access is limited
☐ Temporary access is used where appropriate
☐ Contractor access is reviewed
☐ Supplier personnel screening responsibilities are defined
☐ Contractor offboarding is completed


26. Third-Party Personnel

Verify:

☐ Third-party personnel are identified
☐ Security requirements are contractually defined where appropriate
☐ Screening responsibility is assigned
☐ Access requirements are documented
☐ Privileged access is controlled
☐ Access expiry is defined where practical
☐ Personnel changes are communicated
☐ Offboarding requirements are defined


27. Personnel Changes

Verify:

☐ Promotions trigger appropriate access review
☐ Department transfers trigger access review
☐ Responsibility changes trigger role review
☐ Sensitive-role classification is reassessed
☐ Additional screening is performed where required
☐ Old permissions are removed
☐ New permissions are approved


28. Disciplinary Process

Verify:

☐ Information-security violations are addressed
☐ Disciplinary responsibilities are defined
☐ Security violations can be reported
☐ Investigation process exists
☐ HR and Security responsibilities are defined
☐ Disciplinary actions are appropriately documented
☐ Legal/privacy requirements are considered
☐ Serious violations are escalated appropriately
☐ Process is applied consistently

The disciplinary process should follow applicable employment law and organizational requirements.


29. Security Incident Reporting by Personnel

Verify personnel know:

☐ What constitutes a security incident
☐ How to report incidents
☐ Who to contact
☐ How quickly to report
☐ How to report lost/stolen devices
☐ How to report suspected phishing
☐ How to report unauthorized access
☐ How to report accidental data disclosure


30. Personnel Security During Incidents

Verify:

☐ HR involvement is defined where necessary
☐ Access can be suspended when authorized
☐ Evidence is preserved
☐ Investigations are controlled
☐ Confidentiality is maintained
☐ Legal requirements are considered
☐ Disciplinary processes are coordinated appropriately


31. Employee Offboarding

Verify:

☐ Termination/exit notification is received
☐ Access revocation is initiated promptly
☐ Accounts are disabled
☐ Privileged access is removed
☐ Cloud access is removed
☐ SaaS access is removed
☐ VPN access is removed
☐ Source-code access is removed
☐ Production access is removed
☐ API tokens/keys are addressed
☐ Company devices are returned
☐ Physical access is revoked
☐ Information is returned/deleted where required
☐ Confidentiality obligations are communicated


32. Access Revocation Testing

Sample recently departed personnel.

Verify:

☐ HR exit date
☐ Account disablement date/time
☐ VPN removal
☐ Cloud access removal
☐ SaaS access removal
☐ Source-code access removal
☐ Production access removal
☐ Physical access removal
☐ Privileged access removal

Sample Result


33. Asset Return

Verify:

☐ Laptop returned
☐ Mobile device returned
☐ Security token returned
☐ ID/access card returned
☐ Removable media returned
☐ Other company equipment returned
☐ Asset register updated
☐ Lost assets escalated


34. Information Return and Protection

Verify:

☐ Organizational information returned where required
☐ Customer information addressed
☐ Personal data addressed
☐ Confidential files addressed
☐ Source code remains protected
☐ Local copies addressed where appropriate
☐ Cloud/shared-drive access removed
☐ Data deletion requirements addressed


35. Post-Employment Confidentiality

Verify:

☐ Continuing confidentiality obligations are defined where appropriate
☐ Intellectual-property obligations continue where applicable
☐ Customer confidentiality requirements are addressed
☐ Trade-secret protection is addressed where appropriate
☐ Post-employment obligations are communicated


36. Re-Screening

Verify whether re-screening is required based on:

☐ Role risk
☐ Legal requirement
☐ Contractual requirement
☐ Customer requirement
☐ Regulatory requirement
☐ Privileged role
☐ Security-sensitive role
☐ Significant role change
☐ Organizational policy

Re-Screening Status


37. Personnel Records

Verify:

☐ HR records are appropriately protected
☐ Access is restricted
☐ Personnel records are classified appropriately
☐ Sensitive information is minimized
☐ Retention requirements are defined
☐ Secure disposal is implemented
☐ Unauthorized access is monitored where appropriate
☐ Privacy requirements are addressed


38. HR Systems Security

Assess systems such as:

☐ HRIS
☐ Payroll
☐ Recruitment platform
☐ Background verification platform
☐ Learning management system
☐ Employee document repository
☐ Performance-management platform

Verify:

☐ Access control
☐ MFA
☐ Role-based permissions
☐ Logging
☐ Data protection
☐ Backup
☐ Supplier security
☐ Data retention
☐ Offboarding


39. Sensitive HR Information

Determine whether HR systems contain:

☐ Identity information
☐ Employment information
☐ Background-check information
☐ Compensation information
☐ Bank/payment information
☐ Health information where applicable
☐ Disciplinary information
☐ Performance information
☐ Authentication information

Verify that sensitive information is appropriately protected.


40. HR Supplier Security

For HR-related third parties:

☐ Background verification provider
☐ Payroll provider
☐ Recruitment provider
☐ HRIS provider
☐ Benefits provider
☐ Learning platform
☐ Contractor management platform

Verify:

☐ Supplier due diligence
☐ Security requirements
☐ Privacy requirements
☐ Data-processing requirements where applicable
☐ Subprocessors
☐ Data location
☐ Incident notification
☐ Access controls
☐ Contractual requirements


41. Security Awareness Effectiveness

Do not rely solely on training completion.

Consider:

☐ Training completion
☐ Knowledge assessments
☐ Phishing exercises where appropriate
☐ Security incident trends
☐ Policy violations
☐ Repeated user errors
☐ Security reporting behavior
☐ Role-specific competency


42. Policy Compliance Testing

Sample personnel and verify:

☐ Policies were communicated
☐ Personnel acknowledged where required
☐ Security requirements are understood
☐ Actual behavior aligns with requirements
☐ Exceptions are documented
☐ Violations are addressed


43. Evidence Review

Collect appropriate evidence such as:

☐ HR policies
☐ Screening policy
☐ Background verification procedure
☐ Screening register
☐ Sensitive role register
☐ Employment terms
☐ NDA records
☐ Training records
☐ Policy acknowledgements
☐ Access approvals
☐ Access review records
☐ Contractor records
☐ Offboarding records
☐ Asset-return records
☐ Disciplinary records where appropriately accessible
☐ Re-screening records
☐ HR supplier assessments

Avoid collecting unnecessary sensitive personal information during the audit.


44. Sampling

Define sample methodology.

Population: __________________

Sample Size: ________________

Sampling Method: ____________

Sample Period: ______________

Suggested Samples

☐ New joiners
☐ Recent role changes
☐ Recent leavers
☐ Privileged users
☐ Production users
☐ Contractors
☐ Security personnel
☐ Remote workers
☐ High-risk roles


45. HR Security Findings

Finding IDAreaRequirementConditionEvidenceRiskOwnerDue Date

46. Finding Classification

Classify findings according to the organization’s approved methodology.

Possible categories:

  • Observation
  • Improvement Opportunity
  • Minor Nonconformity
  • Major Nonconformity
  • Security Risk

Do not create a severity methodology unless it is aligned with the organization’s established audit/risk process.


47. HR Security Risk Assessment

For significant findings assess:

Asset: ______________________

Threat: _____________________

Vulnerability: ______________

Impact: _____________________

Likelihood: _________________

Inherent Risk: ______________

Existing Controls: ___________

Residual Risk: ______________

Treatment: __________________


48. Immediate Remediation

Where an immediate security issue exists:

☐ Access removed
☐ Account disabled
☐ Privilege reduced
☐ Information secured
☐ Device recovered
☐ Credential/token revoked
☐ Incident raised
☐ Management notified
☐ Risk accepted temporarily where appropriate


49. Corrective Action

For each significant finding:

☐ Root cause identified
☐ Immediate correction completed
☐ Corrective action defined
☐ Owner assigned
☐ Due date established
☐ Remediation evidence defined
☐ Effectiveness verification defined
☐ Residual risk assessed
☐ Closure criteria defined


50. HR Security Metrics

Track where useful:

MetricResult
Screening completion %
Overdue screening
Screening exceptions
Security training completion %
Policy acknowledgement %
Joiner access completion
Mover access reviews completed
Leaver access revocation completed
Offboarding exceptions
Privileged users reviewed
Sensitive roles reviewed
Security incidents involving personnel
Open HR security findings

51. Management Review Inputs

Consider reporting:

☐ Screening status
☐ Security awareness
☐ Personnel incidents
☐ Policy violations
☐ Access-control issues
☐ Privileged-access findings
☐ Offboarding issues
☐ Contractor security
☐ HR supplier risks
☐ Open corrective actions
☐ Repeated findings
☐ Security trends


52. Overall HR Security Assessment

AreaStatusKey Finding
Governance
Screening
Employment Terms
Confidentiality
Onboarding
Awareness
Access Management
Privileged Access
Remote Working
Contractors
Role Changes
Incident Reporting
Offboarding
HR Systems
HR Suppliers
Records Protection

53. Audit Conclusion

Overall Result

☐ Effective
☐ Partially Effective
☐ Improvement Required
☐ Significant Gaps Identified

Summary

Key Strengths

Key Gaps

Priority Actions


54. Management Response

Management Response:

Responsible Manager: ______________________

Target Date: ______________________________

Management Acceptance: ____________________


55. Audit Approval

Auditor: _________________________________

HR Owner: ________________________________

Information Security: ______________________

Risk Owner: ______________________________

Management Approver: _____________________

Audit Date: _______________________________

Next Review Date: _________________________


56. AWS SaaS Startup Example

For an AWS-based SaaS startup, the HR security audit should pay particular attention to personnel who can access:

  • AWS production
  • IAM
  • Source code
  • CI/CD
  • Production databases
  • Customer information
  • Security monitoring
  • Secrets
  • Encryption keys

A sample audit trail could be:

Recruitment → Role Risk Assessment → Background Verification → Employment Terms → Security Training → Access Approval → MFA → Privileged Access Controls → Periodic Review → Role Change/Leaver Process

For an AWS administrator, the auditor may sample:

  1. Role classification
  2. Screening completion
  3. Employment/security terms
  4. Security training
  5. IAM approval
  6. MFA
  7. Privileged access
  8. Access review
  9. Logging
  10. Offboarding controls

57. Startup-Friendly HR Security Audit Model

A startup can perform a focused HR security audit using five lifecycle stages:

1. Before Joining

  • Role risk
  • Screening
  • Employment terms
  • Confidentiality

2. Joining

  • Security training
  • Policy communication
  • Access approval
  • MFA

3. During Employment

  • Access reviews
  • Security awareness
  • Role changes
  • Security incidents
  • Policy compliance

4. Sensitive Roles

  • Enhanced screening where justified
  • Privileged-access controls
  • Production access controls
  • Additional monitoring

5. Leaving

  • Account disablement
  • Access revocation
  • Asset return
  • Information protection
  • Confidentiality obligations

58. Common Mistakes

Avoid:

  • Treating HR security as only an HR responsibility
  • Checking only whether policies exist
  • Failing to test actual implementation
  • Granting access before required screening
  • Not identifying sensitive roles
  • Ignoring contractors
  • Ignoring third-party personnel
  • Failing to review role changes
  • Not testing leaver access revocation
  • Relying only on training completion
  • Storing excessive personal information
  • Failing to protect HR systems
  • Ignoring HR service providers
  • Applying intrusive screening without a lawful and proportionate basis
  • Not documenting exceptions
  • Not following up on previous findings

59. Relationship With Other ISMS Documents

DocumentRelationship
HR Security PolicyDefines personnel-security requirements
Employee Screening PolicyDefines screening principles
Background Verification ProcedureDefines verification process
Background Verification RegisterTracks screening
Sensitive Role Identification ChecklistIdentifies sensitive roles
Role-Based Screening MatrixDetermines screening level
Security Awareness ProcedureDefines training
Security Policy Acknowledgement RegisterTracks policy acknowledgement
Access Management ProcedureControls user access
Access Compliance Review ChecklistReviews access
Privileged Access ProcedureControls privileged access
Employee Onboarding ProcedureControls joining
Employee Offboarding ProcedureControls exit
Contractor Screening ProcedureControls contractor screening
Incident Response ProcedureHandles personnel-related incidents
Risk RegisterTracks significant personnel risks

60. ISO/IEC 27001 Connection

HR security auditing supports the organization’s assessment of personnel-related security controls across the employee lifecycle.

The audit should consider applicable requirements relating to:

  • Personnel screening
  • Employment terms and responsibilities
  • Security awareness and training
  • Confidentiality
  • Access management
  • Privileged access
  • Remote working
  • Personnel changes
  • Termination or change of employment
  • Contractor and third-party personnel
  • Incident reporting
  • Information protection

The HR Security Audit Checklist is not itself a universally prescribed ISO/IEC 27001 document. The organization should determine its audit scope, sampling, frequency, evidence, and criteria based on the ISMS scope, risk assessment, applicable controls, legal requirements, contractual requirements, customer requirements, and previous findings.


61. Audit Evidence Checklist

The final audit file should contain appropriate evidence such as:

☐ Approved audit checklist
☐ Audit scope and criteria
☐ Sampling methodology
☐ HR security policies
☐ Screening records
☐ Sensitive role assessment
☐ Background Verification Register
☐ Employment/security agreements
☐ Training records
☐ Policy acknowledgement records
☐ Access approvals
☐ Access review evidence
☐ Privileged access evidence
☐ Contractor records
☐ Offboarding evidence
☐ Asset-return evidence
☐ Findings
☐ Risk assessments
☐ Corrective actions
☐ Management response
☐ Audit approval


62. Final HR Security Audit Trail

For every significant personnel-security area, the organization should be able to demonstrate:

What security risk does the role create?
Was the person appropriately screened?
Were security responsibilities defined?
Were confidentiality requirements established?
Was security awareness completed?
Was access properly authorized?
Was privileged access controlled?
Were role changes reviewed?
Were contractors appropriately controlled?
Were security incidents reported?
Was access removed when employment ended?
Were organizational assets returned?
Were sensitive personnel records protected?
Were identified weaknesses corrected and verified?

Final Principle

HR security auditing is not simply checking whether HR policies exist. It verifies that personnel-security requirements operate throughout the employee lifecycle—from role assessment and screening to access, awareness, role changes, and offboarding—and that the organization can demonstrate this with appropriate evidence.