ISO/IEC 27001

⌘K
  1. Home
  2. Docs
  3. ISO/IEC 27001
  4. 3. ISO 27001 Annex A Cont...
  5. ISO 27001 Annex A 6.1 Screening

ISO 27001 Annex A 6.1 Screening

What is ISO 27001 Annex A 6.1?

ISO 27001 Annex A 6.1, Screening, requires the organization to conduct appropriate background verification checks on candidates for employment and, where relevant, contractors and other parties.

The screening process should be:

  • Appropriate to the business requirements.
  • Proportionate to the role.
  • Consistent with applicable laws and regulations.
  • Based on the organization’s information security risks.
  • Performed before employment or engagement where appropriate.

The purpose is to reduce the risk of engaging individuals whose background may create an unacceptable information security risk.

Simple explanation

Before giving someone access to important information or systems, perform appropriate and lawful checks to understand whether they are suitable for the role and its security responsibilities.


Why is Annex A 6.1 Important?

Employees, contractors and temporary workers may receive access to:

  • Customer information.
  • Source code.
  • Production systems.
  • Financial information.
  • Intellectual property.
  • Security systems.
  • Cloud environments.
  • Confidential business information.

A person may therefore represent a significant information security risk if their identity, qualifications or background are not appropriately verified.

Screening helps organizations reduce risks such as:

  • False identity or credentials.
  • Misrepresentation of qualifications.
  • Unauthorized access.
  • Insider threats.
  • Fraud.
  • Conflicts with role requirements.
  • Hiring individuals without verifying important information.

However, screening is not a guarantee that an individual will never become a security risk.

Simple principle

Apply appropriate checks before granting sensitive responsibilities or access, and make sure those checks are lawful and proportionate.


What Does Annex A 6.1 Require?

The organization should establish screening processes appropriate to:

  • The role.
  • The level of access.
  • The sensitivity of information.
  • The business risk.
  • Employment status.
  • Legal requirements.
  • Regulatory requirements.
  • Contractual requirements.

Screening may be different for different roles.

For example:

Junior Marketing Employee

May require:

  • Identity verification.
  • Employment/education verification where appropriate.
  • Basic reference checks.

System Administrator

May require additional checks because the person could have:

  • Privileged access.
  • Production access.
  • Customer-data access.
  • Security-management responsibilities.

Senior Security or Finance Role

May have additional screening requirements based on:

  • Regulatory obligations.
  • Contractual requirements.
  • Role sensitivity.
  • Access to highly confidential information.

The organization should avoid applying excessive or irrelevant screening without a legitimate reason.


What Can Screening Include?

Depending on applicable law and the role, screening may include:

  • Identity verification.
  • Employment history.
  • Professional qualifications.
  • Education verification.
  • Professional references.
  • Employment references.
  • Right-to-work verification where applicable.
  • Criminal record checks where legally permitted and appropriate.
  • Professional license verification.
  • Conflict-of-interest declarations.
  • Other legally permissible checks relevant to the role.

The exact checks should be determined based on the organization’s requirements and applicable law.


Screening Should Be Risk-Based

Not every employee needs the same level of screening.

Consider:

FactorExample
RoleSystem Administrator
Information accessCustomer PII
System accessProduction
Privilege levelHigh
Business impactHigh
Regulatory requirementApplicable
Customer requirementBackground verification
Screening levelEnhanced

A practical approach is:

Higher-risk role → stronger justification for additional screening

This should still be balanced against privacy, employment and other legal requirements.


Activities Required to Implement A.6.1

Step 1 — Identify Roles Requiring Screening

Create a list of roles and determine their information security sensitivity.

Example:

RoleSensitive InformationPrivileged AccessScreening
HR ExecutiveEmployee PIILowStandard
DeveloperSource codeMediumStandard
System AdministratorProduction systemsHighEnhanced
Security EngineerSecurity systemsHighEnhanced
Finance ManagerFinancial informationHighEnhanced
Customer SupportCustomer informationMediumStandard

Step 2 — Define Screening Requirements

Create a screening matrix.

CheckStandard RoleSensitive RoleHigh-Risk Role
Identity verification✓✓✓
Employment verification✓✓✓
Education verificationWhere relevant✓✓
Reference checkWhere relevant✓✓
Professional qualificationWhere relevant✓✓
Criminal record checkWhere legally permitted/requiredAs applicableAs applicable
Regulatory check—As applicableAs applicable

The organization should define its own requirements based on risk and applicable law.


Step 3 — Include Screening Requirements in Recruitment

The organization should communicate relevant screening requirements during recruitment.

For example:

“Employment is subject to completion of applicable background verification checks.”

Candidates should understand what checks are required where appropriate.


Step 4 — Obtain Appropriate Information and Authorization

Screening can involve personal information.

Therefore, the organization should ensure that:

  • Appropriate notices are provided.
  • Required authorization or consent is obtained where applicable.
  • Information is collected lawfully.
  • Only necessary information is collected.
  • Information is protected.

This connects A.6.1 with privacy requirements.


Step 5 — Perform the Screening

The screening may be performed by:

  • Internal HR.
  • A qualified background-verification provider.
  • Recruitment partner.
  • Other authorized third party.

The organization should maintain appropriate records demonstrating that the required checks were completed.


Step 6 — Evaluate the Result

A screening result should not automatically mean:

“Pass” or “Fail” without considering context.

Where relevant, the organization should have a process for handling exceptions or adverse findings.

Consider:

  • Relevance to the role.
  • Accuracy of the information.
  • Applicable legal restrictions.
  • Regulatory requirements.
  • Customer requirements.
  • Risk to the organization.

Decisions should be made according to documented criteria and applicable law.


Step 7 — Protect Screening Information

Screening records can contain highly sensitive personal information.

They should therefore be:

  • Access restricted.
  • Stored securely.
  • Protected from unauthorized disclosure.
  • Retained only as long as required.
  • Disposed of securely.

HR records should not be freely accessible to technical or operational teams.


Step 8 — Complete Screening Before Appropriate Access

Where practical and appropriate, required screening should be completed before the person receives access to sensitive systems or information.

For example:

Candidate selected

↓

Screening initiated

↓

Required checks completed

↓

Result reviewed

↓

Employment/engagement finalized

↓

Access provisioned

This should be aligned with the organization’s employment and onboarding process.


Startup Example

Consider a SaaS startup with 30 employees.

The company provides software to US and European customers.

Its infrastructure team has access to:

  • Production databases.
  • Cloud administration.
  • Customer information.
  • Security logs.
  • Backup systems.

The company decides that all employees receive standard screening, while employees in highly privileged roles receive additional checks appropriate to the role and applicable law.

For a new system administrator:

  1. HR verifies identity.
  2. Employment history is verified.
  3. Relevant qualifications are verified.
  4. Required reference checks are completed.
  5. Additional legally permitted checks are performed where applicable.
  6. Results are reviewed.
  7. Required screening is completed.
  8. Production access is provisioned.
  9. Screening records are securely retained.

Flow

Identify Role Risk

↓

Define Screening

↓

Perform Checks

↓

Review Results

↓

Approve Engagement

↓

Provision Appropriate Access

This provides a controlled connection between HR screening and information security.


Startup-Focused Quick Summary

A startup does not need to build a complicated investigation system.

A practical approach is:

1. Classify roles by risk

Who has access to:

  • Production?
  • Customer PII?
  • Source code?
  • Financial information?
  • Security systems?

2. Define appropriate screening

Use more comprehensive checks for more sensitive roles where justified.

3. Make the process consistent

Document what checks are required.

4. Protect screening information

Treat screening records as sensitive personal information.

5. Keep evidence

Maintain evidence that required checks were completed.

6. Link screening to onboarding

Avoid granting sensitive access before required screening is appropriately completed.


Example Employee Screening Register

A controlled HR register may contain:

Employee IDRoleScreening RequiredChecks CompletedDateStatus
EMP-001DeveloperStandardIdentity + Employment10-JulComplete
EMP-002System AdministratorEnhancedRequired checks12-JulComplete
EMP-003HR ExecutiveStandardIdentity + Employment15-JulComplete
EMP-004Security EngineerEnhancedRequired checks18-JulComplete

Avoid storing unnecessary sensitive screening details in a general-purpose spreadsheet.

Where detailed reports are retained, use a secure HR or document-management system with appropriate access controls.


Example Role-Based Screening Matrix

Role CategoryTypical RiskExample Screening
General employeeLow/MediumIdentity + employment verification
Customer supportMediumIdentity + employment/reference
DeveloperMediumIdentity + employment/qualification where relevant
FinanceHighEnhanced checks as appropriate
System AdministratorHighEnhanced checks as appropriate
Security AdministratorHighEnhanced checks as appropriate
Senior privileged roleHighRisk-based enhanced screening

These are examples, not universal requirements. The organization should determine appropriate screening based on its own risk, legal and contractual environment.


Screening and Privacy

A.6.1 itself involves processing personal information.

This creates an important connection with A.5.34 — Privacy and Protection of PII.

For example, a background verification report may contain:

  • Identity information.
  • Employment history.
  • Education information.
  • Reference information.
  • Potentially sensitive personal information.

Therefore, the organization should determine:

  • Why the information is collected.
  • What information is necessary.
  • Who can access it.
  • How long it is retained.
  • Where it is stored.
  • Who receives it.
  • When it is deleted.

Simple principle

Screening protects the organization, but the screening process itself must also protect the candidate’s personal information.


Screening of Contractors and Third Parties

A.6.1 may also be relevant to:

  • Contractors.
  • Temporary workers.
  • Consultants.
  • Interns.
  • Outsourced personnel.
  • Other parties who receive significant access.

For example, a startup may outsource infrastructure management.

If an external engineer receives privileged production access, the organization should consider:

  • What screening has been performed?
  • Who performed it?
  • Is it appropriate for the role?
  • What contractual requirements apply?
  • How is the information protected?
  • When is access removed?

The exact requirements should be based on risk and applicable obligations.


What if Screening Cannot Be Completed Before Joining?

Sometimes operational requirements may make it necessary to onboard an individual before all checks are complete.

The organization should have a controlled approach.

Possible safeguards may include:

  • Delaying sensitive access.
  • Providing limited access.
  • Requiring additional supervision.
  • Restricting privileged activities.
  • Recording the exception.
  • Defining a completion deadline.
  • Obtaining appropriate approval.

For example:

A new developer can complete general onboarding but does not receive production database access until required screening is completed.

This is generally stronger than simply ignoring the missing check.


Audit Evidence for A.6.1

An auditor may look for:

Policies and Procedures

  • HR Security Policy.
  • Employee Screening Procedure.
  • Recruitment Procedure.
  • Background Verification Procedure.
  • Third-Party Screening Procedure.

Screening Requirements

  • Role-based screening matrix.
  • Job descriptions.
  • Screening criteria.
  • Employment contracts.
  • Contractor agreements.

Screening Records

  • Identity verification evidence.
  • Employment verification.
  • Qualification verification.
  • Reference checks.
  • Background verification completion records.

Sensitive details should only be provided to auditors where appropriate and lawful.

Often, evidence that the required check was completed is preferable to unnecessarily exposing the complete background report.

Exceptions

  • Screening exception records.
  • Approval records.
  • Compensating controls.
  • Completion tracking.

What an Auditor May Ask

Governance

“What is your employee screening process?”

“Who determines which checks are required?”

“Is screening risk-based?”

Recruitment

“How do you ensure required screening is completed?”

“At what stage is screening performed?”

“How do you handle contractors?”

Sensitive Roles

“Do administrators receive different screening from other employees?”

“How do you identify roles requiring enhanced screening?”

Evidence

“Show me evidence that screening was completed for a sample of employees.”

“How do you protect screening records?”

Exceptions

“What happens when screening cannot be completed before access is required?”

“Who approves exceptions?”


Common Mistakes in Implementing A.6.1

1. Screening everyone identically

A receptionist and a production administrator may not have the same information security risk.

A risk-based approach is more appropriate.


2. Screening is performed but not documented

The organization says:

“HR always performs background checks.”

But there is no reliable evidence.

This creates an audit problem.


3. Screening is performed after sensitive access is granted

Where required and practical, sensitive access should not be granted before required screening is appropriately completed.


4. No contractor screening

Organizations sometimes screen employees but ignore contractors who have extensive access to systems.


5. Excessive screening

More screening is not automatically better.

Organizations should consider:

  • Relevance.
  • Necessity.
  • Proportionality.
  • Privacy.
  • Applicable law.

6. Screening records are poorly protected

Background-check reports may contain sensitive personal information.

They should not be stored in:

  • Public folders.
  • Unrestricted shared drives.
  • General employee folders.
  • Unsecured email archives.

7. No exception process

Sometimes checks may be delayed.

There should be a documented method for handling such situations.


8. No connection to onboarding

HR completes screening, but IT is never informed that the employee is cleared for sensitive access.

The process should connect HR and access provisioning appropriately.


Practical Startup Implementation Model

A practical model is:

Identify

Identify roles that handle sensitive information or privileged systems.

↓

Assess

Determine the level of screening appropriate to each role.

↓

Define

Document required screening checks.

↓

Screen

Perform appropriate checks before sensitive access where practical.

↓

Review

Evaluate results according to documented criteria and applicable law.

↓

Protect

Secure screening records.

↓

Onboard

Provision access according to the employee’s role.

↓

Monitor

Ensure changes in role or access are managed appropriately.


Policy vs. Process vs. Evidence

CategoryExample
PolicyHuman Resources Security Policy
PolicyEmployee Screening Policy
ProcessBackground Verification Procedure
ProcessRole-Based Screening Procedure
ProcessContractor Screening Procedure
ProcessScreening Exception Procedure
EvidenceScreening completion record
EvidenceVerification report
EvidenceRole-based screening matrix
EvidenceApproval record
EvidenceException record
EvidenceSecure HR record
EvidenceAccess provisioning record

Simple rule

Policy defines what the organization requires.

Procedure explains how screening is performed.

Evidence demonstrates that required screening was completed.


Relationship with Other ISO 27001 Controls

A.6.1 is connected to several other controls.

ControlRelationship
A.5.15Access control should reflect authorized roles
A.5.16Identity management begins with reliable identity information
A.5.18Access rights should be based on role and authorization
A.5.31Legal and regulatory requirements may affect screening
A.5.34Screening involves processing personal information
A.6.2Employment terms should address security responsibilities
A.6.3Personnel should receive security awareness and training
A.6.5Responsibilities continue after or during changes to employment
A.6.6Confidentiality agreements protect information
A.6.7Remote working may introduce additional security requirements
A.6.8Personnel need a mechanism for reporting security events

A.6.1 vs. A.6.2

These controls are related but different.

A.6.1 — Screening

Focuses on:

“Have we performed appropriate checks before engaging the person?”

A.6.2 — Terms and Conditions of Employment

Focuses on:

“Have security responsibilities and obligations been established as part of the employment relationship?”

For example:

A.6.1

→ Verify identity and relevant background.

A.6.2

→ Employee agrees to confidentiality, security responsibilities and organizational requirements.

Together they create stronger personnel security.


Useful Documents for A.6.1

Organizations may create:

  • [Insert Draft Document Link] — Employee Screening Policy
  • [Insert Draft Document Link] — Background Verification Procedure
  • [Insert Draft Document Link] — Role-Based Screening Matrix
  • [Insert Draft Document Link] — Employee Screening Checklist
  • [Insert Draft Document Link] — Contractor Screening Procedure
  • [Insert Draft Document Link] — Screening Exception Form
  • [Insert Draft Document Link] — Background Verification Register
  • [Insert Draft Document Link] — Sensitive Role Identification Checklist
  • [Insert Draft Document Link] — HR Security Audit Checklist

A.6.1 Audit Readiness Checklist

Before an ISO 27001 audit, ask:

  • Have we documented our employee screening requirements?
  • Have we identified sensitive and privileged roles?
  • Is screening proportionate to role risk?
  • Are required checks defined?
  • Are screening requirements communicated appropriately?
  • Are checks completed before sensitive access where appropriate?
  • Do we screen relevant contractors and third parties?
  • Are screening records securely maintained?
  • Are privacy requirements considered?
  • Do we have a screening exception process?
  • Are exceptions approved and tracked?
  • Can we demonstrate completion of screening for sampled personnel?
  • Are screening requirements reviewed when roles or risks change?

Questions a Startup Should Ask

Before considering A.6.1 implemented, ask:

Which roles have access to our most sensitive information and systems?

What screening is appropriate for those roles?

Are the checks legally permitted and proportionate?

Are contractors included where appropriate?

Do we have evidence that required checks were completed?

Is sensitive screening information protected?

What happens if screening is incomplete?

Do our HR and IT onboarding processes work together?

If these questions have clear answers and supporting evidence, the startup has a much stronger personnel-screening process.


Startup-Focused Final Takeaway

ISO 27001 Annex A 6.1 is about reducing personnel-related information security risk before giving individuals responsibilities or access that could materially affect the organization’s information and systems.

A practical startup approach is:

Identify sensitive roles

↓

Assess the risk

↓

Define appropriate screening

↓

Perform lawful and proportionate checks

↓

Review the results

↓

Protect screening information

↓

Complete appropriate onboarding

↓

Grant access according to role

The key question for A.6.1 is:

“Before giving someone access to our sensitive information or systems, have we performed the appropriate, lawful and risk-based checks for their role?”

Screening is only one part of personnel security. It works together with employment terms, confidentiality, security awareness, access management, offboarding and ongoing compliance to create a complete personnel-security lifecycle.

How can we help?

Leave a Reply

Your email address will not be published. Required fields are marked *