What is ISO 27001 Annex A 6.1?
ISO 27001 Annex A 6.1, Screening, requires the organization to conduct appropriate background verification checks on candidates for employment and, where relevant, contractors and other parties.
The screening process should be:
- Appropriate to the business requirements.
- Proportionate to the role.
- Consistent with applicable laws and regulations.
- Based on the organization’s information security risks.
- Performed before employment or engagement where appropriate.
The purpose is to reduce the risk of engaging individuals whose background may create an unacceptable information security risk.
Simple explanation
Before giving someone access to important information or systems, perform appropriate and lawful checks to understand whether they are suitable for the role and its security responsibilities.
Why is Annex A 6.1 Important?
Employees, contractors and temporary workers may receive access to:
- Customer information.
- Source code.
- Production systems.
- Financial information.
- Intellectual property.
- Security systems.
- Cloud environments.
- Confidential business information.
A person may therefore represent a significant information security risk if their identity, qualifications or background are not appropriately verified.
Screening helps organizations reduce risks such as:
- False identity or credentials.
- Misrepresentation of qualifications.
- Unauthorized access.
- Insider threats.
- Fraud.
- Conflicts with role requirements.
- Hiring individuals without verifying important information.
However, screening is not a guarantee that an individual will never become a security risk.
Simple principle
Apply appropriate checks before granting sensitive responsibilities or access, and make sure those checks are lawful and proportionate.
What Does Annex A 6.1 Require?
The organization should establish screening processes appropriate to:
- The role.
- The level of access.
- The sensitivity of information.
- The business risk.
- Employment status.
- Legal requirements.
- Regulatory requirements.
- Contractual requirements.
Screening may be different for different roles.
For example:
Junior Marketing Employee
May require:
- Identity verification.
- Employment/education verification where appropriate.
- Basic reference checks.
System Administrator
May require additional checks because the person could have:
- Privileged access.
- Production access.
- Customer-data access.
- Security-management responsibilities.
Senior Security or Finance Role
May have additional screening requirements based on:
- Regulatory obligations.
- Contractual requirements.
- Role sensitivity.
- Access to highly confidential information.
The organization should avoid applying excessive or irrelevant screening without a legitimate reason.
What Can Screening Include?
Depending on applicable law and the role, screening may include:
- Identity verification.
- Employment history.
- Professional qualifications.
- Education verification.
- Professional references.
- Employment references.
- Right-to-work verification where applicable.
- Criminal record checks where legally permitted and appropriate.
- Professional license verification.
- Conflict-of-interest declarations.
- Other legally permissible checks relevant to the role.
The exact checks should be determined based on the organization’s requirements and applicable law.
Screening Should Be Risk-Based
Not every employee needs the same level of screening.
Consider:
| Factor | Example |
|---|---|
| Role | System Administrator |
| Information access | Customer PII |
| System access | Production |
| Privilege level | High |
| Business impact | High |
| Regulatory requirement | Applicable |
| Customer requirement | Background verification |
| Screening level | Enhanced |
A practical approach is:
Higher-risk role → stronger justification for additional screening
This should still be balanced against privacy, employment and other legal requirements.
Activities Required to Implement A.6.1
Step 1 — Identify Roles Requiring Screening
Create a list of roles and determine their information security sensitivity.
Example:
| Role | Sensitive Information | Privileged Access | Screening |
|---|---|---|---|
| HR Executive | Employee PII | Low | Standard |
| Developer | Source code | Medium | Standard |
| System Administrator | Production systems | High | Enhanced |
| Security Engineer | Security systems | High | Enhanced |
| Finance Manager | Financial information | High | Enhanced |
| Customer Support | Customer information | Medium | Standard |
Step 2 — Define Screening Requirements
Create a screening matrix.
| Check | Standard Role | Sensitive Role | High-Risk Role |
|---|---|---|---|
| Identity verification | ✓ | ✓ | ✓ |
| Employment verification | ✓ | ✓ | ✓ |
| Education verification | Where relevant | ✓ | ✓ |
| Reference check | Where relevant | ✓ | ✓ |
| Professional qualification | Where relevant | ✓ | ✓ |
| Criminal record check | Where legally permitted/required | As applicable | As applicable |
| Regulatory check | — | As applicable | As applicable |
The organization should define its own requirements based on risk and applicable law.
Step 3 — Include Screening Requirements in Recruitment
The organization should communicate relevant screening requirements during recruitment.
For example:
“Employment is subject to completion of applicable background verification checks.”
Candidates should understand what checks are required where appropriate.
Step 4 — Obtain Appropriate Information and Authorization
Screening can involve personal information.
Therefore, the organization should ensure that:
- Appropriate notices are provided.
- Required authorization or consent is obtained where applicable.
- Information is collected lawfully.
- Only necessary information is collected.
- Information is protected.
This connects A.6.1 with privacy requirements.
Step 5 — Perform the Screening
The screening may be performed by:
- Internal HR.
- A qualified background-verification provider.
- Recruitment partner.
- Other authorized third party.
The organization should maintain appropriate records demonstrating that the required checks were completed.
Step 6 — Evaluate the Result
A screening result should not automatically mean:
“Pass” or “Fail” without considering context.
Where relevant, the organization should have a process for handling exceptions or adverse findings.
Consider:
- Relevance to the role.
- Accuracy of the information.
- Applicable legal restrictions.
- Regulatory requirements.
- Customer requirements.
- Risk to the organization.
Decisions should be made according to documented criteria and applicable law.
Step 7 — Protect Screening Information
Screening records can contain highly sensitive personal information.
They should therefore be:
- Access restricted.
- Stored securely.
- Protected from unauthorized disclosure.
- Retained only as long as required.
- Disposed of securely.
HR records should not be freely accessible to technical or operational teams.
Step 8 — Complete Screening Before Appropriate Access
Where practical and appropriate, required screening should be completed before the person receives access to sensitive systems or information.
For example:
Candidate selected
↓
Screening initiated
↓
Required checks completed
↓
Result reviewed
↓
Employment/engagement finalized
↓
Access provisioned
This should be aligned with the organization’s employment and onboarding process.
Startup Example
Consider a SaaS startup with 30 employees.
The company provides software to US and European customers.
Its infrastructure team has access to:
- Production databases.
- Cloud administration.
- Customer information.
- Security logs.
- Backup systems.
The company decides that all employees receive standard screening, while employees in highly privileged roles receive additional checks appropriate to the role and applicable law.
For a new system administrator:
- HR verifies identity.
- Employment history is verified.
- Relevant qualifications are verified.
- Required reference checks are completed.
- Additional legally permitted checks are performed where applicable.
- Results are reviewed.
- Required screening is completed.
- Production access is provisioned.
- Screening records are securely retained.
Flow
Identify Role Risk
↓
Define Screening
↓
Perform Checks
↓
Review Results
↓
Approve Engagement
↓
Provision Appropriate Access
This provides a controlled connection between HR screening and information security.
Startup-Focused Quick Summary
A startup does not need to build a complicated investigation system.
A practical approach is:
1. Classify roles by risk
Who has access to:
- Production?
- Customer PII?
- Source code?
- Financial information?
- Security systems?
2. Define appropriate screening
Use more comprehensive checks for more sensitive roles where justified.
3. Make the process consistent
Document what checks are required.
4. Protect screening information
Treat screening records as sensitive personal information.
5. Keep evidence
Maintain evidence that required checks were completed.
6. Link screening to onboarding
Avoid granting sensitive access before required screening is appropriately completed.
Example Employee Screening Register
A controlled HR register may contain:
| Employee ID | Role | Screening Required | Checks Completed | Date | Status |
|---|---|---|---|---|---|
| EMP-001 | Developer | Standard | Identity + Employment | 10-Jul | Complete |
| EMP-002 | System Administrator | Enhanced | Required checks | 12-Jul | Complete |
| EMP-003 | HR Executive | Standard | Identity + Employment | 15-Jul | Complete |
| EMP-004 | Security Engineer | Enhanced | Required checks | 18-Jul | Complete |
Avoid storing unnecessary sensitive screening details in a general-purpose spreadsheet.
Where detailed reports are retained, use a secure HR or document-management system with appropriate access controls.
Example Role-Based Screening Matrix
| Role Category | Typical Risk | Example Screening |
|---|---|---|
| General employee | Low/Medium | Identity + employment verification |
| Customer support | Medium | Identity + employment/reference |
| Developer | Medium | Identity + employment/qualification where relevant |
| Finance | High | Enhanced checks as appropriate |
| System Administrator | High | Enhanced checks as appropriate |
| Security Administrator | High | Enhanced checks as appropriate |
| Senior privileged role | High | Risk-based enhanced screening |
These are examples, not universal requirements. The organization should determine appropriate screening based on its own risk, legal and contractual environment.
Screening and Privacy
A.6.1 itself involves processing personal information.
This creates an important connection with A.5.34 — Privacy and Protection of PII.
For example, a background verification report may contain:
- Identity information.
- Employment history.
- Education information.
- Reference information.
- Potentially sensitive personal information.
Therefore, the organization should determine:
- Why the information is collected.
- What information is necessary.
- Who can access it.
- How long it is retained.
- Where it is stored.
- Who receives it.
- When it is deleted.
Simple principle
Screening protects the organization, but the screening process itself must also protect the candidate’s personal information.
Screening of Contractors and Third Parties
A.6.1 may also be relevant to:
- Contractors.
- Temporary workers.
- Consultants.
- Interns.
- Outsourced personnel.
- Other parties who receive significant access.
For example, a startup may outsource infrastructure management.
If an external engineer receives privileged production access, the organization should consider:
- What screening has been performed?
- Who performed it?
- Is it appropriate for the role?
- What contractual requirements apply?
- How is the information protected?
- When is access removed?
The exact requirements should be based on risk and applicable obligations.
What if Screening Cannot Be Completed Before Joining?
Sometimes operational requirements may make it necessary to onboard an individual before all checks are complete.
The organization should have a controlled approach.
Possible safeguards may include:
- Delaying sensitive access.
- Providing limited access.
- Requiring additional supervision.
- Restricting privileged activities.
- Recording the exception.
- Defining a completion deadline.
- Obtaining appropriate approval.
For example:
A new developer can complete general onboarding but does not receive production database access until required screening is completed.
This is generally stronger than simply ignoring the missing check.
Audit Evidence for A.6.1
An auditor may look for:
Policies and Procedures
- HR Security Policy.
- Employee Screening Procedure.
- Recruitment Procedure.
- Background Verification Procedure.
- Third-Party Screening Procedure.
Screening Requirements
- Role-based screening matrix.
- Job descriptions.
- Screening criteria.
- Employment contracts.
- Contractor agreements.
Screening Records
- Identity verification evidence.
- Employment verification.
- Qualification verification.
- Reference checks.
- Background verification completion records.
Sensitive details should only be provided to auditors where appropriate and lawful.
Often, evidence that the required check was completed is preferable to unnecessarily exposing the complete background report.
Exceptions
- Screening exception records.
- Approval records.
- Compensating controls.
- Completion tracking.
What an Auditor May Ask
Governance
“What is your employee screening process?”
“Who determines which checks are required?”
“Is screening risk-based?”
Recruitment
“How do you ensure required screening is completed?”
“At what stage is screening performed?”
“How do you handle contractors?”
Sensitive Roles
“Do administrators receive different screening from other employees?”
“How do you identify roles requiring enhanced screening?”
Evidence
“Show me evidence that screening was completed for a sample of employees.”
“How do you protect screening records?”
Exceptions
“What happens when screening cannot be completed before access is required?”
“Who approves exceptions?”
Common Mistakes in Implementing A.6.1
1. Screening everyone identically
A receptionist and a production administrator may not have the same information security risk.
A risk-based approach is more appropriate.
2. Screening is performed but not documented
The organization says:
“HR always performs background checks.”
But there is no reliable evidence.
This creates an audit problem.
3. Screening is performed after sensitive access is granted
Where required and practical, sensitive access should not be granted before required screening is appropriately completed.
4. No contractor screening
Organizations sometimes screen employees but ignore contractors who have extensive access to systems.
5. Excessive screening
More screening is not automatically better.
Organizations should consider:
- Relevance.
- Necessity.
- Proportionality.
- Privacy.
- Applicable law.
6. Screening records are poorly protected
Background-check reports may contain sensitive personal information.
They should not be stored in:
- Public folders.
- Unrestricted shared drives.
- General employee folders.
- Unsecured email archives.
7. No exception process
Sometimes checks may be delayed.
There should be a documented method for handling such situations.
8. No connection to onboarding
HR completes screening, but IT is never informed that the employee is cleared for sensitive access.
The process should connect HR and access provisioning appropriately.
Practical Startup Implementation Model
A practical model is:
Identify
Identify roles that handle sensitive information or privileged systems.
↓
Assess
Determine the level of screening appropriate to each role.
↓
Define
Document required screening checks.
↓
Screen
Perform appropriate checks before sensitive access where practical.
↓
Review
Evaluate results according to documented criteria and applicable law.
↓
Protect
Secure screening records.
↓
Onboard
Provision access according to the employee’s role.
↓
Monitor
Ensure changes in role or access are managed appropriately.
Policy vs. Process vs. Evidence
| Category | Example |
|---|---|
| Policy | Human Resources Security Policy |
| Policy | Employee Screening Policy |
| Process | Background Verification Procedure |
| Process | Role-Based Screening Procedure |
| Process | Contractor Screening Procedure |
| Process | Screening Exception Procedure |
| Evidence | Screening completion record |
| Evidence | Verification report |
| Evidence | Role-based screening matrix |
| Evidence | Approval record |
| Evidence | Exception record |
| Evidence | Secure HR record |
| Evidence | Access provisioning record |
Simple rule
Policy defines what the organization requires.
Procedure explains how screening is performed.
Evidence demonstrates that required screening was completed.
Relationship with Other ISO 27001 Controls
A.6.1 is connected to several other controls.
| Control | Relationship |
|---|---|
| A.5.15 | Access control should reflect authorized roles |
| A.5.16 | Identity management begins with reliable identity information |
| A.5.18 | Access rights should be based on role and authorization |
| A.5.31 | Legal and regulatory requirements may affect screening |
| A.5.34 | Screening involves processing personal information |
| A.6.2 | Employment terms should address security responsibilities |
| A.6.3 | Personnel should receive security awareness and training |
| A.6.5 | Responsibilities continue after or during changes to employment |
| A.6.6 | Confidentiality agreements protect information |
| A.6.7 | Remote working may introduce additional security requirements |
| A.6.8 | Personnel need a mechanism for reporting security events |
A.6.1 vs. A.6.2
These controls are related but different.
A.6.1 — Screening
Focuses on:
“Have we performed appropriate checks before engaging the person?”
A.6.2 — Terms and Conditions of Employment
Focuses on:
“Have security responsibilities and obligations been established as part of the employment relationship?”
For example:
A.6.1
→ Verify identity and relevant background.
A.6.2
→ Employee agrees to confidentiality, security responsibilities and organizational requirements.
Together they create stronger personnel security.
Useful Documents for A.6.1
Organizations may create:
- [Insert Draft Document Link] — Employee Screening Policy
- [Insert Draft Document Link] — Background Verification Procedure
- [Insert Draft Document Link] — Role-Based Screening Matrix
- [Insert Draft Document Link] — Employee Screening Checklist
- [Insert Draft Document Link] — Contractor Screening Procedure
- [Insert Draft Document Link] — Screening Exception Form
- [Insert Draft Document Link] — Background Verification Register
- [Insert Draft Document Link] — Sensitive Role Identification Checklist
- [Insert Draft Document Link] — HR Security Audit Checklist
A.6.1 Audit Readiness Checklist
Before an ISO 27001 audit, ask:
- Have we documented our employee screening requirements?
- Have we identified sensitive and privileged roles?
- Is screening proportionate to role risk?
- Are required checks defined?
- Are screening requirements communicated appropriately?
- Are checks completed before sensitive access where appropriate?
- Do we screen relevant contractors and third parties?
- Are screening records securely maintained?
- Are privacy requirements considered?
- Do we have a screening exception process?
- Are exceptions approved and tracked?
- Can we demonstrate completion of screening for sampled personnel?
- Are screening requirements reviewed when roles or risks change?
Questions a Startup Should Ask
Before considering A.6.1 implemented, ask:
Which roles have access to our most sensitive information and systems?
What screening is appropriate for those roles?
Are the checks legally permitted and proportionate?
Are contractors included where appropriate?
Do we have evidence that required checks were completed?
Is sensitive screening information protected?
What happens if screening is incomplete?
Do our HR and IT onboarding processes work together?
If these questions have clear answers and supporting evidence, the startup has a much stronger personnel-screening process.
Startup-Focused Final Takeaway
ISO 27001 Annex A 6.1 is about reducing personnel-related information security risk before giving individuals responsibilities or access that could materially affect the organization’s information and systems.
A practical startup approach is:
Identify sensitive roles
↓
Assess the risk
↓
Define appropriate screening
↓
Perform lawful and proportionate checks
↓
Review the results
↓
Protect screening information
↓
Complete appropriate onboarding
↓
Grant access according to role
The key question for A.6.1 is:
“Before giving someone access to our sensitive information or systems, have we performed the appropriate, lawful and risk-based checks for their role?”
Screening is only one part of personnel security. It works together with employment terms, confidentiality, security awareness, access management, offboarding and ongoing compliance to create a complete personnel-security lifecycle.
