ISO 27001:2022 Annex A 6.1 Screening Explained

ISO 27001 Annex A 6.1 Employee Screening

In this guide you will learn how to implement ISO 27001 Annex A 6.1 Employee Screening and pass your audit from ISO 27001 Lead Auditor Stuart Barker – author of the ultimate ISO 27001 Toolkit.

ISO 27001 Annex A 6.1 Employee Screening is an ISO 27001 control that wants you to do background checks on people before, and during, employment.

Purpose & Definition

The purpose of ISO 27001 screening is to ensure we have checked people to an appropriate level before they get access to our data and information. It is proportionate to risk and done in the framework of applicable laws but the purpose is to reduce risk by making sure that people are who they say they are, can do the things they say they can do and don’t have any indicators they will do something bad.

ISO 27001 defines ISO 27001 Screening as:

Background verification checks on all candidates to become personnel should be carried out prior to joining the organisation and on an ongoing basis taking into consideration applicable laws, regulations and ethics and be proportional to the business requirements, the classification of the information to be accessed and the perceived risks.

ISO27001:2022 Annex A 6.1 Employee Screening

ISO 27001 Annex A 6.1 Tutorial

In this free training video you will learn How to implement ISO 27001 Annex A 6.1 Screening and Pass Your Audit.

Implementation Guide

Who should be screened?

The headline guidance is to perform background checks on everyone which includes people that are:

  • full time
  • part time
  • temporary
  • or third party supplier resources.

Background checks and the law

Speak to your legal team or legal counsel to guide and agree with you what can and cannot be done. That always takes precedence.

Given that background checks typically involve the collection, processing, and transfer of personally identifiable information and protected characteristics (as defined by UK law), organisations must adhere rigorously to all applicable employment laws in every jurisdiction where they operate.

ISO 27001 Background Check Requirements

The level of background checks is going to be proportionate to need and risk but to consider the common requirements:

  • References
  • Verify the CV
  • Confirm qualifications
  • Verify Identity
  • Where appropriate, criminal or finance checks.

Enhanced Vetting

The level of checks is going to be proportionate to the role and the risk posed. Not everyone will go through a full and rigorous check but there are roles that are inherently risky and require additional checks to be put in place. Common examples of roles requiring enhanced vetting include:

  • Admins
  • Power users
  • Directors
  • Those with financial authority
  • Those with legal authority
  • Those processing highly confidential or protected characteristic data

Information Security Roles

For people in information security roles you will make sure people are competent to do the job and can be trusted. This seems to push the industry certifications agenda and I am unsure how you can measure trust but be aware of it.

What if you can’t do the checks in time

If you cannot do the checks in time the standard has some pretty harsh guidance. I am not sure I agree in total but their approach is around delaying them joining, not giving them company stuff, allowing them only limited access or even sacking them. There is a limit to how practical this is so use judgement and have something in place for when you don’t get the results of checks back in time.

Do it and do it again

Now there has to be a mechanism for repeating the checks periodically. You define periodically. Just document how often you do it but do it proportionate to your needs and your risks.

Screening Process

Screening procedures must clearly identify responsible personnel and the purpose of the screening process.

Where to get more guidance

You can get more guidance in the beginner’s guide to ISO 27001 background checks.

How to implement ISO 27001 Annex A 6.1

Implementing ISO 27001 Annex A 6.1 requires a risk-based approach to personnel security.

1. Formalise the Personnel Screening Policy

Establish a documented policy that defines the scope, depth, and legal requirements for background verification checks across different job roles.

  • Categorise job roles based on the level of risk and access to sensitive information, such as IAM roles with administrative privileges.
  • Define the mandatory verification requirements for each tier, including identity, employment history, and professional qualifications.
  • Ensure the policy adheres to local data protection laws, such as UK GDPR and the Data Protection Act 2018.

2. Provision Verification for Identity and Right to Work

Execute mandatory identity checks to confirm the candidate is who they claim to be and possesses the legal right to work in the relevant jurisdiction.

  • Verify government-issued photo identification, such as a passport or biometric residence permit.
  • Perform official Right to Work checks via the Home Office or relevant local authority portals.
  • Document the verification date and results within the personnel file as primary audit evidence.

3. Validate Employment History and Professional Credentials

Confirm the accuracy of the candidate’s professional background and educational attainments through independent verification.

  • Obtain written references from previous employers covering a minimum period of 3 to 5 years.
  • Verify academic degrees and professional certifications directly with the issuing institutions or professional bodies.
  • Cross-reference the candidate’s CV against verified data to identify any gaps or inconsistencies in employment.

4. Execute Risk Based Criminal and Financial Checks

Perform additional vetting for high-risk roles that involve handling sensitive financial data or managing critical infrastructure.

  • Request Basic or Enhanced DBS (Disclosure and Barring Service) checks for personnel with significant security responsibilities.
  • Conduct credit checks for roles in Finance, Payroll, or senior leadership to identify potential financial vulnerabilities.
  • Update the Register of Entrants (ROE) to reflect the completion of these specialised checks before provisioning system access.

5. Formalise Agreements with Third Party Screening Providers

Ensure that external agencies used for vetting comply with the organisation’s security standards and legal obligations.

  • Review the service level agreements (SLAs) of third-party screening providers to ensure their vetting depth matches your ISMS requirements.
  • Establish a secure process for the transfer and storage of sensitive candidate data to prevent unauthorised disclosure.
  • Periodically audit the screening provider to verify that checks are being performed consistently and accurately.

6. Document the Decision and Trigger Onboarding

Consolidate all screening evidence into a final decision-making process before the candidate is authorised to access corporate assets.

  • Archive all screening reports, reference letters, and identity copies in a secure document management system.
  • Trigger the provisioning of IAM roles and MFA only after the HR department confirms that all vetting requirements have been met.
  • Maintain a clear audit trail showing that screening was completed prior to the commencement of employment.

What the auditor will check

1. Employee Screening in HR Processes

  • The audit will focus on the integration of employee screening within your HR processes.
  • Auditors will verify the existence of a documented onboarding process that explicitly includes employee screening procedures.
  • They will likely request evidence of completed screenings for recently onboarded employees.
  • If the information is confidential, providing redacted versions of screening results is usually acceptable.

2. Handling Screening Failures

  • Auditors will assess your organisation’s response to failed background checks or screenings.
  • It’s a common oversight to assume all screenings will be successful.
  • A defined procedure for handling failed screenings, even if it involves escalation to the CEO or senior leadership, is crucial.

Top 3 mistakes and how to avoid them

1. Employing Friends, Family, or Acquaintances

While employing friends, family, or acquaintances is not inherently wrong, neglecting thorough background checks and screenings is a significant mistake.

Familiarity can lead to a false sense of security, tempting organisations to overlook necessary checks.

Even for these individuals, basic checks like right-to-work verification are essential, and all legal requirements must be strictly adhered to.

2. Lack of Documentation

ISO 27001 emphasises the importance of well-documented processes.

Relying solely on verbal instructions or informal procedures increases the risk of inconsistencies, errors, and non-compliance.

While HR professionals are valuable resources, ensure all personnel-related processes are formally documented.

3. Inadequate Document and Version Control

Maintaining accurate and up-to-date document versions is crucial for an effective ISO 27001 implementation.

Key aspects of good document control include:

  • Consistent version numbering across all references.
  • Regular reviews (at least annually) with documented evidence.
  • Minimising or eliminating comments within official documents.

FAQ

What should be included in an ISO 27001 background check?

A standard ISO 27001 compliant background check must include identity verification, confirmation of academic/professional credentials, and a review of employment history.
Verification of a government-issued photo ID (e.g., Passport or Driving Licence).
Independent references, typically covering the previous 3 to 5 years of employment.
Confirmation of professional certifications or degrees relevant to the job description.
Verification of the individual’s “Right to Work” in the relevant jurisdiction.

Is background screening mandatory for ISO 27001?

Yes, pre-employment screening is a mandatory requirement for ISO 27001:2022 certification to mitigate the risk of insider threats and unauthorised data access.
Certification auditors require evidence that screening was completed before system access was granted.
Failure to document screening procedures for all staff is a common cause of audit non-conformities.
The process must be formalised within your internal HR and Security policies.

Does ISO 27001 require a criminal record check (DBS)?

ISO 27001 does not explicitly mandate a criminal record check for every role, but it requires you to perform one if the role involves access to highly sensitive data.
Basic or Enhanced DBS checks are recommended for roles with administrative privileges.
Mandatory if required by local laws or specific industry regulations (e.g., Fintech or Healthcare).
Must be conducted in strict compliance with GDPR and relevant data privacy laws.

Do third-party contractors and freelancers need to be screened?

Yes, any third-party contractor or temporary worker with access to your organisation’s information assets must undergo screening equivalent to your permanent staff.
Responsibility for screening can be delegated to an agency, but you must verify their vetting process.
Evidence of the screening must be available for audit inspection.
Contractual agreements should explicitly state the screening standards required for external personnel.

How often should personnel screening be reviewed?

While ISO 27001 focuses on pre-employment, screening should be reviewed if an employee moves to a higher-security role or if the risk landscape changes significantly.
Triggered by internal promotions or transfers to departments handling sensitive financial data.
Periodic re-verification of professional certifications that have an expiry date.
Continuous monitoring is expected for high-clearance administrative roles.

Is a credit check required for ISO 27001 screening?

A credit check is not a default requirement but should be performed for personnel in finance, payroll, or roles with significant procurement authority.
Helps mitigate the risk of financial desperation as a motive for data theft or bribery.
Should be justified by a formal risk assessment for the specific job role.
Commonly used for executive leadership and senior management positions.

ISO 27001 Annex A 6.1 Attributes Table

Control typeInformation
security properties
Cybersecurity
concepts
Operational
capabilities
Security domains
PreventiveAvailability
Confidentiality
Integrity
ProtectHuman resource securityGovernance and ecosystem

Stuart Barker

I am the ISO 27001 Ninja.

I help tech companies, start-ups, and small businesses implement information security management systems without the corporate bloat or massive consultant fees.

If you want to pass your audit the first time, book a call.

Shopping Basket
Scroll to Top