A.6.1
Screening
ISO 27001 · ISO/IEC 27001:2022 · Last verified July 2026
Objective
Verify candidate backgrounds proportionate to business requirements, information classification, and perceived risks.
Points of focus
- Define screening tiers keyed to data access and system privilege, not job title alone
- Complete screening before granting production or customer-data access where local law allows
- Cover contractors and remote/offshore hires under the same or an equivalent tiered process
- Retain completion evidence without over-collecting personal data beyond what the tier requires
Implementation notes
Build a small number of screening tiers — commonly two or three — tied to the sensitivity of the data and systems a role reaches: standard identity and employment verification for most staff, and criminal record or credential checks for roles with production, financial system, or customer-data access, where local employment law permits. What jurisdictions allow varies significantly (EU works-council and data protection rules restrict some check types more than US state law), so document the legal basis and scope per region rather than applying a single global policy that isn't actually enforceable everywhere. Complete screening before provisioning access, not after, and treat contractors, staffing-agency personnel, and offshore engineers identically to employees when they can reach the same systems. Retain only the completion result, not the underlying report contents, to avoid becoming a second data controller for information you don't need.
Audit tip: Bring the tier matrix and one dated completion record per tier, including at least one contractor. Auditors specifically probe whether contractors and offshore staff were carved out of the screening population.
Evidence auditors typically request:
- Screening tier matrix mapping roles to required checks
- Background check vendor reports or completion confirmations (redacted), dated per hire
- Offer letter or onboarding checklist showing screening as a gate before system provisioning
- Contractor/staffing agency attestations for outsourced personnel with system access
Common gaps
- Engineering hires get identity verification only, while the tier matrix says a criminal record check was required for anyone touching the production database
- Contractors and offshore agency staff with admin access are excluded from the screening population entirely
- Access was provisioned on start date, but the background check report is dated two weeks later
Cross-Framework Mapping
| Framework | Requirement | Implementation note |
|---|---|---|
| ISO 27001 | A.6.1 | This control |
| HIPAA | 164.308(a)(3) | 164.308(a)(3)(ii)(B) — Workforce Clearance Procedure — is an addressable specification requiring a process to determine appropriate access based on screening, closely mirroring A.6.1's proportionality principle for anyone reaching ePHI. |
Primary sources
- ISO/IEC 27001:2022 Annex A: ISO/IEC 27001:2022 Annex A (A.6.1)