Skip to content
compliancebase
ISO 27001A.6 — Screening

A.6.1

Screening

ISO 27001 · ISO/IEC 27001:2022 · Last verified July 2026

Objective

Verify candidate backgrounds proportionate to business requirements, information classification, and perceived risks.

Points of focus

  • Define screening tiers keyed to data access and system privilege, not job title alone
  • Complete screening before granting production or customer-data access where local law allows
  • Cover contractors and remote/offshore hires under the same or an equivalent tiered process
  • Retain completion evidence without over-collecting personal data beyond what the tier requires

Implementation notes

Build a small number of screening tiers — commonly two or three — tied to the sensitivity of the data and systems a role reaches: standard identity and employment verification for most staff, and criminal record or credential checks for roles with production, financial system, or customer-data access, where local employment law permits. What jurisdictions allow varies significantly (EU works-council and data protection rules restrict some check types more than US state law), so document the legal basis and scope per region rather than applying a single global policy that isn't actually enforceable everywhere. Complete screening before provisioning access, not after, and treat contractors, staffing-agency personnel, and offshore engineers identically to employees when they can reach the same systems. Retain only the completion result, not the underlying report contents, to avoid becoming a second data controller for information you don't need.

Audit tip: Bring the tier matrix and one dated completion record per tier, including at least one contractor. Auditors specifically probe whether contractors and offshore staff were carved out of the screening population.

Evidence auditors typically request:

  • Screening tier matrix mapping roles to required checks
  • Background check vendor reports or completion confirmations (redacted), dated per hire
  • Offer letter or onboarding checklist showing screening as a gate before system provisioning
  • Contractor/staffing agency attestations for outsourced personnel with system access

Common gaps

  • Engineering hires get identity verification only, while the tier matrix says a criminal record check was required for anyone touching the production database
  • Contractors and offshore agency staff with admin access are excluded from the screening population entirely
  • Access was provisioned on start date, but the background check report is dated two weeks later

Cross-Framework Mapping

FrameworkRequirementImplementation note
ISO 27001A.6.1This control
HIPAA164.308(a)(3)164.308(a)(3)(ii)(B) — Workforce Clearance Procedure — is an addressable specification requiring a process to determine appropriate access based on screening, closely mirroring A.6.1's proportionality principle for anyone reaching ePHI.

Primary sources

Frequently Asked Questions

No. A.6.1 explicitly calls for proportionality. A support agent with no production access can go through a lighter tier than a platform engineer with database admin rights.

Yes, if they can reach the same systems or data as employees. Auditors commonly sample contractor files specifically because they're the population most often left out.

Not always in the same way. Criminal record checks, credit checks, and similar screens are restricted or unavailable in some jurisdictions. Document what your tier requires per region and what substitute verification applies where full checks aren't legally available.

That's a gap auditors flag directly — access should not be provisioned until the required tier of screening completes, or you need a documented, time-boxed exception with compensating controls.

Framework versions referenced in this page:

  • ISO/IEC 27001ISO/IEC 27001:2022

Last verified: July 2026 · Primary sources linked above