ISO 27001 Annex A 6.1 Screening requires organisations to carry out background verification checks on all candidates for employment. Documented screening rules ensure candidates are trustworthy and qualified before gaining access to confidential information.
Table of contents
Key Takeaways
- Verify all candidates: Perform background verification checks on all potential employees, contractors, and temporary staff before hiring.
- Store rules centrally: Keep screening policies, background check criteria, and vetting records in a secure, central document repository.
- Proportionate vetting levels: Scale background checks based on job roles, business risks, and the sensitivity of data accessed.
- Screen before system access: Complete all critical identity, qualification, and reference checks before granting system access or building passes.
- Comply with privacy laws: Ensure candidate vetting respects local employment legislation, personal privacy rules, and candidate consent requirements.
- Include third-party contractors: Require staffing agencies and service providers to screen their personnel to match your internal standards.
- Conduct periodic re-screening: Re-verify background checks when employees transition to high-privilege, administrative, or executive roles.
- Maintain vetting evidence: Keep completed reference checks, identity verifications, and qualification records ready for audit reviews.
How to Implement ISO 27001 Annex A 6.1
- Draft a screening policy: Write a clear background verification policy and store it in your central document repository.
- Define role risk levels: Categorise roles by security risk to determine whether basic, standard, or enhanced checks are required.
- Verify candidate identity: Check official government-issued photo identification and right-to-work documentation for all candidates.
- Confirm work history: Contact past employers to verify employment dates, previous job titles, and professional references.
- Validate qualifications: Confirm relevant educational degrees, industry certifications, and professional memberships directly with issuing bodies.
- Run criminal and financial checks: Perform criminal record and credit checks for high-risk roles where permitted by local laws.
- Enforce supplier screening terms: Include binding clauses in agency contracts requiring external partners to screen supplied workers.
- Obtain candidate consent: Secure written candidate consent before launching background checks to maintain full legal compliance.
- Trigger re-screening on promotion: Run enhanced background checks whenever an existing employee moves into a sensitive role.
When you’re ready to bring compliance into one place

How to Audit ISO 27001 Annex A 6.1
- Review the screening policy: Inspect written procedures to verify clear criteria exist for identity, reference, and background checks.
- Sample new starter records: Check personnel files of recently hired employees to confirm background verification was completed.
- Verify pre-hire timing: Compare background check completion dates against system account start dates to ensure checks came first.
- Audit contractor vetting files: Check agreements with third-party agencies to ensure external personnel underwent equivalent screening.
- Check identity verification proofs: Confirm valid identity documents and right-to-work proofs are securely retained in employee files.
- Review high-risk role checks: Sample records for system administrators and financial staff to verify enhanced vetting took place.
- Confirm legal consent records: Inspect candidate files to verify signed background check consent forms are on file.
- Inspect internal transfer checks: Verify that promoted employees received appropriate screening upgrades before gaining elevated access.
Audit Evidence Checklist
- Background screening policy: Maintain a documented background screening policy with a complete version history in your central repository.
- Completed screening reports: Supply verification reports and completed reference check records for sampled employees.
- Signed candidate consent forms: Provide records showing applicants authorized third-party background and qualification checks.
- Identity verification records: Maintain copies of verified government identity documents and right-to-work checks.
- Third-party screening agreements: Supply vendor contracts showing recruitment agencies must vet temporary and contract workers.
- Role-based risk matrix: Keep a documented matrix mapping business job roles to required background check levels.
- Internal promotion review logs: Produce records showing enhanced vetting was conducted during internal role changes.
What to Teach Employees
- Understand screening goals: Teach hiring managers that background checks protect company data, reputation, and workplace safety.
- Wait for check completion: Instruct managers never to grant system access or issue building passes before screening clears.
- Respect privacy standards: Train human resources staff to handle sensitive candidate verification data confidentially.
- Provide accurate credentials: Remind job candidates and staff to provide accurate employment histories and genuine qualifications.
- Report role transitions: Instruct team leaders to notify human resources when staff move into roles requiring higher security clearance.
- Report contractor changes: Remind project leads to verify that all external contractors pass screening before starting work.
Common Implementation Challenges
- Rushing access for urgent hires: Managers onboard workers fast without waiting for screening results. Block account creation until checks clear.
- Overlooking contractor screening: Companies fail to vet freelance and temporary staff. Make contract worker vetting mandatory in supplier agreements.
- Navigating complex privacy laws: Vetting rules conflict with local data protection laws. Consult legal counsel to ensure lawful checks in each region.
- Applying one-size-fits-all checks: Using identical checks for all roles wastes budget. Match screening intensity directly to role risk levels.
- Forgetting promoted staff: Existing staff gain elevated system access without updated background checks. Link promotions to automated screening reviews.
- Poor record retention: Teams misplace vetting proof after hiring. Store all completed screening records securely in a central repository.
How to Measure Effectiveness (KPIs)
- Screening completion rate: Track the percentage of new employees and contractors with fully completed background checks on file.
- Pre-access vetting compliance: Measure the proportion of workers fully vetted before receiving network, cloud, or building access.
- Contractor screening verification rate: Track the percentage of third-party contractors verified against screening standards.
- Average screening turnaround time: Measure the average number of days taken to complete candidate background checks.
- Promotion re-screening rate: Track the proportion of internally promoted staff who complete required enhanced checks on time.
- Screening audit finding count: Monitor the number of non-conformities or gaps identified during internal screening audits.
Related ISO 27001 Controls
ISO 27001 Control A 6.1 connects to several other ISO 27001 requirements:
- ISO 27001 Clause 7.2: Requirements for personnel competence.
- ISO 27001 Annex A 6.2: Terms and conditions of employment.
- ISO 27001 Annex A 5.20: Information security in supplier relationships.

