Skip to main content

Proof of competence

ISO/IEC 27001:2022 Annex A · Control 6.1

Screening: A Practical Implementation Guide

Use lawful, proportionate background screening to reduce personnel risk before and during sensitive engagements.

This control concerns background verification checks on candidates and personnel, proportionate to business requirements, information sensitivity and applicable law.

Practical interpretation: Screening is not a universal deep investigation. The depth should follow role risk, legal restrictions and fairness principles, with transparent handling of personal information.

What should the control achieve?

  • Screening levels are defined by role risk.
  • Checks are lawful, fair and authorized.
  • Results are confidential and consistently assessed.
  • Rescreening triggers are defined where justified.

Step-by-step implementation

1

Classify role risk

Consider privilege, financial authority, vulnerable persons, sensitive data, critical operations and regulatory duties.

2

Define permitted checks

Use identity, qualification, employment, reference, criminal or financial checks only where relevant and lawful.

3

Inform candidates

Provide notices, obtain authorization where required and explain third-party screening.

4

Use approved providers

Assess confidentiality, accuracy, jurisdiction, retention and dispute processes.

5

Evaluate consistently

Apply documented criteria, escalation and opportunity to correct inaccurate information.

6

Secure and retain

Restrict results, keep only as long as necessary and define rescreening triggers.

What this could look like in practice

A healthcare provider applies basic identity and employment checks to all staff, with additional legally permitted checks for privileged administrators and patient-facing roles. HR reviews results under documented criteria and Security receives only the suitability outcome.

ActivityPractical implementationEvidence
Role assessmentHR and hiring manager select screening tier.Role-risk record
Candidate checkApproved provider performs authorized checks.Screening completion
Adverse resultHR follows consistent review and correction process.Decision record
RescreeningHigh-risk role change triggers updated checks.Mover workflow

Implementation evidence

  • Screening policy
  • Role-risk matrix
  • Candidate privacy notice
  • Authorization records
  • Provider assessment
  • Completion records
  • Decision criteria
  • Retention and deletion evidence

Useful metrics

  • Required screening completed before access
  • Screening exceptions
  • Provider turnaround time
  • Screening records retained beyond schedule

Common mistakes

  • Using identical checks for every role.
  • Conducting checks without legal basis or transparency.
  • Sharing detailed results widely.
  • Treating inaccurate data as final.
  • Granting sensitive access before completion without safeguards.

Questions an auditor may ask

  • How is screening depth determined?
  • Which checks are legally permitted?
  • Show handling of an exception or adverse result.
  • How are screening records protected and deleted?
Implementation test: Select a sensitive role and trace its risk tier, checks, authorization, decision, access timing and retention.

Continue through Annex A

Explore the growing library of practical guides for all 93 Annex A controls.

Open the ISO 27001 Annex A Control Library

This independent educational guide paraphrases the practical intent of the control and does not replace the official ISO standards, professional advice or an organization-specific risk assessment. It is not affiliated with or endorsed by ISO.