ISO/IEC 27001:2022 Annex A · Control 6.1
Screening: A Practical Implementation Guide
Use lawful, proportionate background screening to reduce personnel risk before and during sensitive engagements.
This control concerns background verification checks on candidates and personnel, proportionate to business requirements, information sensitivity and applicable law.
What should the control achieve?
- Screening levels are defined by role risk.
- Checks are lawful, fair and authorized.
- Results are confidential and consistently assessed.
- Rescreening triggers are defined where justified.
Step-by-step implementation
Classify role risk
Consider privilege, financial authority, vulnerable persons, sensitive data, critical operations and regulatory duties.
Define permitted checks
Use identity, qualification, employment, reference, criminal or financial checks only where relevant and lawful.
Inform candidates
Provide notices, obtain authorization where required and explain third-party screening.
Use approved providers
Assess confidentiality, accuracy, jurisdiction, retention and dispute processes.
Evaluate consistently
Apply documented criteria, escalation and opportunity to correct inaccurate information.
Secure and retain
Restrict results, keep only as long as necessary and define rescreening triggers.
What this could look like in practice
A healthcare provider applies basic identity and employment checks to all staff, with additional legally permitted checks for privileged administrators and patient-facing roles. HR reviews results under documented criteria and Security receives only the suitability outcome.
| Activity | Practical implementation | Evidence |
|---|---|---|
| Role assessment | HR and hiring manager select screening tier. | Role-risk record |
| Candidate check | Approved provider performs authorized checks. | Screening completion |
| Adverse result | HR follows consistent review and correction process. | Decision record |
| Rescreening | High-risk role change triggers updated checks. | Mover workflow |
Implementation evidence
- Screening policy
- Role-risk matrix
- Candidate privacy notice
- Authorization records
- Provider assessment
- Completion records
- Decision criteria
- Retention and deletion evidence
Useful metrics
- Required screening completed before access
- Screening exceptions
- Provider turnaround time
- Screening records retained beyond schedule
Common mistakes
- Using identical checks for every role.
- Conducting checks without legal basis or transparency.
- Sharing detailed results widely.
- Treating inaccurate data as final.
- Granting sensitive access before completion without safeguards.
Questions an auditor may ask
- How is screening depth determined?
- Which checks are legally permitted?
- Show handling of an exception or adverse result.
- How are screening records protected and deleted?
Continue through Annex A
Explore the growing library of practical guides for all 93 Annex A controls.
Open the ISO 27001 Annex A Control LibraryThis independent educational guide paraphrases the practical intent of the control and does not replace the official ISO standards, professional advice or an organization-specific risk assessment. It is not affiliated with or endorsed by ISO.