ISO 27001 Control A.6.1: Screening
Control A.6.1 is the first of the eight people controls in Annex A of ISO 27001:2022, and it sits at the very start of the employment lifecycle: before someone can be trusted with your information, you need reasonable assurance they are who they claim to be and are suitable for the role. Screening is background verification - checking identity, work history, qualifications, and, where justified, criminal or financial records. Done proportionately it reduces insider risk without turning hiring into an interrogation. Done carelessly it either waves everyone through or collects far more than the law allows. This is the first control in our walk through Annex A, following the same practical approach we took with the clauses.
What the control requires
Annex A control 6.1 of ISO 27001:2022 states that background verification checks on all candidates to become personnel shall be carried out prior to joining the organization and on an ongoing basis, taking into consideration applicable laws, regulations and ethics, and shall be proportional to the business requirements, the classification of the information to be accessed, and the perceived risks.
Read that carefully, because five requirements are packed into one sentence:
- All candidates - screening applies to everyone who will become personnel, including contractors and temporary staff, not just permanent employees
- Prior to joining - the check happens before access is granted, not after someone is already inside
- On an ongoing basis - screening is not only a hiring gate; it can be repeated where roles or risks warrant it
- Lawful and ethical - checks must respect employment law, data protection law, and local norms
- Proportional - the depth of screening scales with the sensitivity of the information the role will touch and the risk involved
A.6.1 is a preventive people control. In the Annex A attributes it is about protecting confidentiality, integrity and availability by reducing the risk that an unsuitable or misrepresented person gains trusted access. The detailed implementation guidance sits in ISO 27002; Annex A itself states the control, and your Statement of Applicability records how you apply it.
How to implement screening
Define a screening standard tied to information classification
Proportionality is the heart of this control, so the first step is deciding what “proportional” means for you. Tie screening depth to the classification of information a role will access. A common tiered model:
- Standard roles - identity verification, right-to-work confirmation, and reference checks
- Sensitive roles (access to customer data, production systems, finance) - the above plus employment history verification and, where lawful, a criminal record check
- Highly privileged roles (administrators, security team, executives) - the fullest checks the law allows, potentially including financial probity where justified and permitted
Write this into a short screening procedure so hiring managers are not deciding case by case.
Stay inside the law - screening and data protection intersect
Background checks process personal data, often sensitive categories, so this control runs straight into GDPR and local employment law. Only collect what is necessary and proportionate, tell candidates what you will check and why, rely on a lawful basis, and retain the results no longer than needed. Criminal record checks are tightly regulated and in some jurisdictions restricted to specific role types - never run them by default. Screening that over-collects is itself a compliance problem.
Screen contractors and third parties too
The control says all candidates to become personnel, and auditors read that broadly. Contractors, temporary staff, and outsourced personnel who will access your information need equivalent assurance. Where a staffing agency or supplier performs the screening, obtain written confirmation that checks equivalent to your standard were completed - this connects to your supplier controls.
Repeat screening where risk justifies it
The 2022 wording added “on an ongoing basis.” You do not need to re-screen everyone annually, but define where periodic re-checks make sense: on promotion into a highly privileged role, on a significant change of responsibilities, or at intervals for roles with access to the most sensitive information, where lawful. Record the rationale.
Keep proportionate evidence
Auditors need to see the control operating, but the evidence should not itself become a privacy risk. Keep a screening record per person - what checks were done, the date, and who confirmed completion - rather than warehousing raw background reports. A simple screening log or a field in your HR system is usually enough, and it keeps sensitive detail out of wide circulation.
Related controls and clauses
A.6.2 and A.6.6. Screening pairs with terms and conditions of employment (A.6.2) and confidentiality or non-disclosure agreements (A.6.6): you verify the person, then set their obligations in writing before access.
A.5.19 to A.5.22 (supplier controls). Where personnel come through third parties, the supplier relationship controls carry the requirement that equivalent screening was performed.
Clause 7.2 connection. Competence is the sister requirement: screening confirms suitability and integrity, competence confirms the person can actually do the role.
Clause 6.1 connection. Whether and how deeply you screen a given role should trace back to your risk assessment - screening is a treatment for insider and misrepresentation risk.
SoA connection. Your Statement of Applicability declares A.6.1 applicable and points to the screening procedure as justification.
What auditors check
A defined, proportionate standard. Auditors look for a screening procedure that scales with role sensitivity, not a single blanket check or an ad hoc approach.
Screening happened before access. They sample recent joiners and check that verification was completed prior to the start date or before access was granted, with a dated record.
Coverage of contractors. Auditors specifically probe whether non-employees with access were screened to an equivalent standard, since this is a frequent gap.
Lawfulness. They check that checks respect data protection and employment law - a lawful basis, candidate transparency, and proportionate retention. Over-collection is a finding, not a strength.
Evidence without over-retention. Auditors want proof the control ran, but keeping raw background reports indefinitely raises its own questions. A clean screening log is the stronger position.
Common mistakes to avoid
Screening employees but not contractors. The most common gap. Temporary and outsourced people often get access with no equivalent check, directly contradicting “all candidates.”
One-size-fits-all checks. Running identical light checks for a warehouse role and a production database administrator ignores proportionality. So does running heavy checks on everyone, which creates legal exposure.
Checking after the start date. If verification happens weeks into employment, the person already had trusted access unscreened. The control is explicit that checks come first.
Ignoring the law. Default criminal or financial checks where they are restricted, or collecting background data with no lawful basis or candidate notice, turns a security control into a privacy breach.
Hoarding raw reports. Storing full background dossiers forever is both a data protection risk and unnecessary. Keep proportionate confirmation, not the underlying detail.
No ongoing consideration. Treating screening purely as a hiring gate misses the 2022 “ongoing basis” wording. At minimum, define when re-screening applies.
How 27kay can help
We help organizations build a screening standard that is proportionate, lawful, and audit-ready - one that reduces insider risk without creating a data protection problem of its own. As part of ISO 27001 implementation, we tie screening depth to your information classification, align it with GDPR and local law, and set up evidence that satisfies auditors without over-retaining sensitive data. For the full picture, see our ISO 27001 knowledge hub.
Not sure your hiring checks would hold up under audit, or worried they collect too much? Get in touch - we will review your screening approach and help you get the balance right.