Control Definition
Every candidate must go through background verification before joining, with periodic re-checks during employment. The depth of checking must match the business need, the classification of information the role will access, and the risks perceived—and must always stay within applicable laws, regulations, and ethical boundaries.
Control Objective
To ensure that employees, contractors, and third parties are trustworthy and suitable for their roles, reducing the risk of insider threats, fraud, and data breaches caused by hiring individuals with undisclosed criminal history, false credentials, or conflicts of interest.
What This Really Means
Screening means conducting background checks on people before you hire them—verifying their identity, education, employment history, criminal records, and references. It's your first line of defense against hiring someone who might steal data, commit fraud, or otherwise harm your organization.
Think of it like tenant screening before renting property: you check references, verify income, and review rental history to avoid problem tenants. Employee screening works the same way—you're investing trust and access to sensitive systems, so you need confidence the person is who they claim to be and won't abuse that access.
This control requires screening proportional to risk: basic checks for low-risk roles (receptionists, facility staff), comprehensive background checks for high-risk positions (IT administrators, finance team, executives), and ongoing periodic rescreening during employment. It also demands compliance with local laws—in India, you must obtain candidate consent, follow data protection rules, and be careful about what criminal history you can legally consider.
Why It Matters
Insiders are involved in a substantial share of data breaches, and many of those incidents could have been prevented through proper screening. Employees with fabricated credentials, undisclosed criminal histories, or financial desperation pose significant risks that manifest only after they've gained access.
Without proper employee screening, organizations face:
- •Insider Threats and Data Theft – Employees with undisclosed criminal records, financial problems, or grudges against former employers are statistically more likely to steal data, commit fraud, or sabotage systems
- •Credential Fraud and Incompetence – Hiring individuals with fake degrees or fabricated experience leads to unqualified people in critical roles (imagine a "CISSP-certified" CISO who bought a fake certificate)
- •Regulatory Penalties and Liability – Financial services (RBI), healthcare, and government contracts often mandate background checks; failure to screen can result in contract termination and fines
- •Reputation Damage – When an employee commits a crime or breach, media and customers ask "How did you hire this person?" Lack of screening demonstrates negligence
Indian organizations must navigate complex employment laws: criminal record checks require consent, caste/religion-based discrimination is illegal, and DPDPA mandates lawful processing of candidate data.
Implementation Guidance
Define Screening Requirements by Role Risk Level
Categorize roles into risk tiers: High (IT admin, finance, executives, HR—access to sensitive data), Medium (developers, sales, customer support—limited access), Low (facilities, reception—minimal access). Define screening depth for each tier: identity verification (all), education/employment verification (medium+), criminal records (high), credit checks (finance roles), reference checks (high). Document in policy.
Obtain Written Consent from Candidates Before Screening
Indian law (DPDPA, IT Act) requires explicit consent before collecting personal data for background checks. Include consent form in job application: "I authorize [Company] to verify information provided and conduct background checks including employment, education, criminal records, and references." Retain signed consent forms. Never screen without permission.
Verify Identity Documents Using Government-Issued IDs
Collect and verify Aadhaar card, PAN card, passport, or driver's license. Use DigiLocker API or physical document verification to confirm authenticity. Cross-check photo, name, DOB, and address. For remote hires, use video KYC or digital verification services (IDfy, AuthBridge). Retain copies securely with access controls.
Conduct Education and Employment Verification
Contact universities/colleges to verify degrees (many offer online verification portals). Call previous employers (HR departments) to confirm employment dates, job titles, and reasons for leaving. Use third-party verification services (HireRight, SpringVerify in India) for efficiency. Beware of fake degree mills and employment references from friends posing as HR.
Perform Criminal Record Checks Within Legal Boundaries
In India, police verification requires candidate consent and is typically done through local police stations (requires proof of address). For senior/sensitive roles, use court record searches or third-party providers (First Advantage, Equifax). Important: Indian courts have emphasized proportionality and rehabilitation—do not reject candidates automatically for old or minor convictions. Focus on relevant crimes: financial fraud for finance roles, cybercrime for IT positions.
Check Professional References and Conduct Interviews
Call at least 2-3 professional references provided by candidate—former managers or colleagues (not friends/family). Ask specific questions: "Would you rehire this person? Did they handle confidential information responsibly? Any concerns about integrity?" For high-risk roles, conduct behavioral interviews focusing on ethics: "Tell me about a time you witnessed unethical behavior—what did you do?"
Implement Ongoing Rescreening for High-Risk Roles
Don't assume people remain trustworthy forever. Conduct periodic rescreening (every 3-5 years) for roles with privileged access: IT admins, finance team, executives. Include credit checks (financial stress is insider threat predictor), criminal record updates, and employment verification if they claim additional certifications. Document rescreening schedule in policy.
Audit Evidence
During your ISO 27001 certification audit, auditors will expect to see the following evidence to demonstrate compliance with A.6.1:
Documentation
- Screening Policy defining requirements by role risk level and verification procedures
- Consent forms signed by candidates authorizing background checks
- Background check reports from third-party verification vendors
- Verification records showing education, employment, and reference checks completed
- Screening checklist in HR files documenting what checks were performed for each hire
Interviews
- HR team about screening procedures, vendor selection, and consent processes
- Hiring managers about how screening results influence hiring decisions
- Data Protection Officer about compliance with DPDPA and candidate data handling
Observations
- Review of recent hire files showing completed background checks before start date
- Examination of consent forms and verification reports in personnel files
- Check that screening is proportional (high-risk roles have deeper checks than low-risk)
- Verification that no employee started work before screening was completed
Practitioner Insights

A pattern I keep meeting in audits: the impressive big-tech resume that nobody verified. Fabricated employment history surfaces far more often than hiring teams expect, and the gap is usually discovered only after the person has held admin access to production systems for months. Always verify credentials, especially for roles with privileged access. If it seems too good to be true, it probably is.

Many Indian organizations skip reference checks assuming "nobody gives real references anyway." That's lazy. Call the references and ask hard questions: "Is this person eligible for rehire? Any integrity concerns? How did they handle pressure?" Listen for hesitation and non-answers—those are red flags. A lukewarm reference ("They were... fine") is actually a warning sign.
Common Challenges & Solutions
Challenge
Candidates claim previous employers won't provide references or verify employment due to company policy.
Solution
This is often true for large corporations with strict HR policies. Request alternative evidence: offer letter with company letterhead, last payslip, Form 16 (income tax), or relieving letter. For critical roles, use third-party employment verification services that have databases and relationships with HR departments. Document if verification is impossible despite best efforts.
Challenge
Background check vendors take 2-4 weeks delaying candidate onboarding and losing top talent.
Solution
Start screening immediately after job offer (conditional offer pending checks). Use faster digital verification services (IDfy, AuthBridge do most checks in 3-7 days). For urgent hires, grant limited access with supervision until full screening completes. Never skip screening to meet deadlines—it's not worth the risk.
Challenge
We found criminal records or discrepancies—how do we handle this legally without discrimination?
Solution
Evaluate relevance: financial fraud matters for accountants, not for graphic designers. Give candidate opportunity to explain (court records may be wrong or conviction may be disputed). Document decision rationale. Consult legal counsel before rejection based on criminal history. Focus on business necessity, not blanket bans. Indian courts have emphasized rehabilitation over permanent stigma in employment-verification cases.
Challenge
Remote/contract workers from other countries—how do we screen them when Indian services don't cover international checks?
Solution
Use international background check providers (Sterling, Accurate Background, HireRight—operate globally). For countries where checks aren't feasible, rely heavily on portfolio reviews, technical assessments, and video interviews. Require additional references. Grant limited access initially with monitoring. Never skip screening just because it's harder internationally.
Challenge
Candidates complain that background checks invade privacy or violate DPDPA.
Solution
Screening is legal under DPDPA if: (1) You obtain explicit consent. (2) Checks are necessary for the employment decision (employment purposes are a recognized legitimate use under the Act). (3) You process only relevant data (don't ask for caste, religion, etc.). (4) Data is stored securely and deleted per retention policy. Explain why checks are necessary ("We handle customer financial data—we must verify trustworthiness"). Provide privacy notice.