Skip to main contentChat with us

ISO 27001:2022 Annex A  ·  People Control

A.6.1
Screening

To ensure that employees, contractors, and third parties are trustworthy and suitable for their roles, reducing the risk of insider threats, fraud, and data breaches caused by hiring individuals with undisclosed criminal history, false credentials, or conflicts of interest.

Last reviewed: June 12, 2026  ·  Authored by TÜV SÜD & BSI Certified Lead Auditors

Control Definition

Every candidate must go through background verification before joining, with periodic re-checks during employment. The depth of checking must match the business need, the classification of information the role will access, and the risks perceived—and must always stay within applicable laws, regulations, and ethical boundaries.

Control Objective

To ensure that employees, contractors, and third parties are trustworthy and suitable for their roles, reducing the risk of insider threats, fraud, and data breaches caused by hiring individuals with undisclosed criminal history, false credentials, or conflicts of interest.

What This Really Means

Screening means conducting background checks on people before you hire them—verifying their identity, education, employment history, criminal records, and references. It's your first line of defense against hiring someone who might steal data, commit fraud, or otherwise harm your organization.

Think of it like tenant screening before renting property: you check references, verify income, and review rental history to avoid problem tenants. Employee screening works the same way—you're investing trust and access to sensitive systems, so you need confidence the person is who they claim to be and won't abuse that access.

This control requires screening proportional to risk: basic checks for low-risk roles (receptionists, facility staff), comprehensive background checks for high-risk positions (IT administrators, finance team, executives), and ongoing periodic rescreening during employment. It also demands compliance with local laws—in India, you must obtain candidate consent, follow data protection rules, and be careful about what criminal history you can legally consider.

Why It Matters

Insiders are involved in a substantial share of data breaches, and many of those incidents could have been prevented through proper screening. Employees with fabricated credentials, undisclosed criminal histories, or financial desperation pose significant risks that manifest only after they've gained access.

Without proper employee screening, organizations face:

  • Insider Threats and Data Theft – Employees with undisclosed criminal records, financial problems, or grudges against former employers are statistically more likely to steal data, commit fraud, or sabotage systems
  • Credential Fraud and Incompetence – Hiring individuals with fake degrees or fabricated experience leads to unqualified people in critical roles (imagine a "CISSP-certified" CISO who bought a fake certificate)
  • Regulatory Penalties and Liability – Financial services (RBI), healthcare, and government contracts often mandate background checks; failure to screen can result in contract termination and fines
  • Reputation Damage – When an employee commits a crime or breach, media and customers ask "How did you hire this person?" Lack of screening demonstrates negligence

Indian organizations must navigate complex employment laws: criminal record checks require consent, caste/religion-based discrimination is illegal, and DPDPA mandates lawful processing of candidate data.

Implementation Guidance

1

Define Screening Requirements by Role Risk Level

Categorize roles into risk tiers: High (IT admin, finance, executives, HR—access to sensitive data), Medium (developers, sales, customer support—limited access), Low (facilities, reception—minimal access). Define screening depth for each tier: identity verification (all), education/employment verification (medium+), criminal records (high), credit checks (finance roles), reference checks (high). Document in policy.

2

Obtain Written Consent from Candidates Before Screening

Indian law (DPDPA, IT Act) requires explicit consent before collecting personal data for background checks. Include consent form in job application: "I authorize [Company] to verify information provided and conduct background checks including employment, education, criminal records, and references." Retain signed consent forms. Never screen without permission.

3

Verify Identity Documents Using Government-Issued IDs

Collect and verify Aadhaar card, PAN card, passport, or driver's license. Use DigiLocker API or physical document verification to confirm authenticity. Cross-check photo, name, DOB, and address. For remote hires, use video KYC or digital verification services (IDfy, AuthBridge). Retain copies securely with access controls.

4

Conduct Education and Employment Verification

Contact universities/colleges to verify degrees (many offer online verification portals). Call previous employers (HR departments) to confirm employment dates, job titles, and reasons for leaving. Use third-party verification services (HireRight, SpringVerify in India) for efficiency. Beware of fake degree mills and employment references from friends posing as HR.

5

Perform Criminal Record Checks Within Legal Boundaries

In India, police verification requires candidate consent and is typically done through local police stations (requires proof of address). For senior/sensitive roles, use court record searches or third-party providers (First Advantage, Equifax). Important: Indian courts have emphasized proportionality and rehabilitation—do not reject candidates automatically for old or minor convictions. Focus on relevant crimes: financial fraud for finance roles, cybercrime for IT positions.

6

Check Professional References and Conduct Interviews

Call at least 2-3 professional references provided by candidate—former managers or colleagues (not friends/family). Ask specific questions: "Would you rehire this person? Did they handle confidential information responsibly? Any concerns about integrity?" For high-risk roles, conduct behavioral interviews focusing on ethics: "Tell me about a time you witnessed unethical behavior—what did you do?"

7

Implement Ongoing Rescreening for High-Risk Roles

Don't assume people remain trustworthy forever. Conduct periodic rescreening (every 3-5 years) for roles with privileged access: IT admins, finance team, executives. Include credit checks (financial stress is insider threat predictor), criminal record updates, and employment verification if they claim additional certifications. Document rescreening schedule in policy.

Audit Evidence

During your ISO 27001 certification audit, auditors will expect to see the following evidence to demonstrate compliance with A.6.1:

Documentation

  • Screening Policy defining requirements by role risk level and verification procedures
  • Consent forms signed by candidates authorizing background checks
  • Background check reports from third-party verification vendors
  • Verification records showing education, employment, and reference checks completed
  • Screening checklist in HR files documenting what checks were performed for each hire

Interviews

  • HR team about screening procedures, vendor selection, and consent processes
  • Hiring managers about how screening results influence hiring decisions
  • Data Protection Officer about compliance with DPDPA and candidate data handling

Observations

  • Review of recent hire files showing completed background checks before start date
  • Examination of consent forms and verification reports in personnel files
  • Check that screening is proportional (high-risk roles have deeper checks than low-risk)
  • Verification that no employee started work before screening was completed

Practitioner Insights

Surendra Pal Singh

A pattern I keep meeting in audits: the impressive big-tech resume that nobody verified. Fabricated employment history surfaces far more often than hiring teams expect, and the gap is usually discovered only after the person has held admin access to production systems for months. Always verify credentials, especially for roles with privileged access. If it seems too good to be true, it probably is.

Surendra Pal Singh · CISO, DPO, CISA, ISO 27001, 27701, 42001 Lead Auditor
Saundhi Chauhan

Many Indian organizations skip reference checks assuming "nobody gives real references anyway." That's lazy. Call the references and ask hard questions: "Is this person eligible for rehire? Any integrity concerns? How did they handle pressure?" Listen for hesitation and non-answers—those are red flags. A lukewarm reference ("They were... fine") is actually a warning sign.

Saundhi Chauhan · ISO 27001, 27701 Lead Auditor

Common Challenges & Solutions

Challenge

Candidates claim previous employers won't provide references or verify employment due to company policy.

Solution

This is often true for large corporations with strict HR policies. Request alternative evidence: offer letter with company letterhead, last payslip, Form 16 (income tax), or relieving letter. For critical roles, use third-party employment verification services that have databases and relationships with HR departments. Document if verification is impossible despite best efforts.

Challenge

Background check vendors take 2-4 weeks delaying candidate onboarding and losing top talent.

Solution

Start screening immediately after job offer (conditional offer pending checks). Use faster digital verification services (IDfy, AuthBridge do most checks in 3-7 days). For urgent hires, grant limited access with supervision until full screening completes. Never skip screening to meet deadlines—it's not worth the risk.

Challenge

We found criminal records or discrepancies—how do we handle this legally without discrimination?

Solution

Evaluate relevance: financial fraud matters for accountants, not for graphic designers. Give candidate opportunity to explain (court records may be wrong or conviction may be disputed). Document decision rationale. Consult legal counsel before rejection based on criminal history. Focus on business necessity, not blanket bans. Indian courts have emphasized rehabilitation over permanent stigma in employment-verification cases.

Challenge

Remote/contract workers from other countries—how do we screen them when Indian services don't cover international checks?

Solution

Use international background check providers (Sterling, Accurate Background, HireRight—operate globally). For countries where checks aren't feasible, rely heavily on portfolio reviews, technical assessments, and video interviews. Require additional references. Grant limited access initially with monitoring. Never skip screening just because it's harder internationally.

Challenge

Candidates complain that background checks invade privacy or violate DPDPA.

Solution

Screening is legal under DPDPA if: (1) You obtain explicit consent. (2) Checks are necessary for the employment decision (employment purposes are a recognized legitimate use under the Act). (3) You process only relevant data (don't ask for caste, religion, etc.). (4) Data is stored securely and deleted per retention policy. Explain why checks are necessary ("We handle customer financial data—we must verify trustworthiness"). Provide privacy notice.

Frequently Asked Questions

Do we need to screen contractors, temporary staff, and vendors the same way as full-time employees?
Yes, if they have similar access to systems and data. A contractor with database admin access poses the same risk as a full-time DBA. Screening should be proportional to access, not employment type. Include screening requirements in vendor contracts. For short-term contractors (<3 months), you may accept vendor's certification they've screened their staff, but verify vendor's screening standards.
Can we reject a candidate based solely on a criminal record discovered during screening?
Not automatically—Indian courts have emphasized rehabilitation over permanent disqualification. You must demonstrate the crime is relevant to the role: fraud convictions matter for finance positions, cybercrime for IT roles. Old convictions for minor offenses should generally be disregarded unless clearly relevant. Give candidates a chance to explain. Document business justification for any rejection. Consult legal counsel.
What if a candidate refuses to consent to background checks?
You can withdraw the job offer or refuse to hire them. Screening is a legitimate business requirement, not optional. Make screening requirements clear in job postings: "This position requires successful completion of background verification." If someone refuses, they're either hiding something or not serious about the role. Document refusal and move to next candidate.
How long should we retain background check records, and where should they be stored?
Retain in secure personnel files for employment duration plus 3-7 years post-departure (labor-law registers commonly require 3 or more years; many organizations retain longer for legal defense). Store in locked cabinets or encrypted HR systems with restricted access (HR only, not hiring managers). Under DPDPA, you must delete when no longer needed for legal/business purposes. Don't keep indefinitely.
What if an employee lied on their resume and we discover it after they've been working for a year?
Material misrepresentation (fake degree, fabricated employment) is grounds for immediate termination in India—employment contracts typically include clauses like "Termination for cause if screening information is found to be false." Investigate the extent of fraud, consult legal counsel, document everything, and terminate if warranted. Lesser exaggerations (inflated job title) may warrant warning. Consistency matters.
Should we screen existing employees when they move to higher-risk roles internally?
Yes, especially for significant role changes (developer promoted to infrastructure admin, sales moving to finance). Conduct rescreening appropriate to the new role's risk level. This also applies to employees changing from low-risk to high-risk access. Original screening from 5 years ago may not reflect current circumstances (financial stress, new criminal activity). Document rescreening requirements in promotion/transfer policies.

Written By Expert Auditors

Surendra Pal Singh
Surendra Pal Singh
Chief Information Security Officer & Data Protection Officer
CISODPOCISAMCSEITILISO 27001 Lead AuditorISO 27701 Lead AuditorISO 42001 Lead Auditor
Saundhi Chauhan
Saundhi Chauhan
Lead Auditor
ISO 27001 Lead AuditorISO 27701 Lead Auditor
Last reviewed: June 2026Content verified by certified lead auditors

Get in touch

Book a free consultation or send us your requirements. We respond within 24 hours.

Quick Call

Pick a time slot

Send Requirements

Get a custom quote in 24 hours

We're Online

⚠️ Business inquiries only. Personal email addresses will be rejected.

24hr Response
Free Consultation
No Obligations