Screening
In the context of security compliance, screening refers to the process of verifying the background of individuals before they are hired or given access to sensitive systems and information. It typically covers checks such as identity verification, employment history, qualifications, and, where permitted, criminal record checks. The goal is to reduce the risk of granting trust to individuals who could pose a threat to an organization's information or operations.
Screening is a personnel security control under which an organization performs background verification of candidates for employment (and, depending on scope, contractors and third parties) proportionate to business requirements, the classification of information to be accessed, and perceived risks. Under ISO/IEC 27001, screening is addressed as one of the Annex A reference controls in the people-related theme; its inclusion in an organization's control set is determined through the risk assessment and documented in the Statement of Applicability, and the specific control identifier and count depend on the standard edition (the 2013 version contained 114 controls, while the 2022 revision restructured Annex A into 93 controls across four themes). Within a SOC 2 examination, screening-related activities are typically evaluated as part of the entity's controls mapped to the applicable Trust Services Criteria (for example, elements of the Security/Common Criteria concerning the competence and integrity of personnel), rather than as a prescribed control. The precise scope, timing, and depth of screening vary by jurisdiction, applicable legal and regulatory constraints, and the scoping decisions of the engagement; note that verifying screening controls attests only to the controls and period covered and does not guarantee the reliability of any individual or freedom from insider risk.
Why it matters
Screening addresses one of the most fundamental risks in information security: the trust an organization extends to the people who handle its sensitive systems and data. Access controls, encryption, and monitoring all assume that the individuals granted privileges are who they claim to be and are reasonably unlikely to abuse that access. Personnel screening reduces the likelihood of granting trust to individuals who could pose a threat to an organization's information or operations, making it a foundational human resource security control rather than a peripheral HR formality.
Within both ISO/IEC 27001 and SOC 2 engagements, evidence of screening helps demonstrate that an organization manages the competence and integrity of its personnel in a deliberate, documented way. Under ISO/IEC 27001, screening is a people-related Annex A reference control whose inclusion is justified through the risk assessment and recorded in the Statement of Applicability. In a SOC 2 examination, screening-related activities are typically assessed as part of the controls an entity maps to the applicable Trust Services Criteria, particularly elements of the Security (Common Criteria) concerning personnel competence and integrity, rather than as a prescribed, standalone requirement.
It is important to keep expectations proportionate. Verifying that screening controls exist and operated during a defined period attests only to those controls and that period; it does not guarantee the reliability of any individual or eliminate insider risk. Screening is a risk-reduction measure, not a guarantee, and its value depends on being applied consistently, proportionately, and in accordance with applicable legal and regulatory constraints.
Who it's relevant to
Inside Screening
Common questions
Answers to the questions practitioners most commonly ask about Screening.