Skip to main content
Category: Control Types and Framework

Screening

Also known as: Background Screening, Personnel Screening
Simply put

In the context of security compliance, screening refers to the process of verifying the background of individuals before they are hired or given access to sensitive systems and information. It typically covers checks such as identity verification, employment history, qualifications, and, where permitted, criminal record checks. The goal is to reduce the risk of granting trust to individuals who could pose a threat to an organization's information or operations.

Formal definition

Screening is a personnel security control under which an organization performs background verification of candidates for employment (and, depending on scope, contractors and third parties) proportionate to business requirements, the classification of information to be accessed, and perceived risks. Under ISO/IEC 27001, screening is addressed as one of the Annex A reference controls in the people-related theme; its inclusion in an organization's control set is determined through the risk assessment and documented in the Statement of Applicability, and the specific control identifier and count depend on the standard edition (the 2013 version contained 114 controls, while the 2022 revision restructured Annex A into 93 controls across four themes). Within a SOC 2 examination, screening-related activities are typically evaluated as part of the entity's controls mapped to the applicable Trust Services Criteria (for example, elements of the Security/Common Criteria concerning the competence and integrity of personnel), rather than as a prescribed control. The precise scope, timing, and depth of screening vary by jurisdiction, applicable legal and regulatory constraints, and the scoping decisions of the engagement; note that verifying screening controls attests only to the controls and period covered and does not guarantee the reliability of any individual or freedom from insider risk.

Why it matters

Screening addresses one of the most fundamental risks in information security: the trust an organization extends to the people who handle its sensitive systems and data. Access controls, encryption, and monitoring all assume that the individuals granted privileges are who they claim to be and are reasonably unlikely to abuse that access. Personnel screening reduces the likelihood of granting trust to individuals who could pose a threat to an organization's information or operations, making it a foundational human resource security control rather than a peripheral HR formality.

Within both ISO/IEC 27001 and SOC 2 engagements, evidence of screening helps demonstrate that an organization manages the competence and integrity of its personnel in a deliberate, documented way. Under ISO/IEC 27001, screening is a people-related Annex A reference control whose inclusion is justified through the risk assessment and recorded in the Statement of Applicability. In a SOC 2 examination, screening-related activities are typically assessed as part of the controls an entity maps to the applicable Trust Services Criteria, particularly elements of the Security (Common Criteria) concerning personnel competence and integrity, rather than as a prescribed, standalone requirement.

It is important to keep expectations proportionate. Verifying that screening controls exist and operated during a defined period attests only to those controls and that period; it does not guarantee the reliability of any individual or eliminate insider risk. Screening is a risk-reduction measure, not a guarantee, and its value depends on being applied consistently, proportionately, and in accordance with applicable legal and regulatory constraints.

Who it's relevant to

HR and People Operations teams
Because screening is a human resource security control, HR teams often own its day-to-day execution, collecting identity verification, confirming employment history and qualifications, and, where permitted, arranging criminal record checks. They must balance thoroughness against applicable legal and regulatory constraints, which vary by jurisdiction and can limit what may lawfully be checked.
Compliance managers and GRC professionals
These practitioners must ensure screening is appropriately justified and documented. For ISO/IEC 27001, that means reflecting the control decision in the risk assessment and Statement of Applicability; for SOC 2, it means being able to show how screening activities support the entity's controls mapped to the applicable Trust Services Criteria, such as those concerning personnel competence and integrity.
Auditors and certification bodies
Auditors performing a SOC 2 examination evaluate screening as evidence for controls mapped to the applicable criteria over the covered period, while certification body assessors reviewing an ISMS check that screening decisions align with the risk assessment and Statement of Applicability. Both should note that verifying screening controls attests only to the controls and period or scope covered.
Security engineers and access-management owners
Teams responsible for provisioning access to sensitive systems benefit from screening as an upstream trust check, calibrating verification depth to the classification of information a role will access. Screening complements but does not replace technical access controls, monitoring, and other measures against insider risk.

Inside Screening

Background Verification
The process of verifying a candidate's background prior to or upon employment, which may include identity confirmation, employment history, educational qualifications, and, where permitted, criminal record checks. In ISO/IEC 27001:2022, screening is addressed as a reference control within Annex A relating to human resource security.
Proportionality to Risk
The extent and rigor of screening is typically calibrated to the sensitivity of information the individual will access and the associated risk. Higher-risk or privileged roles may warrant more thorough checks, depending on scope and the organization's risk assessment.
Legal and Regulatory Constraints
Screening must be conducted in accordance with applicable laws, regulations, and ethical requirements, which vary by jurisdiction and can limit the type of information that may lawfully be obtained or considered.
Applicability via Statement of Applicability
Under ISO/IEC 27001, Annex A controls such as screening are reference controls selected through the Statement of Applicability and informed by the organization's risk assessment, rather than being universally mandated in a fixed form.
Relationship to SOC 2
In a SOC 2 examination, personnel screening practices may be relevant to the Common Criteria (Security) as part of an organization's control environment. Where evaluated, screening controls would be assessed for design suitability in a Type I engagement and for both design and operating effectiveness over the review period in a Type II engagement, depending on how the auditor and scope define the controls.

Common questions

Answers to the questions practitioners most commonly ask about Screening.

Is background screening a mandatory control that every organization must implement to pass SOC 2 or ISO 27001?
No single screening approach is universally mandatory. For SOC 2, the Security (Common Criteria) category addresses personnel-related controls, but the specific implementation, including whether and how screening is performed, depends on the scope and the controls the organization defines and the auditor evaluates. For ISO 27001, screening appears as an Annex A reference control that is selected via the Statement of Applicability and informed by the risk assessment, meaning an organization may justify its applicability or exclusion based on documented reasoning. In most engagements some form of personnel verification is expected, but the exact requirement varies by scope, applicable criteria, certification body, and auditor judgment rather than being a fixed universal rule.
Does passing background screening prove that an organization's employees pose no security risk?
No. Screening attests only to the checks performed at the time they were conducted and does not guarantee freedom from future risk or misconduct. Within a SOC 2 report, any screening-related control attests only to the controls and the period covered, and within an ISO 27001 certificate it applies only to the defined scope of the ISMS. Screening is one component of a broader set of personnel and access controls and should not be treated as an absolute assurance of trustworthiness.
How is screening typically documented for a SOC 2 examination?
In most engagements, the organization maintains evidence that its defined screening controls were performed for personnel in scope, such as records showing checks were completed before or shortly after hire in accordance with the organization's stated policy. Because a SOC 2 Type II assesses operating effectiveness over a defined review period, auditors typically sample personnel records across that period to test whether the control operated consistently. The specific evidence expected depends on the controls the organization has defined and how the auditor scopes testing.
How does screening relate to the ISO 27001 Statement of Applicability?
Screening is represented among the Annex A reference controls, which are selected through the Statement of Applicability and informed by the organization's risk assessment. An organization documents whether the control is applicable, how it is implemented, or the justification if it is excluded. Because Annex A was restructured in the 2022 revision, the placement and grouping of personnel-related controls differs from the 2013 version, so organizations should reference the version they are certifying against when documenting applicability.
Can one screening program satisfy both SOC 2 and ISO 27001 requirements?
A well-designed screening program can support evidence for both frameworks, but satisfying one does not automatically satisfy the other. SOC 2 evaluates screening against the Trust Services Criteria as part of an attestation examination, while ISO 27001 evaluates it as an Annex A reference control within a certified management system. Mapping between the two is possible but partial, so organizations pursuing both typically confirm that their screening evidence meets the distinct expectations of each framework's scope and evaluators.
Should screening be applied differently to contractors and third-party personnel?
Depending on scope, organizations often define whether screening controls extend to contractors, temporary staff, or third-party personnel who have access to systems or data in scope. Both frameworks emphasize that controls should align with the risk posed by the access granted, so the treatment of non-employee personnel typically depends on the organization's risk assessment, its defined scope, and the controls it commits to in its policies. The specifics vary by engagement and should be documented consistently with how the organization has scoped its personnel controls.

Common misconceptions

Screening requirements are identical and equally prescriptive under SOC 2 and ISO 27001.
The two frameworks treat personnel screening differently. In ISO/IEC 27001 it appears as a reference control in Annex A, selected through the Statement of Applicability and informed by risk. In a SOC 2 examination, screening may be considered as part of the control environment relevant to the Common Criteria, but it is evaluated according to the controls the organization defines and the auditor tests. Mapping between the two is partial, and satisfying screening expectations under one framework does not automatically satisfy the other.
Screening must always include a criminal background check for every employee.
The nature and depth of screening typically depend on the role's risk profile, the sensitivity of information accessed, and applicable legal, regulatory, and ethical constraints. Some checks may not be lawful or permissible in certain jurisdictions, so screening is calibrated to context rather than following a single universal rule.
Documented screening controls guarantee that no personnel-related security incident will occur.
Screening reduces certain risks but does not guarantee freedom from insider threats or breaches. A SOC 2 report attests only to the controls and period covered, and an ISO 27001 certificate covers only the defined scope of the ISMS; neither provides an absolute assurance of security outcomes.

Best practices

Define screening procedures proportionate to the risk and information sensitivity of each role, using your risk assessment to justify the depth of verification for higher-risk or privileged positions.
Confirm that screening activities comply with applicable laws, regulations, and ethical requirements in each relevant jurisdiction before collecting or acting on background information.
Where screening is in scope for ISO/IEC 27001, document its inclusion and rationale in the Statement of Applicability and align it with the results of the risk assessment.
Retain evidence of screening activities so that, for a SOC 2 Type II examination, the control can be demonstrated as operating consistently throughout the review period rather than only at a point in time.
Establish consistent, repeatable screening steps for onboarding and, where relevant, for role changes affecting access to sensitive information, and document any exceptions.
Coordinate with human resources and legal functions to keep screening practices current with evolving regulatory constraints and to avoid overstating what screening can achieve.