Answers to the questions practitioners most commonly ask about Terms and Conditions of Employment.
Is documenting terms and conditions of employment a specific mandatory requirement of ISO 27001 or SOC 2?
Not in the way many assume. ISO/IEC 27001 requires an ISMS built around clauses 4 through 10, and its Annex A includes reference controls related to human resource security that may address employment terms; however, Annex A controls are selected via the Statement of Applicability based on your risk assessment, so their applicability depends on scope. For SOC 2, the Trust Services Criteria (with Security as the required Common Criteria category) include criteria relating to personnel and workforce responsibilities, but there is no single universally mandated 'terms and conditions' control. In both frameworks, whether and how this is addressed depends on the auditor or certification body, the defined scope, and the applicable criteria rather than a fixed rule.
Does having employment terms that reference security obligations mean an organization satisfies both SOC 2 and ISO 27001 in this area?
No. Satisfying a human resource security consideration under one framework does not automatically satisfy the other, because the frameworks are structured differently. SOC 2 is an attestation examination performed by a licensed CPA firm resulting in a report, while ISO/IEC 27001 is a certification issued by an accredited certification body against a management system standard. Mapping between the two is possible but partial. Any given control over employment terms may be evaluated differently depending on the framework, the reviewing party, and the scope covered.
How should security responsibilities be reflected in terms and conditions of employment?
In most engagements, organizations reference security responsibilities within employment agreements or supporting documents so that expectations are established from the outset of the working relationship. The specific wording, placement, and level of detail typically depend on the organization's risk assessment, applicable criteria, and the guidance of the auditor or certification body rather than a prescribed template. Where ISO 27001 Annex A controls addressing this area are selected, the Statement of Applicability should reflect that decision.
What evidence do auditors and certification bodies typically look for regarding employment terms?
Evidence expectations vary by the reviewing party and scope. In many cases, reviewers examine whether employment terms exist, whether they address relevant security obligations, and whether they are consistently applied to in-scope personnel. For a SOC 2 Type II examination, which assesses operating effectiveness over a defined review period whose length is set by scoping decisions, reviewers may also look for evidence that these terms were applied consistently throughout that period rather than at a single point in time. The precise evidence sought depends on the auditor, certification body, and applicable criteria.
How do employment terms relate to broader personnel and access controls?
Terms and conditions of employment are typically one element within a wider set of personnel-related controls that may include onboarding, awareness activities, access provisioning, and offboarding. How these connect depends on scope and the applicable framework. Under ISO 27001, related reference controls are selected through the Statement of Applicability; under SOC 2, related considerations fall within the relevant Trust Services Criteria. Organizations generally aim for consistency across these controls, though the specific relationships depend on their own risk assessment and control environment.
Do employment terms need to be maintained differently for the two frameworks, and what are the limitations of relying on them?
The underlying documentation may be similar, but how it is evaluated differs, so organizations often maintain terms in a way that can be reviewed under either framework while recognizing that a demonstration for one does not automatically transfer to the other. It is also important to note the limitations of these controls: employment terms address expectations and responsibilities but do not, on their own, guarantee compliant behavior or freedom from incidents. A SOC 2 report attests only to the controls and period covered, and an ISO 27001 certificate covers only the defined scope of the ISMS, so employment terms should be understood as part of a broader control set rather than a standalone assurance.