Skip to content
Singahi

Compliance · guide

ISO 27001 A.6.1: Screening

47 min read

Share
On this page

Quick Reference (60 Seconds)

AttributeDetail
Control IDA.6.1
TitleScreening
ObjectiveVerify the suitability of candidates for employment and ongoing suitability of employees
DomainPeople
ISO 27001:2022 ClauseAnnex A.6.1
What You Must DoConduct background verification checks on all candidates and employees commensurate with their role, data access, and business risk
OwnerHR / CISO / Security
Maturity Level 1Basic reference checks for some roles
Maturity Level 2Formal screening policy; police verification for sensitive roles
Maturity Level 3Tiered screening based on role risk; continuous monitoring; vendor screening
Maturity Level 4Automated screening integration; real-time monitoring; re-screening triggers; international screening
Maturity Level 5AI-driven risk scoring; predictive insider threat screening; blockchain-verified credentials; continuous behavioral monitoring

What the Standard Actually Requires

ISO 27001:2022 Control Text

Annex A 6.1 asks organizations to carry out background verification checks on candidates proportionate to the role and applicable laws.

Implementation Guidance (ISO 27002:2022)

  • Screening should be commensurate with the role and the sensitivity of information accessed
  • Screening should include verification of identity, qualifications, employment history, and criminal record where permitted by law
  • Screening should be carried out for contractors, temporary staff, and outsourced personnel as well as permanent employees
  • Screening should be repeated periodically, especially for sensitive roles
  • Screening should comply with all applicable legal and regulatory requirements
  • Candidates should be informed about screening requirements
  • Results should be handled confidentially and securely

"Shall" vs "Should" Analysis

  • Shall: Background verification is mandatory for all candidates
  • Should: The depth and method of screening are flexible based on role risk and legal requirements

Common Misinterpretations

MisinterpretationReality
"Screening is only for senior roles"All personnel require screening; depth varies by role
"Once screened, never need to re-screen"Re-screening is required for sensitive roles, especially after role changes
"Contractors don't need screening"Contractors often have the same access as employees and require the same screening
"Aadhaar verification is enough"Aadhaar verifies identity but not criminal history, qualifications, or employment history
"Screening is an HR-only activity"CISO and security must define screening requirements based on information access

Why Screening Matters

The Business Risk Narrative

Insider threats are a leading cause of security breaches. For Indian organizations, inadequate screening creates direct exposure:

  • 68% of Indian organizations reported at least one insider incident in 2024 (Source: Verizon DBIR)
  • 34% of breaches involve internal actors (malicious or negligent)
  • Average impact of an insider incident in India: ****
  • The impact of a bad hire (including security risk): -25 lakh for mid-level roles, + lakh for senior roles
  • Criminal background check reveals issues in 8-12% of candidates in India (Source: AuthBridge)
  • Fake credentials detected in 5-7% of resume screenings in India

Regulatory Landscape in India

RegulationScreening RequirementPenalty for Non-Compliance
DPDP Act 2023Reasonable security includes personnel screeningUp to
IT Act 2000Section 43A, reasonable security practicesCompensation claims
RBI Cyber Security FrameworkScreening for personnel accessing critical systemsLicense restrictions
SEBI Cybersecurity CircularBackground verification for personnel with access to trading systemsTrading restrictions
IRDAI GuidelinesScreening for insurance personnel handling customer dataLicense suspension
Companies Act 2013Director identification number (DIN); disqualification for certain offencesDirector disqualification
POSH Act 2013Pre-employment inquiry for sexual harassment historyEmployer liability
Factories Act 1948Age verification for workersfine; imprisonment
Contract Labour Act 1970Registration and verification of contract workersPenalties, contract cancellation
Private Security Agencies Act 2005Mandatory police verification for security personnelLicense cancellation

Industry-Specific Consequences

IndustryScreening Failure Scenario
BFSIEmployee with criminal history steals customer funds; RBI penalty; license review
HealthtechUnqualified employee handles PHI; medical malpractice; CDSCO action
SaaS / B2BDeveloper with fake credentials introduces vulnerabilities; customer data breach
E-commerceWarehouse employee with theft history steals customer packages; fraud
GovernmentUnscreened contractor accesses classified data; national security breach
ManufacturingEmployee with substance abuse causes industrial accident; IP theft

impact of Non-Compliance Statistics

  • impact of negligent hiring lawsuit in India: -75 lakh in settlement
  • Average time to replace a bad hire: 6-9 months
  • Revenue impact of insider fraud: -50 lakh per incident
  • Reputational damage from insider incident: 30-40% customer trust reduction
  • Screening overhead per candidate: - (depending on depth)
  • ROI of proper screening: 15-25x (impact of screening vs. impact of bad hire/incident)

Scope and Applicability

Figure · Matrix

Comparison: Tier 1: Critical to Vendors

Screening LevelExample Roles
Tier 1: CriticalFull screening +CISO, CIO, CFO, Database
Tier 2: HighFull screening + periodicDevelopers, QA, Network
Tier 3: MediumStandard screeningMarketing, Sales
Tier 4: LowBasic screeningReception, Facilities
ContractorsSame as equivalentAll contract roles
VendorsBased on access levelODC staff, outsourced
Condensed from the table below, which carries the full detail for each cell.

What the Control Covers

  • Pre-employment screening: All candidates before offer acceptance
  • In-employment re-screening: Periodic re-screening for sensitive roles
  • Post-employment verification: Reference checks for departing employees
  • Contractor screening: Third-party staff, consultants, temporary workers
  • Vendor personnel screening: Staff of outsourced vendors with access to systems/data
  • Role-based screening: Different screening depth based on role risk
  • Continuous monitoring: Ongoing monitoring for criminal records, sanctions, etc.
  • International screening: Candidates with international backgrounds or for global roles

Who It Applies To

Role CategoryScreening LevelExample Roles
Tier 1: CriticalFull screening + continuous monitoringCISO, CIO, CFO, Database Admin, System Admin, Security Engineer, DevOps Lead, Access to Restricted data
Tier 2: HighFull screening + periodic re-screeningDevelopers, QA, Network Admin, IT Support, HR, Finance, Access to Confidential data
Tier 3: MediumStandard screeningMarketing, Sales, Operations, Customer Support, Access to Internal data
Tier 4: LowBasic screeningReception, Facilities, General Admin, Access to Public data
ContractorsSame as equivalent employee tierAll contract roles
VendorsBased on access levelODC staff, outsourced support, cleaning staff with access

Who It Applies To (Roles)

RoleResponsibility
HRScreening policy, vendor selection, candidate communication, record keeping, legal compliance
CISODefining screening requirements based on information access, security risk assessment
LegalCompliance with employment law, privacy law, consent, adverse action procedures
Hiring ManagerDefining role requirements, supporting screening decisions, evaluating results
Background Check VendorConducting checks, verifying credentials, providing reports
Security TeamAccess risk assessment, continuous monitoring, incident response
Candidates / EmployeesProviding accurate information, consenting to checks, updating information

What It Does NOT Cover

  • General performance management (covered by HR processes)
  • Security awareness training (covered by A.6.3)
  • Disciplinary action (covered by A.6.4)
  • Termination procedures (covered by A.6.5)
  • Physical security of personnel (covered by A.7)

Size-Based Applicability

Organization SizeApproach
Startups (< 50)Basic identity + reference checks; police verification for founders; education verification for technical roles
SMB (50-500)Formal screening policy; police verification for sensitive roles; vendor background checks
Mid-market (500-5000)Tiered screening; continuous monitoring; international screening; re-screening program
Enterprise (5000+)Full screening program; AI-driven risk scoring; global screening; continuous monitoring; integration with HRIS

Key Definitions and Terminology

TermDefinitionSource
Background Verification (BGV)Process of verifying a candidate's identity, credentials, employment history, and other relevant informationIndustry
Police VerificationVerification of criminal record through local police authoritiesIndian Law
Reference CheckContacting previous employers or colleagues to verify candidate's work history and characterHR Practice
Education VerificationConfirming academic degrees, certificates, and qualifications with issuing institutionsBGV Practice
Employment VerificationConfirming previous employment details (dates, designation, reason for leaving)BGV Practice
Criminal Record CheckChecking for criminal history through police, court, or database recordsBGV Practice
Address VerificationPhysical verification of candidate's residential addressBGV Practice
Identity VerificationConfirming identity through government ID (Aadhaar, PAN, Passport, Voter ID)BGV Practice
Credit CheckReviewing financial history for roles with financial responsibilityBGV Practice
Sanctions CheckScreening against government sanctions lists (UN, OFAC, EU, etc.)BGV Practice
Media/Social Media ScreeningReviewing public online presence for red flagsBGV Practice
Drug TestingTesting for substance abuse (where legally permitted and role-relevant)BGV Practice
Continuous MonitoringOngoing screening of employees after hire for new criminal records, sanctions, etc.BGV Practice
Re-screeningRepeating background checks periodically or after role changesBGV Practice
Adverse ActionProcedure when screening results lead to rejection or terminationBGV Practice / FCRA (US)
AuthBridgeLeading Indian background verification companyIndustry
First AdvantageGlobal background screening companyIndustry
SterlingGlobal background screening companyIndustry
HireRightGlobal background screening companyIndustry

Relationship to Other Controls

Upstream Controls (Prerequisites)

Control IDRelationshipWhy It Matters
A.5.1Policies for Information SecurityScreening policy must align with security policy
A.5.2Information Security RolesScreening requirements for security roles must be defined
A.5.7Inventory of Information AssetsAsset access determines screening depth

Downstream Controls (Enabled By)

Control IDRelationshipWhy It Matters
A.6.2Terms and Conditions of EmploymentScreening results inform employment terms
A.6.3Information Security AwarenessScreened employees must be trained
A.6.4Disciplinary ProcessScreening failures may lead to disciplinary action
A.6.5Responsibilities after TerminationScreening data informs exit procedures
A.6.6Confidentiality AgreementsScreened employees must sign NDAs
A.6.7Remote WorkingRemote workers require enhanced screening
A.6.8Information Security Event ReportingScreened employees must report incidents

Parallel Controls (Work Alongside)

Control IDRelationshipWhy It Matters
A.5.21Information Security in Supplier RelationshipsVendor staff screening
A.5.30Outsourced DevelopmentDeveloper screening
A.8.1User Endpoint DevicesDevice access requires trusted personnel
A.8.5Secure AuthenticationAuthentication systems accessed by screened users

Implementation Roadmap (Week-by-Week)

Phase 1: Discovery & Assessment (Weeks 1-2)

Week 1: Current Screening Assessment

  • Deliverable: Screening maturity assessment report
  • Owner: HR + CISO
  • Activities:
    1. Review current screening practices across all roles
    2. Identify gaps between current practice and ISO 27001 requirements
    3. Map all roles to information access levels
    4. Assess legal compliance of current screening (DPDP, labour law, privacy)
    5. Review existing vendor contracts and screening quality
    6. Interview hiring managers about screening concerns
    7. Document current screening overhead and turnaround times

Week 2: Risk-Based Screening Framework Design

  • Deliverable: Role-risk mapping + screening tier definitions
  • Owner: CISO + HR + Legal
  • Activities:
    1. Define 4 screening tiers (Critical, High, Medium, Low)
    2. Map all organizational roles to screening tiers
    3. Define screening components for each tier
    4. Assess legal requirements for each check type
    5. Define re-screening frequency by tier
    6. Define continuous monitoring requirements
    7. Create screening vendor selection criteria

Phase 2: Design & Planning (Weeks 3-4)

Week 3: Policy and Procedure Development

  • Deliverable: Screening Policy + Screening Procedure + Consent Forms
  • Owner: HR + Legal + CISO
  • Activities:
    1. Draft Employee Screening Policy
    2. Create screening procedure (pre-hire, in-employment, post-hire)
    3. Create candidate consent forms (DPDP-compliant)
    4. Create adverse action procedure (rejection, remediation, appeal)
    5. Create re-screening trigger procedures (role change, incident, periodic)
    6. Create vendor screening requirements
    7. Create screening records management procedure

Week 4: Vendor Selection and Integration

  • Deliverable: Screening vendor selected and contracted
  • Owner: HR + Procurement + CISO
  • Activities:
    1. Evaluate BGV vendors (AuthBridge, First Advantage, Sterling, HireRight, local vendors)
    2. Assess vendor capabilities (checks offered, turnaround time, technology, compliance)
    3. Conduct vendor security assessment
    4. Negotiate contract with security and privacy requirements
    5. Plan HRIS integration for automated screening triggers
    6. Define SLA (turnaround time, accuracy, dispute resolution)
    7. Conduct pilot screening with 5 candidates

Phase 3: Implementation (Weeks 5-8)

Week 5: Pre-Employment Screening Rollout

  • Deliverable: All new hires screened according to tier
  • Owner: HR + Screening Vendor
  • Activities:
    1. Integrate screening into hiring workflow (ATS trigger)
    2. Train recruiters on screening requirements by role
    3. Implement screening for all new positions
    4. Create candidate communication templates (screening explanation)
    5. Establish screening results review process
    6. Define escalation for adverse findings
    7. Create conditional offer language (contingent on screening)

Week 6: In-Employment Re-Screening

  • Deliverable: Re-screening program operational for sensitive roles
  • Owner: HR + CISO + Security
  • Activities:
    1. Identify all employees in Tier 1 and Tier 2 requiring re-screening
    2. Schedule re-screening (annual for Tier 1, bi-annual for Tier 2)
    3. Implement re-screening triggers (role change, access escalation, security incident)
    4. Create re-screening communication templates
    5. Establish re-screening results review process
    6. Define consequences for re-screening failures

Week 7: Contractor and Vendor Screening

  • Deliverable: All contractors and vendor personnel screened
  • Owner: HR + Vendor Management + CISO
  • Activities:
    1. Extend screening requirements to all contractors
    2. Require screening certificates from staffing vendors
    3. Implement direct screening for critical vendor roles
    4. Create vendor screening attestation template
    5. Add screening clauses to vendor contracts
    6. Verify vendor screening quality through spot checks
    7. Create vendor personnel access approval workflow (screening gate)

Week 8: Continuous Monitoring Implementation

  • Deliverable: Continuous monitoring alerts configured
  • Owner: CISO + HR + Security Vendor
  • Activities:
    1. Deploy continuous monitoring for Tier 1 roles (criminal records, sanctions)
    2. Configure alert thresholds (new criminal record, sanctions listing)
    3. Create incident response for monitoring alerts
    4. Integrate monitoring with HRIS and security systems
    5. Train security team on alert response
    6. Create employee notification procedure for monitoring
    7. Test monitoring system with mock alerts

Phase 4: Testing & Validation (Weeks 9-10)

Week 9: Screening Program Testing

  • Deliverable: Testing report with validation results
  • Owner: HR + Internal Audit + CISO
  • Activities:
    1. Test screening workflow end-to-end (candidate to hire)
    2. Test adverse action procedure (mock adverse finding)
    3. Test re-screening workflow (mock role change)
    4. Test continuous monitoring alerts (mock alert)
    5. Test vendor screening compliance (audit vendor records)
    6. Test screening records security (access, encryption, retention)
    7. Test candidate consent and DPDP compliance

Week 10: Compliance Validation

  • Deliverable: Compliance validation report
  • Owner: Legal + Compliance Manager + HR
  • Activities:
    1. Validate screening policy against DPDP Act 2023
    2. Validate screening against labour law requirements
    3. Validate consent forms for legal compliance
    4. Verify screening vendor compliance with contract
    5. Validate screening data protection (encryption, access, retention)
    6. Test adverse action fairness and appeal process
    7. Prepare compliance evidence package

Phase 5: Documentation & Certification Prep (Weeks 11-12)

Week 11: Documentation

  • Deliverable: Complete screening program documentation
  • Owner: HR + Compliance Manager
  • Activities:
    1. Document all screening policies and procedures
    2. Create screening training materials for recruiters and managers
    3. Create candidate FAQ on screening
    4. Create screening metrics dashboard
    5. Create evidence repository for audits
    6. Document vendor management procedures

Week 12: Certification Readiness

  • Deliverable: Audit-ready evidence package
  • Owner: CISO + Compliance Manager
  • Activities:
    1. Conduct internal audit of screening program
    2. Prepare evidence for external ISO 27001 auditor
    3. Remediate any gaps found
    4. Conduct management review
    5. Present program to certification body

Detailed Implementation Guidance

Figure · Tiers

Maturity levels for screening

Maturity levels for ISO 27001 A.6.1, screening, from most to least mature: Vendors, odc staff, outsourced support; Contractors, same as equivalent employee tier; Tier 4: Low, reception, facilities, general admin; Tier 3: Medium, marketing, sales, operations; Tier 2: High, developer, qa, network admin, it support; Tier 1: Critical, ciso, cio, db admin, system admin.
Where most organisations sit, and what the next level asks for. Full characteristics per level are in the table below.

Step-by-Step Implementation

Step 1: Establish Screening Governance

  • Create Screening Committee (HR Head, CISO, Legal, Head of Recruitment)
  • Define screening budget allocation
  • Establish screening policy approval process
  • Define screening dispute resolution (candidate appeals)
  • Create screening metrics and reporting to management

Step 2: Define Screening Tiers

TierRole ExamplesScreening ComponentsRe-Screening
Tier 1: CriticalCISO, CIO, DB Admin, System Admin, Security Engineer, DevOps Lead, CFO, Access to Restricted dataIdentity, Education, Employment (5 years), Criminal, Police Verification, Credit, Sanctions, Reference (3), Social Media, Continuous MonitoringAnnual
Tier 2: HighDeveloper, QA, Network Admin, IT Support, HR, Finance, Access to Confidential dataIdentity, Education, Employment (3 years), Criminal, Police Verification, Reference (2), SanctionsBi-annual
Tier 3: MediumMarketing, Sales, Operations, Customer Support, Access to Internal dataIdentity, Education, Employment (2 years), Criminal, Reference (1)Every 3 years
Tier 4: LowReception, Facilities, General Admin, Access to Public dataIdentity, Reference (1)Every 5 years
ContractorsSame as equivalent employee tierSame as equivalent tierSame as equivalent tier
Vendors (Critical Access)ODC staff, outsourced support with system accessSame as Tier 2 or 3Per contract

Step 3: Implement Identity Verification

  • Verify government ID: Aadhaar (e-Aadhaar QR scan), PAN, Passport, Voter ID, Driving License
  • Verify photo ID match with candidate
  • Verify address through utility bill, bank statement, or physical verification
  • Use liveness detection for remote verification (prevent deepfake/photo substitution)
  • Cross-check ID numbers with government databases where permitted

Step 4: Implement Education Verification

  • Verify highest degree and relevant certifications
  • Contact university/college registrar directly or through vendor
  • Verify through digital platforms (NAAC, UGC, AICTE databases)
  • Check for fake universities (UGC blacklist)
  • Verify professional certifications (certified, CISA, ISO Lead Auditor, etc.)
  • For international degrees, verify through WES or equivalent

Step 5: Implement Employment Verification

  • Verify last 2-5 employers (based on tier)
  • Confirm: employment dates, designation, reason for leaving, eligibility for rehire
  • Verify gaps in employment (candidate explanation, reference check)
  • Verify self-employment or freelance work (client references, tax records)
  • Use automated employment verification where available (The Work Number, etc.)
  • For international employment, verify through local contacts or vendors

Step 6: Implement Criminal and Police Verification

  • Police verification: Submit Form to local police station or online (state-specific portals)
  • Criminal record check: Search court records, CCTNS (Crime and Criminal Tracking Network System)
  • For Tier 1: Conduct address-based police verification (current + permanent address)
  • For international candidates: Conduct criminal check in home country
  • Note: DPDP Act 2023 and labour law restrictions on criminal record use in employment
  • Ensure adverse action considers nature of offence, time elapsed, and role relevance

Step 7: Implement Reference Checks

  • Contact professional references provided by candidate
  • Ask structured questions: working relationship, reliability, integrity, security awareness, reason for leaving
  • For Tier 1: Contact 3 references including at least 1 supervisor
  • For sensitive roles: Contact unlisted references (backdoor references) if legally permitted
  • Document all reference check conversations
  • Verify reference identity (not fake references)

Step 8: Implement Credit and Financial Checks

  • Conduct for roles with financial responsibility (finance, CFO, procurement, treasury)
  • Check CIBIL score and credit history
  • Look for patterns of financial distress (potential fraud risk factor)
  • Ensure compliance with RBI and DPDP requirements for credit data access
  • Candidate consent mandatory for credit checks

Step 9: Implement Sanctions and Watchlist Screening

  • Screen against: UN sanctions, OFAC (US), EU sanctions, Indian government sanctions lists
  • Screen against: terror watchlists, PEP (Politically Exposed Persons) lists
  • For Tier 1 and financial roles: Mandatory sanctions screening
  • Use automated screening tools for real-time updates
  • Document screening results and any matches

Step 10: Implement Social Media and Online Screening

  • Review public social media profiles (LinkedIn, Twitter/X, Facebook, Instagram)
  • Look for: hate speech, violence, drug use, criminal activity, security violations, confidential information leaks
  • Ensure screening is limited to public information
  • Do not request social media passwords (illegal in many jurisdictions)
  • Document findings and decision rationale
  • Be aware of potential bias and discrimination risks

Step 11: Implement Drug and Substance Testing

  • Only where legally permitted and role-relevant (safety-critical roles, financial roles)
  • Common in manufacturing, transportation, aviation, some BFSI roles
  • Must be with explicit consent and under medical supervision
  • Follow MHA (Ministry of Home Affairs) and state-specific guidelines
  • Ensure compliance with DPDP Act 2023 for health data processing

Step 12: Implement Continuous Monitoring

  • Monitor for: new criminal records, sanctions listings, adverse media, regulatory actions
  • For Tier 1: Real-time or daily monitoring
  • For Tier 2: Monthly monitoring
  • For Tier 3-4: Quarterly monitoring or event-based
  • Create alert workflow: Alert → Security review → HR review → Decision → Action
  • Ensure employee privacy rights are respected (DPDP compliance)

Step 13: Implement Re-Screening

  • Annual re-screening for Tier 1 (criminal, sanctions, continuous monitoring)
  • Bi-annual re-screening for Tier 2
  • Trigger-based re-screening: role change, access escalation, security incident, whistleblower report, suspicious behavior
  • Re-screening upon promotion to higher tier
  • Re-screening after extended leave (maternity, sabbatical, medical leave >6 months)

Step 14: Implement Adverse Action Procedure

  • If screening reveals adverse information:
    1. Review report for accuracy
    2. Consult Legal on employment law implications
    3. Give candidate/employee opportunity to explain
    4. Consider nature of issue, time elapsed, role relevance, candidate explanation
    5. Make decision: proceed, conditional offer, withdraw offer, terminate, or remediate
    6. Document decision rationale
    7. Communicate decision to candidate/employee
    8. Provide appeal mechanism
    9. Maintain confidentiality of screening results
  • For DPDP compliance: Adverse action based on personal data must be documented and fair

Step 15: Implement Screening Records Management

  • Store screening records securely (encrypted, access-controlled)
  • Retain screening records for: 7 years or duration of employment + 7 years (whichever is longer)
  • Maintain screening records separately from personnel files (confidential)
  • Limit access to HR, Legal, and CISO (need-to-know)
  • Secure disposal after retention period (cryptographic erasure)
  • Ensure DPDP compliance for screening data (personal data)

Tools, Technologies, and Solutions

Complete Tool Comparison

Tool/VendorCategoryBest Forlicensing RangeKey FeaturesCoverage
AuthBridgeBGVIndian market leader-3,000/candidateIdentity, education, employment, criminal, police verification, address, creditIndia-focused
First AdvantageBGVGlobal + India-5,000/candidateGlobal checks, criminal, credit, sanctions, drug testing, continuous monitoringGlobal
SterlingBGVGlobal enterprise-5,000/candidateGlobal checks, criminal, credit, sanctions, identity, employment, educationGlobal
HireRightBGVGlobal enterprise-5,000/candidateGlobal checks, criminal, credit, sanctions, drug testing, continuous monitoringGlobal
IDfyBGVIndian tech-focused-2,500/candidateIdentity, education, employment, criminal, police verification, API-firstIndia-focused
VerifitechBGVIndian growing companies-2,000/candidateIdentity, education, employment, criminal, address verificationIndia-focused
OnfidoIdentityRemote identity verification-500/checkAI-powered ID verification, biometric matching, document verificationGlobal
JumioIdentityDigital identity verification-600/checkID verification, liveness detection, document verificationGlobal
TruliooIdentityGlobal identity verification-800/checkGlobal identity verification, 400+ data sources, 195 countriesGlobal
ComplyCubeIdentityAML + KYC + Identity-700/checkID verification, AML screening, sanctions, PEPGlobal
RefCheckReferenceAutomated reference checks-500/checkAutomated reference collection, structured questions, analyticsGlobal
XrefReferenceDigital reference checking-600/checkOnline reference platform, fraud detection, analyticsGlobal
Oracle The Work NumberEmploymentUS employment verificationPer-useAutomated employment verification from payroll databaseUS-focused
CIBILCreditIndian credit reports/reportCIBIL score, credit history, loan detailsIndia
Experian IndiaCreditIndian credit reports/reportCredit score, credit history, risk assessmentIndia
Clear (formerly ClearTax)ComplianceIndian compliance checks-500/checkGST verification, PAN verification, company verificationIndia
LinkedInSocialProfessional backgroundFree/PremiumEmployment history, professional network, recommendationsGlobal
Dow Jones Risk & ComplianceSanctionsSanctions and PEP screening+ per yearSanctions, PEP, adverse media, watchlistsGlobal
Refinitiv World-CheckSanctionsSanctions and PEP screening+ per yearSanctions, PEP, adverse media, risk intelligenceGlobal
ComplyAdvantageSanctionsAI-driven sanctions screening+ per yearSanctions, PEP, adverse media, real-time monitoringGlobal
HRIS IntegrationAutomationWorkday, SAP, OracleVariesAutomated screening triggers, results integration, workflowEnterprise
ATS IntegrationAutomationGreenhouse, Lever, iCIMSVariesScreening trigger at offer stage, status tracking, results in ATSGrowing companies+

Recommendations by Organization Size

SizePrimary VendorIdentityContinuous MonitoringIntegration
Startup (<50)AuthBridge or IDfyOnfido or JumioManualBasic HRIS
SMB (50-500)AuthBridge or First AdvantageOnfido or JumioQuarterly alertsATS + HRIS
Mid-market (500-5000)First Advantage or SterlingTrulioo or OnfidoMonthly alertsFull HRIS + ATS + IAM
Enterprise (5000+)Sterling + First Advantage + Dow JonesTrulioo + JumioReal-time monitoringFull HRIS + ATS + IAM + GRC

Policy and Procedure Templates

Employee Screening Policy (Key Sections)

Template

Screening Procedure

Template


Risk Assessment and Treatment

Key Risks Addressed by This Control

Risk IDRisk DescriptionLikelihoodImpactRisk LevelTreatment
R-001Employee with criminal history causes security incidentMediumCriticalHighMitigate, Criminal screening, police verification, continuous monitoring
R-002Employee with fake credentials causes operational failureMediumHighMediumMitigate, Education verification, employment verification
R-003Employee with financial distress commits fraudMediumHighMediumMitigate, Credit checks for financial roles, continuous monitoring
R-004Sanctioned individual employed in sensitive roleLowCriticalHighMitigate, Sanctions screening, PEP screening
R-005Insider threat from employee with undisclosed historyMediumCriticalHighMitigate, Complete screening, reference checks, social media screening
R-006Contractor/vendor personnel with bad historyMediumHighMediumMitigate, Vendor screening requirements, attestation, direct screening
R-007Screening data breach exposes candidate informationLowHighMediumMitigate, Encryption, access controls, DPDP compliance, vendor security
R-008Discrimination or bias in screening processMediumMediumLowMitigate, Structured procedures, training, legal review, adverse action fairness
R-009Re-screening not conducted, new risks missedMediumHighMediumMitigate, Automated re-screening triggers, calendar reminders, HRIS integration
R-010Screening vendor provides inaccurate resultsLowHighMediumMitigate, Vendor SLA, quality checks, dispute resolution, multiple vendors

Audit and Compliance Checklist

Audit Questions (25 Questions)

#Audit QuestionExpected EvidenceRed Flags
1Is there a screening policy?Approved policyNo screening policy
2Are all roles assigned a screening tier?Role-tier mapping documentNo tier assignment, all roles treated same
3Are candidates screened before employment?Screening records for recent hiresNo screening, screening after start date
4Is identity verified for all candidates?Identity verification recordsNo ID verification
5Is education verified?Education verification reportsNo education verification, fake credentials undetected
6Is employment history verified?Employment verification reportsNo employment verification, gaps unexplained
7Is criminal/police verification conducted?Police verification reportsNo criminal check for sensitive roles
8Are reference checks conducted?Reference check recordsNo reference checks
9Is candidate consent obtained?Consent formsNo consent, consent not DPDP-compliant
10Are contractors screened?Contractor screening recordsContractors not screened
11Are vendor personnel screened?Vendor screening attestationsVendor personnel with unverified backgrounds
12Is re-screening conducted?Re-screening schedule and recordsNo re-screening, never re-screened
13Is continuous monitoring implemented?Monitoring alerts, recordsNo continuous monitoring for sensitive roles
14Are screening results confidential?Access controls on screening recordsOpen access to screening records
15Is there an adverse action procedure?Adverse action procedure, documented casesNo procedure, arbitrary rejections
16Are screening vendors assessed?Vendor security assessmentNo vendor assessment, unknown vendor quality
17Is screening data protected?Encryption, access controls, DPDP complianceScreening data stored insecurely
18Is screening integrated with hiring workflow?ATS/HRIS screening triggersManual, disconnected screening process
19Are screening records retained?Retention records, disposal logsNo retention, no disposal records
20Are screening overhead tracked?Budget recordsNo budget, uncontrolled spending
21Is screening quality monitored?Accuracy reports, dispute recordsNo quality monitoring
22Are screening results used for access decisions?Access provisioning recordsScreening not linked to access
23Are employees trained on screening?Training recordsNo training for recruiters or managers
24Is screening reviewed for legal compliance?Legal review recordsNo legal review, potential discrimination
25Is the screening program reviewed?Management review minutesNo review, no improvement

Metrics and KPIs

Figure · Measures

The measures that show A.6.1 is working

  • Screening Coverage100%Monthly
  • Screening Completion Rate>95%Monthly
  • Screening Turnaround Time<10 daysMonthly
  • Adverse Finding Rate<10%Monthly
  • Re-Screening Compliance100%Quarterly
Targets and reporting cadence as defined in the table below, where the formula for each is given.

Key Metrics Dashboard

KPIFormulaTargetFrequency
Screening Coverage(Screened candidates / Total candidates) × 100100%Monthly
Screening Completion Rate(Completed screenings / Initiated screenings) × 100>95%Monthly
Screening Turnaround TimeAverage days from initiation to report<10 daysMonthly
Adverse Finding Rate(Adverse findings / Total screenings) × 100<10%Monthly
Re-Screening Compliance(Re-screened on time / Required re-screenings) × 100100%Quarterly
Contractor Screening Rate(Screened contractors / Total contractors) × 100100%Quarterly
Vendor Screening Attestation Rate(Vendors with screening attestation / Total vendors) × 100100%Quarterly
Continuous Monitoring Alert CountAlerts generated by monitoringTrending downMonthly
Screening Data Breach CountBreaches of screening data0Quarterly
Screening overhead per HireTotal screening overhead / Number of hires<Monthly
Screening Vendor SLA Compliance(Vendor SLA met / Total screenings) × 100>95%Monthly
Screening Record Retention Compliance(Records retained per policy / Total records) × 100100%Quarterly
Screening Dispute Resolution TimeAverage days to resolve screening disputes<7 daysMonthly
Screening Training Completion(Trained recruiters / Total recruiters) × 100100%Annual
Screening Program Audit ScoreAudit score (0-100)>90Annual

Common Pitfalls and How to Avoid Them

#PitfallWhy It HappensHow to Avoid
1No screening for contractorsAssumption that contractor vendor handles itRequire screening attestation or direct screening for all contractors
2Screening after employee startsTime pressure, urgent hireMake offer conditional on screening; integrate screening into hiring timeline
3Same screening for all rolesSimplicity, efficiency gainsImplement tiered screening based on information access risk
4No re-screeningOne-time mindset, overheadSchedule re-screening, automate triggers, integrate with HRIS
5Ignoring adverse findingsBias toward candidate, urgent needEstablish structured adverse action procedure with Legal review
6Screening data not protectedAssumption that vendor handles securityEncrypt screening data, limit access, DPDP compliance, vendor security assessment
7No candidate consentAssumption that application implies consentObtain explicit, informed, DPDP-compliant consent before screening
8Over-reliance on one vendorContract convenience, volume discountsUse primary + backup vendor; spot-check quality
9No integration with access provisioningSiloed HR and IT processesIntegrate screening clearance with IAM; no access without clearance
10Discriminatory screening practicesUnconscious bias, lack of trainingStructured procedures, training, legal review, diverse review committee
11Ignoring international screeningAssumption that Indian checks are sufficientUse global vendors for international candidates and roles
12No screening for remote workersAssumption that remote = lower riskRemote workers often have more access; require same or enhanced screening

Illustrative Scenarios

Illustrative scenario, a composite example for guidance, not a specific Singahi engagement or a verified outcome.

Illustrative Scenario 1: Indian Fintech Startup, Finova Payments

Company Profile:

  • Size: 120 employees
  • Industry: Fintech, Payment Gateway and Digital Lending
  • Location: Bengaluru, India
  • Customers: 800,000 users, 12,000 merchants
  • Regulatory Scope: RBI, NPCI, DPDP Act 2023, PCI DSS

Challenge: Finova was growing rapidly but had minimal screening:

  • No formal screening policy; only informal reference checks
  • No police verification or criminal checks
  • A developer hired without education verification was found to have fake engineering degree
  • The developer had access to production payment database and stole over 6 months
  • No re-screening of existing employees; a senior employee with access to UPI infrastructure had criminal fraud case pending (not discovered)
  • Customer support staff (30 people) had no screening; one support agent sold customer data to competitor for
  • RBI audit flagged lack of personnel screening as major concern
  • NPCI threatened to suspend UPI integration
  • Reputational damage: 15% customer churn in 2 months

Solution:

  1. Week 1-2: Emergency Screening Implementation

    • Engaged Singahi for emergency screening program design
    • Conducted retrospective screening of all 120 employees
    • Found 8 employees with adverse findings (fake credentials, criminal history, undisclosed employment gaps)
    • Found 1 ongoing criminal case in senior employee
    • Terminated 3 employees with serious adverse findings; placed 5 on probation with restricted access
    • Implemented immediate access revocation for terminated employees
  2. Week 3-4: Policy and Vendor

    • Created 4-tier screening policy (Critical, High, Medium, Low)
    • Selected AuthBridge as primary screening vendor
    • Integrated screening with HRIS (BambooHR) and ATS (Greenhouse)
    • Created candidate consent forms (DPDP-compliant)
    • Established adverse action procedure with Legal review
  3. Week 5-6: Full Screening Rollout

    • Implemented screening for all new hires (100% coverage)
    • Conducted police verification for all Tier 1 and Tier 2 roles
    • Implemented education verification for all technical roles
    • Created reference check procedure (minimum 2 references)
    • Implemented sanctions screening for all financial roles
  4. Week 7-8: Re-Screening and Monitoring

    • Implemented annual re-screening for Tier 1 (20 employees)
    • Implemented bi-annual re-screening for Tier 2 (45 employees)
    • Deployed continuous monitoring for Tier 1 (criminal, sanctions)
    • Created re-screening trigger: role change, incident, suspicious behavior
    • Integrated screening clearance with IAM (no system access without clearance)
  5. Week 9-12: Vendor and Contractor Screening

    • Extended screening to all 15 contractors
    • Required screening attestations from 8 vendor companies
    • Conducted direct screening for 12 vendor personnel with system access
    • Added screening clauses to all vendor contracts
    • Created vendor personnel access approval workflow

Results:

  • Security incidents: Zero insider incidents in 12 months post-implementation
  • Fraud prevention: loss prevented through screening (detected 1 attempted fraud)
  • RBI compliance: Passed audit with commendation for screening program
  • NPCI: UPI integration maintained; no regulatory action
  • Customer trust: Churn stabilized; won 2 enterprise customers citing security program
  • Screening ROI: annual screening overhead vs. prevented fraud + regulatory savings
  • Hiring quality: 12% of candidates had adverse findings; improved overall hire quality
  • Process maturity: Screening became a competitive advantage in talent acquisition

Illustrative Scenario 2: Large Enterprise, Bharat Defence Systems (BDS)

Company Profile:

  • Size: 8,500 employees, 3,200 with security clearance
  • Industry: Defence Manufacturing and R&D
  • Location: Hyderabad (HQ), with facilities in 6 cities
  • Customers: Indian Armed Forces, DRDO, ISRO, international defence clients
  • Regulatory Scope: DPDP Act 2023, Official Secrets Act 1923, Defence Procurement Procedure, ISO 27001, CMMI
  • Security Clearance: Government security clearance required for 3,200 employees

Challenge: BDS had government-mandated security clearance but significant gaps in broader screening:

  • Government security clearance was slow (6-12 months) and did not cover all personnel
  • 5,300 employees without security clearance had no formal screening
  • Contractors (2,800) had minimal screening beyond basic identity check
  • International hires (180) from 12 countries had no standardized screening
  • No continuous monitoring, 3 employees developed criminal issues after hire that were not detected
  • Re-screening was only for security clearance renewal (every 5 years), not for role changes
  • A contractor with access to classified facility was found to have ties to foreign intelligence (discovered by accident, not screening)
  • No social media screening; employee posted classified information on LinkedIn
  • No adverse action procedure; screening results were ignored if employee was "valuable"
  • Background check vendor was not security-cleared; vendor had access to sensitive employee data

Solution:

  1. Months 1-2: Complete Screening Program

    • Established Security Screening Office (SSO) with 12 staff
    • Created complete screening policy (government + corporate standards)
    • Defined 5 tiers: Critical (security clearance + full screening), High, Medium, Low, Contractor
    • Selected multiple vendors: AuthBridge (India), Sterling (International), Dow Jones (Sanctions)
    • All vendors underwent security clearance and facility access review
    • Implemented air-gapped screening data storage (no internet access for screening records)
  2. Months 3-4: Full Workforce Screening

    • Conducted retrospective screening of all 5,300 non-cleared employees
    • Found 47 adverse findings (criminal history, fake credentials, undisclosed foreign ties)
    • 12 employees required termination; 35 required remediation or role change
    • Implemented full screening for all 2,800 contractors
    • Found 23 contractors with adverse findings; 8 terminated, 15 restricted
    • Implemented international screening for 180 foreign nationals
  3. Months 5-6: Continuous Monitoring and Re-Screening

    • Deployed continuous monitoring for all 8,500 employees (criminal, sanctions, adverse media)
    • Implemented quarterly monitoring for Tier 1 and 2
    • Implemented annual re-screening for all roles (supplementing 5-year security clearance renewal)
    • Created re-screening triggers: role change, access escalation, foreign travel, financial distress indicators
    • Implemented social media monitoring for Tier 1 (public posts only, privacy-compliant)
  4. Months 7-9: Advanced Screening and Technology

    • Implemented biometric identity verification (fingerprint + iris) for all facility access
    • Deployed AI-driven risk scoring for screening results (pattern analysis, anomaly detection)
    • Implemented psychological assessment for Tier 1 roles (critical for defence)
    • Created insider threat program integrating screening with behavioral monitoring
    • Implemented polygraph for select critical roles (where legally permitted)
    • Created foreign influence screening for employees with foreign contacts
  5. Months 10-12: Governance and Certification

    • Established Screening Board (monthly review of adverse findings, appeals, policy changes)
    • Created screening metrics dashboard for management and government liaison
    • Passed government security audit with zero findings
    • Achieved ISO 27001 certification with commendation for screening program
    • Created screening best practice guide shared with defence industry consortium

Results:

  • Security clearance: 100% of eligible employees cleared; zero clearance revocations in 18 months
  • Insider threat: Zero insider incidents; 3 potential threats detected through continuous monitoring and prevented
  • Foreign influence: 2 employees with undisclosed foreign ties identified and reassigned
  • Social media: 1 classified information leak prevented through social media monitoring
  • Contractor security: 8 high-risk contractors removed; no contractor-related incidents
  • Government audit: Passed all audits with commendation; became industry reference
  • International hiring: Standardized screening for 12 countries; reduced international hiring risk
  • overhead: annual screening program vs. potential national security breach + regulatory sanctions
  • Industry recognition: BDS screening program won Defence Industry Security Excellence Award

Multi-Framework Mapping

ISO 27001:2022 A.6.1SOC 2 Trust Services CriteriaPCI DSS v4.0NIST 800-53 Rev 5CIS Controls v8COBIT 2019GDPR / DPDP Act 2023
ScreeningCC1.1: Management philosophy and operating style12.4.1: Security awareness programPS-1: Personnel security policy and proceduresControl 6.1: Establish an inventory of assetsAPO07.01: Manage peopleDPDP S. 8: Reasonable security
CC1.2: Board of directors12.4.2: Security awareness contentPS-2: Position risk designationControl 6.2: Address unauthorized assetsAPO07.02: Manage competenciesDPDP S. 10: Consent
CC1.3: Management oversight12.4.3: Security awareness program contentPS-3: Personnel screeningControl 6.3: Establish and maintain an inventory of personnelAPO07.03: Manage contractsGDPR Art. 32: Security of processing
CC1.4: Integrity and ethical values12.4.4: Security awareness trainingPS-4: Personnel terminationControl 6.4: Establish and maintain an inventory of third-party personnelAPO07.04: Manage cultural diversityGDPR Art. 5: Principles
CC1.5: Accountability12.4.5: Security awareness program evaluationPS-5: Personnel transferControl 6.5: Establish and maintain an inventory of service accountsAPO07.05: Manage performanceGDPR Art. 25: Data protection by design
CC2.1: Communication and information12.8.1: Third-party security policiesPS-6: Access agreementsControl 6.6: Establish and maintain an inventory of privileged accountsDSS05.02: Manage securityGDPR Art. 28: Processor requirements
12.8.2: Third-party security agreementsPS-7: External personnel securityControl 6.7: Establish and maintain an inventory of shared accountsDSS05.03: Manage security servicesGDPR Art. 32: Security of processing
12.8.3: Third-party security assurancePS-8: Personnel sanctionsControl 6.8: Establish and maintain an inventory of emergency accountsDSS06.01: Manage business process controlsDPDP S. 11: Rights of data principal
PS-9: Position descriptionsControl 6.9: Establish and maintain an inventory of temporary accountsDSS06.02: Manage business process controlsDPDP S. 13: Grievance redressal
Control 6.10: Establish and maintain an inventory of generic accountsDSS06.03: Manage business process controlsDPDP S. 14: Nomination
Control 6.11: Establish and maintain an inventory of dormant accountsMEA01.02: Monitor and evaluateDPDP S. 17: Children's data

Regulatory and Industry Context

India Regulatory Framework

RegulationScreening RequirementPenalty
DPDP Act 2023Section 8, reasonable security includes personnel screeningUp to
IT Act 2000 (Section 43A)Reasonable security practices for sensitive dataCompensation claims
RBI Cyber Security FrameworkBackground verification for personnel accessing critical systemsLicense restrictions
SEBI Cybersecurity CircularBackground verification for trading system personnelTrading restrictions
IRDAI GuidelinesScreening for insurance personnel handling customer dataLicense suspension
Companies Act 2013Director disqualification for certain criminal offencesDirector disqualification
POSH Act 2013Pre-employment inquiry for sexual harassment historyEmployer liability
Factories Act 1948Age verification for workersfine; imprisonment
Contract Labour Act 1970Registration and verification of contract workersPenalties
Private Security Agencies Act 2005Mandatory police verification for security personnelLicense cancellation
Official Secrets Act 1923Security clearance for classified workImprisonment up to 14 years
Aadhaar Act 2016Background verification for Aadhaar operatorsLicense cancellation

International Regulations

RegulationScreening Requirement
GDPR (EU)Article 32, security measures including personnel; Article 28, processor personnel
HIPAA (US)§164.308(a)(3)(ii)(B)**, Workforce clearance procedure
SOX (US)IT general controls including personnel access
FCRA (US)Fair Credit Reporting Act governs background checks
BS 7858 (UK)Security screening of individuals employed in security environment
HMG Baseline Personnel Security Standard (UK)Government personnel screening

Sector-Specific Requirements

SectorScreening-Specific Requirements
BFSIRBI-mandated background verification; credit checks for financial roles; sanctions screening; integrity checks
HealthcareMedical license verification; CDSCO requirements; clinical trial personnel screening; patient safety checks
TelecomDOT security clearance; subscriber data access controls; SIM seller verification
ManufacturingSafety-critical role screening; substance testing; industrial accident history
GovernmentSecurity clearance; police verification; CBI check for sensitive roles; Official Secrets Act compliance
DefenceSecurity clearance (secret/top secret); foreign influence screening; polygraph (select roles); family background
AviationDGCA-mandated background checks; substance testing; security training
EducationTeacher verification; police verification for school staff; child safety checks
SaaS / B2BVendor personnel screening; customer data access controls; SOC 2 personnel requirements
E-commerceDelivery personnel verification; warehouse staff screening; payment handler checks

Roles and Responsibilities (RACI)

ActivityAccountableResponsibleConsultedInformed
Screening PolicyCISOHR HeadLegalBoard
Role Tier AssignmentCISOHRHiring ManagerSecurity
Candidate ConsentHRRecruiterLegalCandidate
Screening ExecutionHRScreening VendorCISOHiring Manager
Results ReviewCISOHRLegalHiring Manager
Adverse ActionLegalHRCISOCandidate/Employee
Re-ScreeningCISOHRSecurityEmployee
Continuous MonitoringCISOSecurity TeamHRManagement
Vendor ScreeningCISOVendor ManagementHRLegal
Contractor ScreeningHRContractor ManagerCISOSecurity
Screening RecordsHRHR AdminCISOLegal
Screening TrainingHRTraining TeamCISOAll Recruiters
Screening MetricsCISOHR AnalystComplianceBoard
Screening AuditInternal AuditHRCISOBoard
Screening TechnologyCISOITHRManagement
International ScreeningCISOHRLegalManagement
Social Media ScreeningCISOSecurity AnalystHRLegal
Sanctions ScreeningCISOComplianceLegalManagement

Documentation and Evidence Requirements

Required Documents

DocumentOwnerRetention PeriodFormat
Screening PolicyCISO7 yearsPDF + Word
Screening ProcedureHR7 yearsPDF + Word
Role-Tier MappingCISO3 yearsSpreadsheet
Candidate Consent FormsHR7 yearsSigned forms / digital
Screening ReportsHR7 yearsVendor reports
Adverse Action RecordsLegal7 yearsCase files
Re-Screening ScheduleHR3 yearsCalendar / system
Re-Screening ResultsHR7 yearsVendor reports
Continuous Monitoring AlertsCISO3 yearsAlert logs
Contractor Screening RecordsHRDuration of contract + 3 yearsVendor reports
Vendor Screening AttestationsVendor Management3 yearsCertificates
Screening Vendor ContractsProcurement7 yearsContracts
Screening Vendor AssessmentCISO3 yearsAssessment reports
Screening Training RecordsHR5 yearsLMS records
Screening MetricsHR3 yearsDashboard / reports
Screening Audit ReportsInternal Audit5 yearsPDF
Screening Dispute RecordsLegal7 yearsCase files
International Screening RecordsHR7 yearsVendor reports
Social Media Screening RecordsCISO3 yearsScreening logs
Sanctions Screening RecordsCISO3 yearsScreening logs

Continuous Improvement

Maturity Model (Level 1-5)

LevelNameDescription
1InitialAd-hoc reference checks; no policy; no formal screening; no records
2ManagedBasic screening for some roles; police verification for sensitive; informal records
3DefinedTiered screening program; formal policy; vendor screening; re-screening; continuous monitoring; DPDP compliance
4Quantitatively ManagedAutomated screening; integrated with HRIS/ATS; real-time monitoring; metrics-driven; international screening
5OptimizingAI-driven risk scoring; predictive insider threat detection; blockchain-verified credentials; behavioral analytics; continuous optimization; industry leadership

Improvement Cycle

  • Plan: Annual screening program review; quarterly metrics; technology trend assessment; regulatory change monitoring
  • Do: Deploy new tools; update tiers; train staff; enhance vendor management; improve integration
  • Check: Measure effectiveness; benchmark against industry; audit; gather feedback
  • Act: Standardize; communicate; update procedures; report to management; industry sharing
  • AI Risk Scoring: AI analyzing screening data + behavior for risk prediction
  • Blockchain Credentials: Verifiable, tamper-proof academic and professional credentials
  • Real-Time Monitoring: Continuous criminal, sanctions, and social media monitoring
  • Biometric Verification: Advanced liveness detection, facial recognition, behavioral biometrics
  • Remote Verification: AI-powered remote identity verification (no in-person required)
  • Psychometric Screening: Behavioral and psychological risk assessment for sensitive roles
  • Global Screening Networks: Cross-border screening data sharing (with privacy safeguards)
  • Automated Adverse Action: AI-assisted fair adverse action decisions with bias mitigation

FAQ

Frequently Asked Questions (20 Questions)

Q1: Is screening mandatory for all employees under ISO 27001? A: Yes, ISO 27001 A.6.1 requires screening for all candidates. The depth varies by role, but some form of screening (identity, reference, employment) is expected for all.

Q2: Can we reject a candidate based on a criminal record? A: It depends. Under Indian law, you must consider the nature of the offence, time elapsed, and role relevance. Some roles (defence, government, financial) have legal restrictions. For other roles, a fair assessment is required. Consult Legal.

Q3: Do we need police verification for all employees? A: Police verification is recommended for Tier 1 and Tier 2 roles (access to sensitive data). For Tier 3 and 4, it may not be necessary unless required by specific regulations (e.g., security agencies, factories).

Q4: How long does screening take in India? A: Identity: 1-2 days. Education: 3-7 days. Employment: 3-7 days. Police verification: 7-15 days. Full Tier 1 screening: 2-3 weeks. Use vendor SLAs to manage timelines.

Q5: Can we screen existing employees? A: Yes, but with consent and notice. Re-screening should be part of employment terms. For sensitive roles, re-screening is best practice. For existing employees without prior consent, obtain fresh consent before re-screening.

Q6: What is continuous monitoring? A: Continuous monitoring is ongoing screening after employment. It alerts you to new criminal records, sanctions listings, or adverse media. It's recommended for Tier 1 roles and financial roles.

Q7: Do we need to screen interns and trainees? A: Yes, if they have access to information or systems. Screening depth may be lighter (identity, education, basic reference) but should still be conducted.

Q8: What if a candidate refuses screening? A: You can withdraw the offer. Screening is a condition of employment. However, ensure your policy and offer letter clearly state that employment is contingent on successful screening.

Q9: How do we handle screening for remote workers? A: Remote workers often have the same or greater access. Use remote identity verification (Onfido, Jumio), video interviews, and digital document verification. Ensure address verification is thorough.

Q10: What is the difference between police verification and criminal record check? A: Police verification is conducted by local police and covers the candidate's address. Criminal record check searches court and database records for criminal history. Both are important but cover different aspects.

Q11: Do we need to screen board members and directors? A: Yes, especially for listed companies and regulated entities. Directors have significant access and influence. DIN (Director Identification Number) verification is mandatory under Companies Act 2013.

Q12: How do we protect screening data under DPDP? A: Screening data is personal data. Obtain consent, limit access, encrypt, retain only as long as necessary, and dispose securely. Use DPDP-compliant consent forms.

Q13: Can we use social media for screening? A: Yes, but only public information. Do not request passwords or hack private accounts. Document what you review and ensure decisions are not discriminatory. Be aware of DPDP and labour law implications.

Q14: What is a backdoor reference check? A: Contacting references not provided by the candidate (e.g., former colleagues found through LinkedIn). This is common in Tier 1 roles but must be done discreetly and legally. Be transparent if required by law.

Q15: Do we need drug testing? A: Only for safety-critical roles (manufacturing, transportation, aviation) where legally permitted. Drug testing is not common in IT/services roles in India. Ensure legal compliance and explicit consent.

Q16: What is adverse action and how do we handle it? A: Adverse action is taking negative action (rejecting candidate, terminating employee) based on screening results. You must: verify accuracy, give opportunity to explain, document decision, provide appeal mechanism.

Q17: How do we screen international candidates? A: Use global screening vendors (Sterling, First Advantage). Verify international degrees through WES or equivalent. Conduct criminal checks in home country. Verify work permits and visa status.

Q18: What is the role of CISO in screening? A: CISO defines screening requirements based on information access risk, reviews security-relevant findings, approves access for screened personnel, and manages continuous monitoring.

Q19: Can we use AI for screening? A: AI can assist in risk scoring and pattern detection, but final decisions should involve human review. Be cautious of AI bias in screening decisions. Document AI use and ensure fairness.

Q20: What will an ISO 27001 auditor look for in A.6.1? A: The auditor will verify: (1) screening policy exists, (2) all roles have defined screening requirements, (3) candidates are screened before employment, (4) screening is commensurate with role, (5) contractors are screened, (6) re-screening is conducted, (7) records are maintained, (8) adverse action is handled fairly, and (9) compliance with legal requirements.


References and Further Reading

ISO Standards

  • ISO 27001:2022, Information Security Management Systems
  • ISO 27002:2022, Information Security Controls
  • ISO 27036, Information Security for Supplier Relationships
  • ISO 27701:2019, Privacy Information Management System

Indian Law

  • DPDP Act 2023, Digital Personal Data Protection Act
  • Information Technology Act 2000, Sections 43A, 66, 72
  • Companies Act 2013, Director disqualification, DIN
  • Factories Act 1948, Age verification, worker registration
  • Contract Labour Act 1970, Contract worker registration
  • Private Security Agencies Act 2005, Security personnel verification
  • POSH Act 2013, Pre-employment sexual harassment inquiry
  • Official Secrets Act 1923, Security clearance
  • Aadhaar Act 2016, Aadhaar operator verification

International

  • FCRA (US), Fair Credit Reporting Act
  • GDPR (EU), Articles 5, 32, 28
  • BS 7858 (UK), Security screening
  • HMG Baseline Personnel Security Standard (UK), Government screening
  • HIPAA (US), §164.308(a)(3)(ii)(B)**, Workforce clearance

Industry

  • NASSCOM, IT industry personnel practices
  • AuthBridge, Indian BGV research and reports
  • Verizon DBIR, Data breach investigations report (insider threat data)
  • ISACA, Screening and insider threat guidance

Screening for Specific Roles

Executive and Board-Level Screening

Check TypeC-SuiteBoard MembersCFO/FinanceCTO/EngineeringCHRO/HR
Identity verificationMandatoryMandatoryMandatoryMandatoryMandatory
Address verificationMandatoryMandatoryMandatoryMandatoryMandatory
Education verificationMandatoryMandatoryMandatoryMandatoryMandatory
Employment history10 years10 years10 years10 years10 years
Criminal record checkMandatoryMandatoryMandatoryMandatoryMandatory
Credit checkMandatoryMandatoryMandatoryOptionalOptional
Directorship searchMandatoryMandatoryMandatoryOptionalOptional
Media/social media screeningMandatoryMandatoryMandatoryMandatoryMandatory
Conflict of interest checkMandatoryMandatoryMandatoryMandatoryMandatory
Reference checks5 references5 references5 references3 references3 references
Psychometric assessmentRecommendedRecommendedRecommendedOptionalRecommended
Re-screening frequencyAnnualAnnualAnnualBiennialBiennial

IT and Engineering Roles

Check TypeDevelopersDevOpsSecurity EngineersDatabase AdminsNetwork Engineers
Identity verificationMandatoryMandatoryMandatoryMandatoryMandatory
Address verificationMandatoryMandatoryMandatoryMandatoryMandatory
Education verificationMandatoryMandatoryMandatoryMandatoryMandatory
Employment history5 years5 years7 years7 years7 years
Criminal record checkMandatoryMandatoryMandatoryMandatoryMandatory
Credit checkOptionalOptionalOptionalMandatoryOptional
Open source contribution reviewOptionalOptionalRecommendedOptionalOptional
Reference checks2 references2 references3 references3 references3 references
Re-screening frequencyBiennialBiennialAnnualAnnualBiennial

Vendor and Contractor Screening

Check TypeCritical VendorsStandard VendorsContractorsTemp StaffInterns
Identity verificationMandatoryMandatoryMandatoryMandatoryMandatory
Address verificationMandatoryMandatoryMandatoryMandatoryOptional
Criminal record checkMandatoryOptionalMandatoryOptionalOptional
Company verificationMandatoryMandatoryN/AN/AN/A
Financial health checkMandatoryOptionalN/AN/AN/A
Reference checks3 references2 references2 references1 reference1 reference
Re-screening frequencyAnnualBiennialPer contractPer engagementPer engagement

Continuous Screening and Re-Screening

Why Continuous Screening Matters

Initial screening is a point-in-time check. Employees' circumstances change over time:

  • Financial stress increases insider threat risk
  • Criminal convictions after hiring
  • Changes in personal circumstances (divorce, addiction, gambling)
  • Changes in political or ideological affiliations
  • New conflicts of interest
  • Moonlighting or side businesses competing with employer

Continuous Screening Program

TriggerActionTimelineOwner
Role change to high-riskFull re-screening including credit checkWithin 30 days of role changeHR + Security
Promotion to managementEnhanced screening (references, media, directorship)Before promotion effectiveHR
Access to sensitive dataSecurity clearance reviewBefore access grantedCISO
Financial stress indicatorsConfidential counseling, monitoring, supportAs neededHR + Manager
Criminal convictionImmediate review, disciplinary actionWithin 48 hoursHR + Legal + Security
Regulatory complaintReview and potential re-screeningWithin 30 daysCompliance + HR
Annual re-screeningBasic checks (criminal, address, employment)Annual anniversaryHR
Vendor contract renewalRe-screening before renewal60 days before renewalVendor Management
Post-incidentEnhanced screening for affected teamWithin 30 days of incidentHR + Security
M&A integrationScreening for acquired employeesWithin 90 days of closeHR + Integration Team

Re-Screening Policy Template

RE-SCREENING POLICY

1. ANNUAL RE-SCREENING
   All employees undergo basic re-screening annually:
   - Criminal record check (last 12 months)
   - Address verification (if changed)
   - Employment verification (if changed)
   - Conflict of interest declaration

2. ROLE CHANGE RE-SCREENING
   Employees moving to higher-risk roles undergo enhanced re-screening:
   - Full background check as per new role requirements
   - Credit check (if role requires)
   - Enhanced reference checks
   - Media/social media screening

3. TRIGGERED RE-SCREENING
   Events triggering immediate re-screening:
   - Criminal conviction (any level)
   - Regulatory complaint or investigation
   - Security incident involvement
   - Financial irregularities
   - Conflict of interest concerns
   - Significant behavioral changes

4. VENDOR RE-SCREENING
   Critical vendors screened annually:
   - Company financial health
   - Key personnel criminal checks
   - Compliance certification validity
   - Security incident history

5. DOCUMENTATION
   All re-screening results documented in personnel file
   Adverse findings reviewed by HR + Security + Legal
   Decision matrix for adverse findings maintained
   Appeals process documented

Additional Illustrative Scenarios: Indian Screening Incidents

Illustrative Scenario 3: Indian IT Company, Fake Degree Scandal (2022)

What happened: A mid-sized IT company in Hyderabad discovered that 12 employees (including 3 team leads) had submitted fake degrees during hiring. The fake degrees were from universities that did not exist. The issue was discovered when a client requested degree verification for an onsite deployment.

Impact:

  • 12 employees terminated immediately
  • Client contract cancelled ( annual revenue lost)
  • Reputational damage in client market
  • Legal action from clients for misrepresentation
  • Remediation overhead: (re-hiring, re-training, legal)
  • Company implemented mandatory degree verification for all hires

Root causes:

  • No mandatory degree verification during hiring
  • HR relied on self-attested copies without verification
  • No third-party verification vendor engaged
  • No audit of screening process
  • Pressure to hire quickly led to skipped checks

Lessons:

  • Mandatory degree verification for all roles (not just claimed degrees)
  • Use third-party verification vendors (AuthBridge, First Advantage)
  • Verify all educational credentials directly with institutions
  • Include degree verification clause in offer letter (termination if false)
  • Audit screening process annually
  • Never skip verification due to hiring pressure

Illustrative Scenario 4: Indian Bank, Employee with Criminal Record (2023)

What happened: A bank employee in Mumbai was arrested for involvement in a loan fraud scheme. The employee had a prior criminal record for financial fraud that was not discovered during hiring because the bank only conducted local police verification (in the employee's hometown, not the city where the fraud occurred). The employee used their position to approve fraudulent loans totaling .

Impact:

  • Loan fraud: in fraudulent loans approved
  • RBI penalty: for inadequate employee screening
  • Customer trust erosion
  • Employee arrested, bank named in criminal investigation
  • Remediation overhead: (investigation, legal, system changes)
  • Bank implemented nationwide criminal verification

Root causes:

  • Local-only police verification (not nationwide)
  • No criminal record check in the city where fraud occurred
  • No credit check for financial roles
  • No reference checks with previous employers
  • No ongoing monitoring for financial stress indicators

Lessons:

  • Nationwide criminal verification (not just local police station)
  • Credit check mandatory for all financial roles
  • Enhanced reference checks for financial roles (direct supervisor, not just HR)
  • Ongoing monitoring for financial stress indicators
  • Segregation of duties for loan approval (no single person can approve)
  • Regular re-screening for financial roles (annual)
  • Implement fraud detection systems that flag unusual patterns

How Singahi can help

Singahi is one team for compliance, assessment and managed security. We help growing companies implement and certify ISO 27001:2022, and stay secure afterward.


Continue the toolkit

How we can help

Working toward this?

If a certification or a customer's security questionnaire is what brought you here, tell us where you are. We'll give you an honest read on the work and the timeline, with no obligation.

What happens next

  1. Tell us the trigger

    A questionnaire, an audit date or an investor ask. The short form or a call both work.

  2. A practitioner replies

    A senior practitioner, not a bot, within four business hours.

  3. You get a scoped next step

    An honest view of what the work involves. No pressure, no theatre.