On this page
- Quick Reference (60 Seconds)
- What the Standard Actually Requires
- Why Screening Matters
- Scope and Applicability
- Key Definitions and Terminology
- Relationship to Other Controls
- Implementation Roadmap (Week-by-Week)
- Detailed Implementation Guidance
- Tools, Technologies, and Solutions
- Policy and Procedure Templates
- Risk Assessment and Treatment
- Audit and Compliance Checklist
- Metrics and KPIs
- Common Pitfalls and How to Avoid Them
- Illustrative Scenarios
- Multi-Framework Mapping
- Regulatory and Industry Context
- Roles and Responsibilities (RACI)
- Documentation and Evidence Requirements
- Continuous Improvement
- FAQ
- References and Further Reading
- Screening for Specific Roles
- Continuous Screening and Re-Screening
- Additional Illustrative Scenarios: Indian Screening Incidents
Quick Reference (60 Seconds)
| Attribute | Detail |
|---|---|
| Control ID | A.6.1 |
| Title | Screening |
| Objective | Verify the suitability of candidates for employment and ongoing suitability of employees |
| Domain | People |
| ISO 27001:2022 Clause | Annex A.6.1 |
| What You Must Do | Conduct background verification checks on all candidates and employees commensurate with their role, data access, and business risk |
| Owner | HR / CISO / Security |
| Maturity Level 1 | Basic reference checks for some roles |
| Maturity Level 2 | Formal screening policy; police verification for sensitive roles |
| Maturity Level 3 | Tiered screening based on role risk; continuous monitoring; vendor screening |
| Maturity Level 4 | Automated screening integration; real-time monitoring; re-screening triggers; international screening |
| Maturity Level 5 | AI-driven risk scoring; predictive insider threat screening; blockchain-verified credentials; continuous behavioral monitoring |
What the Standard Actually Requires
ISO 27001:2022 Control Text
Annex A 6.1 asks organizations to carry out background verification checks on candidates proportionate to the role and applicable laws.
Implementation Guidance (ISO 27002:2022)
- Screening should be commensurate with the role and the sensitivity of information accessed
- Screening should include verification of identity, qualifications, employment history, and criminal record where permitted by law
- Screening should be carried out for contractors, temporary staff, and outsourced personnel as well as permanent employees
- Screening should be repeated periodically, especially for sensitive roles
- Screening should comply with all applicable legal and regulatory requirements
- Candidates should be informed about screening requirements
- Results should be handled confidentially and securely
"Shall" vs "Should" Analysis
- Shall: Background verification is mandatory for all candidates
- Should: The depth and method of screening are flexible based on role risk and legal requirements
Common Misinterpretations
| Misinterpretation | Reality |
|---|---|
| "Screening is only for senior roles" | All personnel require screening; depth varies by role |
| "Once screened, never need to re-screen" | Re-screening is required for sensitive roles, especially after role changes |
| "Contractors don't need screening" | Contractors often have the same access as employees and require the same screening |
| "Aadhaar verification is enough" | Aadhaar verifies identity but not criminal history, qualifications, or employment history |
| "Screening is an HR-only activity" | CISO and security must define screening requirements based on information access |
Why Screening Matters
The Business Risk Narrative
Insider threats are a leading cause of security breaches. For Indian organizations, inadequate screening creates direct exposure:
- 68% of Indian organizations reported at least one insider incident in 2024 (Source: Verizon DBIR)
- 34% of breaches involve internal actors (malicious or negligent)
- Average impact of an insider incident in India: ****
- The impact of a bad hire (including security risk): -25 lakh for mid-level roles, + lakh for senior roles
- Criminal background check reveals issues in 8-12% of candidates in India (Source: AuthBridge)
- Fake credentials detected in 5-7% of resume screenings in India
Regulatory Landscape in India
| Regulation | Screening Requirement | Penalty for Non-Compliance |
|---|---|---|
| DPDP Act 2023 | Reasonable security includes personnel screening | Up to |
| IT Act 2000 | Section 43A, reasonable security practices | Compensation claims |
| RBI Cyber Security Framework | Screening for personnel accessing critical systems | License restrictions |
| SEBI Cybersecurity Circular | Background verification for personnel with access to trading systems | Trading restrictions |
| IRDAI Guidelines | Screening for insurance personnel handling customer data | License suspension |
| Companies Act 2013 | Director identification number (DIN); disqualification for certain offences | Director disqualification |
| POSH Act 2013 | Pre-employment inquiry for sexual harassment history | Employer liability |
| Factories Act 1948 | Age verification for workers | fine; imprisonment |
| Contract Labour Act 1970 | Registration and verification of contract workers | Penalties, contract cancellation |
| Private Security Agencies Act 2005 | Mandatory police verification for security personnel | License cancellation |
Industry-Specific Consequences
| Industry | Screening Failure Scenario |
|---|---|
| BFSI | Employee with criminal history steals customer funds; RBI penalty; license review |
| Healthtech | Unqualified employee handles PHI; medical malpractice; CDSCO action |
| SaaS / B2B | Developer with fake credentials introduces vulnerabilities; customer data breach |
| E-commerce | Warehouse employee with theft history steals customer packages; fraud |
| Government | Unscreened contractor accesses classified data; national security breach |
| Manufacturing | Employee with substance abuse causes industrial accident; IP theft |
impact of Non-Compliance Statistics
- impact of negligent hiring lawsuit in India: -75 lakh in settlement
- Average time to replace a bad hire: 6-9 months
- Revenue impact of insider fraud: -50 lakh per incident
- Reputational damage from insider incident: 30-40% customer trust reduction
- Screening overhead per candidate: - (depending on depth)
- ROI of proper screening: 15-25x (impact of screening vs. impact of bad hire/incident)
Scope and Applicability
Figure · Matrix
Comparison: Tier 1: Critical to Vendors
What the Control Covers
- Pre-employment screening: All candidates before offer acceptance
- In-employment re-screening: Periodic re-screening for sensitive roles
- Post-employment verification: Reference checks for departing employees
- Contractor screening: Third-party staff, consultants, temporary workers
- Vendor personnel screening: Staff of outsourced vendors with access to systems/data
- Role-based screening: Different screening depth based on role risk
- Continuous monitoring: Ongoing monitoring for criminal records, sanctions, etc.
- International screening: Candidates with international backgrounds or for global roles
Who It Applies To
| Role Category | Screening Level | Example Roles |
|---|---|---|
| Tier 1: Critical | Full screening + continuous monitoring | CISO, CIO, CFO, Database Admin, System Admin, Security Engineer, DevOps Lead, Access to Restricted data |
| Tier 2: High | Full screening + periodic re-screening | Developers, QA, Network Admin, IT Support, HR, Finance, Access to Confidential data |
| Tier 3: Medium | Standard screening | Marketing, Sales, Operations, Customer Support, Access to Internal data |
| Tier 4: Low | Basic screening | Reception, Facilities, General Admin, Access to Public data |
| Contractors | Same as equivalent employee tier | All contract roles |
| Vendors | Based on access level | ODC staff, outsourced support, cleaning staff with access |
Who It Applies To (Roles)
| Role | Responsibility |
|---|---|
| HR | Screening policy, vendor selection, candidate communication, record keeping, legal compliance |
| CISO | Defining screening requirements based on information access, security risk assessment |
| Legal | Compliance with employment law, privacy law, consent, adverse action procedures |
| Hiring Manager | Defining role requirements, supporting screening decisions, evaluating results |
| Background Check Vendor | Conducting checks, verifying credentials, providing reports |
| Security Team | Access risk assessment, continuous monitoring, incident response |
| Candidates / Employees | Providing accurate information, consenting to checks, updating information |
What It Does NOT Cover
- General performance management (covered by HR processes)
- Security awareness training (covered by A.6.3)
- Disciplinary action (covered by A.6.4)
- Termination procedures (covered by A.6.5)
- Physical security of personnel (covered by A.7)
Size-Based Applicability
| Organization Size | Approach |
|---|---|
| Startups (< 50) | Basic identity + reference checks; police verification for founders; education verification for technical roles |
| SMB (50-500) | Formal screening policy; police verification for sensitive roles; vendor background checks |
| Mid-market (500-5000) | Tiered screening; continuous monitoring; international screening; re-screening program |
| Enterprise (5000+) | Full screening program; AI-driven risk scoring; global screening; continuous monitoring; integration with HRIS |
Key Definitions and Terminology
| Term | Definition | Source |
|---|---|---|
| Background Verification (BGV) | Process of verifying a candidate's identity, credentials, employment history, and other relevant information | Industry |
| Police Verification | Verification of criminal record through local police authorities | Indian Law |
| Reference Check | Contacting previous employers or colleagues to verify candidate's work history and character | HR Practice |
| Education Verification | Confirming academic degrees, certificates, and qualifications with issuing institutions | BGV Practice |
| Employment Verification | Confirming previous employment details (dates, designation, reason for leaving) | BGV Practice |
| Criminal Record Check | Checking for criminal history through police, court, or database records | BGV Practice |
| Address Verification | Physical verification of candidate's residential address | BGV Practice |
| Identity Verification | Confirming identity through government ID (Aadhaar, PAN, Passport, Voter ID) | BGV Practice |
| Credit Check | Reviewing financial history for roles with financial responsibility | BGV Practice |
| Sanctions Check | Screening against government sanctions lists (UN, OFAC, EU, etc.) | BGV Practice |
| Media/Social Media Screening | Reviewing public online presence for red flags | BGV Practice |
| Drug Testing | Testing for substance abuse (where legally permitted and role-relevant) | BGV Practice |
| Continuous Monitoring | Ongoing screening of employees after hire for new criminal records, sanctions, etc. | BGV Practice |
| Re-screening | Repeating background checks periodically or after role changes | BGV Practice |
| Adverse Action | Procedure when screening results lead to rejection or termination | BGV Practice / FCRA (US) |
| AuthBridge | Leading Indian background verification company | Industry |
| First Advantage | Global background screening company | Industry |
| Sterling | Global background screening company | Industry |
| HireRight | Global background screening company | Industry |
Relationship to Other Controls
Upstream Controls (Prerequisites)
| Control ID | Relationship | Why It Matters |
|---|---|---|
| A.5.1 | Policies for Information Security | Screening policy must align with security policy |
| A.5.2 | Information Security Roles | Screening requirements for security roles must be defined |
| A.5.7 | Inventory of Information Assets | Asset access determines screening depth |
Downstream Controls (Enabled By)
| Control ID | Relationship | Why It Matters |
|---|---|---|
| A.6.2 | Terms and Conditions of Employment | Screening results inform employment terms |
| A.6.3 | Information Security Awareness | Screened employees must be trained |
| A.6.4 | Disciplinary Process | Screening failures may lead to disciplinary action |
| A.6.5 | Responsibilities after Termination | Screening data informs exit procedures |
| A.6.6 | Confidentiality Agreements | Screened employees must sign NDAs |
| A.6.7 | Remote Working | Remote workers require enhanced screening |
| A.6.8 | Information Security Event Reporting | Screened employees must report incidents |
Parallel Controls (Work Alongside)
| Control ID | Relationship | Why It Matters |
|---|---|---|
| A.5.21 | Information Security in Supplier Relationships | Vendor staff screening |
| A.5.30 | Outsourced Development | Developer screening |
| A.8.1 | User Endpoint Devices | Device access requires trusted personnel |
| A.8.5 | Secure Authentication | Authentication systems accessed by screened users |
Implementation Roadmap (Week-by-Week)
Phase 1: Discovery & Assessment (Weeks 1-2)
Week 1: Current Screening Assessment
- Deliverable: Screening maturity assessment report
- Owner: HR + CISO
- Activities:
- Review current screening practices across all roles
- Identify gaps between current practice and ISO 27001 requirements
- Map all roles to information access levels
- Assess legal compliance of current screening (DPDP, labour law, privacy)
- Review existing vendor contracts and screening quality
- Interview hiring managers about screening concerns
- Document current screening overhead and turnaround times
Week 2: Risk-Based Screening Framework Design
- Deliverable: Role-risk mapping + screening tier definitions
- Owner: CISO + HR + Legal
- Activities:
- Define 4 screening tiers (Critical, High, Medium, Low)
- Map all organizational roles to screening tiers
- Define screening components for each tier
- Assess legal requirements for each check type
- Define re-screening frequency by tier
- Define continuous monitoring requirements
- Create screening vendor selection criteria
Phase 2: Design & Planning (Weeks 3-4)
Week 3: Policy and Procedure Development
- Deliverable: Screening Policy + Screening Procedure + Consent Forms
- Owner: HR + Legal + CISO
- Activities:
- Draft Employee Screening Policy
- Create screening procedure (pre-hire, in-employment, post-hire)
- Create candidate consent forms (DPDP-compliant)
- Create adverse action procedure (rejection, remediation, appeal)
- Create re-screening trigger procedures (role change, incident, periodic)
- Create vendor screening requirements
- Create screening records management procedure
Week 4: Vendor Selection and Integration
- Deliverable: Screening vendor selected and contracted
- Owner: HR + Procurement + CISO
- Activities:
- Evaluate BGV vendors (AuthBridge, First Advantage, Sterling, HireRight, local vendors)
- Assess vendor capabilities (checks offered, turnaround time, technology, compliance)
- Conduct vendor security assessment
- Negotiate contract with security and privacy requirements
- Plan HRIS integration for automated screening triggers
- Define SLA (turnaround time, accuracy, dispute resolution)
- Conduct pilot screening with 5 candidates
Phase 3: Implementation (Weeks 5-8)
Week 5: Pre-Employment Screening Rollout
- Deliverable: All new hires screened according to tier
- Owner: HR + Screening Vendor
- Activities:
- Integrate screening into hiring workflow (ATS trigger)
- Train recruiters on screening requirements by role
- Implement screening for all new positions
- Create candidate communication templates (screening explanation)
- Establish screening results review process
- Define escalation for adverse findings
- Create conditional offer language (contingent on screening)
Week 6: In-Employment Re-Screening
- Deliverable: Re-screening program operational for sensitive roles
- Owner: HR + CISO + Security
- Activities:
- Identify all employees in Tier 1 and Tier 2 requiring re-screening
- Schedule re-screening (annual for Tier 1, bi-annual for Tier 2)
- Implement re-screening triggers (role change, access escalation, security incident)
- Create re-screening communication templates
- Establish re-screening results review process
- Define consequences for re-screening failures
Week 7: Contractor and Vendor Screening
- Deliverable: All contractors and vendor personnel screened
- Owner: HR + Vendor Management + CISO
- Activities:
- Extend screening requirements to all contractors
- Require screening certificates from staffing vendors
- Implement direct screening for critical vendor roles
- Create vendor screening attestation template
- Add screening clauses to vendor contracts
- Verify vendor screening quality through spot checks
- Create vendor personnel access approval workflow (screening gate)
Week 8: Continuous Monitoring Implementation
- Deliverable: Continuous monitoring alerts configured
- Owner: CISO + HR + Security Vendor
- Activities:
- Deploy continuous monitoring for Tier 1 roles (criminal records, sanctions)
- Configure alert thresholds (new criminal record, sanctions listing)
- Create incident response for monitoring alerts
- Integrate monitoring with HRIS and security systems
- Train security team on alert response
- Create employee notification procedure for monitoring
- Test monitoring system with mock alerts
Phase 4: Testing & Validation (Weeks 9-10)
Week 9: Screening Program Testing
- Deliverable: Testing report with validation results
- Owner: HR + Internal Audit + CISO
- Activities:
- Test screening workflow end-to-end (candidate to hire)
- Test adverse action procedure (mock adverse finding)
- Test re-screening workflow (mock role change)
- Test continuous monitoring alerts (mock alert)
- Test vendor screening compliance (audit vendor records)
- Test screening records security (access, encryption, retention)
- Test candidate consent and DPDP compliance
Week 10: Compliance Validation
- Deliverable: Compliance validation report
- Owner: Legal + Compliance Manager + HR
- Activities:
- Validate screening policy against DPDP Act 2023
- Validate screening against labour law requirements
- Validate consent forms for legal compliance
- Verify screening vendor compliance with contract
- Validate screening data protection (encryption, access, retention)
- Test adverse action fairness and appeal process
- Prepare compliance evidence package
Phase 5: Documentation & Certification Prep (Weeks 11-12)
Week 11: Documentation
- Deliverable: Complete screening program documentation
- Owner: HR + Compliance Manager
- Activities:
- Document all screening policies and procedures
- Create screening training materials for recruiters and managers
- Create candidate FAQ on screening
- Create screening metrics dashboard
- Create evidence repository for audits
- Document vendor management procedures
Week 12: Certification Readiness
- Deliverable: Audit-ready evidence package
- Owner: CISO + Compliance Manager
- Activities:
- Conduct internal audit of screening program
- Prepare evidence for external ISO 27001 auditor
- Remediate any gaps found
- Conduct management review
- Present program to certification body
Detailed Implementation Guidance
Figure · Tiers
Maturity levels for screening

Step-by-Step Implementation
Step 1: Establish Screening Governance
- Create Screening Committee (HR Head, CISO, Legal, Head of Recruitment)
- Define screening budget allocation
- Establish screening policy approval process
- Define screening dispute resolution (candidate appeals)
- Create screening metrics and reporting to management
Step 2: Define Screening Tiers
| Tier | Role Examples | Screening Components | Re-Screening |
|---|---|---|---|
| Tier 1: Critical | CISO, CIO, DB Admin, System Admin, Security Engineer, DevOps Lead, CFO, Access to Restricted data | Identity, Education, Employment (5 years), Criminal, Police Verification, Credit, Sanctions, Reference (3), Social Media, Continuous Monitoring | Annual |
| Tier 2: High | Developer, QA, Network Admin, IT Support, HR, Finance, Access to Confidential data | Identity, Education, Employment (3 years), Criminal, Police Verification, Reference (2), Sanctions | Bi-annual |
| Tier 3: Medium | Marketing, Sales, Operations, Customer Support, Access to Internal data | Identity, Education, Employment (2 years), Criminal, Reference (1) | Every 3 years |
| Tier 4: Low | Reception, Facilities, General Admin, Access to Public data | Identity, Reference (1) | Every 5 years |
| Contractors | Same as equivalent employee tier | Same as equivalent tier | Same as equivalent tier |
| Vendors (Critical Access) | ODC staff, outsourced support with system access | Same as Tier 2 or 3 | Per contract |
Step 3: Implement Identity Verification
- Verify government ID: Aadhaar (e-Aadhaar QR scan), PAN, Passport, Voter ID, Driving License
- Verify photo ID match with candidate
- Verify address through utility bill, bank statement, or physical verification
- Use liveness detection for remote verification (prevent deepfake/photo substitution)
- Cross-check ID numbers with government databases where permitted
Step 4: Implement Education Verification
- Verify highest degree and relevant certifications
- Contact university/college registrar directly or through vendor
- Verify through digital platforms (NAAC, UGC, AICTE databases)
- Check for fake universities (UGC blacklist)
- Verify professional certifications (certified, CISA, ISO Lead Auditor, etc.)
- For international degrees, verify through WES or equivalent
Step 5: Implement Employment Verification
- Verify last 2-5 employers (based on tier)
- Confirm: employment dates, designation, reason for leaving, eligibility for rehire
- Verify gaps in employment (candidate explanation, reference check)
- Verify self-employment or freelance work (client references, tax records)
- Use automated employment verification where available (The Work Number, etc.)
- For international employment, verify through local contacts or vendors
Step 6: Implement Criminal and Police Verification
- Police verification: Submit Form to local police station or online (state-specific portals)
- Criminal record check: Search court records, CCTNS (Crime and Criminal Tracking Network System)
- For Tier 1: Conduct address-based police verification (current + permanent address)
- For international candidates: Conduct criminal check in home country
- Note: DPDP Act 2023 and labour law restrictions on criminal record use in employment
- Ensure adverse action considers nature of offence, time elapsed, and role relevance
Step 7: Implement Reference Checks
- Contact professional references provided by candidate
- Ask structured questions: working relationship, reliability, integrity, security awareness, reason for leaving
- For Tier 1: Contact 3 references including at least 1 supervisor
- For sensitive roles: Contact unlisted references (backdoor references) if legally permitted
- Document all reference check conversations
- Verify reference identity (not fake references)
Step 8: Implement Credit and Financial Checks
- Conduct for roles with financial responsibility (finance, CFO, procurement, treasury)
- Check CIBIL score and credit history
- Look for patterns of financial distress (potential fraud risk factor)
- Ensure compliance with RBI and DPDP requirements for credit data access
- Candidate consent mandatory for credit checks
Step 9: Implement Sanctions and Watchlist Screening
- Screen against: UN sanctions, OFAC (US), EU sanctions, Indian government sanctions lists
- Screen against: terror watchlists, PEP (Politically Exposed Persons) lists
- For Tier 1 and financial roles: Mandatory sanctions screening
- Use automated screening tools for real-time updates
- Document screening results and any matches
Step 10: Implement Social Media and Online Screening
- Review public social media profiles (LinkedIn, Twitter/X, Facebook, Instagram)
- Look for: hate speech, violence, drug use, criminal activity, security violations, confidential information leaks
- Ensure screening is limited to public information
- Do not request social media passwords (illegal in many jurisdictions)
- Document findings and decision rationale
- Be aware of potential bias and discrimination risks
Step 11: Implement Drug and Substance Testing
- Only where legally permitted and role-relevant (safety-critical roles, financial roles)
- Common in manufacturing, transportation, aviation, some BFSI roles
- Must be with explicit consent and under medical supervision
- Follow MHA (Ministry of Home Affairs) and state-specific guidelines
- Ensure compliance with DPDP Act 2023 for health data processing
Step 12: Implement Continuous Monitoring
- Monitor for: new criminal records, sanctions listings, adverse media, regulatory actions
- For Tier 1: Real-time or daily monitoring
- For Tier 2: Monthly monitoring
- For Tier 3-4: Quarterly monitoring or event-based
- Create alert workflow: Alert → Security review → HR review → Decision → Action
- Ensure employee privacy rights are respected (DPDP compliance)
Step 13: Implement Re-Screening
- Annual re-screening for Tier 1 (criminal, sanctions, continuous monitoring)
- Bi-annual re-screening for Tier 2
- Trigger-based re-screening: role change, access escalation, security incident, whistleblower report, suspicious behavior
- Re-screening upon promotion to higher tier
- Re-screening after extended leave (maternity, sabbatical, medical leave >6 months)
Step 14: Implement Adverse Action Procedure
- If screening reveals adverse information:
- Review report for accuracy
- Consult Legal on employment law implications
- Give candidate/employee opportunity to explain
- Consider nature of issue, time elapsed, role relevance, candidate explanation
- Make decision: proceed, conditional offer, withdraw offer, terminate, or remediate
- Document decision rationale
- Communicate decision to candidate/employee
- Provide appeal mechanism
- Maintain confidentiality of screening results
- For DPDP compliance: Adverse action based on personal data must be documented and fair
Step 15: Implement Screening Records Management
- Store screening records securely (encrypted, access-controlled)
- Retain screening records for: 7 years or duration of employment + 7 years (whichever is longer)
- Maintain screening records separately from personnel files (confidential)
- Limit access to HR, Legal, and CISO (need-to-know)
- Secure disposal after retention period (cryptographic erasure)
- Ensure DPDP compliance for screening data (personal data)
Tools, Technologies, and Solutions
Complete Tool Comparison
| Tool/Vendor | Category | Best For | licensing Range | Key Features | Coverage |
|---|---|---|---|---|---|
| AuthBridge | BGV | Indian market leader | -3,000/candidate | Identity, education, employment, criminal, police verification, address, credit | India-focused |
| First Advantage | BGV | Global + India | -5,000/candidate | Global checks, criminal, credit, sanctions, drug testing, continuous monitoring | Global |
| Sterling | BGV | Global enterprise | -5,000/candidate | Global checks, criminal, credit, sanctions, identity, employment, education | Global |
| HireRight | BGV | Global enterprise | -5,000/candidate | Global checks, criminal, credit, sanctions, drug testing, continuous monitoring | Global |
| IDfy | BGV | Indian tech-focused | -2,500/candidate | Identity, education, employment, criminal, police verification, API-first | India-focused |
| Verifitech | BGV | Indian growing companies | -2,000/candidate | Identity, education, employment, criminal, address verification | India-focused |
| Onfido | Identity | Remote identity verification | -500/check | AI-powered ID verification, biometric matching, document verification | Global |
| Jumio | Identity | Digital identity verification | -600/check | ID verification, liveness detection, document verification | Global |
| Trulioo | Identity | Global identity verification | -800/check | Global identity verification, 400+ data sources, 195 countries | Global |
| ComplyCube | Identity | AML + KYC + Identity | -700/check | ID verification, AML screening, sanctions, PEP | Global |
| RefCheck | Reference | Automated reference checks | -500/check | Automated reference collection, structured questions, analytics | Global |
| Xref | Reference | Digital reference checking | -600/check | Online reference platform, fraud detection, analytics | Global |
| Oracle The Work Number | Employment | US employment verification | Per-use | Automated employment verification from payroll database | US-focused |
| CIBIL | Credit | Indian credit reports | /report | CIBIL score, credit history, loan details | India |
| Experian India | Credit | Indian credit reports | /report | Credit score, credit history, risk assessment | India |
| Clear (formerly ClearTax) | Compliance | Indian compliance checks | -500/check | GST verification, PAN verification, company verification | India |
| Social | Professional background | Free/Premium | Employment history, professional network, recommendations | Global | |
| Dow Jones Risk & Compliance | Sanctions | Sanctions and PEP screening | + per year | Sanctions, PEP, adverse media, watchlists | Global |
| Refinitiv World-Check | Sanctions | Sanctions and PEP screening | + per year | Sanctions, PEP, adverse media, risk intelligence | Global |
| ComplyAdvantage | Sanctions | AI-driven sanctions screening | + per year | Sanctions, PEP, adverse media, real-time monitoring | Global |
| HRIS Integration | Automation | Workday, SAP, Oracle | Varies | Automated screening triggers, results integration, workflow | Enterprise |
| ATS Integration | Automation | Greenhouse, Lever, iCIMS | Varies | Screening trigger at offer stage, status tracking, results in ATS | Growing companies+ |
Recommendations by Organization Size
| Size | Primary Vendor | Identity | Continuous Monitoring | Integration |
|---|---|---|---|---|
| Startup (<50) | AuthBridge or IDfy | Onfido or Jumio | Manual | Basic HRIS |
| SMB (50-500) | AuthBridge or First Advantage | Onfido or Jumio | Quarterly alerts | ATS + HRIS |
| Mid-market (500-5000) | First Advantage or Sterling | Trulioo or Onfido | Monthly alerts | Full HRIS + ATS + IAM |
| Enterprise (5000+) | Sterling + First Advantage + Dow Jones | Trulioo + Jumio | Real-time monitoring | Full HRIS + ATS + IAM + GRC |
Policy and Procedure Templates
Employee Screening Policy (Key Sections)
Template
Employee Screening Policy
1. Purpose
To ensure all personnel with access to [Organization] information and systems are properly screened to verify their identity, qualifications, and suitability.
2. Scope
This policy applies to all candidates for employment, current employees, contractors, temporary staff, and vendor personnel with access to [Organization] information or systems.
3. Policy Statements
3.1 Screening Tiers
All roles are classified into screening tiers based on information access:
- Tier 1 (Critical): Access to Restricted information. Full screening + continuous monitoring.
- Tier 2 (High): Access to Confidential information. Full screening + periodic re-screening.
- Tier 3 (Medium): Access to Internal information. Standard screening.
- Tier 4 (Low): Access to Public information. Basic screening.
3.2 Pre-Employment Screening
All candidates must complete screening before employment commences:
- Identity verification (government ID, address)
- Education verification (highest degree and relevant certifications)
- Employment verification (last 2-5 employers depending on tier)
- Criminal and police verification (for Tier 1 and 2)
- Reference checks (1-3 depending on tier)
- Additional checks for specific roles: credit, sanctions, social media, drug testing
3.3 In-Employment Re-Screening
- Tier 1: Annual re-screening
- Tier 2: Bi-annual re-screening
- Tier 3: Every 3 years
- Tier 4: Every 5 years
- Re-screening is also triggered by: role change, access escalation, security incident, whistleblower report, suspicious behavior, extended leave >6 months
3.4 Contractor and Vendor Screening
- Contractors: Same screening as equivalent employee tier
- Vendors: Screening attestation required; direct screening for critical access
- Vendor contracts must include screening requirements
- Vendor personnel access is contingent on screening completion
3.5 Continuous Monitoring
- Tier 1 roles are subject to continuous monitoring for criminal records, sanctions, and adverse media
- Monitoring alerts are reviewed by Security and HR
- Appropriate action is taken based on alert severity
3.6 Consent and Privacy
- All candidates must provide informed consent for screening
- Screening data is handled in accordance with DPDP Act 2023
- Screening results are confidential and shared only on need-to-know basis
- Candidates have the right to review their screening results and dispute inaccuracies
3.7 Adverse Action
- If screening reveals adverse information, the organization will:
- Review the report for accuracy
- Give the candidate/employee opportunity to explain
- Consider the nature of the issue, time elapsed, and role relevance
- Make a fair and documented decision
- Provide an appeal mechanism
- Adverse action decisions are documented and reviewed by HR and Legal
3.8 Roles and Responsibilities
- HR: Screening administration, vendor management, candidate communication, records management
- CISO: Defining screening requirements, security risk assessment, continuous monitoring, incident response
- Legal: Compliance, adverse action review, dispute resolution, DPDP compliance
- Hiring Manager: Role tier assignment, supporting screening decisions
- Candidates/Employees: Providing accurate information, consent, cooperation
3.9 Enforcement
Failure to comply with this policy may result in disciplinary action. Falsification of screening information is grounds for immediate termination.
4. Review
This policy is reviewed annually by HR and CISO.
Screening Procedure
Template
Procedure: Employee Screening
1. Objective
To define the step-by-step process for conducting background verification checks.
2. Procedure Steps
Step 1: Role Tier Assignment
- Hiring manager assigns role tier based on information access (with HR and CISO approval)
- Tier is documented in job requisition
- Screening requirements are auto-populated based on tier
Step 2: Candidate Consent
- Candidate receives screening explanation and consent form
- Consent includes: types of checks, data usage, retention period, DPDP rights
- Candidate signs consent before screening begins
- Consent is stored securely with audit trail
Step 3: Screening Initiation
- HR initiates screening through vendor portal upon receipt of consent
- Candidate provides required documents (ID, education certificates, employment details, references)
- Screening package is configured based on role tier
- Turnaround time is communicated to candidate and hiring manager
Step 4: Screening Execution
- Vendor conducts checks according to package
- Identity verification (1-2 days)
- Education verification (3-7 days)
- Employment verification (3-7 days)
- Criminal/police verification (7-15 days)
- Additional checks as required
- Vendor provides preliminary and final reports
Step 5: Results Review
- HR reviews screening report for completeness
- CISO reviews security-relevant findings (criminal, sanctions, adverse media)
- Legal reviews adverse action requirements
- Hiring manager reviews findings relevant to role
- For adverse findings, conduct additional review meeting
Step 6: Decision
- Clear: Proceed with offer/onboarding
- Minor Issue: Proceed with conditions (additional monitoring, restricted access, probation)
- Major Issue: Withdraw offer or terminate (with Legal review and adverse action procedure)
- Discrepancy: Request candidate explanation; verify with additional checks if needed
Step 7: Onboarding Integration
- Screening results are linked to employee record (confidential section)
- Access provisioning is based on screening clearance and role tier
- Security briefing is provided during onboarding
- NDA and security agreements are signed
Step 8: Re-Screening
- Re-screening is scheduled based on tier and triggers
- Employee is notified of re-screening requirement
- Re-screening follows same procedure as initial screening
- Results are reviewed and actioned
Step 9: Records Management
- Screening records are stored securely for 7 years or employment duration + 7 years
- Access is limited to HR, Legal, and CISO
- Records are securely disposed after retention period
- DPDP compliance is maintained for all screening data
Risk Assessment and Treatment
Key Risks Addressed by This Control
| Risk ID | Risk Description | Likelihood | Impact | Risk Level | Treatment |
|---|---|---|---|---|---|
| R-001 | Employee with criminal history causes security incident | Medium | Critical | High | Mitigate, Criminal screening, police verification, continuous monitoring |
| R-002 | Employee with fake credentials causes operational failure | Medium | High | Medium | Mitigate, Education verification, employment verification |
| R-003 | Employee with financial distress commits fraud | Medium | High | Medium | Mitigate, Credit checks for financial roles, continuous monitoring |
| R-004 | Sanctioned individual employed in sensitive role | Low | Critical | High | Mitigate, Sanctions screening, PEP screening |
| R-005 | Insider threat from employee with undisclosed history | Medium | Critical | High | Mitigate, Complete screening, reference checks, social media screening |
| R-006 | Contractor/vendor personnel with bad history | Medium | High | Medium | Mitigate, Vendor screening requirements, attestation, direct screening |
| R-007 | Screening data breach exposes candidate information | Low | High | Medium | Mitigate, Encryption, access controls, DPDP compliance, vendor security |
| R-008 | Discrimination or bias in screening process | Medium | Medium | Low | Mitigate, Structured procedures, training, legal review, adverse action fairness |
| R-009 | Re-screening not conducted, new risks missed | Medium | High | Medium | Mitigate, Automated re-screening triggers, calendar reminders, HRIS integration |
| R-010 | Screening vendor provides inaccurate results | Low | High | Medium | Mitigate, Vendor SLA, quality checks, dispute resolution, multiple vendors |
Audit and Compliance Checklist
Audit Questions (25 Questions)
| # | Audit Question | Expected Evidence | Red Flags |
|---|---|---|---|
| 1 | Is there a screening policy? | Approved policy | No screening policy |
| 2 | Are all roles assigned a screening tier? | Role-tier mapping document | No tier assignment, all roles treated same |
| 3 | Are candidates screened before employment? | Screening records for recent hires | No screening, screening after start date |
| 4 | Is identity verified for all candidates? | Identity verification records | No ID verification |
| 5 | Is education verified? | Education verification reports | No education verification, fake credentials undetected |
| 6 | Is employment history verified? | Employment verification reports | No employment verification, gaps unexplained |
| 7 | Is criminal/police verification conducted? | Police verification reports | No criminal check for sensitive roles |
| 8 | Are reference checks conducted? | Reference check records | No reference checks |
| 9 | Is candidate consent obtained? | Consent forms | No consent, consent not DPDP-compliant |
| 10 | Are contractors screened? | Contractor screening records | Contractors not screened |
| 11 | Are vendor personnel screened? | Vendor screening attestations | Vendor personnel with unverified backgrounds |
| 12 | Is re-screening conducted? | Re-screening schedule and records | No re-screening, never re-screened |
| 13 | Is continuous monitoring implemented? | Monitoring alerts, records | No continuous monitoring for sensitive roles |
| 14 | Are screening results confidential? | Access controls on screening records | Open access to screening records |
| 15 | Is there an adverse action procedure? | Adverse action procedure, documented cases | No procedure, arbitrary rejections |
| 16 | Are screening vendors assessed? | Vendor security assessment | No vendor assessment, unknown vendor quality |
| 17 | Is screening data protected? | Encryption, access controls, DPDP compliance | Screening data stored insecurely |
| 18 | Is screening integrated with hiring workflow? | ATS/HRIS screening triggers | Manual, disconnected screening process |
| 19 | Are screening records retained? | Retention records, disposal logs | No retention, no disposal records |
| 20 | Are screening overhead tracked? | Budget records | No budget, uncontrolled spending |
| 21 | Is screening quality monitored? | Accuracy reports, dispute records | No quality monitoring |
| 22 | Are screening results used for access decisions? | Access provisioning records | Screening not linked to access |
| 23 | Are employees trained on screening? | Training records | No training for recruiters or managers |
| 24 | Is screening reviewed for legal compliance? | Legal review records | No legal review, potential discrimination |
| 25 | Is the screening program reviewed? | Management review minutes | No review, no improvement |
Metrics and KPIs
Figure · Measures
The measures that show A.6.1 is working
- Screening Coverage100%Monthly
- Screening Completion Rate>95%Monthly
- Screening Turnaround Time<10 daysMonthly
- Adverse Finding Rate<10%Monthly
- Re-Screening Compliance100%Quarterly
Key Metrics Dashboard
| KPI | Formula | Target | Frequency |
|---|---|---|---|
| Screening Coverage | (Screened candidates / Total candidates) × 100 | 100% | Monthly |
| Screening Completion Rate | (Completed screenings / Initiated screenings) × 100 | >95% | Monthly |
| Screening Turnaround Time | Average days from initiation to report | <10 days | Monthly |
| Adverse Finding Rate | (Adverse findings / Total screenings) × 100 | <10% | Monthly |
| Re-Screening Compliance | (Re-screened on time / Required re-screenings) × 100 | 100% | Quarterly |
| Contractor Screening Rate | (Screened contractors / Total contractors) × 100 | 100% | Quarterly |
| Vendor Screening Attestation Rate | (Vendors with screening attestation / Total vendors) × 100 | 100% | Quarterly |
| Continuous Monitoring Alert Count | Alerts generated by monitoring | Trending down | Monthly |
| Screening Data Breach Count | Breaches of screening data | 0 | Quarterly |
| Screening overhead per Hire | Total screening overhead / Number of hires | < | Monthly |
| Screening Vendor SLA Compliance | (Vendor SLA met / Total screenings) × 100 | >95% | Monthly |
| Screening Record Retention Compliance | (Records retained per policy / Total records) × 100 | 100% | Quarterly |
| Screening Dispute Resolution Time | Average days to resolve screening disputes | <7 days | Monthly |
| Screening Training Completion | (Trained recruiters / Total recruiters) × 100 | 100% | Annual |
| Screening Program Audit Score | Audit score (0-100) | >90 | Annual |
Common Pitfalls and How to Avoid Them
| # | Pitfall | Why It Happens | How to Avoid |
|---|---|---|---|
| 1 | No screening for contractors | Assumption that contractor vendor handles it | Require screening attestation or direct screening for all contractors |
| 2 | Screening after employee starts | Time pressure, urgent hire | Make offer conditional on screening; integrate screening into hiring timeline |
| 3 | Same screening for all roles | Simplicity, efficiency gains | Implement tiered screening based on information access risk |
| 4 | No re-screening | One-time mindset, overhead | Schedule re-screening, automate triggers, integrate with HRIS |
| 5 | Ignoring adverse findings | Bias toward candidate, urgent need | Establish structured adverse action procedure with Legal review |
| 6 | Screening data not protected | Assumption that vendor handles security | Encrypt screening data, limit access, DPDP compliance, vendor security assessment |
| 7 | No candidate consent | Assumption that application implies consent | Obtain explicit, informed, DPDP-compliant consent before screening |
| 8 | Over-reliance on one vendor | Contract convenience, volume discounts | Use primary + backup vendor; spot-check quality |
| 9 | No integration with access provisioning | Siloed HR and IT processes | Integrate screening clearance with IAM; no access without clearance |
| 10 | Discriminatory screening practices | Unconscious bias, lack of training | Structured procedures, training, legal review, diverse review committee |
| 11 | Ignoring international screening | Assumption that Indian checks are sufficient | Use global vendors for international candidates and roles |
| 12 | No screening for remote workers | Assumption that remote = lower risk | Remote workers often have more access; require same or enhanced screening |
Illustrative Scenarios
Illustrative scenario, a composite example for guidance, not a specific Singahi engagement or a verified outcome.
Illustrative Scenario 1: Indian Fintech Startup, Finova Payments
Company Profile:
- Size: 120 employees
- Industry: Fintech, Payment Gateway and Digital Lending
- Location: Bengaluru, India
- Customers: 800,000 users, 12,000 merchants
- Regulatory Scope: RBI, NPCI, DPDP Act 2023, PCI DSS
Challenge: Finova was growing rapidly but had minimal screening:
- No formal screening policy; only informal reference checks
- No police verification or criminal checks
- A developer hired without education verification was found to have fake engineering degree
- The developer had access to production payment database and stole over 6 months
- No re-screening of existing employees; a senior employee with access to UPI infrastructure had criminal fraud case pending (not discovered)
- Customer support staff (30 people) had no screening; one support agent sold customer data to competitor for
- RBI audit flagged lack of personnel screening as major concern
- NPCI threatened to suspend UPI integration
- Reputational damage: 15% customer churn in 2 months
Solution:
-
Week 1-2: Emergency Screening Implementation
- Engaged Singahi for emergency screening program design
- Conducted retrospective screening of all 120 employees
- Found 8 employees with adverse findings (fake credentials, criminal history, undisclosed employment gaps)
- Found 1 ongoing criminal case in senior employee
- Terminated 3 employees with serious adverse findings; placed 5 on probation with restricted access
- Implemented immediate access revocation for terminated employees
-
Week 3-4: Policy and Vendor
- Created 4-tier screening policy (Critical, High, Medium, Low)
- Selected AuthBridge as primary screening vendor
- Integrated screening with HRIS (BambooHR) and ATS (Greenhouse)
- Created candidate consent forms (DPDP-compliant)
- Established adverse action procedure with Legal review
-
Week 5-6: Full Screening Rollout
- Implemented screening for all new hires (100% coverage)
- Conducted police verification for all Tier 1 and Tier 2 roles
- Implemented education verification for all technical roles
- Created reference check procedure (minimum 2 references)
- Implemented sanctions screening for all financial roles
-
Week 7-8: Re-Screening and Monitoring
- Implemented annual re-screening for Tier 1 (20 employees)
- Implemented bi-annual re-screening for Tier 2 (45 employees)
- Deployed continuous monitoring for Tier 1 (criminal, sanctions)
- Created re-screening trigger: role change, incident, suspicious behavior
- Integrated screening clearance with IAM (no system access without clearance)
-
Week 9-12: Vendor and Contractor Screening
- Extended screening to all 15 contractors
- Required screening attestations from 8 vendor companies
- Conducted direct screening for 12 vendor personnel with system access
- Added screening clauses to all vendor contracts
- Created vendor personnel access approval workflow
Results:
- Security incidents: Zero insider incidents in 12 months post-implementation
- Fraud prevention: loss prevented through screening (detected 1 attempted fraud)
- RBI compliance: Passed audit with commendation for screening program
- NPCI: UPI integration maintained; no regulatory action
- Customer trust: Churn stabilized; won 2 enterprise customers citing security program
- Screening ROI: annual screening overhead vs. prevented fraud + regulatory savings
- Hiring quality: 12% of candidates had adverse findings; improved overall hire quality
- Process maturity: Screening became a competitive advantage in talent acquisition
Illustrative Scenario 2: Large Enterprise, Bharat Defence Systems (BDS)
Company Profile:
- Size: 8,500 employees, 3,200 with security clearance
- Industry: Defence Manufacturing and R&D
- Location: Hyderabad (HQ), with facilities in 6 cities
- Customers: Indian Armed Forces, DRDO, ISRO, international defence clients
- Regulatory Scope: DPDP Act 2023, Official Secrets Act 1923, Defence Procurement Procedure, ISO 27001, CMMI
- Security Clearance: Government security clearance required for 3,200 employees
Challenge: BDS had government-mandated security clearance but significant gaps in broader screening:
- Government security clearance was slow (6-12 months) and did not cover all personnel
- 5,300 employees without security clearance had no formal screening
- Contractors (2,800) had minimal screening beyond basic identity check
- International hires (180) from 12 countries had no standardized screening
- No continuous monitoring, 3 employees developed criminal issues after hire that were not detected
- Re-screening was only for security clearance renewal (every 5 years), not for role changes
- A contractor with access to classified facility was found to have ties to foreign intelligence (discovered by accident, not screening)
- No social media screening; employee posted classified information on LinkedIn
- No adverse action procedure; screening results were ignored if employee was "valuable"
- Background check vendor was not security-cleared; vendor had access to sensitive employee data
Solution:
-
Months 1-2: Complete Screening Program
- Established Security Screening Office (SSO) with 12 staff
- Created complete screening policy (government + corporate standards)
- Defined 5 tiers: Critical (security clearance + full screening), High, Medium, Low, Contractor
- Selected multiple vendors: AuthBridge (India), Sterling (International), Dow Jones (Sanctions)
- All vendors underwent security clearance and facility access review
- Implemented air-gapped screening data storage (no internet access for screening records)
-
Months 3-4: Full Workforce Screening
- Conducted retrospective screening of all 5,300 non-cleared employees
- Found 47 adverse findings (criminal history, fake credentials, undisclosed foreign ties)
- 12 employees required termination; 35 required remediation or role change
- Implemented full screening for all 2,800 contractors
- Found 23 contractors with adverse findings; 8 terminated, 15 restricted
- Implemented international screening for 180 foreign nationals
-
Months 5-6: Continuous Monitoring and Re-Screening
- Deployed continuous monitoring for all 8,500 employees (criminal, sanctions, adverse media)
- Implemented quarterly monitoring for Tier 1 and 2
- Implemented annual re-screening for all roles (supplementing 5-year security clearance renewal)
- Created re-screening triggers: role change, access escalation, foreign travel, financial distress indicators
- Implemented social media monitoring for Tier 1 (public posts only, privacy-compliant)
-
Months 7-9: Advanced Screening and Technology
- Implemented biometric identity verification (fingerprint + iris) for all facility access
- Deployed AI-driven risk scoring for screening results (pattern analysis, anomaly detection)
- Implemented psychological assessment for Tier 1 roles (critical for defence)
- Created insider threat program integrating screening with behavioral monitoring
- Implemented polygraph for select critical roles (where legally permitted)
- Created foreign influence screening for employees with foreign contacts
-
Months 10-12: Governance and Certification
- Established Screening Board (monthly review of adverse findings, appeals, policy changes)
- Created screening metrics dashboard for management and government liaison
- Passed government security audit with zero findings
- Achieved ISO 27001 certification with commendation for screening program
- Created screening best practice guide shared with defence industry consortium
Results:
- Security clearance: 100% of eligible employees cleared; zero clearance revocations in 18 months
- Insider threat: Zero insider incidents; 3 potential threats detected through continuous monitoring and prevented
- Foreign influence: 2 employees with undisclosed foreign ties identified and reassigned
- Social media: 1 classified information leak prevented through social media monitoring
- Contractor security: 8 high-risk contractors removed; no contractor-related incidents
- Government audit: Passed all audits with commendation; became industry reference
- International hiring: Standardized screening for 12 countries; reduced international hiring risk
- overhead: annual screening program vs. potential national security breach + regulatory sanctions
- Industry recognition: BDS screening program won Defence Industry Security Excellence Award
Multi-Framework Mapping
| ISO 27001:2022 A.6.1 | SOC 2 Trust Services Criteria | PCI DSS v4.0 | NIST 800-53 Rev 5 | CIS Controls v8 | COBIT 2019 | GDPR / DPDP Act 2023 |
|---|---|---|---|---|---|---|
| Screening | CC1.1: Management philosophy and operating style | 12.4.1: Security awareness program | PS-1: Personnel security policy and procedures | Control 6.1: Establish an inventory of assets | APO07.01: Manage people | DPDP S. 8: Reasonable security |
| CC1.2: Board of directors | 12.4.2: Security awareness content | PS-2: Position risk designation | Control 6.2: Address unauthorized assets | APO07.02: Manage competencies | DPDP S. 10: Consent | |
| CC1.3: Management oversight | 12.4.3: Security awareness program content | PS-3: Personnel screening | Control 6.3: Establish and maintain an inventory of personnel | APO07.03: Manage contracts | GDPR Art. 32: Security of processing | |
| CC1.4: Integrity and ethical values | 12.4.4: Security awareness training | PS-4: Personnel termination | Control 6.4: Establish and maintain an inventory of third-party personnel | APO07.04: Manage cultural diversity | GDPR Art. 5: Principles | |
| CC1.5: Accountability | 12.4.5: Security awareness program evaluation | PS-5: Personnel transfer | Control 6.5: Establish and maintain an inventory of service accounts | APO07.05: Manage performance | GDPR Art. 25: Data protection by design | |
| CC2.1: Communication and information | 12.8.1: Third-party security policies | PS-6: Access agreements | Control 6.6: Establish and maintain an inventory of privileged accounts | DSS05.02: Manage security | GDPR Art. 28: Processor requirements | |
| 12.8.2: Third-party security agreements | PS-7: External personnel security | Control 6.7: Establish and maintain an inventory of shared accounts | DSS05.03: Manage security services | GDPR Art. 32: Security of processing | ||
| 12.8.3: Third-party security assurance | PS-8: Personnel sanctions | Control 6.8: Establish and maintain an inventory of emergency accounts | DSS06.01: Manage business process controls | DPDP S. 11: Rights of data principal | ||
| PS-9: Position descriptions | Control 6.9: Establish and maintain an inventory of temporary accounts | DSS06.02: Manage business process controls | DPDP S. 13: Grievance redressal | |||
| Control 6.10: Establish and maintain an inventory of generic accounts | DSS06.03: Manage business process controls | DPDP S. 14: Nomination | ||||
| Control 6.11: Establish and maintain an inventory of dormant accounts | MEA01.02: Monitor and evaluate | DPDP S. 17: Children's data |
Regulatory and Industry Context
India Regulatory Framework
| Regulation | Screening Requirement | Penalty |
|---|---|---|
| DPDP Act 2023 | Section 8, reasonable security includes personnel screening | Up to |
| IT Act 2000 (Section 43A) | Reasonable security practices for sensitive data | Compensation claims |
| RBI Cyber Security Framework | Background verification for personnel accessing critical systems | License restrictions |
| SEBI Cybersecurity Circular | Background verification for trading system personnel | Trading restrictions |
| IRDAI Guidelines | Screening for insurance personnel handling customer data | License suspension |
| Companies Act 2013 | Director disqualification for certain criminal offences | Director disqualification |
| POSH Act 2013 | Pre-employment inquiry for sexual harassment history | Employer liability |
| Factories Act 1948 | Age verification for workers | fine; imprisonment |
| Contract Labour Act 1970 | Registration and verification of contract workers | Penalties |
| Private Security Agencies Act 2005 | Mandatory police verification for security personnel | License cancellation |
| Official Secrets Act 1923 | Security clearance for classified work | Imprisonment up to 14 years |
| Aadhaar Act 2016 | Background verification for Aadhaar operators | License cancellation |
International Regulations
| Regulation | Screening Requirement |
|---|---|
| GDPR (EU) | Article 32, security measures including personnel; Article 28, processor personnel |
| HIPAA (US) | §164.308(a)(3)(ii)(B)**, Workforce clearance procedure |
| SOX (US) | IT general controls including personnel access |
| FCRA (US) | Fair Credit Reporting Act governs background checks |
| BS 7858 (UK) | Security screening of individuals employed in security environment |
| HMG Baseline Personnel Security Standard (UK) | Government personnel screening |
Sector-Specific Requirements
| Sector | Screening-Specific Requirements |
|---|---|
| BFSI | RBI-mandated background verification; credit checks for financial roles; sanctions screening; integrity checks |
| Healthcare | Medical license verification; CDSCO requirements; clinical trial personnel screening; patient safety checks |
| Telecom | DOT security clearance; subscriber data access controls; SIM seller verification |
| Manufacturing | Safety-critical role screening; substance testing; industrial accident history |
| Government | Security clearance; police verification; CBI check for sensitive roles; Official Secrets Act compliance |
| Defence | Security clearance (secret/top secret); foreign influence screening; polygraph (select roles); family background |
| Aviation | DGCA-mandated background checks; substance testing; security training |
| Education | Teacher verification; police verification for school staff; child safety checks |
| SaaS / B2B | Vendor personnel screening; customer data access controls; SOC 2 personnel requirements |
| E-commerce | Delivery personnel verification; warehouse staff screening; payment handler checks |
Roles and Responsibilities (RACI)
| Activity | Accountable | Responsible | Consulted | Informed |
|---|---|---|---|---|
| Screening Policy | CISO | HR Head | Legal | Board |
| Role Tier Assignment | CISO | HR | Hiring Manager | Security |
| Candidate Consent | HR | Recruiter | Legal | Candidate |
| Screening Execution | HR | Screening Vendor | CISO | Hiring Manager |
| Results Review | CISO | HR | Legal | Hiring Manager |
| Adverse Action | Legal | HR | CISO | Candidate/Employee |
| Re-Screening | CISO | HR | Security | Employee |
| Continuous Monitoring | CISO | Security Team | HR | Management |
| Vendor Screening | CISO | Vendor Management | HR | Legal |
| Contractor Screening | HR | Contractor Manager | CISO | Security |
| Screening Records | HR | HR Admin | CISO | Legal |
| Screening Training | HR | Training Team | CISO | All Recruiters |
| Screening Metrics | CISO | HR Analyst | Compliance | Board |
| Screening Audit | Internal Audit | HR | CISO | Board |
| Screening Technology | CISO | IT | HR | Management |
| International Screening | CISO | HR | Legal | Management |
| Social Media Screening | CISO | Security Analyst | HR | Legal |
| Sanctions Screening | CISO | Compliance | Legal | Management |
Documentation and Evidence Requirements
Required Documents
| Document | Owner | Retention Period | Format |
|---|---|---|---|
| Screening Policy | CISO | 7 years | PDF + Word |
| Screening Procedure | HR | 7 years | PDF + Word |
| Role-Tier Mapping | CISO | 3 years | Spreadsheet |
| Candidate Consent Forms | HR | 7 years | Signed forms / digital |
| Screening Reports | HR | 7 years | Vendor reports |
| Adverse Action Records | Legal | 7 years | Case files |
| Re-Screening Schedule | HR | 3 years | Calendar / system |
| Re-Screening Results | HR | 7 years | Vendor reports |
| Continuous Monitoring Alerts | CISO | 3 years | Alert logs |
| Contractor Screening Records | HR | Duration of contract + 3 years | Vendor reports |
| Vendor Screening Attestations | Vendor Management | 3 years | Certificates |
| Screening Vendor Contracts | Procurement | 7 years | Contracts |
| Screening Vendor Assessment | CISO | 3 years | Assessment reports |
| Screening Training Records | HR | 5 years | LMS records |
| Screening Metrics | HR | 3 years | Dashboard / reports |
| Screening Audit Reports | Internal Audit | 5 years | |
| Screening Dispute Records | Legal | 7 years | Case files |
| International Screening Records | HR | 7 years | Vendor reports |
| Social Media Screening Records | CISO | 3 years | Screening logs |
| Sanctions Screening Records | CISO | 3 years | Screening logs |
Continuous Improvement
Maturity Model (Level 1-5)
| Level | Name | Description |
|---|---|---|
| 1 | Initial | Ad-hoc reference checks; no policy; no formal screening; no records |
| 2 | Managed | Basic screening for some roles; police verification for sensitive; informal records |
| 3 | Defined | Tiered screening program; formal policy; vendor screening; re-screening; continuous monitoring; DPDP compliance |
| 4 | Quantitatively Managed | Automated screening; integrated with HRIS/ATS; real-time monitoring; metrics-driven; international screening |
| 5 | Optimizing | AI-driven risk scoring; predictive insider threat detection; blockchain-verified credentials; behavioral analytics; continuous optimization; industry leadership |
Improvement Cycle
- Plan: Annual screening program review; quarterly metrics; technology trend assessment; regulatory change monitoring
- Do: Deploy new tools; update tiers; train staff; enhance vendor management; improve integration
- Check: Measure effectiveness; benchmark against industry; audit; gather feedback
- Act: Standardize; communicate; update procedures; report to management; industry sharing
Technology Trends
- AI Risk Scoring: AI analyzing screening data + behavior for risk prediction
- Blockchain Credentials: Verifiable, tamper-proof academic and professional credentials
- Real-Time Monitoring: Continuous criminal, sanctions, and social media monitoring
- Biometric Verification: Advanced liveness detection, facial recognition, behavioral biometrics
- Remote Verification: AI-powered remote identity verification (no in-person required)
- Psychometric Screening: Behavioral and psychological risk assessment for sensitive roles
- Global Screening Networks: Cross-border screening data sharing (with privacy safeguards)
- Automated Adverse Action: AI-assisted fair adverse action decisions with bias mitigation
FAQ
Frequently Asked Questions (20 Questions)
Q1: Is screening mandatory for all employees under ISO 27001? A: Yes, ISO 27001 A.6.1 requires screening for all candidates. The depth varies by role, but some form of screening (identity, reference, employment) is expected for all.
Q2: Can we reject a candidate based on a criminal record? A: It depends. Under Indian law, you must consider the nature of the offence, time elapsed, and role relevance. Some roles (defence, government, financial) have legal restrictions. For other roles, a fair assessment is required. Consult Legal.
Q3: Do we need police verification for all employees? A: Police verification is recommended for Tier 1 and Tier 2 roles (access to sensitive data). For Tier 3 and 4, it may not be necessary unless required by specific regulations (e.g., security agencies, factories).
Q4: How long does screening take in India? A: Identity: 1-2 days. Education: 3-7 days. Employment: 3-7 days. Police verification: 7-15 days. Full Tier 1 screening: 2-3 weeks. Use vendor SLAs to manage timelines.
Q5: Can we screen existing employees? A: Yes, but with consent and notice. Re-screening should be part of employment terms. For sensitive roles, re-screening is best practice. For existing employees without prior consent, obtain fresh consent before re-screening.
Q6: What is continuous monitoring? A: Continuous monitoring is ongoing screening after employment. It alerts you to new criminal records, sanctions listings, or adverse media. It's recommended for Tier 1 roles and financial roles.
Q7: Do we need to screen interns and trainees? A: Yes, if they have access to information or systems. Screening depth may be lighter (identity, education, basic reference) but should still be conducted.
Q8: What if a candidate refuses screening? A: You can withdraw the offer. Screening is a condition of employment. However, ensure your policy and offer letter clearly state that employment is contingent on successful screening.
Q9: How do we handle screening for remote workers? A: Remote workers often have the same or greater access. Use remote identity verification (Onfido, Jumio), video interviews, and digital document verification. Ensure address verification is thorough.
Q10: What is the difference between police verification and criminal record check? A: Police verification is conducted by local police and covers the candidate's address. Criminal record check searches court and database records for criminal history. Both are important but cover different aspects.
Q11: Do we need to screen board members and directors? A: Yes, especially for listed companies and regulated entities. Directors have significant access and influence. DIN (Director Identification Number) verification is mandatory under Companies Act 2013.
Q12: How do we protect screening data under DPDP? A: Screening data is personal data. Obtain consent, limit access, encrypt, retain only as long as necessary, and dispose securely. Use DPDP-compliant consent forms.
Q13: Can we use social media for screening? A: Yes, but only public information. Do not request passwords or hack private accounts. Document what you review and ensure decisions are not discriminatory. Be aware of DPDP and labour law implications.
Q14: What is a backdoor reference check? A: Contacting references not provided by the candidate (e.g., former colleagues found through LinkedIn). This is common in Tier 1 roles but must be done discreetly and legally. Be transparent if required by law.
Q15: Do we need drug testing? A: Only for safety-critical roles (manufacturing, transportation, aviation) where legally permitted. Drug testing is not common in IT/services roles in India. Ensure legal compliance and explicit consent.
Q16: What is adverse action and how do we handle it? A: Adverse action is taking negative action (rejecting candidate, terminating employee) based on screening results. You must: verify accuracy, give opportunity to explain, document decision, provide appeal mechanism.
Q17: How do we screen international candidates? A: Use global screening vendors (Sterling, First Advantage). Verify international degrees through WES or equivalent. Conduct criminal checks in home country. Verify work permits and visa status.
Q18: What is the role of CISO in screening? A: CISO defines screening requirements based on information access risk, reviews security-relevant findings, approves access for screened personnel, and manages continuous monitoring.
Q19: Can we use AI for screening? A: AI can assist in risk scoring and pattern detection, but final decisions should involve human review. Be cautious of AI bias in screening decisions. Document AI use and ensure fairness.
Q20: What will an ISO 27001 auditor look for in A.6.1? A: The auditor will verify: (1) screening policy exists, (2) all roles have defined screening requirements, (3) candidates are screened before employment, (4) screening is commensurate with role, (5) contractors are screened, (6) re-screening is conducted, (7) records are maintained, (8) adverse action is handled fairly, and (9) compliance with legal requirements.
References and Further Reading
ISO Standards
- ISO 27001:2022, Information Security Management Systems
- ISO 27002:2022, Information Security Controls
- ISO 27036, Information Security for Supplier Relationships
- ISO 27701:2019, Privacy Information Management System
Indian Law
- DPDP Act 2023, Digital Personal Data Protection Act
- Information Technology Act 2000, Sections 43A, 66, 72
- Companies Act 2013, Director disqualification, DIN
- Factories Act 1948, Age verification, worker registration
- Contract Labour Act 1970, Contract worker registration
- Private Security Agencies Act 2005, Security personnel verification
- POSH Act 2013, Pre-employment sexual harassment inquiry
- Official Secrets Act 1923, Security clearance
- Aadhaar Act 2016, Aadhaar operator verification
International
- FCRA (US), Fair Credit Reporting Act
- GDPR (EU), Articles 5, 32, 28
- BS 7858 (UK), Security screening
- HMG Baseline Personnel Security Standard (UK), Government screening
- HIPAA (US), §164.308(a)(3)(ii)(B)**, Workforce clearance
Industry
- NASSCOM, IT industry personnel practices
- AuthBridge, Indian BGV research and reports
- Verizon DBIR, Data breach investigations report (insider threat data)
- ISACA, Screening and insider threat guidance
Screening for Specific Roles
Executive and Board-Level Screening
| Check Type | C-Suite | Board Members | CFO/Finance | CTO/Engineering | CHRO/HR |
|---|---|---|---|---|---|
| Identity verification | Mandatory | Mandatory | Mandatory | Mandatory | Mandatory |
| Address verification | Mandatory | Mandatory | Mandatory | Mandatory | Mandatory |
| Education verification | Mandatory | Mandatory | Mandatory | Mandatory | Mandatory |
| Employment history | 10 years | 10 years | 10 years | 10 years | 10 years |
| Criminal record check | Mandatory | Mandatory | Mandatory | Mandatory | Mandatory |
| Credit check | Mandatory | Mandatory | Mandatory | Optional | Optional |
| Directorship search | Mandatory | Mandatory | Mandatory | Optional | Optional |
| Media/social media screening | Mandatory | Mandatory | Mandatory | Mandatory | Mandatory |
| Conflict of interest check | Mandatory | Mandatory | Mandatory | Mandatory | Mandatory |
| Reference checks | 5 references | 5 references | 5 references | 3 references | 3 references |
| Psychometric assessment | Recommended | Recommended | Recommended | Optional | Recommended |
| Re-screening frequency | Annual | Annual | Annual | Biennial | Biennial |
IT and Engineering Roles
| Check Type | Developers | DevOps | Security Engineers | Database Admins | Network Engineers |
|---|---|---|---|---|---|
| Identity verification | Mandatory | Mandatory | Mandatory | Mandatory | Mandatory |
| Address verification | Mandatory | Mandatory | Mandatory | Mandatory | Mandatory |
| Education verification | Mandatory | Mandatory | Mandatory | Mandatory | Mandatory |
| Employment history | 5 years | 5 years | 7 years | 7 years | 7 years |
| Criminal record check | Mandatory | Mandatory | Mandatory | Mandatory | Mandatory |
| Credit check | Optional | Optional | Optional | Mandatory | Optional |
| Open source contribution review | Optional | Optional | Recommended | Optional | Optional |
| Reference checks | 2 references | 2 references | 3 references | 3 references | 3 references |
| Re-screening frequency | Biennial | Biennial | Annual | Annual | Biennial |
Vendor and Contractor Screening
| Check Type | Critical Vendors | Standard Vendors | Contractors | Temp Staff | Interns |
|---|---|---|---|---|---|
| Identity verification | Mandatory | Mandatory | Mandatory | Mandatory | Mandatory |
| Address verification | Mandatory | Mandatory | Mandatory | Mandatory | Optional |
| Criminal record check | Mandatory | Optional | Mandatory | Optional | Optional |
| Company verification | Mandatory | Mandatory | N/A | N/A | N/A |
| Financial health check | Mandatory | Optional | N/A | N/A | N/A |
| Reference checks | 3 references | 2 references | 2 references | 1 reference | 1 reference |
| Re-screening frequency | Annual | Biennial | Per contract | Per engagement | Per engagement |
Continuous Screening and Re-Screening
Why Continuous Screening Matters
Initial screening is a point-in-time check. Employees' circumstances change over time:
- Financial stress increases insider threat risk
- Criminal convictions after hiring
- Changes in personal circumstances (divorce, addiction, gambling)
- Changes in political or ideological affiliations
- New conflicts of interest
- Moonlighting or side businesses competing with employer
Continuous Screening Program
| Trigger | Action | Timeline | Owner |
|---|---|---|---|
| Role change to high-risk | Full re-screening including credit check | Within 30 days of role change | HR + Security |
| Promotion to management | Enhanced screening (references, media, directorship) | Before promotion effective | HR |
| Access to sensitive data | Security clearance review | Before access granted | CISO |
| Financial stress indicators | Confidential counseling, monitoring, support | As needed | HR + Manager |
| Criminal conviction | Immediate review, disciplinary action | Within 48 hours | HR + Legal + Security |
| Regulatory complaint | Review and potential re-screening | Within 30 days | Compliance + HR |
| Annual re-screening | Basic checks (criminal, address, employment) | Annual anniversary | HR |
| Vendor contract renewal | Re-screening before renewal | 60 days before renewal | Vendor Management |
| Post-incident | Enhanced screening for affected team | Within 30 days of incident | HR + Security |
| M&A integration | Screening for acquired employees | Within 90 days of close | HR + Integration Team |
Re-Screening Policy Template
RE-SCREENING POLICY
1. ANNUAL RE-SCREENING
All employees undergo basic re-screening annually:
- Criminal record check (last 12 months)
- Address verification (if changed)
- Employment verification (if changed)
- Conflict of interest declaration
2. ROLE CHANGE RE-SCREENING
Employees moving to higher-risk roles undergo enhanced re-screening:
- Full background check as per new role requirements
- Credit check (if role requires)
- Enhanced reference checks
- Media/social media screening
3. TRIGGERED RE-SCREENING
Events triggering immediate re-screening:
- Criminal conviction (any level)
- Regulatory complaint or investigation
- Security incident involvement
- Financial irregularities
- Conflict of interest concerns
- Significant behavioral changes
4. VENDOR RE-SCREENING
Critical vendors screened annually:
- Company financial health
- Key personnel criminal checks
- Compliance certification validity
- Security incident history
5. DOCUMENTATION
All re-screening results documented in personnel file
Adverse findings reviewed by HR + Security + Legal
Decision matrix for adverse findings maintained
Appeals process documented
Additional Illustrative Scenarios: Indian Screening Incidents
Illustrative Scenario 3: Indian IT Company, Fake Degree Scandal (2022)
What happened: A mid-sized IT company in Hyderabad discovered that 12 employees (including 3 team leads) had submitted fake degrees during hiring. The fake degrees were from universities that did not exist. The issue was discovered when a client requested degree verification for an onsite deployment.
Impact:
- 12 employees terminated immediately
- Client contract cancelled ( annual revenue lost)
- Reputational damage in client market
- Legal action from clients for misrepresentation
- Remediation overhead: (re-hiring, re-training, legal)
- Company implemented mandatory degree verification for all hires
Root causes:
- No mandatory degree verification during hiring
- HR relied on self-attested copies without verification
- No third-party verification vendor engaged
- No audit of screening process
- Pressure to hire quickly led to skipped checks
Lessons:
- Mandatory degree verification for all roles (not just claimed degrees)
- Use third-party verification vendors (AuthBridge, First Advantage)
- Verify all educational credentials directly with institutions
- Include degree verification clause in offer letter (termination if false)
- Audit screening process annually
- Never skip verification due to hiring pressure
Illustrative Scenario 4: Indian Bank, Employee with Criminal Record (2023)
What happened: A bank employee in Mumbai was arrested for involvement in a loan fraud scheme. The employee had a prior criminal record for financial fraud that was not discovered during hiring because the bank only conducted local police verification (in the employee's hometown, not the city where the fraud occurred). The employee used their position to approve fraudulent loans totaling .
Impact:
- Loan fraud: in fraudulent loans approved
- RBI penalty: for inadequate employee screening
- Customer trust erosion
- Employee arrested, bank named in criminal investigation
- Remediation overhead: (investigation, legal, system changes)
- Bank implemented nationwide criminal verification
Root causes:
- Local-only police verification (not nationwide)
- No criminal record check in the city where fraud occurred
- No credit check for financial roles
- No reference checks with previous employers
- No ongoing monitoring for financial stress indicators
Lessons:
- Nationwide criminal verification (not just local police station)
- Credit check mandatory for all financial roles
- Enhanced reference checks for financial roles (direct supervisor, not just HR)
- Ongoing monitoring for financial stress indicators
- Segregation of duties for loan approval (no single person can approve)
- Regular re-screening for financial roles (annual)
- Implement fraud detection systems that flag unusual patterns