IndiciumIndicium
Log in
← Back to blog
Background checks for HR, Legal and Compliance

Turn public-source risk signals into audit-ready decisions.

Indicium helps regulated teams screen candidates, counterparties and sensitive hires — with dated sources, human review and reports your Legal team can defend.

The Indicium report documents verification of key personnel from dated public sources with a human final review, producing records an ISO 27001 auditor can sample.

ISO 27001 A.6 Personnel Security: Screening Before, During and After Employment

ISO 27001 A.6.1 screening: the exact control wording, who must be screened, ongoing rescreening, auditor evidence and the German limits of BDSG § 26 and AGG.

ISO/IEC 27001:2022 control A.6.1 (Screening) requires background verification checks on all candidates to become personnel, employees and contractors alike, before they join and on an ongoing basis, bounded by applicable laws, regulations and ethics and proportional to business requirements, the classification of the information to be accessed and the perceived risks. That translates into one operational rule: nobody receives access to in-scope systems before the check is completed, and the record joins the ISMS evidence trail.

Eight People controls across the employee lifecycle

Annex A holds 93 controls in four themes: Organizational (A.5), People (A.6), Physical (A.7) and Technological (A.8). Theme A.6 is the smallest of the four with exactly eight controls, and read in sequence they follow a career from first interview to final handover:

  • A.6.1 Screening: verification before someone joins, and again while they work
  • A.6.2 Terms and conditions of employment: security duties written into the contract
  • A.6.3 Awareness, training and education: security competence kept current
  • A.6.4 Disciplinary process: a formal path for information security policy violations
  • A.6.5 Responsibilities after termination or change of employment: access and duties wound down
  • A.6.6 Confidentiality or non-disclosure agreements: confidentiality fixed in writing
  • A.6.7 Remote working: rules for work outside secured premises
  • A.6.8 Information security event reporting: a duty to report that reaches every employee

Three controls sit before a person starts (6.1, 6.2, 6.6), three govern the employment (6.3, 6.7, 6.8), one the exit (6.5), one the enforcement path (6.4). Screening is therefore not an HR formality at the edge of the ISMS but the entry gate the remaining People controls depend on: an awareness programme reaches the wrong audience if the organization never verified who joined.

Control A.6.1: the exact wording in ISO/IEC 27001:2022

ISO/IEC 27001:2022, control A.6.1 Screening, reads:

Background verification checks on all candidates to become personnel shall be carried out prior to joining the organization and on an ongoing basis taking into consideration applicable laws, regulations and ethics and be proportional to the business requirements, the classification of the information to be accessed and the perceived risks.

One sentence, three obligations. First, the check happens before the person joins. Second, it does not end with the hire: the standard demands checks on an ongoing basis. Third, the depth is not dictated by the standard itself. Applicable laws, regulations and ethics set the outer boundary of what may be checked, while business requirements, the classification of the information the person will access and the perceived risks determine how deep each check must go.

A.6.1.1 or A.6.1: which numbering applies

Searches for ISO 27001 A.6.1.1 are common for a structural reason. The 2013 edition numbered controls with a third level and placed screening under theme A.7 as control A.7.1.1, and a large body of guides, internal policies and audit reports was written against that numbering. The 2022 revision reorganized Annex A into 93 controls in four themes, renumbering the People theme to A.6, where screening is simply A.6.1. No A.6.1.1 exists in the current edition. A policy, Statement of Applicability or audit report that cites A.6.1.1 is pointing at the older structure, while certification auditors work against the 2022 list. The subject of the control is unchanged: screen before joining, keep the check proportionate, document the result.

Who must be screened, and what does “on an ongoing basis” mean

“All candidates to become personnel” is deliberately broader than the payroll list. It covers employees, contractors, temporary staff and agency workers: anyone the organization takes on into a position with access to information or systems. It cannot defer to the staffing provider’s own processes: the ISMS must make sure screening happens before access is granted, fixed contractually and verified on the organization’s side.

“On an ongoing basis” ends the one-and-done reading of the control. The duty resurfaces whenever the risk picture around a person changes. Typical triggers are role changes, promotions into privileged positions, moves into finance-critical or trust-critical functions, and a changed risk context for the role. Regulated firms therefore run trigger-based rescreening for privileged roles and periodic rescreening for finance-critical functions instead of relying on the check performed on the day of hire.

Which checks does ISO/IEC 27002:2022 describe

ISO/IEC 27001 states the requirement; ISO/IEC 27002:2022 mirrors Annex A control by control and supplies the implementation guidance. For screening, the guidance names typical components: references, verification of the CV, confirmation of qualifications and verification of a government-issued identity document. For roles suited to enhanced vetting, it adds credit checks and criminal-record checks. Ownership typically sits with HR, and the guidance covers what to do when a verification comes back incomplete, up to restricting access or ending the employment.

What may you lawfully check in Germany

ISO 27001 sets a floor; German law sets the frame. Section 26 BDSG (Bundesdatenschutzgesetz) and the AGG (Allgemeines Gleichbehandlungsgesetz) draw tight limits around applicant and employee data. In practice: criminal-record (Führungszeugnis) requests are defensible for trust-critical roles and when proportionate, ideally announced in the job posting; credit checks require consent and a finance-relevant role; verification of identity, qualifications and employment history is the defensible baseline for almost every role. Because A.6.1 sizes each check to the role, a written, role-based screening matrix does double duty: it is the proportionality decision the ISO auditor wants to see, and it is the necessity argument the GDPR requires for each check category. We cover the legal basis per check category in pre-employment screening under the GDPR and the works council dimension in codetermination over background screening.

How auditors test screening, and what good evidence looks like

Auditors reach A.6.1 early in a Stage 2 audit because the records are quick to sample and telling about ISMS maturity. The documented pattern: a written screening procedure defining check depth per role level; evidence it is applied consistently, including long-tenured and privileged staff, not only new hires; a sample of recent hires with screening records and access grants; contractor coverage through contracts; documented rescreening triggers; a defined path for incomplete checks. A typical request is the most recent new joiners together with their access grants, linking each screening record to the access decision it should have gated.

Classic findings: no documented screening process, an informal “I know him, he is trustworthy” practice, or missing records for people who joined before the ISMS existed. Weak evidence is a signed CV. Strong evidence is a dated record of what was checked, against which sources, leading to a documented decision with defined retention.

This is also the seam where professional background verification becomes ISMS evidence rather than an HR chore. Structured, documented, reviewable verification of key personnel, built on registry data, sanctions and adverse media, employment and education history, and closed with a human final review, produces the records auditor and data protection officer look for: traceable sources, dates, a documented decision, retention that respects the BDSG. The Indicium report is built for this class of decision in regulated firms. For the audit context, see what ISO 27001 auditors ask for first; for where Annex A sits in the wider standard, the ISO 27001 overview for regulated firms.

Frequently asked questions

What does ISO 27001 A.6.1 require in screening?

Background verification checks on all candidates to become personnel before they join and on an ongoing basis. The depth must respect applicable laws, regulations and ethics and stay proportional to business requirements, information classification and perceived risks.

Does screening apply to freelancers, temporary agency staff and service providers?

Yes. “All candidates to become personnel” includes employees, contractors, temporary and agency staff. For external personnel it is typically secured contractually with the provider, but the access decision and its evidence remain the organization’s responsibility.

How deep must the screening be?

Deep enough to match the role. Business requirements, the classification of information the person will access and the perceived risks size the check, while applicable law bounds what may be checked at all. A written role-based screening matrix makes that decision reviewable.

What happens if screening evidence is incomplete?

ISO/IEC 27002:2022 names the options: restrict access, delay onboarding or, in the extreme case, end the employment. What auditors look for is a defined, documented path, not improvisation.

This article provides general information on ISO/IEC 27001 personnel controls and their German legal context; it does not constitute legal advice.

Ready to move from reading to doing?

See how a reviewable risk report is built – from name to verdict in minutes, not weeks.

Book a demo See a sample report