A.6.1A.6 People controls

Screening

A.5EVIDENCEA.6EVIDENCEA.7EVIDENCEA.8EVIDENCECONTROL MAPA.6.1 Evidence MapPOLICY / CONTROL / EVIDENCE / REVIEW

Purpose

Confirm that everyone hired is appropriate for their role and stays appropriate throughout their employment.

How to meet this control

In short: Perform background verification checks before people join and repeat them periodically, proportionate to role risk.

  1. Step 01Build a screening matrix that ties check depth to role risk, so a general staff member gets identity and reference checks while a sysadmin or finance role also gets a National Police Check and credit history
  2. Step 02Engage an accredited provider such as an ACIC-accredited agency for police checks, and use VEVO to confirm work rights for visa holders
  3. Step 03Capture written candidate consent before any check and store results separately from the general HR file under restricted access, in line with the Privacy Act and the Fair Work Act
  4. Step 04Add equivalent screening clauses to contracts with labour-hire firms, recruiters and outsourced providers so contractors meet the same bar as employees
  5. Step 05Hold a documented sign-off gate where the hiring manager confirms screening is complete and acceptable before access or a start date is granted
  6. Step 06Diarise re-screening for sensitive roles on a set cycle, for example every two to three years, and trigger an ad hoc check on promotion into a privileged role

Tip: Keep records of checks; align depth with role sensitivity and local law.

What ISO 27002 says to cover

Reference points from the ISO/IEC 27002:2022 guidance for this control. Use them to check the steps above cover everything relevant to you.

  • ›Screen all staff before they join, and put screening requirements into supplier contracts for outsourced staff
  • ›Collect and handle candidate information in line with privacy and employment laws of the relevant jurisdiction
  • ›Where allowed, check references, verify the CV, confirm qualifications and independently verify identity
  • ›Run deeper checks such as credit or criminal record reviews for candidates in critical or sensitive roles
  • ›For security-specific roles, confirm the person has the right competence and can be trusted
  • ›Set out clear procedures defining who can screen, plus when, how and why screening is done
  • ›If screening cannot finish in time, apply interim measures such as delayed onboarding or reduced access
  • ›Repeat screening checks periodically based on how critical the person's role is

Audit evidence to keep

  • - Completed background-check records for a sample of recent hires, including police and right-to-work verification
  • - The screening policy or matrix mapping check types to role categories
  • - Signed candidate consent forms authorising the checks
  • - Screening clauses within a labour-hire or recruitment-agency contract
  • - Hiring-manager sign-off records confirming screening cleared before start date

Common mistakes

  • - Writing a policy but not operating the process
  • - Keeping evidence in personal folders where auditors cannot trace it
  • - Letting exceptions stay open with no owner or expiry date

Owner, cadence, and proof

Assign one accountable owner for A.6.1. Review this control at least annually, after related incidents, and whenever the underlying process, supplier, system, office, or legal obligation changes. The control is audit-ready when the owner can show the policy or procedure, the latest operating evidence, the latest review, and any open exceptions with due dates.

Policy templates for this control

Use these starting documents to turn the control into evidence. Adapt each template to your scope, systems, legal obligations and actual operating process.

Open the control-to-policy map
Back to all people controls or see the requirements (clauses 4 to 10). To run this control with automation, read how AI manages controls.