Security Questionnaire Mapper
People and HR security · question family

Background checks: the clause the question tests

Whether people are screened before they reach the customer's data, and how far the checks go.

How the customer usually asks it

example

"Are background checks performed on employees with access to customer data?"

Read this question

Anchor clauses

4 frameworks
FrameworkAnchor clause
ISO/IEC 27001:20226.1 Screening
SIG (Shared Assessments)domain E Human Resources Security
CSA Cloud Controls Matrix v4.0.1HRS-01 Background Screening Policy and Procedures
NIST SP 800-53 Rev 5PS-3 Personnel screening

Every framework that anchors this family is listed here; a register shows the ones ticked for the customer.

Evidence expected

The screening procedure scaled to role and data access, and the screening records for the people who will reach the customer's data.

The clauses, with what an assessor asks for

ISO 27001 6.1 Screening

Background-check candidates and personnel proportional to risk and classification, within the law.

Evidence an assessor expects: Screening policy; Risk based screening procedures; Candidate check records; Employee screening logs; Third party screening reports
Where answers usually fall short: One‑size‑fits‑all screening regardless of risk; Missing documentation of approvals for exceptions
Source: ISO/IEC 27001:2022
SIG domain E Human Resources Security

What it asks for, in one line (the standard's own text is not quoted here):

Implement background screening, onboarding, training, awareness, sanctions, and termination procedures appropriate to data sensitivity and role risk.

Evidence an assessor expects: Background check policy and records; Annual security awareness training completion logs; Sanctions policy; Termination checklists and access removal records
Where answers usually fall short: Contractor screening not performed; Awareness training completion below threshold
Source: SIG (Shared Assessments)
CSA CCM HRS-01 Background Screening Policy and Procedures

What it asks for, in one line (the standard's own text is not quoted here):

Keep approved background verification procedures for all new employees, contractors and third parties, scaled to the data they will access, the business requirement and accepted risk, and consistent with local law. Review at least annually.

Evidence an assessor expects: The background screening procedure with the scaling criteria; Screening records for recent hires, contractors and third party staff; Evidence of legal constraints considered per jurisdiction; Annual review record
Where answers usually fall short: Contractors and third party staff excluded from screening; One screening depth applied regardless of data access
Source: CSA Cloud Controls Matrix v4.0.1
SP 800-53 PS-3 Personnel screening

Requires individuals to be screened before access to the system is authorized, and to be rescreened where organization-defined conditions require it and at the frequency defined for those conditions.

Evidence an assessor expects: Screening records showing completion before access authorization; Documented rescreening conditions and their frequencies; Rescreening completion records for the populations covered; Evidence of the treatment applied where screening cannot be completed
Where answers usually fall short: Access granted on the start date while screening is still in progress; Rescreening conditions never defined, so screening happens once in a career
Source: NIST SP 800-53 Rev 5

Other families in people and hr security