Background checks: the clause the question tests
Whether people are screened before they reach the customer's data, and how far the checks go.
How the customer usually asks it
example"Are background checks performed on employees with access to customer data?"
Anchor clauses
4 frameworks| Framework | Anchor clause |
|---|---|
| ISO/IEC 27001:2022 | 6.1 Screening |
| SIG (Shared Assessments) | domain E Human Resources Security |
| CSA Cloud Controls Matrix v4.0.1 | HRS-01 Background Screening Policy and Procedures |
| NIST SP 800-53 Rev 5 | PS-3 Personnel screening |
Every framework that anchors this family is listed here; a register shows the ones ticked for the customer.
Evidence expected
The screening procedure scaled to role and data access, and the screening records for the people who will reach the customer's data.
The clauses, with what an assessor asks for
ISO 27001 6.1 ScreeningBackground-check candidates and personnel proportional to risk and classification, within the law.
Where answers usually fall short: One‑size‑fits‑all screening regardless of risk; Missing documentation of approvals for exceptions
Source: ISO/IEC 27001:2022
SIG domain E Human Resources SecurityWhat it asks for, in one line (the standard's own text is not quoted here):
Implement background screening, onboarding, training, awareness, sanctions, and termination procedures appropriate to data sensitivity and role risk.
Where answers usually fall short: Contractor screening not performed; Awareness training completion below threshold
Source: SIG (Shared Assessments)
CSA CCM HRS-01 Background Screening Policy and ProceduresWhat it asks for, in one line (the standard's own text is not quoted here):
Keep approved background verification procedures for all new employees, contractors and third parties, scaled to the data they will access, the business requirement and accepted risk, and consistent with local law. Review at least annually.
Where answers usually fall short: Contractors and third party staff excluded from screening; One screening depth applied regardless of data access
Source: CSA Cloud Controls Matrix v4.0.1
SP 800-53 PS-3 Personnel screeningRequires individuals to be screened before access to the system is authorized, and to be rescreened where organization-defined conditions require it and at the frequency defined for those conditions.
Where answers usually fall short: Access granted on the start date while screening is still in progress; Rescreening conditions never defined, so screening happens once in a career
Source: NIST SP 800-53 Rev 5