HRS-002 Pre-Employment Background Screening
Description
Background screening is completed for every candidate, contractor and third-party person before system access is granted, to a scope set by the sensitivity of the role and by applicable law. The screening standard names the checks performed per role band, and each record shows the checks completed before the start date. Identity proofing is performed for every person at registration: identity evidence is presented to the person or function that registers them, that evidence is validated and verified by a method the standard names, and a registration code or a notice of proofing is delivered through an out-of-band channel to the person's address of record.
Rationale
Access to sensitive systems requires confidence in the identity and integrity of the people granted it, and screening gives a documented, repeatable way to establish that before access is provisioned. Screening and proofing answer different questions: screening asks what is known about this person, proofing asks whether the person in front of you is that person. Remote hiring has made the second question the harder one, and an out-of-band confirmation to an independently held address is the cheapest check that an attacker impersonating a new joiner has to defeat.
Applicability (9 profiles)
164.308(a)(3)(ii)(B) makes a clearance determination before a grant an addressable specification, so a decision not to screen for a role that reaches the data is a written determination rather than a silent choice.
Framework Mappings (16)
| HRS-01 | Background Screening Policy and Procedures | full |
| HRS-01 | Background Screening Policy and Procedures | full |
| HIPAA-164.308.a.3.ii.B | Workforce Clearance Procedure | full |
| HIPAA-164.312.d | Person or Entity Authentication | informative |
| 6.1 | Screening | full |
| NIS2-CIR-10.1 | Human Resources Security | informative |
| NIS2-CIR-10.2 | Verification of Background | partial |
| IA-12 | Identity Proofing | partial |
| IA-12(2) | Identity Proofing | Identity Evidence | full |
| IA-12(3) | Identity Proofing | Identity Evidence Validation and Verification | full |
| IA-12(5) | Identity Proofing | Address Confirmation | full |
| PS-2 | Position Risk Designation | partial |
| PS-3 | Personnel Screening | full |
| PS-3(3) | Personnel Screening | Information Requiring Special Protective Measures | full |
| SA-21 | Developer Screening | full |
| CC1.4 | COSO Principle 4: Demonstrates Commitment to Competence | partial |
Evidence (3)
Background screening completion records for a representative sample of employees and contractors, confirming screening was completed before access was granted.
Example: Background check completion certificates or pass/fail records from a background screening provider (Checkr, Sterling, HireRight, or equivalent) for a sample of recent hires and privileged-access contractors, showing completion date preceding the access provisioning date.
Test: Request background screening records for a sample of at least five employees hired in the last 12 months and at least two contractors with privileged access. For each, verify: (1) a background check was completed, (2) the completion date is before the individual's first access provisioning date, (3) the scope of the check matches the role's risk classification.
Background screening policy or procedure defining required screening elements per role risk level.
Example: Pre-Employment Screening Procedure (Confluence / HR policy), listing: role risk tiers, required screening elements per tier (e.g. identity, employment history, criminal record, right-to-work), process for screening contractors and third parties, and handling of adverse findings.
Test: Request the background screening procedure. Verify: (1) role risk tiers are defined, (2) required screening elements are specified per tier, (3) contractors and privileged-access third parties are explicitly included in scope, (4) a process for handling adverse or incomplete screening results is described, (5) the document is approved and dated within the last 12 months.
Identity proofing records for a sample of people registered during the period, showing the evidence presented, the validation method applied and the out-of-band confirmation sent.
Example: Onboarding proofing records, 12 joiners, Q2 2026
Test: Select a sample of people registered in the last 12 months, including at least two contractors. For each verify: (1) the record names the identity evidence presented and who received it, (2) the validation and verification method matches one the screening standard names, (3) an out-of-band confirmation was sent to an address of record held independently of the registration itself, with delivery recorded, (4) no access was provisioned before the proofing record was complete, (5) a proofing that failed or could not be completed resolves to a recorded decision rather than to silent provisioning.
Questions (3)
Does your organisation conduct background screening on all candidates before system access is granted, proportional to the sensitivity of the role?
Screening should be completed before access is provisioned. The scope of the check should match the role risk band the screening standard defines, covering identity, employment history and any criminal record check the band requires.
Which of the following personnel categories are subject to pre-employment background screening in your organisation?
ISO 27001 and most enterprise customer requirements expect screening for contractors and third parties with privileged access, not just direct employees.
Which of the following does your screening and identity proofing record hold for each person, dated before their first system access?
Options run from the most commonly held to the least. Every element has to be dated before the individual's first system access, which is the part that most often fails under hiring pressure. Screening and proofing answer different questions: screening asks what is known about this person, proofing asks whether the person in front of you is that person.