Hey everyone, I'm currently reviewing approaches to ISO 27001 Annex A 6.1 screening and it’s interesting to see how differently organisations interpret the ongoing/periodic aspect of people screening. I’ve seen some organisations take a broad approach across all employees, while others seem to align it more closely to role sensitivity, access levels, or overall risk exposure. There also appears to be quite a bit of variation in how these expectations are documented internally, whether through contracts, onboarding processes, policies, or elsewhere. I would be interested to hear how others have approached this in practice, particularly what has worked well operationally and during audits.
Hey Ffion this is a good one, thanks for starting this discussion
From what I've heard, (it's been a mix, to your point), the all employees route usually applying to the initial screening at time of hire, and then high risk roles have periodic screening.
ultimately, ive seen two buckets: risk-based screening, and then role-based, (not sure how common role-based is). But I have more to learn in this specific realm, so I too would like to hear what others have seen out in the industry. curious how many of you are doing true role-based vs. risk-based and whether that distinction came up in audit.
ultimately if theres a clear policy, evidence to support, and rationale (of course with good framing), that would make for solid auditor acceptance ![]()
