IndiciumIndicium
Log in
← Back to blog
Background checks for HR, Legal and Compliance

Turn public-source risk signals into audit-ready decisions.

Indicium helps regulated teams screen candidates, counterparties and sensitive hires — with dated sources, human review and reports your Legal team can defend.

For security-sensitive roles without a federal nexus, the Indicium report delivers FADP-compliant screening with dated sources and human final review.

Personnel Security Screening in Switzerland: PSP Under ISG and PSPV

Personnel security screening under ISG and PSPV: screening levels, consent — and why private employers without a federal nexus need their own screening.

The Personensicherheitsprüfung (PSP, personnel security screening) is the Swiss Confederation’s instrument for vetting persons with access to classified information or critical federal systems. Since 1 January 2024, it has been governed by the Informationssicherheitsgesetz (ISG, SR 128 — the Swiss Information Security Act) and the new ordinance on personnel security screening (PSPV, SR 128.31): there are two screening levels — the basic security screening and the extended security screening (Art. 30 ISG) —, the screening is conducted only with the consent of the person concerned (Art. 32 ISG), and it is carried out by the specialised PSP units within the DDPS (Swiss Federal Department of Defence, VBS). The decisive point for the private sector: the PSP is a federal instrument. Private employers without a federal nexus cannot obtain a PSP — and need their own, data-protection-compliant screening for security-sensitive roles.

With the entry into force of the ISG, personnel security screening was placed on a new statutory footing and the previous regulatory landscape was replaced. Art. 30 to 32 ISG define the screening levels, procedure and consent requirement; the PSPV specifies the procedure in detail. What is assessed is whether a person poses a risk to the information or physical security of the Confederation — for example before access to classified information, to protected IT resources or to security-sensitive areas.

Two Screening Levels Instead of Three

The ISG has simplified the system. Under Art. 30 ISG there are two levels:

  • Basic security screening: the standard level for functions with access to information classified as confidential or comparably sensitive areas.
  • Extended security screening: the in-depth level for functions with further-reaching access, for example to information classified as secret — with correspondingly broader data collection.

Which function is subject to which level follows from the function lists of the competent authorities; the depth of screening thus follows the sensitivity of the function, not the person.

The PSP is carried out by the specialised PSP units within the DDPS and mandatorily requires the consent of the person being screened (Art. 32 ISG) — no consent, no screening. The specialised unit collects the data provided for by law, assesses the risk and issues a formal ruling. For requesting bodies this means: the PSP is a formal administrative procedure with corresponding lead time, which must be factored into recruitment planning. How state security vetting and employer-side screening relate to each other in principle is set out — from a German perspective, but transferable in its logic — in the article State security clearance vs. employer screening.

Who Cannot Obtain a PSP — and What Applies Then

The PSP is available only for functions with a nexus to the Confederation: federal personnel, members of the armed forces, and employees of cantons and third parties insofar as they work on classified federal projects or federal IT resources. For suppliers this means a two-way split: those working on a classified federal project may fall within the scope of the PSP for the persons deployed there — for all other employees and engagements, this does not apply. A private company — the bank, the energy utility, the hospital, the technology supplier without a federal contract — cannot request a PSP for its own security-sensitive roles. This affects precisely the operators of critical infrastructure in Switzerland, whose control-room, grid and IT functions are highly sensitive yet lie outside federal classified-information protection. The integrity screening of these roles is therefore entirely the employer’s responsibility: structured, proportionate and transparent under the requirements of the revised Swiss Data Protection Act (revDSG/FADP, SR 235.1). The yardstick is relevance to suitability for the specific function — a screening depth tiered by position rather than blanket maximum research. What applies under employment and data protection law is explored in depth in the article Background checks in Switzerland.

First clarify whether your security-sensitive functions have a federal nexus — only then does the route lead through the specialised PSP units. For all other roles, define your own screening concept: classify functions by sensitivity, set the screening depth per tier, inform the persons concerned transparently and document every check. Indicium delivers audit-ready software reports for this, with dated sources and human final review (Art. 22 GDPR) — from €79 per report. We would be happy to show you what this looks like for your industry in a demo.

This article provides general information and does not constitute legal advice.

Ready to move from reading to doing?

See how a reviewable risk report is built — from name to verdict in minutes, not weeks.

Book a demo See a sample report