IndiciumIndicium
Log in
ISO 27001 Personnel security & ISMS evidence

Audit-ready personnel security — the A.6.1 evidence your auditor wants.

ISO/IEC 27001:2022 Annex A 6.1 requires background verification checks before anyone joins the organization and on an ongoing basis — and in Stage 2 audits, the auditor samples the screening records and access grants of recent hires. Indicium turns that control into dated, documented, reviewable evidence that slots straight into your ISMS.

ISO/IEC 27001:2022Annex A 6.1ISO/IEC 27002:2022BDSG §26AGGGDPR Art. 6(1)(f)
from €79 per report·120+ companies trust Indicium·3,000+ reports in the last two years·six-month satisfaction guarantee
See a sample report
01 Where certification projects actually get stuck

The control exists on paper. The audit tests the records.

a
A.6.1 obligations
Control A.6.1 requires background verification checks on all candidates to become personnel prior to joining the organization and on an ongoing basis — proportional to business requirements, the classification of the information to be accessed and the perceived risks. Which roles get which depth, and on which legal basis, is your documented call.
b
Auditors sample personnel evidence early
A documented Stage 2 example: 'Show me the most recent new hires, their screening records and their access grants.' Personnel records are fast to sample and telling about ISMS maturity — each one either exists, dated and traceable, or does not.
c
The cost of missing evidence
Classic findings: no documented screening process, an informal 'I know him, he is trustworthy' practice, or no records at all for people who joined before the ISMS existed. A major nonconformity blocks the certificate until a follow-up audit confirms the correction — weak evidence costs time exactly where it looks harmless.
02 Regulatory mapping

Your framework, our documentation.

Every report is built so its documentation slots directly into your ISMS evidence trail — under the 2022 numbering, where screening is control A.6.1.

FrameworkWhat it requiresHow Indicium documents it
ISO/IEC 27001:2022 A.6.1Background verification before joining and on an ongoing basis, proportionate to the roleRole-based check depth, dated sources, documented decision, audit trail
ISO/IEC 27002:2022Implementation guidance: references, CV verification, qualifications, identity documentEach check category documented with its sources and dates in the report
Ongoing rescreeningRe-checks when the risk picture changes — role changes, promotions into privileged positions, moves into trust-critical functionsTrigger- and period-based rescreening documented per role level
Incomplete checksRestrict access, delay onboarding or end employment — via a defined pathDefined path for incomplete verifications, documented in the process
BDSG §26 & AGGTight limits around applicant and employee data in GermanyProportionality reasoning per check category; criminal-record and credit checks only where defensible
GDPR Art. 6(1)(f)Lawful basis for pre-employment screening of candidatesBerechtigtes Interesse assessment documented in the report annex

The honest boundary: Indicium does not decide how deep each check may go under BDSG §26 and the AGG — your written, role-based screening matrix does. It doubles as the proportionality decision the ISO auditor wants to see and the necessity argument the GDPR requires per check category. Indicium executes and documents the checks your matrix defines.

03 Audit-readiness support

Records your auditor can sample — and your DPO can accept.

The biggest gap in certification projects is not the screening itself — it is the documentation. Indicium produces the paper trail that makes the A.6.1 sample uneventful: everything exists, everything is dated, everything traces back to a source.

a
Audit-ready records
A dated record of what was checked, against which sources, leading to a documented decision with defined retention — the properties auditors and data protection officers look for.
b
Role-based screening matrix
Check depth written down per role level before the audit: the proportionality decision the ISO auditor wants to see, and the necessity argument the GDPR requires for each check category.
c
Pre-employment vs. employee screening
Clear differentiation with distinct legal bases: verification of candidates before employment vs. screening of existing employees under BDSG §26. ISO 27001 sets the floor; German law sets the frame.
04 Matching depth to the role

From routine role screening to analyst-led escalation.

a
Software-Report
Seven check categories in parallel, from €79 — routine role screening, resolved in under 30 minutes for 80% of cases.
b
Hybrid
Software depth plus documented human review — for privileged positions and trust-critical roles with enhanced vetting requirements.
c
Boutique
Fully analyst-led investigation for high-stakes cases, multi-jurisdiction backgrounds, or board-level appointments where the screening record must withstand the closest look.
FAQ What your auditor and your DPO will ask
Does Indicium certify us against ISO 27001?+
No. Certification is granted exclusively by an accredited certification body. Indicium supplies the A.6.1 evidence layer: documented screening records for your key personnel that a Stage 2 auditor can sample — dated sources, a documented decision and defined retention, ready to file in your ISMS documentation.
Who counts as "all candidates to become personnel" under A.6.1?+
Deliberately more than the payroll list: employees, contractors, temporary and agency staff — anyone taken on into a role with access to in-scope information or systems. For external personnel, screening is fixed contractually with the provider, but the access decision and its evidence remain your organization's responsibility.
How deep must each check be?+
Deep enough for the role. Business requirements, the classification of the information the person will access and the perceived risks size the check, while applicable laws, regulations and ethics bound what may be checked at all. A written, role-based screening matrix makes that proportionality decision reviewable — which is exactly what the auditor wants to see.
What does "on an ongoing basis" mean in practice?+
The duty does not end with the hire. It resurfaces whenever the risk picture around a person changes — role changes, promotions into privileged positions, moves into finance-critical or trust-critical functions, or a changed risk context for the role. Trigger-based rescreening for privileged roles and periodic rescreening for finance-critical functions keep the records current.
What evidence will the auditor ask for?+
A typical Stage 2 request is the most recent new joiners together with their screening records and their access grants. Alongside that: a written screening procedure defining check depth per role level, contractor coverage through contracts, documented rescreening triggers and a defined path for incomplete checks. Weak evidence is a signed CV; strong evidence is a dated record of what was checked, against which sources, leading to a documented decision with defined retention.
What happens if screening evidence is incomplete?+
ISO/IEC 27002:2022 names the options: restrict access, delay onboarding or, in the extreme case, end the employment. Auditors look for a defined, documented path — not improvisation. A major nonconformity blocks the certificate until a follow-up audit confirms the correction, so gaps cost time exactly where they look harmless.

This page provides general information about Indicium's services and the frameworks named above (ISO/IEC 27001:2022, ISO/IEC 27002:2022, BDSG, AGG, GDPR). It does not constitute legal or regulatory advice and does not replace an assessment by your own counsel, your data protection officer, or your certification body for your specific case. Regulatory mapping reflects our understanding of the cited frameworks and does not guarantee a particular compliance outcome or certification decision.

Personnel security your ISO 27001 auditor can sample.

Software for the repeatable, people for the decisive, made in Europe.

Book a demo See a sample report