Audit-ready personnel security — the A.6.1 evidence your auditor wants.
ISO/IEC 27001:2022 Annex A 6.1 requires background verification checks before anyone joins the organization and on an ongoing basis — and in Stage 2 audits, the auditor samples the screening records and access grants of recent hires. Indicium turns that control into dated, documented, reviewable evidence that slots straight into your ISMS.
The control exists on paper. The audit tests the records.
Your framework, our documentation.
Every report is built so its documentation slots directly into your ISMS evidence trail — under the 2022 numbering, where screening is control A.6.1.
| Framework | What it requires | How Indicium documents it |
|---|---|---|
| ISO/IEC 27001:2022 A.6.1 | Background verification before joining and on an ongoing basis, proportionate to the role | Role-based check depth, dated sources, documented decision, audit trail |
| ISO/IEC 27002:2022 | Implementation guidance: references, CV verification, qualifications, identity document | Each check category documented with its sources and dates in the report |
| Ongoing rescreening | Re-checks when the risk picture changes — role changes, promotions into privileged positions, moves into trust-critical functions | Trigger- and period-based rescreening documented per role level |
| Incomplete checks | Restrict access, delay onboarding or end employment — via a defined path | Defined path for incomplete verifications, documented in the process |
| BDSG §26 & AGG | Tight limits around applicant and employee data in Germany | Proportionality reasoning per check category; criminal-record and credit checks only where defensible |
| GDPR Art. 6(1)(f) | Lawful basis for pre-employment screening of candidates | Berechtigtes Interesse assessment documented in the report annex |
The honest boundary: Indicium does not decide how deep each check may go under BDSG §26 and the AGG — your written, role-based screening matrix does. It doubles as the proportionality decision the ISO auditor wants to see and the necessity argument the GDPR requires per check category. Indicium executes and documents the checks your matrix defines.
Records your auditor can sample — and your DPO can accept.
The biggest gap in certification projects is not the screening itself — it is the documentation. Indicium produces the paper trail that makes the A.6.1 sample uneventful: everything exists, everything is dated, everything traces back to a source.
From routine role screening to analyst-led escalation.
Does Indicium certify us against ISO 27001?+
Who counts as "all candidates to become personnel" under A.6.1?+
How deep must each check be?+
What does "on an ongoing basis" mean in practice?+
What evidence will the auditor ask for?+
What happens if screening evidence is incomplete?+
This page provides general information about Indicium's services and the frameworks named above (ISO/IEC 27001:2022, ISO/IEC 27002:2022, BDSG, AGG, GDPR). It does not constitute legal or regulatory advice and does not replace an assessment by your own counsel, your data protection officer, or your certification body for your specific case. Regulatory mapping reflects our understanding of the cited frameworks and does not guarantee a particular compliance outcome or certification decision.