GASP AICF

Search controls and profiles

Search by control ID, name, domain or profile

HRS-002 Pre-Employment Background Screening

Tier 2+ProviderDeployerGPAI Model ProviderManaged Service Provider

Description

Background screening is completed for every candidate, contractor and third-party person before system access is granted, to a scope set by the sensitivity of the role and by applicable law. The screening standard names the checks performed per role band, and each record shows the checks completed before the start date. Identity proofing is performed for every person at registration: identity evidence is presented to the person or function that registers them, that evidence is validated and verified by a method the standard names, and a registration code or a notice of proofing is delivered through an out-of-band channel to the person's address of record.

Rationale

Access to sensitive systems requires confidence in the identity and integrity of the people granted it, and screening gives a documented, repeatable way to establish that before access is provisioned. Screening and proofing answer different questions: screening asks what is known about this person, proofing asks whether the person in front of you is that person. Remote hiring has made the second question the harder one, and an out-of-band confirmation to an independently held address is the cheapest check that an attacker impersonating a new joiner has to defeat.

Applicability (9 profiles)

SaaS AI Providerstablerequiredcore
Enterprise AI Deployerstablerequiredcore
GPAI Model Providerstablerequiredcore
High-Risk Provider (EU)stablerequiredcore
Public Body Deployer (EU)stablerequiredcore
DORA ICT Provider (EU)stablerequiredcore
HIPAA Business Associate (US)stablerequiredrole duty

164.308(a)(3)(ii)(B) makes a clearance determination before a grant an addressable specification, so a decision not to screen for a role that reaches the data is a written determination rather than a silent choice.

NIS2 Cloud Provider (EU)stablerequiredcore

Framework Mappings (16)

HRS-01Background Screening Policy and Proceduresfull
HRS-01Background Screening Policy and Proceduresfull
HIPAA-164.308.a.3.ii.BWorkforce Clearance Procedurefull
HIPAA-164.312.dPerson or Entity Authenticationinformative
6.1Screeningfull
NIS2-CIR-10.1Human Resources Securityinformative
NIS2-CIR-10.2Verification of Backgroundpartial
IA-12Identity Proofingpartial
IA-12(2)Identity Proofing | Identity Evidencefull
IA-12(3)Identity Proofing | Identity Evidence Validation and Verificationfull
IA-12(5)Identity Proofing | Address Confirmationfull
PS-2Position Risk Designationpartial
PS-3Personnel Screeningfull
PS-3(3)Personnel Screening | Information Requiring Special Protective Measuresfull
SA-21Developer Screeningfull
CC1.4COSO Principle 4: Demonstrates Commitment to Competencepartial

Evidence (3)

recorddocumentmanual

Background screening completion records for a representative sample of employees and contractors, confirming screening was completed before access was granted.

Example: Background check completion certificates or pass/fail records from a background screening provider (Checkr, Sterling, HireRight, or equivalent) for a sample of recent hires and privileged-access contractors, showing completion date preceding the access provisioning date.

Test: Request background screening records for a sample of at least five employees hired in the last 12 months and at least two contractors with privileged access. For each, verify: (1) a background check was completed, (2) the completion date is before the individual's first access provisioning date, (3) the scope of the check matches the role's risk classification.

policydocumentmanual

Background screening policy or procedure defining required screening elements per role risk level.

Example: Pre-Employment Screening Procedure (Confluence / HR policy), listing: role risk tiers, required screening elements per tier (e.g. identity, employment history, criminal record, right-to-work), process for screening contractors and third parties, and handling of adverse findings.

Test: Request the background screening procedure. Verify: (1) role risk tiers are defined, (2) required screening elements are specified per tier, (3) contractors and privileged-access third parties are explicitly included in scope, (4) a process for handling adverse or incomplete screening results is described, (5) the document is approved and dated within the last 12 months.

recorddocumentmanual

Identity proofing records for a sample of people registered during the period, showing the evidence presented, the validation method applied and the out-of-band confirmation sent.

Example: Onboarding proofing records, 12 joiners, Q2 2026

Test: Select a sample of people registered in the last 12 months, including at least two contractors. For each verify: (1) the record names the identity evidence presented and who received it, (2) the validation and verification method matches one the screening standard names, (3) an out-of-band confirmation was sent to an address of record held independently of the registration itself, with delivery recorded, (4) no access was provisioned before the proofing record was complete, (5) a proofing that failed or could not be completed resolves to a recorded decision rather than to silent provisioning.

Questions (3)

boolean

Does your organisation conduct background screening on all candidates before system access is granted, proportional to the sensitivity of the role?

Screening should be completed before access is provisioned. The scope of the check should match the role risk band the screening standard defines, covering identity, employment history and any criminal record check the band requires.

multi

Which of the following personnel categories are subject to pre-employment background screening in your organisation?

All permanent employeesContractors with access to production systemsThird-party personnel with privileged accessContractors with access to sensitive or personal data onlyNone of the above

ISO 27001 and most enterprise customer requirements expect screening for contractors and third parties with privileged access, not just direct employees.

multi

Which of the following does your screening and identity proofing record hold for each person, dated before their first system access?

The checks completed for the person's role bandThe identity evidence presented at registrationThe method used to validate and verify that evidenceAn out-of-band confirmation delivered to the person's address of recordNone of the above

Options run from the most commonly held to the least. Every element has to be dated before the individual's first system access, which is the part that most often fails under hiring pressure. Screening and proofing answer different questions: screening asks what is known about this person, proofing asks whether the person in front of you is that person.