Every major framework has a human resources security section, and it is consistently the least prepared area in an audit - not because it is difficult, but because it is owned by a function that was never told it holds security controls. HR runs the process; security is accountable for the outcome; nobody has had the conversation.
Before employment: screening
Frameworks expect background verification proportionate to the role and the sensitivity of the access it carries. Typically:
- Identity and right to work.
- Employment history and reference checks.
- Qualification verification where the role depends on it.
- Criminal record checks where lawful and proportionate - this varies substantially by jurisdiction, and "where permitted by local law" is a legitimate and expected qualification.
- Financial checks for roles with payment authority, in sectors where that is customary.
Two points organisations miss. Screening must be proportionate and documented as such - the same checks for a warehouse role and a database administrator suggest the policy was never thought through. And it must extend to contractors and temporary staff, who frequently receive equivalent access with no screening at all because they arrive through procurement rather than HR.
Where screening is performed by a staffing agency, get written confirmation of what was checked. "The agency does it" is not evidence, and it is the answer auditors hear most often.
Terms of employment
The contract is a control. It should carry:
- Confidentiality obligations that survive termination.
- Acceptable use and an obligation to follow security policies, referenced so they can be updated without reissuing contracts.
- Intellectual property assignment.
- Consequences of violation, linking explicitly to the disciplinary process.
- Return of assets and information on termination.
- Monitoring notice, where lawful - required in many jurisdictions before any workplace monitoring is permissible.
Evidence the controls other teams operate
GRC Copilot assigns controls to owners outside security, tracks completion, and files the evidence - so HR-owned requirements are covered without security chasing them by email.
Try GRC Copilot free Generate an AI-powered assessment Download checklist Book a demo
During employment
- Awareness training at induction, before or immediately on receiving access - not at the next quarterly session, which may be two months away.
- Policy acknowledgement, recorded with a date. This is the single most requested HR-security artefact in an audit, and the easiest to produce if the process captures it.
- Ongoing awareness with role-specific content: developers, finance and executives face materially different attacks.
- A disciplinary process that explicitly covers security violations. Frameworks require it to exist and be communicated - the point is deterrence, and an unpublicised process deters nobody.
- Role change notification to trigger access changes. The mover case fails because HR knows and IT does not.
Termination and change of employment
- HR triggers the process - this is the dependency that makes offboarding reliable. Informal notification means the control depends on someone remembering.
- Return of assets: laptops, phones, tokens, badges, documents, and anything held at home. Maintain a per-person asset list, or the return checklist is guesswork.
- Access revocation to the timeline in your policy, coordinated with the departure rather than after it.
- Exit briefing reminding the individual of obligations that continue - confidentiality above all. It is a genuine deterrent and it is documented evidence of notice.
- Involuntary departures handled differently: revoke first, or simultaneously with the conversation. This is the highest-risk scenario in the whole domain and it needs a pre-agreed protocol between HR, security and the line manager - decided in advance, not improvised on the day.
Making it work across the boundary
Security does not manage HR, so the controls succeed or fail on the working relationship. What helps:
- Name the HR control owner explicitly and put them in the control register like any other owner.
- Embed the requirements into HR's existing workflows rather than adding a parallel security checklist - checklists that live outside the tool people work in do not get completed.
- Explain the "why" once, properly. HR teams are generally receptive when the risk is explained and resistant when handed a compliance mandate.
- Agree in advance who produces the evidence at audit time, and confirm the format before fieldwork rather than during it.
Frequently asked questions
Is criminal record screening mandatory?
No - frameworks require screening proportionate to the role and permitted by applicable law. Document what you check, for which roles, and why.
Do contractors need the same screening?
They need screening proportionate to their access, which for many contractors equals or exceeds that of employees. Obtain written confirmation from the supplying agency.
What evidence will auditors ask for?
Screening records for sampled hires, signed contracts containing the required clauses, dated policy acknowledgements, training completion records, and offboarding checklists for sampled leavers.
What if HR will not cooperate?
Escalate it as a risk with the consequence stated - unowned controls fail at audit. It is a leadership issue, not one security can solve by persistence.
Key takeaways
- HR security controls are framework requirements owned outside security - name the owner.
- Screening must be proportionate, documented, and extended to contractors.
- Dated policy acknowledgements are the most-requested artefact in this domain.
- Agree the involuntary-departure protocol before you need it.