SOC 2 Control Implementation Guide

Workforce Security

Workforce Screening for SOC 2

Background or reference checks are completed where legally permitted and appropriate based on role, responsibility, and access level.

Use this guide to put the control into operation, decide what records to retain, and check that an auditor can trace the evidence back to the work your team performed.

Maintained by GreenHat Security · Reviewed August 21, 2026

What this control should accomplish

People receive the screening appropriate to their role, access, location, and employment relationship before sensitive access is granted, where screening is legally permitted. Results and exceptions are handled confidentially.

First SOC 2 program

A credible starting point

Define which employee and contractor roles need background or reference checks, confirm local legal constraints, and use a reputable screening provider or documented reference process. Keep only the completion status and decision needed by the business in broadly accessible HR records.

As the company scales

Make it repeatable

Drive screening rules from job and access profiles in the recruiting and HR systems. Automate status handoff to onboarding, restrict detailed reports to authorized HR or legal personnel, and reconcile new starters against completed or approved-exception results.

How to implement Workforce Screening

  1. 1

    Set role-based screening rules

    For each job family, contractor type, access level, and relevant location, document which checks are appropriate and where legal or HR review is needed.

    You should end up with: An approved screening matrix with role, check type, timing, and reviewer.

  2. 2

    Obtain required authorization

    Provide the applicable disclosure and collect authorization before initiating a check, following the process confirmed by qualified HR or legal advisers.

    You should end up with: A dated authorization record tied to the candidate or worker.

  3. 3

    Complete screening before access

    Track the screening to completion before granting the access covered by the rule, or document a specifically approved restricted-access exception.

    You should end up with: Provider completion status or reference-check record linked to onboarding.

  4. 4

    Review results confidentially

    Limit result review to authorized personnel, record the employment decision without exposing unnecessary report details, and follow applicable adverse-action procedures when relevant.

    You should end up with: A restricted review record showing reviewer, date, and disposition.

  5. 5

    Control and revisit exceptions

    Record why screening could not be completed, who accepted the risk, which access restrictions apply, and when the exception expires.

    You should end up with: A time-bound exception record with approval and compensating restrictions.

  6. 6

    Reconcile the population

    Compare employees and covered contractors who started during the period with screening completion and exception records.

    You should end up with: A dated reconciliation with discrepancies assigned and resolved.

Evidence to keep, and what it should prove

Build the evidence set in three layers: what defines the control, who approved or reviewed it, and what proves it operated. Collect operating records when the work happens so they remain dated, attributable, correctly scoped, and traceable to the underlying activity.

Before sharing, remove unrelated personal or customer data, never expose passwords, tokens, or secret values, preserve enough source context to authenticate the record, and use the secure exchange approved for the engagement.

Policy / design artifacts

Documents that define the control, its scope, ownership, and expected way of working.

role screening requirements

  • Confirm what the record proves

    Shows how job duties, access level, worker type, and location determine which screening is appropriate and legally permitted.

  • Include this context

    role or job family

  • Include this context

    worker type

  • Include this context

    location or jurisdiction

  • Include this context

    required check

  • Include this context

    timing requirement

  • Include this context

    approval owner

Weak evidence to avoid

A single statement that all workers receive a background check, with no role, contractor, location, or legal distinctions.

Approval / review evidence

Records showing that an accountable person reviewed, approved, challenged, or accepted the work.

Background/reference check records

  • Confirm what the record proves

    Shows that the check required for a specific worker and role reached a documented result before covered access began, without exposing unnecessary report detail.

  • Include this context

    candidate or worker identifier

  • Include this context

    check type

  • Include this context

    initiated date

  • Include this context

    completion date and status

  • Include this context

    authorized reviewer

Weak evidence to avoid

A provider invoice or portal screenshot showing a total number of checks but not which starters completed them or when.

exception records

  • Confirm what the record proves

    Shows that an incomplete, delayed, or inapplicable check was consciously evaluated and paired with approved, time-bound access restrictions or another response.

  • Include this context

    worker and role

  • Include this context

    reason for exception

  • Include this context

    risk and access restriction

  • Include this context

    approver

  • Include this context

    approval and expiry dates

  • Include this context

    final disposition

Weak evidence to avoid

A chat message saying the check is fine to complete later, with no approver, access boundary, or expiration.

Which records should you prepare for the audit?

Type 1

Evidence at the as-of date

The screening rules in force on the examination date, a current list of authorized result reviewers, and all open screening exceptions with their access restrictions and expiry dates.

Type 2

Evidence across the review period

Every employee and contractor start during the review period whose role and location met the screening rules, every role change that introduced a new screening requirement, and every screening exception opened, changed, or closed during the period.

Completeness check

Export all employee and contractor starts and relevant role changes from recruiting and HR systems, derive the required check from the approved rule set, and reconcile each person to provider completion or an approved exception before comparing the result with access activation time.

Build the record set from

  • applicant tracking system
  • HR information system
  • screening provider
  • onboarding and access ticket queue

Keep these fields for each record

  • worker identifier
  • worker type and location
  • role and access profile
  • start or role-change date
  • required check type
  • completion status and date
  • exception identifier
  • access activation date

How an auditor may test this control

Use this checklist to prepare for procedures an auditor may perform. The exact steps and sample selection depend on your engagement scope and the service auditor's professional judgment.

  • Confirm the intended control outcome

    Determine whether the control is designed to achieve this result: People receive the screening appropriate to their role, access, location, and employment relationship before sensitive access is granted, where screening is legally permitted. Results and exceptions are handled confidentially.

  • Confirm ownership and operating cadence

    Compare the documented owner with the intended role (HR Owner / IT / CISO), then compare dated records with the stated cadence: Upon hire/change/termination; annual as applicable.

  • Establish the complete audit record set

    Export all employee and contractor starts and relevant role changes from recruiting and HR systems, derive the required check from the approved rule set, and reconcile each person to provider completion or an approved exception before comparing the result with access activation time.

  • Prepare the as-of-date evidence for a Type 1 engagement

    The screening rules in force on the examination date, a current list of authorized result reviewers, and all open screening exceptions with their access restrictions and expiry dates.

  • Prepare period evidence for a Type 2 engagement

    Every employee and contractor start during the review period whose role and location met the screening rules, every role change that introduced a new screening requirement, and every screening exception opened, changed, or closed during the period.

  • Inspect the policy / design artifacts

    Documents that define the control, its scope, ownership, and expected way of working.

    • Inspect role screening requirements

      For each selected record, confirm it demonstrates Shows how job duties, access level, worker type, and location determine which screening is appropriate and legally permitted.

      • role or job family
      • worker type
      • location or jurisdiction
      • required check
      • timing requirement
      • approval owner
  • Inspect the approval / review evidence

    Records showing that an accountable person reviewed, approved, challenged, or accepted the work.

    • Inspect Background/reference check records

      For each selected record, confirm it demonstrates Shows that the check required for a specific worker and role reached a documented result before covered access began, without exposing unnecessary report detail.

      • candidate or worker identifier
      • check type
      • initiated date
      • completion date and status
      • authorized reviewer
    • Inspect exception records

      For each selected record, confirm it demonstrates Shows that an incomplete, delayed, or inapplicable check was consciously evaluated and paired with approved, time-bound access restrictions or another response.

      • worker and role
      • reason for exception
      • risk and access restriction
      • approver
      • approval and expiry dates
      • final disposition
  • Trace the control from design to operation

    Use the categories that apply to this control: connect any policy or design artifact to its approval or review record, then trace a selected operating record through execution, result, and any exception or remediation.

Common implementation and evidence gaps

  • The same screening is applied everywhere without considering local legal restrictions.
  • System access is active before screening is complete or an exception is approved.
  • Contractors with production or customer-data access are omitted from the process.
  • Detailed screening reports are stored where hiring managers or IT staff can browse them.
  • An exception has no expiration date, restricted-access plan, or accountable approver.

Before you call this control ready

  • For a sample of recent starters, was the required check complete before covered access began?
  • Are screening requirements documented for employees, contractors, and different locations?
  • Can only authorized HR or legal personnel access detailed results?
  • Does every incomplete check have a documented decision and time-bound restriction?
  • Does the latest reconciliation account for every person in the scoped starting population?

Trust Services Criteria references

These identifiers help you navigate related Trust Services Criteria. They do not reproduce the criteria or prove that this control fully addresses them in your environment.

  • CC1.4

Confirm final scope, mappings, and testing expectations with your service auditor. SOC 2® is an AICPA trademark; GreenHat Security is not affiliated with or endorsed by AICPA.