Home/Questions/Governance and workforce/Pre-employment screening
Governance and workforce

Are job applicants screened (credit, criminal records, drug testing) as permitted by law?

Screening addresses insider risk at the only point where it is cheap to address: before access is granted.

Attested, not tenant-verifiable

What the carrier is actually asking

The carrier is asking whether background checks are performed on new hires to the extent permitted by law, which varies considerably by jurisdiction. It is usually more concerned with roles holding privileged access or financial authority than with the whole workforce.

Why it is underwritten

Insider incidents are less frequent than external ones and more damaging per event, because the insider already has access and knows where things are. Screening is the control that operates before access exists, and carriers ask about it as part of the personnel security picture.

Where the answer lives in Microsoft 365, Entra ID, and Azure

Screening is a human resources process, so it is attested. The important part is that it is risk-based and legally compliant.

PlatformWhere the setting livesWhat has to be true
HR processScreening policy by role, with what is checkedIdentity, right to work, references, and where lawful and proportionate, criminal record checks. Attested
HR processEnhanced screening for privileged and finance rolesDeeper checks where the access justifies it, rather than a uniform baseline
ContractorsWhether contractors and agency staff are screenedScreening carried through to the workforce that is not on payroll
LegalCompliance with local employment and privacy lawChecks limited to what is lawful in each jurisdiction, since over-collection creates its own liability
RecordsEvidence that screening was completed before access was grantedSequence matters: screening after access has been granted answers a different question
Screening is jurisdictionally constrained

The question says as permitted by law for a reason. Several jurisdictions restrict criminal record and credit checks sharply. A risk-based approach that respects those limits is the correct answer, and it should be described as such rather than as a blanket yes.

What a defensible yes requires

  • Screening is risk-based, with deeper checks for privileged and financial roles.
  • It respects the legal limits of each jurisdiction.
  • Contractors and agency staff are covered.
  • Screening completes before access is granted.
  • Records are retained in line with privacy obligations.

How this answer goes wrong

Employees are screened thoroughly and contractors are not, while contractors hold administrative access. The screening programme covers the population with the least access and omits the one with the most.

Frequently asked

Are criminal record checks required?

Not by carriers, and they are restricted in several jurisdictions. Identity and right-to-work verification plus references is a reasonable baseline.

Should we re-screen existing staff?

Periodic re-screening for privileged roles is done in some sectors and is not a general expectation. Where it happens it should be lawful and disclosed.

What about acquired employees?

They arrive with whatever screening the acquired company performed. Reviewing that during integration is worth doing, particularly for privileged roles.

Does this matter much to carriers?

Less than the technical controls. It contributes to the personnel security picture alongside offboarding and training.

Related questions

Stop answering this from memory

Connect Microsoft 365, Entra ID, and Azure read-only. Insurance Posture reads the live configuration behind each application answer and shows you which ones you can prove before you sign.

Assess your posture