Does SOC 2 require background checks? What auditors actually expect
Short answer: SOC 2 doesn't contain the words "background check" as a hard requirement - but in practice, if you're pursuing SOC 2 and you can't show screening evidence for new hires, expect a finding. The same pattern holds across ISO 27001, PCI DSS, and NIST-based frameworks: personnel screening is a standard control, and the auditor wants evidence per hire. Here's what each framework actually says, and where international hires make it complicated.
SOC 2 (AICPA Trust Services Criteria)
SOC 2's control environment criteria (CC1 series, built on COSO) require the organization to demonstrate a commitment to attracting and developing competent individuals (CC1.4) and to integrity and ethical values (CC1.1). Auditors routinely map background screening of new hires to these criteria: a screening policy plus per-hire evidence is the expected artifact. It's technically your control design choice - but a SOC 2 report with no personnel screening control is a hard sell.
ISO/IEC 27001:2022
The most explicit of the bunch. Annex A control 6.1 (Screening) says background verification checks on candidates should be carried out before joining and proportionally to business requirements, data classification, and perceived risks. Education and employment verification are the classic components.
PCI DSS 4.0
Requirement 12.7: screen potential personnel before hire for roles with access to cardholder data, to reduce insider risk. Not optional if the role touches CHD.
NIST 800-53 / FedRAMP
Control PS-3 (Personnel Screening) requires screening individuals before authorizing system access, with rescreening on defined conditions. Flows into FedRAMP and anything federal-adjacent.
The international-hire gap
These controls are easy to satisfy for US employees - domestic screening is a commodity. The gap opens when your new hire is in Brazil: generic international providers take 6-20+ business days and frequently close education checks as "Unable to Verify". An "Unable to Verify" isn't screening evidence an auditor loves - it documents that you tried, not that you screened.
What audit-ready evidence looks like for a Brazilian hire
- Education verified against official sources - e-MEC accreditation plus either cryptographic Diploma Digital validation or direct registrar confirmation, not a form email that timed out
- Identity confirmed via government-backed assurance (Gov.br), so the credentials belong to the person you hired
- Employment history from employer-filed government records (CTPS Digital), not self-reported dates
- A dated report per hire stating what was verified, how, and what wasn't - with evidence retained and available on request
That's the artifact set your auditor samples during the observation period: policy + per-hire report + evidence trail. VerifyBR's workflow produces exactly that for Brazilian hires, in days instead of weeks, at $49 per candidate.
Hiring in Brazil under a compliance framework?
Run your first Full Verification free - start here - or compare us against your current provider.
This article is educational information about common audit practice, not legal or compliance advice. Framework requirements are paraphrased; consult the current published standards and your auditor for decisions about your control environment. VerifyBR provides verification services and reports; it does not certify organizations against any framework.