Vetting

Personnel Security Vetting & Insider Risk

Lawful, proportionate screening frameworks for the people inside the perimeter.

The situation

Screening people in the EU is a legal minefield: GDPR Articles 6, 9 and 10 sharply limit what an employer may collect, and national employment law differs in every Member State.

We design and govern the framework that determines who gets vetted, to what depth, on what lawful basis, with what evidence retention, and how insider risk is monitored afterwards without turning the workplace into a surveillance regime. Screening itself is carried out by licensed providers under that framework, with local employment counsel engaged where the jurisdiction requires it.

What the client receives

Schedule of deliverables

  1. 01Role-based vetting policy tied to access and asset sensitivity
  2. 02Lawful basis analysis, DPIA and retention schedule for screening data
  3. 03Vetting depth matrix (identity, right to work, references, qualifications, adverse media, financial probity where lawful)
  4. 04Insider risk indicators, escalation and case-handling procedure
  5. 05Joiner-mover-leaver control design
  6. 06Clearance support for EU institution and defence-adjacent engagements

Frameworks and standards

Assessment is carried out against named references, so a conclusion can be traced back to the requirement it was measured against.

  • GDPR Art. 6 / 9 / 10
  • ISO/IEC 27001 A.6.1–A.6.6
  • ISO/IEC 27002:2022
  • National employment law (per jurisdiction)

Discuss this engagement

Tell us about the roles in scope and the jurisdictions they sit in and we will set out the scope, the method and the reporting format.

Contact us