Do You Need Background Checks for SOC 2?
SOC 2 does not explicitly mandate background checks. But if you skip them, you will have a hard time passing your audit and an even harder time closing enterprise deals. Here is why, and how to set up screening that actually holds up.
If your startup is chasing SOC 2, someone on your team has probably asked this exact question. The framework never says “run a criminal record check.” So is screening optional?
We put the question to Andrew Amaro, founder of Klavan Security and creator of BaseCamp, a 12-month guided security program for startups closing enterprise deals. Andrew spends his days walking founders through SOC 2 audits, and his answer reframes the whole debate.
What SOC 2 actually says
SOC 2 is built on the Trust Services Criteria. The one that matters here is CC1.4, which requires organizations to demonstrate a commitment to attracting, developing, and retaining competent individuals. Background screening is the most common way companies show it. Some auditors also map screening evidence to CC1.1 or, for contractors, CC9.2.
“SOC 2 doesn’t mandate them. CC1.4 is about competent personnel and screening is one way to show it. But that’s the compliance answer to a security question.”
Andrew Amaro, founder, Klavan Security
The security question is the one that should keep you up at night.
Why screening matters beyond the checkbox
“You’re about to hand someone you’ve never verified admin access to production and customer data,” Andrew says. “Screening isn’t a hiring control that touches security. It’s an access control that happens at hiring.”
His point: the losses that hurt most often don’t come from an outside attacker. They come from someone who was given access legitimately. The outsider has to break in. The insider is already authenticated and looks like a normal Tuesday in your logs.
And there is a commercial reality on top of the security one. “Your enterprise customers ask about it on every vendor questionnaire anyway,” Andrew notes. “Skip it and you don’t fail the audit. You fail the deal.”
That matches what we see at Credibled. For a startup, the background check policy is rarely about the audit alone. It is about the security questionnaire sitting between you and your first 6-figure contract.
What auditors actually look for
Here is the part most founders get wrong. Auditors are not grading how strict your screening is. They are grading whether you do what your own policy says.
“Consistency with your own policy. That’s the whole thing. Do you have a documented policy that says what screening you do, on whom, and when? Is it scoped by role and risk? Is there evidence you actually did it for the people hired during the audit period?”
Andrew Amaro
Three details founders routinely miss:
- A Type II audit samples across the entire audit window. If you start screening in month 8, months 1 through 7 are still visible, and every unscreened hire in that window becomes a finding.
- Contractors count if they touch your systems. Your screening policy needs to cover them, not just employees.
- Exceptions must be documented and approved. An undocumented exception is just a gap.
The most common mistake: the template trap
Ask Andrew where startups fail on this control and his answer is not “weak screening.” It is overpromising.
“Somebody grabs a template. It says comprehensive criminal, credit, education and employment verification for all personnel. Into the policy library it goes. Nobody reads it again. Then the audit arrives, the auditor tests against that document, and every hire is now an exception against a standard you never intended to meet.”
“They didn’t fail because their screening was weak. They failed because they wrote a promise they had no process to keep.”
Andrew Amaro
The fix is to write a policy that describes what you will actually do, scoped by role and risk, and then do it every time.
The second mistake is treating screening as one-and-done. “Screening is a snapshot of a person whose access keeps changing,” Andrew says. “Someone gets hired into a low-access role, and 18 months later they’re an admin. The check they passed was for a job they don’t have anymore. Tie re-screening to access change, not to a calendar.”
How to scope screening by risk
In BaseCamp, Andrew maps access before writing the screening policy, because the tiers should fall out of who can reach what. His baseline for startups:
- Identity verification for everyone. Fabricated identities in remote hiring are a live problem now, not a theoretical one.
- Criminal record checks for anyone touching production or customer data. For most SaaS startups, that is engineering, DevOps, and support.
- Employment and reference verification across the board. The cheapest fraud to catch is the résumé kind, and the gaps matter more than the embellishments.
- Credit checks only where someone handles money. Screening beyond real risk adds cost and friction without adding security.
Setting it up so it runs itself
A screening policy that depends on someone remembering to email a vendor breaks the first week hiring gets busy. “Manual screening turns into a filing habit,” Andrew says. “You want it firing off onboarding with its own evidence trail.”
This is where he points his Canadian clients to us. “For Canadian clients we point at Credibled. Canadian owned, hosted in Canada, PIPEDA compliant,” Andrew told us, citing the open API and pay-per-check pricing as well. “Running your Canadian employees’ criminal and identity data through a US platform creates a cross-border problem on the exact control you’re trying to demonstrate.”
For a SOC 2 audit specifically, here is what that looks like in practice with Credibled:
Canadian criminal record checks come back in about 15 minutes, with identity verification included in the price rather than billed as a separate line item. Reference checks run automatically, with reminders every 24 hours for up to 10 days, so completion does not depend on a recruiter chasing referees. Every check produces a timestamped record, which is exactly the evidence trail your auditor will sample. And because it is pay per check with no subscription, a 10-person startup is not paying enterprise-platform pricing to screen 4 hires a year.
One caution Andrew insists on, and we agree: screening is not a silver bullet. “It thins out the population of people who show up already intending harm. It does nothing about the ones who decide later. That’s what least privilege, logging and real offboarding are for. Screening is the door check. It isn’t the building’s security.”
About BaseCamp
BaseCamp by Klavan Security is a 12-month guided security cycle for startups closing enterprise deals, covering SOC 2 Type II, ISO 27001, CMMC and more. Rather than selling you a policy library, BaseCamp builds your security program in the order that protects you: security first, documentation second.
BaseCamp comes in 3 tiers, each including the platform and a public Trust Center from day 1:
- BaseCamp Scout ($297/month): full platform access to self-direct your security program, including all 10 security sections, a guided 12-month Mission Plan, policy library with auto-generation, tech stack inventory, risk matrix with built-in scoring, and email support.
- BaseCamp Guide ($597/month): everything in Scout plus a dedicated Klavan Security Guide for the entire 12-month cycle, direct Slack access to the Klavan team, vendor management, security questionnaire support, and AI governance guidance.
- BaseCamp Operator ($1,497/month): for teams that want the Klavan team handling the heavy lifting, with quarterly strategy sessions, security questionnaire handling done for you, audit liaison, priority response, and a Startup Pentest by SHELLHOUNDS included.
There is also BaseCamp Recon, a one-time month 0 add-on (from $499, or $4,950 for a full Startup Pentest) where the Shellhounds test your app and infrastructure before the compliance cycle begins, feeding findings directly into your month 1 risk matrix.
Learn more at soc2success.io.
FAQ
Is a background check mandatory for SOC 2?
No. SOC 2 does not explicitly require background checks. However, CC1.4 requires evidence of personnel competence, and screening is the standard way to demonstrate it. Most auditors expect to see a screening policy and evidence it was followed.
Do contractors need background checks for SOC 2?
Yes, if they access your systems or customer data. Auditors treat contractors with system access the same as employees.
How often should employees be re-screened?
Tie re-screening to access changes rather than a calendar. When someone moves into a role with production or financial access, re-screen at that point.
What happens if we started screening partway through our audit period?
A Type II audit samples the full window. Hires made before your screening process started may show up as exceptions, so document and remediate them proactively.
How fast can a Canadian criminal record check come back?
Through Credibled, most Canadian criminal record checks are completed in about 15 minutes, with identity verification included.
Building toward SOC 2 and need screening that produces its own audit trail? Start with a check at credibled.com. Startups get preferential onboarding through our Startup Program.

