Annex A.6: People Controls
Eight controls, one theme: the human layer — screening, terms, awareness, discipline, remote working and reporting. Small count, but the controls auditors verify through interviews rather than documents, which is why unprepared organisations fail them in the corridor, not the audit room.
Reviewed by Tanya Kumari, Director — compliance assessment & certification readiness · Part of the Annex A series
The controls that decide your audit
Control numbers reference ISO/IEC 27001:2022 Annex A (ISO/IEC 27002:2022 numbering). The 2013→2022 transition ended 31 October 2025 — audits now run against this control set.
Where audits actually fail
Auditors sample joiners and ask for verification records; "HR does it" without artefacts fails A.6.1 — especially for contractors, who are routinely skipped.
A.6.3 asks for role-relevant content and effectiveness measurement — phishing-simulation results, quiz outcomes, targeted refreshers.
The interview question that decides A.6.8: "you see something suspicious — what do you do?" A hesitant answer outweighs a beautiful procedure document.
A.6.5 needs exit communication evidence — a checklist item confirming post-employment duties were restated at departure.
Evidence an auditor accepts
- Sampled screening records for employees AND contractors (A.6.1)
- Contract template clauses + signed NDA register (A.6.2/6.6)
- Training records with role mapping and effectiveness measures (A.6.3)
- Remote-working policy and technical enforcement evidence (A.6.7)
- Event-report samples showing the channel works end to end (A.6.8)
- Exit checklist samples: asset return, access revocation, duty restatement
Annex A.6 FAQ
Does screening apply to contractors and third-party staff?
Yes — A.6.1 covers candidates for employment broadly, and auditors increasingly sample contractor onboarding precisely because it is the common gap.
How often must security awareness training run?
On joining and at planned intervals thereafter (annually in most ISMS), with content appropriate to role and evidence that effectiveness is evaluated (A.6.3).
Is a remote-working policy mandatory?
Where remote working happens, A.6.7 requires implemented security measures — policy plus enforcement (MDM, VPN, disk encryption), verified rather than assumed.
Annex A.6 in your ISMS
We take organisations from gap assessment to certificate — and keep the ISMS audit-ready on SigmaTrust afterwards.
