Objective
Ensure personnel are appropriately screened before employment, access or AML-relevant duties begin.
Control Activity
Compliance and the responsible hiring function define risk-based screening for each in-scope role, complete identity and relevant qualification, reference, sanctions, PEP, adverse-information, integrity, conflict and lawful criminal-record checks, resolve findings and evidence approval before the start date or access grant. The screening scope must be proportionate to the proposed role, access, authority and financial-crime exposure. For lower-risk activities or roles, simplified procedures may be used; higher-risk situations trigger enhanced due diligence, additional verification, or management review, consistent with the handbook’s proportionality principles.
Evidence
- Expected evidence: in-scope role and screening checklist.
- Expected evidence: completed verification and screening reports.
- Expected evidence: finding assessment and approval.
- Expected evidence: screening completion, start date and access-grant chronology.
- Evidence location: source evidence in SYS-ECM-002 Compliance Reporting and Evidence Repository; target Hermes assessment record in Odoo under ISS-HERMES-001.
- Retention: according to applicable employee, privacy and AML record-retention requirements.
- Testing method: sample new employees and other in-scope personnel and confirm proportionate screening, finding resolution and approval occurred before the start date, privileged access or AML duties.
- Testing frequency: quarterly population reconciliation and after material role, access, legal, risk or integrity triggers.
Relationships
- AML policy: POL-AML-001 AML CTF CPF Compliance Manual
- Employee policy: POL-EMP-001 Employee Handbook
- Processes: PRC-FCI-001 Financial Crime and Integrity, PRC-RSA-001 Resilience Systems and Assurance
- Procedure: PROC-EMP-008 Screen Personnel Before Employment
- Manual coverage: section 1.3 and the employee-screening element of section 10.3.
Assurance
Runtime effectiveness results are maintained in Odoo and assessed through the Hermes workflow tracked in ISS-HERMES-001. This note defines design, ownership, evidence expectations and testing method; it does not contain a manually maintained operation, evidence or overall effectiveness rating.
- Design status: implemented from approved AML/CTF/CPF Compliance Manual version 2.2
History
- 2026-07-26: Created after a full AML manual rescreen to test the pre-employment screening requirement.