ENS starts from a risk-based logic
Spain's National Security Framework (Royal Decree 311/2022) structures public-sector security around principles, measures and risk management. Annex II also contains an express people-related measure: for MEDIUM and HIGH category systems, requirements must be defined for persons occupying roles directly related to handling information or services, including verification of employment history, education and other references, in accordance with the law and fundamental rights. For suppliers, this means looking beyond their own infrastructure: people who develop, administer or maintain services for a public authority may form part of the customer's risk environment. Human Risk Management provides a way to relate people, responsibilities and access to proportionate controls.
Suppliers are part of the perimeter
A software, cloud or support provider may have remote access to public systems, production environments or sensitive information. From a risk perspective, the boundary between internal and external personnel matters less when both can perform similar actions. Supplier security processes should therefore include criteria for who may work on particular contracts and what evidence of identity, qualifications or integrity is reasonable for each function.
Access and trust should be documented
Documenting access and trust does not mean building unlimited dossiers on employees. It means being able to explain why a person has a privilege, which controls were applied and when they should be reviewed. This traceability is useful in audits and discussions with public-sector customers. It also helps when roles change: if a technician moves from first-line support to critical infrastructure administration, controls can be adjusted to the new exposure.
Screening should follow role sensitivity
Role sensitivity should drive screening. Under the ENS, measure mp.per.1 on job-role characterization and verification of employment history, education and other references applies to MEDIUM and HIGH categories, not BASIC. This does not amount to a general authorization to process criminal-record data, which remains subject to the specific restrictions of the GDPR and Spain's LOPDGDD. Lower-access functions may need basic verification, while higher-impact environments may justify additional checks where they are relevant and lawful. This avoids a uniform policy across all contracts. It also helps the supplier demonstrate that its security model is selective and reasoned rather than simply a collection of controls applied without a necessity assessment.
Useful evidence for public-sector customers
For public-sector customers, the most useful evidence is often a clear policy covering role categories, access requirements, onboarding and offboarding, reviews and ownership. Background checks can sit within that evidence as one of several controls. The supplier benefits twice: its own security is strengthened and it can respond more precisely to questionnaires, audits and contractual requirements concerning personnel in sensitive services.
Want to integrate Human Risk Management into your risk model?
Validato helps organizations design modular, proportionate background checks for candidates and employees, with international reach and data governance in Switzerland and the EU. Contact us to discuss which screening level fits your higher-risk roles.
From