Baseline Personnel Security Standard (BPSS) checks matter.

They establish a baseline level of personnel security before someone is given access to government assets, sensitive environments or roles where baseline trust is required. They help confirm identity, right to work, employment history and relevant declarations.

But in high-trust environments, BPSS should not be treated as the whole trust decision.

It is the starting point.

For critical infrastructure, including CNI environments, the better question is not simply:

“Has this person passed BPSS?”

It is:

“What risk indicators were identified before employment, what access is this person being given, and does their current behaviour and circumstances still support that level of trust?”

It's an important distinction to make.

Insider risk is rarely static. Roles change. Access expands. Contractors move between projects. Suppliers rotate staff. Temporary access becomes long-term. Personal circumstances, external pressures or role changes can alter the risk context over time.

In some cases, credible, role-relevant indicators may suggest someone is vulnerable to coercion, recruitment or exploitation by hostile actors.

None of this means organisations should monitor everyone constantly.

They should not.

It means organisations need a clear, proportionate way to assess trust before access is granted, and review trust when something material changes.

Pre-employment checks are the first chance to spot risk indicators

Personnel security starts before someone is given access.

Pre-employment checks are not just a hiring hurdle. In high-trust environments, they are the first stage of an access decision.

They help organisations identify whether there are any risk indicators that need context, judgement or mitigation before someone is trusted with sensitive access.

That might include:

  • inconsistencies in employment history
  • unexplained gaps
  • adverse information
  • conduct concerns
  • undeclared issues
  • other signals relevant to the role or environment

The important point is simple.

A risk indicator should not automatically mean exclusion.

A flag is not a verdict.

It should trigger human review.

The question is whether the issue is relevant, current, explainable and proportionate to the access being granted. A concern that may be immaterial for a low-risk role could be highly relevant for someone entering a safeguarding environment, accessing sensitive data, holding privileged credentials or working in critical infrastructure.

Pre-employment screening should not sit separately from access decisions. If an indicator is identified before employment, it should help inform what access is granted, what review points are needed, whether support or supervision is appropriate, and whether additional checks are justified.

The question is not simply whether someone can be employed.

It is whether any risk indicators need to be understood before that person is trusted with sensitive access.

BPSS answers an entry question

BPSS is best understood as a baseline control.

It helps answer whether someone can be brought inside the perimeter at a particular point in time. That might mean joining an organisation, working on a contract, accessing a secure site, supporting a sensitive system or operating in a regulated environment.

That is valuable.

UK government BPSS policy recognises that organisations may apply additional checks and controls in line with their risk appetite. That is the important point: BPSS sets the baseline, but higher-risk access may justify stronger governance.

BPSS should also be understood in relation to the wider personnel-security framework. It is not National Security Vetting, and it should not be treated as a substitute for higher levels of assurance where the role, access or threat context requires them.

The principle is simpler.

The level of checking and review should match the level of access and risk.

The problem comes when BPSS is treated as a one-off event.

A person may be checked when they first join, but their access six months later may look very different. A contractor may arrive with a limited scope, then gain privileged access to systems. A supplier engineer may start with supervised site access, then become familiar, trusted and left alone. A temporary account may remain open after the original requirement has passed.

In those cases, the original check may still exist on file, but the risk decision has changed.

The check answered the entry question.

It did not necessarily answer the current access question.

Insider risk follows access, not the organisation chart

Many organisations still think about personnel security through employment categories.

Employee. Contractor. Supplier. Visitor. Consultant.

Risk does not follow those categories neatly.

A permanent employee in a low-access role may present very little practical risk. A third-party administrator with privileged credentials may sit outside the organisation, but inside the operational risk perimeter. A contractor with unsupervised site access may have more opportunity to cause harm than someone who appears more senior on the org chart.

This is especially true in critical infrastructure and other high-trust environments, where the impact of access can be significant.

The better question is:

What can this person reach, influence, disrupt or expose?

That includes physical sites, sensitive data, operational systems, safeguarding environments, supplier portals, privileged credentials and decision-making processes.

Once access is understood, the level of personnel security can be matched to the level of risk.

BPSS may be enough for some roles. For others, the organisation may need stronger review, tighter access expiry, additional checks, closer supervision or periodic revalidation.

The principle is not more checking for everyone.

It is proportionate checking for the right people, at the right moment, based on the access they hold.

Behaviour matters too

Access is one trigger for review.

Behaviour is another.

This is where personnel security can learn from safeguarding practice.

In safeguarding, a concern does not automatically mean guilt. It does not mean someone is removed, accused or treated unfairly. It means the concern is noticed, recorded, escalated to the right person and assessed proportionately.

The same principle should apply to insider risk.

If someone’s behaviour changes in a way that creates a credible, role-relevant concern, there should be a clear route to report and review it.

That might include:

  • unusual attempts to access information
  • unexplained interest in systems or sites outside their role
  • credible indicators of coercion or external pressure
  • repeated policy breaches
  • concerning judgement in a relevant context
  • a material change in circumstances that affects the trust decision attached to their access

The point is not to encourage suspicion, informal profiling or speculative judgements about people’s private lives.

The point is to create a responsible review mechanism. Behavioural triggers should be limited to credible, role-relevant concerns, handled through defined reporting routes, assessed by appropriate people, and recorded with a clear rationale.

Who records it?
Who reviews it?
Who decides whether further checks are justified?
Who makes sure the response is fair, proportionate and auditable?

Without that process, concerns either get ignored or handled inconsistently.

Both are dangerous.

This needs a written procedure

This should not be left to informal judgement.

Organisations need a written, approved procedure that sets out when a baseline trust decision should be reviewed, who owns the review, what information can be considered, how decisions are recorded, and when matters should be escalated.

That procedure should cover:

  • pre-employment indicators that require review before access is granted
  • access changes that trigger revalidation
  • credible behavioural or conduct concerns
  • role, contract or supplier changes
  • ownership between HR, security, safeguarding, legal and operational teams
  • decision-making authority
  • record-keeping and audit requirements
  • escalation routes
  • safeguards against unfair, speculative or discriminatory decisions

Without a written procedure, organisations rely on memory, judgement and informal escalation.

That is not enough.

A serious concern may be missed. A minor concern may be overreacted to. Similar cases may be handled differently. Decisions may be difficult to explain later.

The procedure matters because it protects both the organisation and the individual.

It makes the response lawful, fair, proportionate and auditable.

This is not surveillance

There is an important line here.

A modern personnel-security programme should not become a culture of spying on staff.

That would be wrong, counterproductive and damaging to trust.

The better model is much more practical.

Organisations should define a small number of review triggers that are relevant to the level of access involved. Those triggers should be clear, lawful, proportionate and human-led.

For example:

  • a pre-employment check identifies a risk indicator that needs context before access is granted
  • a contractor is given higher-risk or unsupervised access
  • a supplier role changes from temporary to long-term
  • privileged credentials are granted or expanded
  • someone moves onto a sensitive project or site
  • a safeguarding-style concern is raised
  • there is a credible behavioural or conduct concern
  • there is evidence of external pressure, coercion or vulnerability
  • a material period has passed since the original check
  • access no longer matches the original business need

None of these should automatically lead to a punitive outcome.

They should lead to review.

That review might result in no action. It might result in additional support. It might mean changing access, tightening supervision, renewing checks or escalating to a formal process.

The aim is not to investigate people without cause.

It is to make sure credible, role-relevant concerns are handled consistently, fairly and with an auditable rationale.

BPSS renewal is the missing question

There is also a practical question many organisations have not fully answered.

BPSS does not operate like National Security Vetting, with a simple equivalent renewal cycle. That makes the governance question more practical: when should the original baseline trust decision be revisited because the access, role or risk context has materially changed?

For many organisations, BPSS is completed at onboarding and then left alone. That may be appropriate for some roles.

Where someone continues to hold meaningful access to sensitive sites, systems, data or safeguarding environments, it is reasonable to ask when baseline trust should be revalidated.

That does not necessarily mean repeating the same process on a fixed schedule for everyone.

A more sensible approach is trigger-based.

Review BPSS, or equivalent baseline checks, when the risk changes.

That might be because access has increased, the role has changed, a concern has been raised, the contract has been extended, new risk indicators have emerged, or enough time has passed that the original decision needs refreshing.

The missing governance question is not whether BPSS has a formal renewal cycle.

It is when a baseline trust decision should be revalidated because the access or risk context has changed.

The key is to move from a static model of trust to an active one.

Not constant monitoring.

Not unnecessary bureaucracy.

Just a clear answer to a simple question:

When should we check again?

Hostile actors look for vulnerability

Insider risk is not only about malicious employees.

It can involve people under pressure. People being manipulated. People with access they should no longer have. People targeted by hostile actors because of the systems, sites or information they can reach.

Recruitment, coercion and exploitation often start with vulnerability.

That could include external pressure, grievance, coercion, personal crisis or simply opportunity. In sensitive environments, those vulnerabilities can become operational risks if they combine with meaningful access.

Again, the answer is not to treat everyone as a threat.

The answer is to recognise that trust is a live condition.

It depends on pre-employment risk indicators, access, behaviour, circumstances and context.

A BPSS check at the start of a role cannot carry all of that weight forever.

Building a trust lifecycle around access and behaviour

A more mature approach brings four things together.

1. Pre-employment risk indicators

Before access is granted, organisations should use pre-employment checks to identify any indicators that require further context, review or mitigation.

This is not about automatic exclusion.

It is about making better trust decisions before someone is placed into a sensitive environment.

2. Baseline checks

BPSS or equivalent checks establish the starting point.

They help confirm identity, right to work, employment history and relevant declarations before access is granted.

This remains important.

It should be treated as the floor, not the ceiling.

3. Access classification

Organisations should classify access by potential impact.

That means understanding who can access:

  • sensitive physical sites
  • operational technology
  • privileged IT systems
  • confidential data
  • safeguarding environments
  • supplier systems
  • financial or commercial information
  • critical processes
  • vulnerable populations

The higher the potential impact, the stronger the governance should be.

4. Review triggers

Organisations should define when trust may need to be reviewed.

Those triggers should include pre-employment indicators, access changes and credible behavioural concerns.

For example:

  • new privileged access
  • unsupervised site access
  • role or contract extension
  • supplier staff change
  • movement onto a sensitive project
  • concerning conduct or judgement
  • safeguarding-style concern
  • evidence of coercion or external pressure
  • long gap since the original check
  • mismatch between current access and original approval

This creates a proportionate governance model.

Not everyone is checked all the time.

The people with meaningful access are reviewed when the risk changes.

A stronger personnel-security model is not more paperwork

A stronger personnel-security model is not simply more forms at onboarding.

It is better visibility of who has meaningful access, clearer ownership of trust decisions, written procedures, defined review triggers, and a security culture where credible concerns are escalated rather than ignored.

BPSS plays an important role in that system.

It cannot be the whole system.

For critical infrastructure and other high-trust environments, the question is not whether BPSS matters.

It does.

The question is whether the organisation knows what happens before and after BPSS is complete.

When pre-employment checks identify risk indicators.
When access expands.
When behaviour changes.
When circumstances shift.
When a contractor becomes embedded.
When a supplier account remains live.
When a safeguarding-style concern is raised.
When the original trust decision no longer matches the current risk.

That is where insider-risk programmes need to mature.

Pre-employment checks should identify initial risk indicators.
BPSS should establish the baseline.
Access should define the level of control.
Behaviour and circumstance should trigger review.
A written procedure should govern the process.
Human judgement should sit at the centre.

Because the point is not to watch everyone.

The point is to know when trust should be reviewed.

Most critical infrastructure organisations will already have parts of this in place: onboarding checks, joiner-mover-leaver processes, access recertification, privileged access management, HR escalation routes, security reporting and incident response.

The opportunity is to connect those controls into a clearer trust lifecycle, so pre-employment indicators, access level, behavioural concerns and revalidation decisions are handled together rather than in isolation.

For organisations that want to understand what wider risk indicators may look like before access is granted, Safehire’s Digital Risk Screening can add useful context beyond standard checks. It is not a replacement for BPSS, National Security Vetting or human judgement. It is a way to support proportionate, evidence-led decisions about trust, access and review.

Continue reading