Insights

    Security vetting in recruitment – how it works

    A security vetting is a check that a person is reliable enough for a post that touches national security. It consists of a background enquiry, a structured interview and, in some cases, a records check by the Swedish Security Service.

    Written by Jonas Renander

    When is vetting required?

    The requirement comes from the Swedish Protective Security Act and applies to anyone taking part in security-sensitive activity. In practice that means defence, energy, transport, telecoms, healthcare and public authorities — and subcontractors to them, once they gain access to classified information.

    The employer is responsible for the vetting. A recruitment partner can prepare and coordinate it, but never take over the decision.

    What the vetting covers

    1. Background enquiry. Identity, employment history, references, financial situation and any conflicts of loyalty.
    2. Vetting interview. A structured conversation about background, contacts and vulnerabilities. It must be documented.
    3. Records check. Carried out by the Security Service on application, and only for posts placed in security class 1–3.

    Effect on the timeline

    The background enquiry and the interview can run alongside final interviews and normally add one to two weeks. The records check is the part that cannot be rushed: expect three to eight weeks from application to decision, and longer for the higher security classes.

    In practice a classified role is rarely filled in less than three months from kick-off, even when the candidate is settled. Plan the start date around that, not around the signature.

    Common mistakes

    • Starting the vetting only after the contract is signed.
    • Telling the candidate what vetting involves late in the process.
    • Treating a foreign citizenship as a bar in itself — it is not, though it does affect processing time.
    • Keeping vetting material longer than necessary. The data is sensitive and covered by the GDPR.

    How OGR handles it

    We flag the security class in the role profile, tell the candidate about the vetting in the first conversation, and hand a complete file to your protective security manager. The decision stays with you.