See what's new

Testlify
Back to HR Glossary
HR Glossary

Background Check HR

A background check is a process of verifying an individual’s personal, employment, and/or criminal history to ensure the safety and security of the employer, landlord, or organization.

Summarise this term with:ChatGPTGeminiClaudeGrokPerplexity

Background Check HR is the UK-specific equivalent of a criminal background check, administered by the UK Home Office.

A background check is a formal pre-hire verification process that confirms a candidate’s employment history, criminal record, education credentials, and identity before a conditional offer becomes final, required for FCRA compliance in the US.

Image showing the meaning of Background Check
Image showing the meaning of Background Check

Why background check HR matters for enterprise teams

For organizations hiring at scale, background checks are not a formality. They are a compliance obligation and a risk management tool. According to the Professional Background Screening Association (PBSA), 96% of U.S. employers run at least one background check before hiring – and 89% cite protecting employees, customers, and the business as the primary reason (PBSA, 2023).

For enterprise HR teams managing thousands of hires annually, the stakes are higher. A single mis-hire in a regulated role – finance, healthcare, data access – can trigger regulatory penalties, reputational damage, or direct liability. At the same time, inconsistent screening across business units, geographies, or seniority levels creates EEOC exposure through disparate impact, even when discrimination is unintentional.

Screening programs at 1,000+ employee organizations must also contend with multi-jurisdiction compliance: FCRA at the federal level, ban-the-box laws in 37+ U.S. states, GDPR for candidates in the EU, and sector-specific requirements (FINRA, HIPAA, NERC-CIP). Connecting background checks to pre-employment testing gives HR teams an objective evidence base that holds up in audit and supports defensible, documented hiring decisions. Learn how this fits into a broader pre-employment testing framework.

Types of background check used in enterprise hiring

Enterprise screening programs typically use several check types, often in packages configured by role and risk level.

For high-volume enterprise programs, criminal checks are run in 97% of cases (PBSA, 2023). Credit and license checks are role-specific. Running a blanket credit check on every candidate regardless of role is an EEOC flag – always tie check type to a documented job-related business necessity.

How to run a background check program in your organization

A compliant, audit-ready background check process follows a defined sequence.

1. Document your screening policy. Define which check types apply to which role families. Document the job-related business necessity for each check type. Store this policy in your HRIS and review it annually.

2. Obtain written consent. Under FCRA, you must provide a clear and conspicuous written disclosure – on a standalone document, not buried in an offer letter – and obtain signed authorization before ordering any consumer report. For EU candidates, consent under GDPR must be specific and freely given.

3. Initiate through a PBSA-accredited provider. For enterprise volume, use a provider with ATS integration (Workday, Greenhouse, or Lever). Direct triggers from the candidate profile eliminate manual data re-entry and create an audit trail. Platforms with native screening integrations report 3-5 day time-to-clear versus 7-12 days for manually-integrated systems.

4. Review results with a documented adjudication matrix. Apply consistent criteria across all candidates in the same role family. Do not use blanket disqualification for arrest records. EEOC guidance requires individualized assessment: consider nature of offense, time elapsed, and job responsibilities.

5. Follow adverse action protocol if needed. Before rejecting a candidate based on a background report, send a pre-adverse action notice with a copy of the report and a summary of rights. Wait a reasonable period (typically 5 business days) before issuing the final adverse action notice. Both steps are FCRA-required and omitting either creates material legal exposure.

6. Store records and run audits. Retain background check records per your jurisdiction’s data retention rules. For GDPR-covered candidates, deletion timelines apply. Conduct an annual compliance audit against current federal, state, and local requirements.

Background check vs reference check: key differences

Both are part of candidate due diligence, but they serve different purposes and surface different risk types.

Background checks verify what candidates claim. Reference checks reveal how they are likely to perform. Research shows 89% of early-stage employee failures stem from behavioral or motivational factors, not credential gaps – which is why reference checks and skills assessments complement rather than replace formal screening (Crosschq, 2024).

Best practices for enterprise background check programs

  • Standardize by role family, not individual judgment. Define a tiered screening matrix: Tier 1 (all roles: criminal, identity, employment), Tier 2 (finance/data: credit, watchlist), Tier 3 (licensed: professional license verification). Apply tiers consistently to avoid disparate impact claims.
  • Integrate with your ATS before scaling. For Workday, Greenhouse, or Lever users, configure background screening as a workflow stage – not a manual off-system step. Status updates push back into the ATS and create a candidate-facing experience that reduces drop-off during the waiting period.
  • Build an individualized assessment protocol. Do not auto-reject on criminal records. EEOC guidance and ban-the-box laws in 37+ states require context-specific review. Document the matrix in writing so any hiring manager follows the same logic.
  • Train hiring managers on adverse action rules. Most FCRA violations occur because a manager verbally rejects a candidate before the pre-adverse action waiting period ends. Make the two-step notice process non-negotiable in your TA playbook.
  • Review scope annually for GDPR and state law changes. Illinois, California, Colorado, and New York have specific credit check restrictions and criminal record lookups beyond 7 years. New laws pass regularly. Assign a compliance owner to track changes.
  • Pair screening with skills-based assessment. Objective pre-employment testing through Testlify reduces the volume of candidates reaching the screening stage and lowers per-screen costs at scale. Skills data also supplements decision-making in borderline cases where background records require individualized review. See how skills assessment complements the screening process.

Frequently asked questions about background check HR

Frequently asked questions

What does a background check show for employment?

A standard employment background check typically shows criminal conviction records (county, state, and national), employment history verification (titles, dates, and any discrepancies), education credentials, and may include credit history, professional license status, and motor vehicle records depending on the role. The exact scope is defined by the employer’s screening package and the candidate’s job family.

How long does an employment background check take?

Most standard background checks complete in 1-3 business days when candidates respond quickly and records are accessible digitally. County-level criminal searches are the most common delay – some rural jurisdictions require manual court research, extending turnaround to 5-7 business days. Enterprise teams using ATS-integrated providers (Workday, Greenhouse) typically report a time-to-clear of 3-5 days (Checkr, 2025).

What laws govern background checks in the U.S.?

The primary federal law is the Fair Credit Reporting Act (FCRA), enforced by the FTC. It governs disclosure, consent, and adverse action procedures. EEOC guidelines prohibit discriminatory application of screening results. Ban-the-box laws in 37+ states restrict when criminal history can be requested. At the state level, credit check restrictions and 7-year lookback limits apply in several jurisdictions including California, Colorado, Illinois, and New York.

Can an employer reject a candidate based on a background check?

Yes, but the decision must follow FCRA adverse action procedures: provide a pre-adverse action notice with the report and summary of rights, allow a waiting period (typically 5 business days), then issue the final adverse action notice. The EEOC also requires that the reason for rejection be job-related – blanket policies that disproportionately screen out protected classes create disparate impact liability (EEOC, 2023).

What is FCRA compliance for background checks?

FCRA compliance requires: (1) providing a clear, standalone written disclosure before ordering a background check, (2) obtaining signed written authorization from the candidate, (3) using a PBSA-accredited consumer reporting agency, and (4) following the two-step adverse action notice process if the report results in a rejected offer. Violations carry statutory damages of $100-$1,000 per violation plus class action risk (FCRA, 15 U.S.C. 1681 et seq.).

How does GDPR affect background checks for EU candidates?

Under GDPR, processing personal data for background screening requires a lawful basis – typically explicit consent or a legitimate interest assessment. Consent must be specific to the screening purpose, freely given, and documented. Data must be deleted after a defined retention period once the hiring decision is made. Criminal record data is “special category” data under Article 10 and subject to additional restrictions. U.S. multinationals hiring in the EU should establish a separate GDPR-compliant screening workflow.

What is the difference between a background check and a DBS check?

A Disclosure and Barring Service (DBS) check is the UK-specific equivalent of a criminal background check, administered by the UK Home Office. There are three tiers: Basic (unspent convictions only), Standard (spent and unspent convictions), and Enhanced (includes barred list checks for regulated roles like healthcare and education). U.S. background checks under FCRA use a different system – county, state, and national criminal databases rather than a centralized government disclosure service. Multinational employers must run separate checks through each country’s appropriate mechanism.

Should background checks be run before or after a job offer?

Best practice – and in many jurisdictions, legal requirement – is to run background checks after a conditional job offer, not before. Running checks at the application stage creates ban-the-box violations in 37+ U.S. states and local jurisdictions. Post-offer screening is also more efficient: you only screen candidates who have already passed the assessment and interview stages, reducing per-hire screening costs significantly. This sequencing also aligns with GDPR’s data minimization principle for EU candidates. Enterprise HR and talent acquisition teams handling high-volume or regulated hiring can reduce screening delays and compliance risk by integrating background checks with structured skills-based assessments earlier in the funnel. Testlify connects talent acquisition workflows with objective candidate data – so by the time a candidate reaches the screening stage, your team has verified competency, not just credentials. Learn more about building a defensible, bias-reduced hiring process with pre-employment testing or explore how talent management integrates screening into broader workforce planning.

Get started.

Hire on proof, not resumes.

Run your first skills-based assessment free — no credit card required.

We use cookies to enhance your browsing experience, serve personalised ads or content, and analyse our traffic. By clicking "Accept All", you consent to our use of cookies.