Commercial Investigations LLC

View Original

Five Essential Steps for Employers to Ensure Background Check Compliance

A thorough background check can help verify a candidate's qualifications, identify potential red flags, and ultimately make more informed hiring decisions. 

However, employers must be careful to comply with the Federal Fair Credit Reporting Act (FCRA) when conducting background checks to avoid risks.

The FCRA is a federal law that regulates the collection, dissemination, and use of consumer information, including background checks for employment purposes. 

Failure to comply with the FCRA's requirements can result in costly fines, lawsuits, and damage to an employer's reputation.

Some potential consequences of non-compliance with the FCRA include:

  • Civil liability for willful or negligent violations, including actual damages, statutory damages, punitive damages, and attorneys' fees.

  • Criminal penalties for obtaining background reports under false pretenses.

  • Regulatory enforcement actions by the Federal Trade Commission (FTC) and state agencies.

Given the legal risks and the importance of building a qualified workforce, it’s essential for employers to understand and follow proper procedures. 

By prioritizing FCRA compliance, employers can mitigate legal risks, treat applicants fairly, and make well-informed hiring decisions.

Proven Process

To help employers navigate the FCRA requirements and ensure compliance throughout the background check process, this guide outlines five essential steps to follow.

Step 1: Develop a Written Background Check Policy

The first step in maintaining FCRA compliance is to develop a clear, well-documented background check policy for your organization. 

Having a written policy in place helps ensure consistency in your hiring practices and fair treatment of all applicants.

Your background check policy should outline:

  • The types of background checks conducted (e.g., criminal records, employment verification, education verification).

  • At what point background checks are performed during the hiring process.

  • The specific positions/job roles that require different levels of screening.

  • Procedures for obtaining proper authorization from applicants.

  • Processes for providing pre-adverse and adverse action notices.

  • Guidelines for storing and disposing of background check records securely.

By documenting your policy, you create standards that must be followed by everyone involved in the hiring process. This helps prevent oversights, inconsistencies, and potential discrimination claims. 

The policy should be reviewed regularly and updated as hiring practices or legal requirements evolve.

Step 2: Tailor Background Checks to the Role

Not all jobs carry the same level of risk or responsibility, so it's important to tailor your background screening practices to the specific requirements of each position. 

Conducting background checks that are overly broad or unrelated to the job can potentially raise legal concerns.

When determining what to perform, consider factors such as:

  • The position's duties and degree of sensitive information/resources accessed.

  • Whether the role involves interaction with vulnerable populations (e.g. minors or the elderly).

  • The level of financial or confidentiality risk associated with the role.

For example, a background check for an entry-level retail position may simply involve a criminal records search. 

In contrast, a senior financial analyst role with access to sensitive data might warrant a more comprehensive screening, including employment verification, education verification, and a credit check.

By aligning your background checks with legitimate business needs related to the job's responsibilities as listed in a job description, you demonstrate they are job-related and consistent. 

That happens to be a key requirement under the FCRA.

Taking a tailored approach also helps use your organization's time and resources efficiently during the hiring process. 

Be sure to document the justification and criteria used to determine background check procedures for each position or group of positions.

Step 3: Get Written Authorization from Applicants

Before conducting any employment background checks, the FCRA requires employers to obtain written authorization from the applicant. 

This authorization must be a stand-alone document that exists solely for this purpose. 

The authorization form should be clear and easy for the applicant to understand. It must state that the background check may be conducted by a third-party consumer reporting agency and that information obtained may be used for employment purposes.

Specifically, the FCRA requires the authorization document to be separate from the employment application and include:

  • A disclosure that a consumer report may be obtained for employment purposes.

  • A statement identifying the consumer reporting agency conducting the check.

The applicant's signature on the authorization form confirms they have been notified, and they give consent for you to proceed with the background check.

Attempted oral authorization or burying the authorization statement deep within the employment application itself does not meet FCRA requirements. The written consent must be obvious and unmistakable.

Without proper authorization, your organization risks improperly accessing the applicant's information and facing potential legal action. 

Be sure to retain the signed authorization form securely throughout the hiring process and the employee's tenure.

Step 4: Follow Adverse Action Procedures

If the information uncovered during a background check may cause you to deny employment to an applicant, the FCRA requires employers to follow specific adverse action procedures.

Adverse action refers to any denial of employment or other decision that negatively impacts the applicant based on information contained in a consumer report, such as a background check.

Before taking any adverse action, employers must:

1. Provide a pre-adverse action notice to the applicant, including:

  • A copy of the background check report.

  • A summary of the applicant's rights under the FCRA.

  • Information about the applicant’s right to dispute.

  • Contact details of the CRA to contact for dispute resolution

2. Allow the applicant a reasonable opportunity (typically around 5-10 business days) to dispute or explain any negative information.

3. Consider any information the applicant provides, challenging the report.

4. If you are still proceeding with the adverse action after the waiting period, issue an adverse action notice that includes:

  •   The specific reasons for the decision.

  •   The contact information of the company that provided the report.

  •    A statement notifying the applicant of their right to dispute inaccuracies.

This required two-step notification gives the applicant a chance to correct any errors or present mitigating circumstances before a final decision is made. 

Failing to follow these procedures can expose your company to claims of negligence or violation of the FCRA.

Maintain clear documentation of the entire adverse action process, including copies of all notices sent to the applicant. Some states require additional steps in the process, so it’s important to consult legal counsel for guidance on time frames and notice wording.

Step 5: Maintain Secure Records and Disposal Practices

Maintaining the privacy and security of personal information is essential for FCRA compliance. 

The law requires employers to use consumer reports solely for permissible purposes and to properly store or dispose of them after their intended use.

To protect applicant and employee data, employers should:

  • Restrict access to background check records to those directly involved in the hiring process on a need-to-know basis.

  • Follow proper record retention practices based on applicable laws and your organization's document retention policy.

  • Permanently dispose of background check records (shredding reports) once the permissible purpose has been served and retention requirements met.

Failing to implement and follow secure record handling and disposal practices can result in FCRA violations.

Improperly disposed background check information that enables identity theft or consumer harm can lead to liability exposures.

Work closely with your legal and compliance teams to develop a documented data security plan and train all relevant employees on proper protocols. 

Regular audits of your record keeping and disposal practices are recommended.

Maintaining FCRA-compliant security standards demonstrates your organization's commitment to applicant and employee privacy while mitigating risks.

The Benefits of Using Commercial Investigations for Background Checks  

While employers can conduct background checks themselves, using Commercial Investigations as your third-party provider for background investigations offers significant advantages in maintaining FCRA compliance and running an efficient screening program.

At Commercial Investigations, we have over 20 years of experience navigating the complex landscape of federal, state, and local record sources while staying ahead of changing regulations. 

We invest heavily in compliance resources, allowing our clients to leverage our deep expertise.

When you partner with Commercial Investigations, you can be confident you are:

  • Only conducting background checks permissibly and directly relevant to each position.

  • Using the latest disclosure and authorization forms vetted by our compliance team.

  • Following all required adverse action procedures 

  • Accessing the most comprehensive and up-to-date data sources available.

  • Properly securing background check records and disposing of them per FCRA regulations.

We offer user-friendly online portals allowing applicants to easily provide consent and dispute any inaccuracies. 

Our rigorous quality assurance processes deliver reliable, court-verified data to support well-informed hiring decisions.

While conducting in-house background checks may seem cost-effective initially, the risks of non-compliance can prove extremely costly. 

Partnering with an experienced, accredited provider like Commercial Investigations is an investment in compliance that mitigates legal risks.

Don't Roll the Dice on FCRA Compliance

Following the five key steps outlined in this guide is crucial for employers who want to conduct background checks while remaining compliant with the FCRA.

Prioritizing FCRA compliance not only helps mitigate legal risks, but also demonstrates your organization's commitment to fairness, privacy, and building a qualified, trustworthy workforce.

At Commercial Investigations, we understand the intricacies of the FCRA and make compliance our top priority. We offer employers a proven path to conduct background screenings confidently and consistently.

Don't gamble with background checks and risk the potential consequences of non-compliance. Contact our team today to get started.