A background check program is only as strong as its weakest step. Most employers run checks — but far fewer have a documented, consistently applied program that covers provider selection, FCRA compliance, adjudication, post-hire monitoring, and policy review. This checklist covers every step. Use it to audit your current program or build a new one from scratch.
Why Best Practices Matter More Than the Check Itself
Running a background check is easy. Running one correctly — with the right scope, the right compliance process, and the right follow-through — is where most programs fall short. The liability in background screening rarely comes from a missed record. It comes from a broken process: a disclosure buried in an employment application, an adverse action taken without the required notice, an inconsistent policy applied differently to different candidates, or a post-hire gap that left a vulnerable population exposed.
The checklist below is organized by phase — before the check, during the check, after the check, and ongoing. Work through each phase against your current program and flag any gaps.
Phase 1: Before You Run Any Checks — Program Setup
Provider Selection
- Provider is PBSA-accredited — independently audited for data quality, compliance, and security
- Provider uses direct county court access, not database-only searches
- Provider automates FCRA disclosure, consent, and adverse action workflows
- Provider offers component-level status tracking — not just a generic "in process" status
- Provider pricing is transparent with no hidden platform fees or monthly minimums
- Provider has a documented accuracy rate and turnaround benchmarks you can verify
Written Screening Policy
- Written policy exists and is documented — not just an informal practice
- Policy specifies which roles get which checks — not a one-size-fits-all package
- Policy defines adjudication criteria by role type — what is automatically disqualifying, what requires individualized review
- Policy includes post-hire rescreening cadence by role risk tier
- Policy specifies continuous monitoring enrollment criteria for high-access roles
- Policy is applied uniformly to every candidate for the same role — no exceptions for familiarity or urgency
- Policy is reviewed at least annually for state law changes and regulatory updates
State Law Compliance
- Ban-the-box laws reviewed for every state where you hire — timing of criminal history inquiry confirmed
- State-specific conviction reporting limits confirmed (11 states limit convictions to 7 years)
- Credit check restrictions reviewed for each relevant state
- State-specific adverse action notice requirements confirmed beyond federal FCRA baseline
- Clean Slate law status reviewed for states where you hire — California, Pennsylvania, Minnesota, Virginia, New York, Oklahoma all have active provisions as of 2026
Phase 2: For Each Candidate — The Pre-Hire Process
Disclosure and Consent
- Standalone written disclosure provided to candidate — not embedded in the employment application
- Disclosure contains no extraneous information — a disclosure form with added language has generated FCRA class action settlements
- Written consent obtained before any check is ordered
- Fresh consent is not needed if original consent form indicates an employee can be rescreened at any time during the duration of their employment
Scope Selection
- Check package matched to role risk level — not defaulted to the same package for every role
- Address history trace included — identifies residential history and aliases for comprehensive coverage
- County criminal searches ordered for all relevant jurisdictions identified by address history
- Federal criminal search included for standard professional roles and above
- Role-specific components added where applicable: MVR for driving roles, credit for financial roles, professional license for credentialed roles, drug testing where policy requires
- For healthcare roles: OIG exclusion screening included
- For roles involving vulnerable populations: sex offender registry check included
Candidate Information Quality
- Full legal name collected — including any prior or maiden names
- Exact employment dates collected — month and year, not just year
- Legal employer names collected — not trade names or DBAs
- PEO arrangement confirmed if applicable
- Prior states of residence collected for multi-state candidates
Phase 3: When Results Come Back — Adjudication and Adverse Action
Clear Results
- Results reviewed before candidate proceeds — clear doesn't mean unreviewed
- Results documented and retained
Flagged Results
- Adjudication matrix applied — does the record meet automatic disqualification criteria for this role?
- If not automatically disqualifying: EEOC individualized assessment conducted — nature of offense, time elapsed, job relevance evaluated
- Individualized assessment documented — what was considered and what conclusion was reached
- Candidate given opportunity to provide context before final decision for borderline cases
- Decision applied consistently — same criteria applied to every candidate in the same role with a similar record
Pre-Adverse Action Process
- Pre-adverse action notice sent before any final adverse decision
- Notice includes: copy of the background check report, FCRA Summary of Rights
- Candidate given a reasonable waiting period — typically five business days minimum
- Candidate's response reviewed before final decision if received
Final Adverse Action
- Final adverse action notice sent if proceeding with not hiring
- Notice includes: name and contact information of the CRA, statement that CRA did not make the hiring decision, candidate's right to dispute at any time
- All documentation retained — adjudication record, pre-adverse notice, any candidate response, final notice
For the complete step-by-step adverse action process, see Background Check Compliance Explained (FCRA Guide).
Phase 4: After the Hire — Post-Hire Screening
Rescreening Program
- Rescreening cadence defined by role risk tier — annual for high-risk, every 1-2 years for moderate, every 2-3 years for lower-risk
- Role changes trigger immediate rescreen — regardless of when last check ran
- Fresh written consent collected before each rescreen
- FCRA adverse action process applied if rescreen surfaces a disqualifying finding
Continuous Monitoring
- High-access roles enrolled in continuous monitoring — employees working with children, patients, financial accounts, or security-sensitive systems
- Written consent collected at enrollment — separate from pre-hire background check consent
- Alert workflow defined — who receives alerts, what response is required, how decisions are documented
- For healthcare employers: OIG exclusion monitoring running on monthly cadence minimum
MVR Monitoring
- Driving roles enrolled in ongoing MVR monitoring — not just a pre-hire check
- DOT-regulated employers confirming annual MVR review is in place per FMCSA requirements
- Alert workflow for driving-related disqualifying events defined
For more on post-hire monitoring options, see How Do Companies Monitor Employees for Criminal Activity After Hiring?
Phase 5: Policy Maintenance
|
Review Item
|
Frequency
|
Why
|
|
Ban-the-box law updates
|
Annually (minimum)
|
37+ states and 150+ localities — requirements change regularly
|
|
Clean Slate law changes
|
Annually
|
New states adopting; existing provisions expanding
|
|
State conviction reporting limits
|
Annually
|
Legislature-driven changes
|
|
Adjudication matrix
|
Annually
|
EEOC guidance updates, new court decisions
|
|
Provider accreditation status
|
Annually
|
Confirm PBSA accreditation is current
|
|
OIG exclusion list screening
|
Monthly
|
Healthcare employers — OIG's stated standard
|
|
Continuous monitoring alerts
|
As received
|
Review and document every alert per adjudication policy
|
|
Acquisition news for your provider
|
Ongoing
|
Post-acquisition pricing and service changes are predictable
|
The Five Questions to Ask Your Provider Right Now
If you're not sure whether your current provider and program are holding up, ask these five:
1. Are you PBSA-accredited? Verify in the PBSA directory — don't just take their word for it.
2. What percentage of standard packages return within 24 hours — and can you show the distribution, not just the average?
3. Do you use direct county court access or database aggregation for criminal searches?
4. Do your FCRA workflows automate disclosure, consent, and adverse action — or does our team manage those steps manually?
5. What is your NPS and applicant satisfaction score?
FAQs: Background Check Best Practices
What is the most important background check compliance requirement for employers?
The FCRA pre-adverse and adverse action process — sending the candidate a copy of the report and their Summary of Rights before making a final adverse decision, then allowing a waiting period for them to respond. This is the most commonly skipped step and the most common source of FCRA litigation against employers. See our FCRA compliance guide for the complete process.
How often should employers review their background check policy?
At minimum annually — and more frequently if you hire across multiple states or in regulated industries. Ban-the-box laws, Clean Slate provisions, state conviction reporting limits, and adjudication guidance all change regularly. A policy that was compliant 18 months ago may have gaps today.
What is PBSA accreditation and why does it matter for choosing a provider?
PBSA accreditation is an independent audit of a screening company's data quality, compliance practices, and security standards. Fewer than 13% of U.S. screening companies hold it. For employers whose hiring decisions carry legal and safety consequences, working with an accredited provider is the most reliable way to verify that your vendor's processes meet an independently audited standard.
Should employers run the same background check on every candidate?
No — check scope should be matched to the access level and risk profile of the role. A standard professional role warrants county and federal criminal searches plus employment verification. A driving role adds an MVR. A credentialed role adds license verification. Running the same comprehensive package on every role costs more and slows hiring for positions where the extra components add no meaningful risk reduction.
What is the biggest mistake employers make with background checks?
Taking adverse action based on a background check result without following the FCRA pre-adverse action process — sending the notice, waiting the required period, and then issuing a final notice. Many employers also skip individualized assessment before declining candidates based on criminal history, creating EEOC disparate impact exposure. Both are fixable with a compliant provider and a documented adjudication process.
Do the same best practices apply to contractor and volunteer background checks?
Yes — FCRA applies to contractor and volunteer checks run through third-party providers the same way it applies to employee checks. The scope may differ based on access level, but the compliance process is identical. See Background Checks for Contractors: What Employers Need to Know and Background Checks for Volunteers: What's Required and What's Smart for population-specific guidance.
Related Blogs
Conclusion
A background check program with gaps in any one phase creates exposure in every phase — because the FCRA, EEOC, and negligent hiring liability don't distinguish between "we didn't know" and "we knew but didn't follow through." Use this checklist to audit your current program against each phase. Fix the gaps you find before they become the basis of a complaint, a lawsuit, or an incident that a compliant program would have prevented.
Ready to build a background check program that holds up at every step? Explore Bchex Core Screening — PBSA-accredited, with automated FCRA compliance, county-level coverage, and post-hire monitoring built in.