
Industry
Part of Background checks with the guesswork removed (2027 update)
Background check policy: what protects the person being checked
A background checks policy for a small organization: what it must decide, a skeleton to adapt, and the parts that protect the person being checked.
A policy for checking people is mostly a policy about restraint. Deciding what you will not look at is harder, and more useful, than deciding what you will.
This skeleton is for a small employer, a club, a landlord, or a volunteer group: anyone who runs checks occasionally, not constantly, and wants the receiving end of it to look like the ordinary process described in background checks.
It assumes no legal advice and gives none. Your regulator owns the jurisdictional detail. The shape below stays constant while that detail changes.
What to take away
- Decide the purpose first. Everything else in the policy is downstream of what decision the check informs.
- Collect the minimum, hold it briefly, and write down when it gets deleted.
- The clause that matters most to the person being checked is the one that lets them see and correct the report.
What the policy has to decide
Seven questions. A draft that skips any of them will be improvised in the moment, which is where unfairness comes from.
| The question | The failure if it is unanswered |
|---|
Seven questions a policy must answer
- Which roles are checked, and why
- What kind of check each role gets
- Who runs it, and who pays
- What is collected, and what is refused
- Where it is stored, and for how long
- Who sees the result
- What happens when something appears
The skeleton
Change the wording. Keep the order, because the order is the policy.
Policy skeleton, in order
- Purposecheck only to inform a decision
- Scopenamed roles, levels, reasons
- Consent and timingwritten, after real decision
- What we collectminimum identity data only
- Storage and deletionone place, dated schedule
- Adverse informationdisclose before decision closes
Purpose. We check people only where the check informs a specific decision, and we write down what that decision is for each role. We do not check people out of general caution.
Scope. These roles are checked, at this level, for this reason. Roles not listed are not checked. Adding a role to the list is a decision made in advance rather than during an application.
Consent and timing. We ask for written consent, separately from the application, and only once there is a genuine decision to make. We do not request identity documents before an offer, conditional or otherwise. We pay for any check we require.
What we collect. The minimum needed for identity matching. We do not collect financial details, we do not ask for account access of any kind, and we never ask anybody for a login, a password, or a verification code.
Storage and deletion. Documents are stored in one named place, seen by one named role, and deleted on a stated schedule. The date of deletion is recorded. Nothing is kept in email.
Adverse information. If something in a report may count against a person, we tell them before the decision is final, give them the report, and allow a stated period for them to respond or to dispute it with the company that produced it. A decision is not communicated as final until that period has passed.
Relevance. We consider whether what appears is relevant to this role, how long ago it was, and what has happened since. We record the reasoning in one or two sentences, because a reason written down is a reason that can be reviewed.
Complaints. Anybody checked may ask what was held about them and how the decision was reached, and may complain to the regulator without going through us first.
Review. The named role reviews this document annually, and after any incident, with the date recorded.
The clauses people leave out
Three, and each of them is the one the person being checked cares about most.
Three clauses people leave out
Clause
- Disclosure
- Report before decision closes
- Deletion
- An actual deletion date
- Relevance
- One written sentence linking finding to role
What it gives the person checked
- Disclosure
- A real chance to correct
- Deletion
- No indefinite document hoard
- Relevance
- A decision someone can explain
The disclosure clause, which gives them the report before the decision closes rather than after it. Without that window, the correction route in background checks rules 2027 is theoretical.
The deletion clause, with an actual date. Organizations that check people occasionally accumulate identity documents indefinitely, and a breach then exposes people who applied years ago and were never hired.
The relevance clause, which forces one written sentence connecting what appeared to the role in question. It is the only defense against a decision that nobody can later explain.
What not to put in it
Keep it short enough to be read by the person who has to apply it at four on a Friday.
Leave out statements of law, including thresholds and time limits. They change, and a stale policy that quotes them is worse than one that points at the regulator.
US employers can start from the Equal Employment Opportunity Commission's guidance on background checks and the consumer reporting side from the Consumer Financial Protection Bureau's explanation of what a credit report is. Elsewhere, name your own regulator.
Leave out any process that involves asking a candidate for access to an account, which is not screening. And leave out social media searching as a formal step unless you can say what decision it informs, since in practice it collects protected characteristics you then cannot unsee.
Running it without a compliance team
Small organizations do this well by keeping the moving parts to a minimum.
Minimum moving parts
- One named person handles checks
- One place stores the documents
- One calendar entry deletes them
- One sentence records the reasoning
- Unanswerable questionsfind out, come back
One named person handles checks, one place stores the documents, one calendar entry deletes them, and one sentence records the reasoning. Where an applicant asks a question you cannot answer, the honest response is that you will find out and come back, not an improvised assurance.
If your organization is also targeted by impersonation, which is common wherever hiring happens, internal rules to stop a fake candidate or recruiter are in impersonation policy template.
The candidate-side view of what a fake process looks like is in background checks examples.
Common questions
Do we need a policy if we hire twice a year?
Yes, at one page. The decisions it settles are the ones you will otherwise make while under time pressure with a candidate waiting.
Can we ask candidates to pay for their own checks?
Do not. Whatever the local position, it is the single clearest marker of a fraudulent process, and asking puts your organization in that company.
How long should we keep the documents?
Long enough for the decision, plus any period your regulator requires, and then delete. Write the number in the policy rather than deciding case by case.
What if a check reveals something unrelated to the role?
Record why it is unrelated and move on. The relevance clause exists to make that a decision rather than a drift.
Should candidates be told which company runs our checks?
Yes. It costs nothing, it lets them correct an error at the source, and a process you are unwilling to name is a process worth reviewing.







