Remote and global hiring have allowed us to actually hire the best person for a role no matter where they live. What it hasn’t done, though, is made it any easier to manage the compliance obligations that come with screening them. A background check process that’s designed based on the norms of domestic hiring is destined to fail as soon as your candidate pool starts to cross a border – and that failure can be costly, legally risky, or both.
The good news is that a well-structured process can handle this complexity without adding unnecessary time to your hiring pipeline. The golden rule here is to design it with your candidate’s location in the driver’s seat, and then layer on your employer requirements.
- Start with a compliance map, not a checklist
- Apply a locale-first screening protocol
- Verify identity before you run anything
- Standardize your adverse action workflow for US candidates
- Evaluate criminal records against EEOC guidance
- Plan around international turnaround times
- Build secure data storage and access controls
- Work with a screening platform built for global complexity
- A process that protects speed and integrity at the same time
Related Articles
-
The Impact of Criminal Convictions on Employment Opportunities
-
5 Things to Know About a Pre-Employment Background Check
-
Complying with the Fair Credit Reporting Act
-
8 Important Reasons You Donโt Drink and Drive
-
Whatโs Considered Public Record?
-
Legal Checklist for New Hires
-
Background checks for overseas employees โ what businesses…
-
The Importance of Background Checks When Hiring Non-Nationals
-
Understanding the Dynamics of Wages and Employment: A Holistic Ex…
Start with a compliance map, not a checklist
Before initiating any background checks, you must first be aware of the legal framework that should apply to each candidate. There is no one-size-fits-all solution. The regulations determining what you can check, under what circumstances, and for how long you can store this information differ significantly from one country to another.
For example, in the US, the Fair Credit Reporting Act (FCRA) is the legal framework that regulates how agencies collect criminal record data and then how you verify it. The FCRA requires written consent to collect a report, specific disclosure language, and a formal Adverse Action process if you decide to turn someone away based on a report. In addition to the FCRA, US employers’ criminal background checking is influenced by EEOC guidance, “ban the box” laws at the state level and many local levels, and ongoing legislation.
For the EU, criminal record data is viewed under GDPR as a special category of personal data with very stringent limits on collection. In general, EU employers can’t run a criminal background check on an applicant except in very defined circumstances where the law justifies it. Typically that’s because the role the applicant is seeking is regulated in a way that requires a check. Germany and Spain apply this standard in the most extreme form, barring the commercial employment context from any criminal check unless the role hits a very high-security legal threshold.
Latin American privacy regulation is another layer different from the US and Europe, and most Asia Pac countries have a unique set of expectations around obtaining consent, data localization, and permissible use.
The first step to nailing this is to build a compliance map that documents the rules you must follow based on where the candidate lives. Then start building the rest of your process.
Apply a locale-first screening protocol
Once you’ve got a compliance map, your screening workflow has to feed into it automatically. This is easier said than done. The checks you can run for a candidate in Texas are quite different from the checks you can run for someone in Toronto, Frankfurt, or Sรฃo Paulo.
It’s a locale-first protocol. You don’t throw a screening package over the entire globe and cross your fingers. Instead, you decide what’s legally permissible and contextually appropriate for each locale. In many places, criminal record checks are only sanctioned for jobs with financial access, working with vulnerable populations, or government contracts and security clearance. Those jurisdictions tend to have a slightly broader criminal check with more stringent consent requirements. Other places don’t allow third-party criminal record checks at all.
It’s not that you can’t screen international candidates fully. It’s that the mix of what you’re checking changes. For some jurisdictions, employment verification and professional reference checks are far more important than criminal record checks, and they come with their whole suite of compliance concerns.
Verify identity before you run anything
Remote hiring has introduced a fraud risk that in-person hiring never had to manage: bad actors using stolen or synthetic identities to pass background checks for jobs they wouldn’t qualify for otherwise. A platform like Direct Screening can help catch this early – a criminal check on a fraudulent candidate isn’t a bad check – it’s someone else’s check.
Identity verification (IDV) needs to become the prerequisite step before ever initiating a criminal background check. Modern IDV includes biometric matching along with government-issued document verification to ensure the individual applying for a job is the same individual whose information will be screened.
This also helps protect you from a liability perspective. If you run a check and onboard an employee based on fake credentials, you’ve opened your organization up to risk well beyond a poor hire. Adding IDV into your consent flow, verifying identity at the same time you obtain authorization to run a check, is a low friction, high impact modification.
Standardize your adverse action workflow for US candidates
The Adverse Action process of FCRA cannot be compromised for US-based hires. Failing this process is often one of the most expensive legal lapses when it comes to employment screening compliance.
The FCRA outlines a particular order of operations. When pre-hire screening results lead you to consider taking adverse action against a candidate, the first document you must send is a pre-adverse action notice. This needs to include a copy of their background report and a summary of rights. The prospective employee is due a legally-mandated period to review the results and dispute their accuracy which means you can’t immediately proceed. The FCRA provides no exact number of days here – five business days is often cited as a proper ‘reasonable’ timeframe.
If you choose to go ahead with adverse action after this window then comes the final adverse action notice. This also must contain a specific reference to the name and contact information of the consumer reporting agency and a clear statement that this entity did not make the personnel decision.
Unfortunately, this rather strict but transparent procedure is vulnerable to truncation or outright flouting. No time for the prospective employee to respond to the report or no clear indication of the reporting agency in your final adverse action notice? You could be toast. Far too many employers face class-action lawsuits and serious settlements each year for these errors.
Evaluate criminal records against EEOC guidance
Ensuring that criminal records come to light in an accurate fashion is only part of the process. Once those records have been uncovered, you also need a set of criteria to measure the applicant against what you’ve found. The EEOC provides three factors to evaluate circumstances against. They are: the nature and gravity of the offense or offenses, the time that has passed since the conviction and/or completion of the sentence, and the nature of the job (in other words, whether the crime is relevant to the position).
A decade-old minor conviction shouldn’t weigh too heavily either compared to a recent, serious one, or to one that directly relates to the responsibilities of the role in question. Treasury Department positions asking applicants about financial-related arrests fit in here, as would a conviction or series of convictions for financial fraud.
Document every evaluation. When you have a written rationale tied to these factors, you can demonstrate that decisions are consistent across candidates and not influenced by protected characteristics. Arbitrary or inconsistent application of criminal record policies is exactly the kind of practice that draws EEOC scrutiny.
Plan around international turnaround times
One aspect that catches many HR teams flat-footed when they first build a global screening process is how widely international turnaround times (TAT) can vary. In the US, many criminal record databases are becoming digitized and searches are processed within hours. Domestically, this pushes out employer expectations on TAT for the rest of the world. But the reality isn’t so clean everywhere else.
In countries that require manual court record requests, have only physical archives, or rely on government agencies’ responses to requests – a criminal background check can take two to four weeks. Or longer. Especially if the documents require notarization, the request has to be submitted by a local national, or there’s no centralized criminal record system at all and everything has to be run through district level courts.
If your onboarding doesn’t pad your critical path timeline for this reality, the only choices you’ll have are to slip start dates somehow, or consider onboarding candidates before screening results come back. Neither is a position anyone wants to be in.
Last year, 93% of organizations conducted some form of employment background screening, with an increasing percentage sending these checks to candidates who have lived or live outside the country of hire. But that last statistic is growing at a faster rate than the ratio of many companies’ process evolutions.
There are two parts to getting this right in your hiring plan. Firstly, build regional international TAT estimates into the timeline. A global role with candidates in five countries should have five parallel screening tracks. The fastest track isn’t positively impacting your timeline if you’re holding up the other four. Build your hiring plan around the slowest.
Build secure data storage and access controls
Criminal record data is among the most sensitive personal information an employer handles. Once a background check is complete and a hiring decision is made, that data needs to be stored securely and purged on a defined schedule.
Your data retention policy should specify how long reports are held, who has access to them during the retention period, and how they’re destroyed when the retention window closes. Access should be limited to the people who genuinely need it – typically HR and legal – with audit logs that track every access event.
Encryption at rest and in transit is the baseline technical requirement. Cloud-based screening platforms that meet SOC 2 standards provide a reasonable starting point. What you want to avoid is sensitive reports sitting in shared drives, email inboxes, or HR folders without any meaningful access restriction.
GDPR adds a specific obligation here: data collected for a purpose that’s been fulfilled must be deleted. If you collected criminal record data to evaluate a candidate for a role and that process is concluded – either by hire or rejection – the clock starts on your retention window.
Work with a screening platform built for global complexity
Manually managing the moving parts of global background screening, such as using different consent forms and check packages by country, having varying turnaround time (TAT) expectations, and applying contrasting data handling and adverse action standards, is operationally fragile. A human mistake made in a compliance-sensitive process is not a matter of if but when it will happen.
Process reliability in screening for locations across the globe is achieved through a centralized screening platform, governed by the local compliance nuances of where your candidates live and automating their consent, then managing the adverse action workflow. An ATS integration with your centralized screening platform also matters, because it automates data transfer and removes the error-prone manual handoff between the recruiting module and your screening provider.
Sanctions and watchlist screening – checking candidates against databases like OFAC lists and Interpol red notices – is a component many employers add to global checks. It’s particularly relevant for roles with financial authority, international travel requirements, or access to sensitive government contracts.
A process that protects speed and integrity at the same time
Hiring managers often argue that a more thorough process leads to slower hiring. However, this is only the case if the process is not well-structured. When you have a clear global background check workflow, use the right technology and ensure compliance, you will avoid unnecessary delays caused by legal issues, unresolved results, or unexpected delays in processing checks. So, focus on setting up a good foundation and the speed of the process will improve.









