AI in reference and background checks
HR artefact

What to ask a background-check vendor before you sign

Seven questions to put to any screening or background-intelligence vendor, the five-step process that keeps a person on the decision, and the bright lines AI never crosses in a background check.

Background-check vendor question set · Free, no sign-up · Plain markdown

Download the Background-check vendor question set (.md)

What this is for

So much of the verification stage now runs through vendors that the procurement decision is a control in its own right. A tool you cannot bound is a tool that collects and decides on your behalf, and you wear the consequences, not the vendor.

This is the vendor question set from the reference and background checks explainer, with the five-step process and the bright lines that sit alongside it.

How to use it

Send the seven questions to whoever owns your screening tool contract and keep the answers in the file. A vendor who cannot answer them has told you something useful.

Then run the five-step process on your next vacancy. Use placeholders, never real candidate data, when you build and test it. The whole design separates two things the tools deliberately blur: verifying a fact is confirming something checkable against a source, while inferring a character is a model producing a judgement from indirect signals. A safe process collects verifiable facts and lets a person form the judgement.

The artefact

Section 1: seven questions to ask before you sign

  1. What exactly does the tool collect about a candidate, and can each collection be switched off individually?
  2. Can the automated scoring or risk rating be disabled entirely while keeping the verification and drafting features?
  3. Where is candidate data processed, and if any step is offshore, what does your APP 8 position rest on?
  4. Have you tested the tool for bias against protected attributes, and can we see the method and the results?
  5. What sources feed any digital footprint or social media feature, and how do you handle mistaken identity?
  6. How long do you keep candidate data after the check, and can we direct deletion when it is finished?
  7. When the tool gets something wrong about a candidate, what does the contract say about who is responsible?

Section 2: the five-step process that holds the line

1. Scope before you collect.

Decide, for the specific role, what verification is actually reasonably necessary: confirming employment history and dates, confirming qualifications where they are an inherent requirement, and role-relevant referee input. Write it down. Anything outside that list needs a specific justification, not a default scrape.

2. Get real consent, and be specific.

Tell the candidate exactly what you will check, how, and by whom, including any third-party or offshore provider, and get consent for anything sensitive. Notice alone is not consent. If you use a screening vendor, that consent has to cover them.

3. Let AI draft the questions and structure the notes.

Have the model produce a consistent, role-relevant set of reference questions for the role, the same for every candidate so comparisons are fair, and use it to capture structured notes and a neutral summary of what the referee actually said. This is where AI earns its place: consistency and completeness.

4. Verify against the source, not the summary.

Treat the AI summary as a draft. Confirm the load-bearing facts, dates, title, and whether they would re-hire, against what the referee said and the documents, not against the model's paraphrase. If a background report contains adverse information, give the candidate a genuine chance to respond before it counts against them.

5. A person decides, and records why.

The hiring decision, and the weight given to each piece of verification, is made and documented by a person. No automated risk score is the decision. If the answer is no, the recorded reason is a role-relevant, defensible one, never a protected attribute.

Section 3: the bright lines

Never let a model:

  • Make the hire or no-hire decision, or reduce a person to a risk score you act on without reading.
  • Run indiscriminate social media or web scraping on candidates as a default control. It collects too much, it is often wrong or about the wrong person, and it drags protected attributes into the decision.
  • Receive a candidate's sensitive information, including health or criminal history, in a public AI tool with no data agreement.
  • Displace the candidate's right to respond to adverse information.

And do not keep what you did not need. Sensitive candidate information gathered for a check that is now finished should not linger in a model's history or a vendor's store. Collect narrowly, then dispose of it under your retention rules.

Section 4: the Monday checklist

  • Pull the reference questions you used for your last hire and count how many were genuinely tied to the role's inherent requirements. That gap is your baseline.
  • Write a one-page collection scope for your next vacancy: what you will verify, why each item is reasonably necessary, and who will see it.
  • Save a role-relevant reference question set into your recruitment templates.
  • Update your candidate consent wording so it names every check, every third-party provider, and any offshore processing, then have it reviewed.
  • Check every line of an AI summary of an old, fully de-identified reference call against the source.
  • Send the seven vendor questions to whoever owns your screening tool contract, and diarise the answers.
  • Brief your hiring managers in one paragraph: AI drafts and summarises, a person verifies, decides and records why.

TheAICommand. Intelligence, At Your Command.

Download the Background-check vendor question set (.md)← Read the full article

General information and education only. Not legal, compliance, financial, or professional advice. This artefact is assembled from AI in reference and background checks and adds nothing to it. Free to use and adapt internally, with attribution appreciated and no warranty. Check it against your own obligations and your organisation's policies before you rely on it.