
Ensure your business meets background check compliance with our 2026 guide. Follow essential FCRA and EEOC steps to avoid costly mistakes.
Employers must follow a defined FCRA workflow, apply EEOC individualized-assessment principles, and map state and local exceptions before acting on any background-check results. The core sequence is non-negotiable: issue a standalone written disclosure, obtain written authorization, certify your permissible purpose to the consumer reporting agency (CRA), send a pre-adverse notice that includes the full consumer report and the current CFPB Summary of Rights, wait a meaningful period (typically at least five business days, longer in some jurisdictions), conduct an individualized assessment for any criminal history, and then issue a final adverse-action notice if you proceed. State and local rules layer on top of every one of those steps.
Top three immediate compliance checks HR can execute today:
The Fair Credit Reporting Act (FCRA) governs third-party consumer reports used in hiring. The Equal Employment Opportunity Commission (EEOC) sets the nondiscrimination guardrails. The Federal Trade Commission (FTC) and CFPB share enforcement authority over FCRA compliance. Getting all three right simultaneously is the baseline expectation for any U.S. employer running background checks.
Background check compliance requires a defined FCRA procedure, documented EEOC individualized assessments, and a living state-rule matrix that is updated as new laws take effect.
| Point | Details |
|---|---|
| Standalone disclosure is mandatory | The FCRA disclosure must be a separate document with no extraneous text before any report is ordered. |
| Full report in pre-adverse notice | Send the complete consumer report, not a summary, along with the current CFPB Summary of Rights. |
| Map jurisdictional hold periods | Federal guidance supports at least five business days; several states and cities require longer windows. |
| Document individualized assessments | Apply the EEOC’s three-factor framework and retain written records for every criminal-history decision. |
| Paradigm advisory support | Paradigm provides multi-state compliance audits, adverse-action playbook implementation, and vendor oversight to reduce hiring-related legal exposure. |
The FCRA is the federal baseline for any employer that uses a third-party consumer reporting agency to obtain background information on applicants or employees. It prescribes specific documents, specific timing, and specific certifications — none of which are optional. According to FTC guidance, when employers use third-party consumer reports, they must provide a standalone disclosure, obtain written authorization, certify user responsibilities to the CRA, and follow a two-step adverse-action process that includes the full report and a Summary of Rights.
Every employer using a CRA must have these documents in place before ordering a report:
Common FCRA violation drivers: Courts and plaintiffs’ attorneys focus on three procedural failures more than any others: bundling the disclosure with other application documents, sending a summary rather than the full consumer report in the pre-adverse notice, and truncating the waiting period between pre-adverse and final adverse notices. SHRM notes that providing a summary instead of the full CRA report during pre-adverse action is among the most frequent employer mistakes, and courts have relied on this distinction in FCRA cases.
The CFPB’s updated Summary of Rights is a required attachment to every pre-adverse notice. Verify with your CRA that the version they are delivering matches the current CFPB-published form. If your vendor cannot confirm this, treat it as a contract compliance issue and escalate accordingly.
The EEOC expects employers to avoid discrimination when using background information and to conduct individualized assessments whenever criminal-history information factors into a hiring decision. This is not a courtesy standard — it is the framework the EEOC uses to evaluate disparate-impact claims under Title VII. The EEOC’s guidance on background checks makes clear that blanket exclusion policies based on any criminal record, without regard to job-relatedness, carry significant legal risk.
When criminal history appears in a report and you are considering it in your decision, document your analysis against three factors:
Document this analysis in writing for every candidate whose criminal history influenced the decision. A hiring manager’s verbal judgment is not a defensible record.
Practical steps to reduce disparate-impact risk:
Pro Tip: Design a one-page individualized assessment form that hiring managers complete for every candidate whose criminal history is under review. The form should capture the three EEOC factors, the job-relatedness analysis, and the final recommendation with a signature line. Standardizing the form reduces inconsistency and creates a defensible paper trail.
Federal law is the floor. States and cities build walls, ceilings, and entirely separate rooms on top of it. Treating FCRA compliance as sufficient for multi-state hiring is one of the most common and costly mistakes employers make. Background check laws vary materially by state, affecting timing, lookback periods, permitted check types, and the adverse-action process itself.
The categories of state and local rules that most frequently affect hiring workflows are:
| Rule Category | What It Restricts or Requires | High-Impact Jurisdictions |
|---|---|---|
| Ban-the-box timing | Delays criminal-history inquiry until after conditional offer or later stage | California, New York, Massachusetts, Philadelphia, Washington D.C. |
| Conviction lookback windows | Limits how far back a report may go (commonly 7 years for non-conviction records) | California, New York, Maryland, Massachusetts |
| Credit-check restrictions | Prohibits or limits credit reports for most non-financial roles | California, Colorado, Connecticut, Illinois, Maryland, Oregon, Washington |
| Automatic sealing / Clean Slate | Requires vendors to exclude automatically sealed or expunged records | Pennsylvania, Michigan, California, Utah, and expanding |
| Local adverse-action timing extensions | Requires hold periods longer than the federal baseline | San Francisco, New York City |
| Public contractor rules | Imposes additional background-check or E-Verify obligations | Federal contractors, many state agencies |

Ban-the-box laws vary by state and locality and commonly require delaying criminal-history inquiries until after a conditional offer or a later hiring stage. In jurisdictions like New York City, the Fair Chance Act goes further, requiring a full individualized assessment and a specific waiting period before a final adverse decision on criminal history.
Clean Slate laws are expanding rapidly across multiple states, automatically sealing or expunging older nonviolent records. Employers must confirm that their CRA vendors are filtering these sealed records out of reports. Receiving and acting on a sealed record is a compliance failure regardless of whether the employer knew the record was sealed.
E-Verify is a separate but related obligation. It is a web-based system that verifies employment eligibility and connects to Form I-9 obligations. Federal contractors and employers in certain states face mandatory enrollment. If your organization operates in states with E-Verify mandates, confirm enrollment status and I-9 audit readiness as part of your background-check compliance program.
High-impact jurisdictions to audit first: California, New York, Massachusetts, Washington State, and Philadelphia each have layered rules that affect timing, lookback, and permitted check types. Texas has seen recent legislative activity affecting public-sector hiring. Any employer operating in more than two of these states should treat jurisdictional mapping as a standing compliance function, not a one-time project.
Pro Tip: Maintain a living state rule matrix in a shared document or compliance platform, with columns for ban-the-box trigger stage, lookback window, credit-check permission, Clean Slate filtering requirement, and local adverse-action hold period. Automate the longest applicable hold period in your ATS based on the candidate’s work location. When a new law passes, update the matrix before it takes effect.
Follow this sequence every time you use a third-party consumer report. Skipping or reordering any step creates procedural exposure regardless of the underlying hiring decision.
Step 1: Issue the standalone disclosure. Before ordering the report, provide the applicant with a document that contains only the FCRA-required disclosure language. No application text, no arbitration clauses, no liability waivers. Deliver it as a separate document, whether paper or electronic.
Step 2: Obtain written authorization. Collect a signed authorization from the applicant. The authorization may appear on the same page as the disclosure or on a separate page, but it must be distinct from any other document.
Step 3: Certify to the CRA. Submit the required FCRA §604(b) certification to your CRA before the report is ordered. This certification confirms your permissible purpose, your compliance obligations, and your commitment not to use the report in violation of equal-opportunity laws.
Step 4: Order the report and review results. When the report arrives, review it against your written job-related criteria. Do not make a final decision at this stage if adverse information is present.
Step 5: Send the pre-adverse notice. If you are considering taking adverse action, send the applicant the following before making a final decision:
Providing a summary rather than the full report is a documented litigation trigger. Courts have found this distinction sufficient to sustain FCRA claims.
Step 6: Wait a reasonable period. The FCRA does not specify an exact number of days, but regulatory guidance and court decisions support at least five business days as a baseline. Several jurisdictions require longer periods. Check the candidate’s work location before setting the timer.
Step 7: Conduct the individualized assessment (if criminal history is involved). During the waiting period, complete the three-factor EEOC assessment and document the analysis. If the applicant submits a dispute or provides mitigating information, review it before proceeding.
Step 8: Send the final adverse-action notice. If you proceed with the adverse decision, the final notice must include:
Pro Tip: Configure your ATS to block the final adverse-action send while a CRA reinvestigation is open. If an applicant disputes the report and the CRA is actively investigating, sending a final adverse notice before the reinvestigation closes is a procedural violation. An ATS rule that checks reinvestigation status before allowing the final notice to go out is a low-cost safeguard.
Electronic delivery is generally acceptable for all notices when the applicant has consented to electronic communications and the delivery method meets applicable e-signature and delivery confirmation standards. Retain proof of delivery for every notice.
Use narrower, role-focused checks. Criminal-history and driving records belong in safety-sensitive roles; credit reports apply only where the job involves genuine financial responsibility; education and license verifications are appropriate when role competency depends on a credential. Ordering every available check for every role is not a compliance strategy — it is a liability strategy for plaintiffs.
Common check types and their lawful limits:
Medical and genetic information are categorically off-limits in pre-offer screening. The Americans with Disabilities Act (ADA) prohibits medical inquiries before a conditional offer of employment. The Genetic Information Nondiscrimination Act (GINA) prohibits requesting or using genetic information in employment decisions. Post-offer medical examinations are permissible only when required of all candidates in the same job category and when the results are kept confidential in a separate medical file.
When you rely on a CRA or staffing partner, the employer’s compliance obligations do not transfer to the vendor. The employer remains responsible for the accuracy of the process. What vendor contracts and annual audits do is create a contractual and operational framework that reduces the risk of vendor-side failures becoming employer-side liability.
Contract clauses to require from every CRA:
Under FCRA §604(b), the employer must certify to the CRA before each report is ordered. Maintain records of these certifications as part of your background-check file for each candidate. Audit rights in the contract allow you to request documentation of the CRA’s accuracy procedures and filtering logic — exercise them annually.
Pro Tip: Run four vendor audit tests each year: (1) pull a sample of reports and verify that lookback windows match the candidate’s work-location requirements; (2) confirm that sealed and expunged records from Clean Slate jurisdictions are absent from the sample; (3) check that the CFPB Summary of Rights version matches the current published form; and (4) verify that the CRA’s reinvestigation turnaround times are meeting the contractual SLA. Document the results and retain them as part of your compliance program record.
For employers evaluating screening tools and vendor features, the selection criteria should include jurisdictional filtering capability, real-time Clean Slate updates, and documented FCRA accuracy procedures — not just turnaround speed and price.
Build a centralized policy with discrete state and local addenda, a job-related criteria matrix, and clear governance for final adverse decisions. A single national policy that ignores jurisdictional variation is not a compliance program — it is a liability waiting for a plaintiff.
The architecture of a defensible multi-state program follows this sequence:
Governance decisions that must be made in writing:
Pro Tip: Centralize final adverse-action decisions for criminal-history cases rather than delegating them to hiring managers. Hiring managers who apply criteria inconsistently — even with good intentions — create the disparate-impact patterns that EEOC investigations and class actions are built on. A centralized review step, even a brief one, adds a defensible layer of consistency.
For a broader view of how background-check programs fit into overall HR compliance, the governance decisions above should align with your organization’s existing documentation and escalation protocols.

Use these excerpted template elements and the checklist below to operationalize compliance. They reflect FCRA requirements, EEOC individualized-assessment expectations, and common state addenda obligations. They are content checklists, not legal forms — have counsel review final versions before use.
| Document | Must-Have Elements | Who Sends |
|---|---|---|
| Standalone disclosure | FCRA disclosure language only; no extraneous text | Employer, before ordering report |
| Written authorization | Applicant name, consent statement, signature, date | Applicant signs; employer retains |
| CRA certification | Permissible purpose, EEOC compliance commitment, adverse-action acknowledgment | Employer, to CRA before each report |
| Pre-adverse notice | Full report, CFPB Summary of Rights, dispute instructions, CRA contact | Employer, before final decision |
| Final adverse-action notice | Adverse decision statement, CRA contact, dispute rights, free-report notice | Employer, after waiting period |
When to consult an HR risk advisor:
Non-compliance with background-check regulations can produce statutory damages under the FCRA, EEOC disparate-impact claims, agency enforcement actions, class-action litigation, and reputational harm — and the risks are procedural as well as outcome-based. Courts do not require proof of actual harm to the applicant when the employer has committed a willful procedural violation.
Common claim types and their drivers:
FCRA litigation has risen materially in recent years, with procedural errors — missing fields, shortened waiting periods, and bundled disclosures — among the most frequent drivers of claims. Courts focus heavily on paperwork and timing, which means an employer can face significant liability even when the underlying hiring decision was substantively defensible.
The FTC and EEOC both maintain active enforcement programs. The FTC can seek civil penalties for willful FCRA violations, and the EEOC can pursue systemic investigations when adverse-impact data suggests a pattern of discriminatory screening. Neither agency requires a formal complaint to open an investigation.
For employers who want to understand the downstream financial exposure of non-compliance, HR cost control and claims management is a related risk area worth reviewing alongside background-check procedures.
The procedural requirements of background-check compliance are not complicated in isolation. A standalone disclosure, a written authorization, a pre-adverse notice with the full report — these are not ambiguous obligations. What makes them difficult is the operational reality of hiring at scale across multiple states, with multiple hiring managers, through a vendor whose filtering logic you may not have audited in two years.
The employers who face the most significant FCRA and EEOC exposure are rarely the ones who ignored the rules entirely. They are the ones who built a compliance program once, trained their team once, and then let the program drift as the organization grew, the vendor changed, and new state laws took effect without triggering an update. A disclosure form that was compliant in 2022 may not be compliant today if your CRA has changed its Summary of Rights delivery process or if a new Clean Slate law has taken effect in a state where you now hire.
The practical implication is that background-check compliance is a maintenance function, not a setup function. Automated hold periods in your ATS, a living state rule matrix, annual vendor audits, and periodic adverse-impact reviews are not bureaucratic overhead. They are the operational controls that keep a defensible program defensible over time. Small, systematic investments in these controls yield outsized risk reduction compared to the cost of a single class-action settlement or EEOC investigation.
Pro Tip: Three operational changes that reduce risk disproportionately to their cost: (1) automate the longest-applicable hold period in your ATS by work location, so no hiring manager can accidentally shorten it; (2) implement a universal individualized-assessment form that routes through HR before a final adverse decision is made; and (3) schedule an annual vendor audit on your compliance calendar the same way you schedule benefits renewal.
Paradigm’s advisory approach treats background-check compliance as one component of a broader HR risk architecture — not a standalone checklist, but a set of interconnected controls that protect the organization at every stage of the hiring process.
Operationalizing the guidance in this article — across multiple states, multiple job categories, and a vendor relationship that needs active oversight — is where most HR teams hit capacity constraints. Paradigm offers HR risk advisory and compliance support specifically designed for employers navigating these challenges, including multi-state background-check program design, vendor contract review, adverse-action playbook implementation, and procedural compliance audits.
Relevant services include:
For employers who need hands-on implementation support rather than a self-service checklist, request a risk advisory conversation with Paradigm’s team to discuss your organization’s specific compliance gaps and priorities.
These primary sources and trackers are the references HR leaders and legal counsel should consult for current statutory text, agency guidance, and jurisdictional updates:
This article is general information, not a substitute for advice from a qualified lawyer. Consult a qualified legal professional about your own circumstances before acting on anything here.