· Digital Footprint Check · Content Marketing  · 20 min read

Criminal Record Check for Employers a How-to Guide

A complete guide to compliant criminal record check for employers. Learn the legal rules, consent process, and how to make fair, defensible hiring decisions.

A complete guide to compliant criminal record check for employers. Learn the legal rules, consent process, and how to make fair, defensible hiring decisions.

A criminal record check is a standard part of hiring. It screens candidates for convictions that could be a problem for the job. It’s part of responsible hiring: managing risk, keeping the workplace safe, and meeting regulations. But you have to follow federal, state, and local laws.

Building Your Compliant Screening Foundation

A person signing a document on a clipboard, symbolizing consent for a background check.

Before running your first search, build a solid legal and ethical framework for the whole process. You need a documented, consistent process tied to your business’s specific needs and risks.

It starts with a written background check policy. This document outlines your procedures so every hiring manager applies the same standards. That consistency is your best defense in a discrimination claim.

Define Which Roles Require a Check

A common mistake is applying one screening policy to every opening. It’s inefficient and can cause legal trouble. Your policy should specify which roles warrant a check, and why.

A job handling cash, sensitive financial data, or work with vulnerable people has a clear business need for a background check. A role without those responsibilities probably doesn’t.

Key Takeaway: Avoid blanket policies. The principle is “job-relatedness”: any screening criteria must be relevant to the specific duties of the role you’re filling.

A tailored approach shows you’ve thought through the risks for each position, rather than erecting a broad, potentially discriminatory barrier.

The laws governing background checks are a patchwork of federal, state, and local rules. The Fair Credit Reporting Act (FCRA) sets the ground rules at the federal level, but it’s just the starting point.

The Equal Employment Opportunity Commission (EEOC) offers guidance so your screening doesn’t discriminate against protected classes. This is where “individualized assessment” matters: you consider the nature of the crime, how much time has passed, and whether it’s relevant to the job. See the full process in our guide on how to conduct background checks.

Here’s a quick breakdown of the main legal frameworks you’ll deal with.

Legal FrameworkKey Requirement for EmployersPrimary Goal
FCRAObtain written consent, provide pre-adverse and adverse action notices.Ensure accuracy, fairness, and privacy of information in consumer reports.
EEOC GuidanceAvoid blanket bans and perform individualized assessments of records.Prevent employment discrimination against protected classes.
State & Local LawsComply with “ban-the-box” rules and specific reporting limits.Provide fair hiring opportunities by delaying criminal history inquiries.

Understanding these layers of compliance is crucial for building a process that is both effective and fair.

Beyond these general rules, some industries have their own specific requirements. For instance, the transportation sector relies heavily on tools like the FMCSA Pre-employment Screening Program (PSP) to review a commercial driver’s safety history, adding another layer to their compliant screening foundation.

The demand for these checks is exploding. The global market for employment criminal background checks is on track to hit $6.38 billion by 2029, growing at an impressive 10.3% annually. In the U.S. alone, over 90% of employers now use these checks for at least some of their hires, especially in high-risk industries where mitigating liability is paramount.

On criminal record checks, getting a candidate’s consent is your first real move—and it’s where compliance gets serious right out of the gate. This isn’t just about having someone sign a form. It’s a critical legal step governed by the Fair Credit Reporting Act (FCRA), and one tiny misstep can torpedo your entire screening process before it even launches.

The whole thing hinges on two key documents: the disclosure and the authorization. They might sound similar, but they do two very different, equally important jobs. Think of it like this: the disclosure is the “what and why,” and the authorization is the “yes, you can.”

Why a Standalone Disclosure Is Non-Negotiable

Under the FCRA, you must give the applicant a “clear and conspicuous” disclosure, letting them know you might run a background check (which the law calls a “consumer report”) for the job. The golden rule here? This document has to be standalone.

That means it can’t be buried on page five of a massive job application or tucked away in a thick onboarding packet. It needs to be its own thing, with the sole purpose of notifying the applicant about the background check.

Why the strict rule? The law is designed to make sure a candidate can’t possibly miss it. Picture someone rushing through a 10-page application; a single sentence about a background check squeezed between job history and references is easy to overlook. A standalone form is impossible to ignore.

A surprisingly common—and expensive—mistake is trying to cram extra legal language onto the disclosure. For instance, some companies will try to include a liability waiver, asking the applicant to release them from any claims tied to the background check. Don’t do it.

Critical Compliance Tip: Adding any extra information—like a liability waiver or an at-will employment clause—to your FCRA disclosure form can legally void the entire document. A federal court could easily decide you never got proper consent, opening your company up to serious legal trouble.

Keep the disclosure pure. Its only job is to disclose.

Securing Lawful Authorization

Once you’ve handed over that crystal-clear disclosure, your next step is getting the applicant’s written authorization. This is the document where the candidate officially gives you permission to proceed with the criminal record check.

Unlike the disclosure, the authorization form can be combined with other application materials. However, the best practice is to keep it separate or pair it directly with the disclosure. It just keeps things cleaner and leaves no room for confusion. This form is the applicant’s official green light.

So, what does a compliant consent process look like? It’s a three-part package:

  • Provide a Clear Disclosure: Present a document that only states a background check might be run for employment purposes.
  • Get Written Authorization: Obtain the candidate’s signature on a form that clearly allows you to conduct the check.
  • Supply an FCRA Rights Summary: You must also give the applicant a copy of the document “A Summary of Your Rights Under the Fair Credit Reporting Act.” This isn’t optional; it’s required.

Following these three steps ensures everyone is on the same page. The candidate knows what you’re doing, they’ve given you the go-ahead, and they understand their legal rights from the very beginning.

While the FCRA creates the federal standard, you can’t stop there. You have to pay close attention to state and even city laws, which often add extra layers of compliance. These local rules can get specific and almost always provide greater protection for applicants.

For example, some states have unique requirements for the exact wording that must appear on the consent forms. Others might mandate that you provide a specific state-issued summary of rights in addition to the federal one. In North Carolina, an employer requesting a state-level check has to provide a special form signed by the applicant that consents to the use of fingerprints and other identifying information.

Keeping up with these local quirks is an absolute must for any company hiring in multiple states. What works perfectly in Texas might fall short in California or New York. It’s precisely why so many businesses partner with professional screening providers who can supply legally vetted, jurisdiction-specific forms to handle all this complexity for them.

How to Interpret Background Check Results Fairly

You’ve got the background check report in hand. Now comes the hard part—the moment that requires real judgment, not just data collection. This is where you shift from simply gathering facts to making a nuanced, human decision. The goal isn’t to find a reason to say “no,” but to fairly assess potential risk in the context of the actual job.

First things first, you need to understand what you’re even looking at. The report from your Consumer Reporting Agency (CRA) isn’t a simple pass/fail slip. It’s a complex collection of information pulled from different places, and knowing how to decode it is everything.

Infographic about criminal record check for employers

This decision tree really drives home the point that a fair interpretation starts way before you even see a record. It begins with a transparent, legally sound consent process, ensuring candidates know exactly what’s happening from the get-go.

Decoding Criminal Records

Let’s be clear: not all criminal records carry the same weight. A common and costly mistake is treating every flag on a report with the same level of alarm. To do this right, you have to know the difference between the types of records you might see.

  • Felonies vs. Misdemeanors: The difference is huge. Felonies are serious crimes like major fraud or assault. Misdemeanors are less severe—think petty theft or disorderly conduct. The gravity of the crime itself should be your starting point.
  • Convictions vs. Non-Convictions: A conviction means someone was found guilty. A non-conviction, on the other hand, could be a dismissed case, an acquittal, or an arrest that never even led to charges. Many states, including New York and Kentucky, flat-out prohibit employers from considering non-conviction records.
  • Pending Charges: This means the case is still open. Your company policy needs a clear rule for this. Most employers will simply pause the hiring decision until there’s a resolution.

It’s also worth noting a pretty surprising trend. Over the last decade, the number of job candidates with a criminal record has actually dropped from around 7–8% to about 4–5% in most Western countries. This shift, analyzed in a 2025 report from First Advantage on global screening trends, is largely thanks to better screening technology, “ban-the-box” laws, and reforms that seal minor offenses.

The EEOC’s Individualized Assessment Framework

If you take one thing away from this section, let it be this: you must perform an individualized assessment, as required by the EEOC. This means you have to ditch any blanket policy that automatically disqualifies someone just for having a criminal record. It just doesn’t fly. You need to look at each case on its own merit using a specific three-part framework.

Key Takeaway: An individualized assessment is your legal safeguard against discrimination claims. It proves you made a thoughtful, job-related decision rather than relying on a rigid, unfair rule.

This framework boils down to considering three key factors for any record that gives you pause.

1 The Nature and Gravity of the Offense

First, look at the crime itself. What actually happened? A conviction for financial fraud is a massive deal for an accounting role but might be almost meaningless for a landscaping job. On the flip side, a history of assault would be a major red flag for a customer-facing position but less critical for someone doing solitary data entry. You have to draw a direct line between the offense and the specific risks of the job.

2 The Time That Has Passed

Next, how long ago did this happen? Time is a powerful indicator of rehabilitation. A non-violent misdemeanor from when the applicant was 19 carries far less weight than a serious felony from last year. The EEOC wants to see that you’ve considered what the candidate has been doing since the offense, not just the offense itself. A long stretch of law-abiding behavior speaks volumes.

3 The Nature of the Job

Finally, and this is the most critical piece, you have to connect the criminal conduct to the specific duties of the job. This is the “job-relatedness” test. Will the person be handling cash? Working with vulnerable people like children or the elderly? Accessing sensitive data? Operating dangerous machinery?

The link has to be direct and tangible. For example, a DUI from five years ago is highly relevant for a delivery driver but almost irrelevant for a remote graphic designer. By focusing on this connection, you ensure your decision is based on a real business necessity, not an unfair bias.

What to Do When a Background Check Comes Back with Red Flags

So, you’ve run a background check, and something concerning popped up. This isn’t the end of the road. In fact, it’s the start of a very specific, legally required process you cannot skip.

This is called the adverse action process. It’s a two-part communication dance mandated by the Fair Credit Reporting Act (FCRA). Getting the steps right is critical. Fumbling here can land your company in some seriously hot water, leading to expensive lawsuits and painful compliance fines.

The whole point is to give the candidate a fair shake—a chance to see what you’re seeing and correct any errors before you make a final call. It’s a fundamental protection for them, but it also protects you.

Step 1: The Pre-Adverse Action Notice

Before you even think about disqualifying a candidate based on their background report, you have to send them a pre-adverse action notice. Think of this as a heads-up. You’re saying, “Hey, we found something in your report that we’re concerned about.”

This is not a rejection letter. It’s an invitation for the candidate to review the information and respond.

You must include two specific documents in this notice:

  1. A full copy of their background check report. They need to see the exact same document you’re looking at. No summaries, no shortcuts.
  2. The official “A Summary of Your Rights Under the FCRA” document. This is a standardized government form that explains their right to dispute any inaccuracies with the company that ran the check (the Consumer Reporting Agency, or CRA).

Once you send this package, the clock starts ticking on a mandatory waiting period.

Step 2: The All-Important Waiting Period

The FCRA doesn’t give a hard-and-fast deadline, but legal precedent and FTC guidance point to a minimum of five business days as a reasonable amount of time. This is your legal safe harbor.

This isn’t just a formality. This waiting period gives the candidate time to actually read the report, spot potential mistakes, and start the dispute process with the CRA. Rushing this step is one of the easiest ways to violate the FCRA.

Let’s imagine a real-world scenario. A candidate named Sarah applies for a role managing your warehouse inventory. Her background check reveals a felony fraud conviction. Your hiring policy, based on an individualized assessment, flags this as a dealbreaker for a job with access to valuable goods.

Instead of just tossing her application, you follow the law and send the pre-adverse action notice. Sarah gets the report and her jaw drops. The conviction belongs to someone else with the same name and a similar birthday—a classic mixed-file error. She immediately calls the CRA to get it fixed.

If you had skipped the waiting period, you would have illegally rejected a perfectly qualified candidate and opened your company up to a lawsuit.

Key Takeaway: The waiting period is a non-negotiable part of a fair and legally sound hiring process. It shields candidates from errors and shields your business from massive liability.

Step 3: The Final Adverse Action Notice

What happens if the candidate doesn’t respond, or they do, but the report is confirmed to be accurate? If you decide to stick with your decision not to hire them, you must send one last communication: the final adverse action notice.

This is the official notification that you are not moving forward with their candidacy.

This final letter must spell out a few key things:

  • The name, address, and phone number of the CRA that provided the report.
  • A clear statement that the CRA did not make the hiring decision and can’t explain why you made it.
  • A reminder of the candidate’s right to dispute the report’s accuracy with the CRA.
  • Information on their right to get another free copy of their report from that CRA within 60 days.

Throughout this entire back-and-forth, your communication needs to be professional, clear, and respectful. Following this framework ensures your hiring decisions aren’t just defensible—they’re also fair.

And remember, the results of a single background check are just one piece of the puzzle. It’s just as important to regularly review your overall screening policies to avoid systemic issues, which includes understanding adverse impact and how seemingly neutral policies can unintentionally screen out protected groups.

Ongoing Monitoring and Secure Recordkeeping

A secure server room with glowing lights, symbolizing data privacy and recordkeeping.

A successful pre-employment criminal check is a fantastic starting point. It gives you a clear snapshot of a candidate’s history right before you hire them. But what happens after they’re on the payroll?

The truth is, workplace risk doesn’t just disappear on an employee’s first day. That’s why the old “one-and-done” screening model is quickly becoming a thing of the past. The conversation is now shifting from a pre-hire-only mindset to a more continuous approach, closing a major gap in your company’s risk management plan.

The Rise of Continuous Criminal Monitoring

Continuous monitoring isn’t some fringe idea anymore; it’s rapidly becoming standard practice, especially in highly regulated fields like healthcare, finance, and transportation. These industries have always known that an employee’s off-the-clock conduct can directly impact their fitness for a job, particularly when they’re in a position of trust.

But this trend is spreading far beyond those regulated sectors. Recent background screening trend reports show that criminal background screening is undergoing a fundamental shift. A 2025 industry survey found that nearly 40% of large employers in the US and EU have either adopted or are currently piloting continuous monitoring programs.

The logic is simple. A traditional background check leaves you exposed if a current employee is later convicted of a crime that would have made them ineligible in the first place.

Of course, setting up a program like this demands the same legal care as pre-employment screening. You’ll need to get separate, crystal-clear consent from current employees for ongoing checks. Transparency is everything—make sure the policy is clear and applied consistently to everyone in a given role.

Best Practices for Secure Recordkeeping

Whether you’re handling pre-hire reports or alerts from an ongoing monitoring system, how you store that sensitive information is just as critical as how you get it. A sloppy recordkeeping process is a lawsuit waiting to happen.

Your number one job is to protect confidentiality. Background check results are filled with personal data and should never be tossed into a general employee personnel file where any manager can stumble upon them.

Key Takeaway: Create a separate, secure file—digital or physical—for all background check reports and related documents. Access must be locked down to a small number of authorized people, like specific HR staff, who have a legitimate business reason to view them.

This simple act of separation is your best defense against privacy breaches and claims that the information was used improperly.

Retention and Disposal Policies

Hoarding records forever is a liability, not an asset. You need a clear, written policy that spells out how long you keep background check files and, just as importantly, how you get rid of them securely.

So, how long is long enough?

  • FCRA Guidance: The Fair Credit Reporting Act doesn’t actually give a specific retention period, but the EEOC does.
  • EEOC Requirement: Federal anti-discrimination laws mandate that employers keep all personnel or employment records for one year after they are created.
  • Post-Termination: If an employee is involuntarily terminated, you must hang onto their records for one year from their last day.

As a practical rule of thumb, a retention period of at least two to three years is a safe bet. This covers the statute of limitations for most potential legal claims. Once that time is up, you have to destroy the files securely. That means shredding paper documents and permanently deleting digital files so they can’t be recovered.

For more insights on keeping sensitive information locked down, take a look at our guide on the top tools for monitoring your digital footprint.

Common Questions About Criminal Record Checks

Even with a solid process in place, you’re going to run into specific questions when conducting criminal record checks. It just happens. Getting these right is all about having clear, direct answers to make sure you stay compliant and confident in your hiring.

Let’s walk through some of the most frequent questions we hear from employers.

How Far Back Can an Employer Criminal Record Check Go?

This is easily one of the biggest points of confusion, and the honest answer is: it depends. The federal Fair Credit Reporting Act (FCRA) sets the floor, not the ceiling. For the most part, it stops consumer reporting agencies (CRAs) from reporting non-conviction information—think arrests that never led to a guilty plea—after seven years.

But here’s the catch: the FCRA doesn’t put any time limit on reporting actual criminal convictions. So, technically, a conviction from 20 years ago could pop up on a report at the federal level. This is where state laws become important.

Many states, like California, Kansas, and New York, are much stricter. They often cap the lookback period for all criminal history, including convictions, at seven or ten years. You have to know the specific laws for where your candidate lives and where they’ll be working.

What Actually Shows Up on a Background Check?

When you run a standard employment background check, you’re looking at a pretty specific set of records. You can generally expect to see details on:

  • Felony convictions, which are the more serious crimes.
  • Misdemeanor convictions, which are less severe offenses.
  • Pending criminal cases where charges have been filed but the case isn’t resolved yet.
  • Active warrants for an individual’s arrest.

What you won’t see are records that have been legally sealed or expunged by a court. Civil matters, like lawsuits or old bankruptcies, aren’t part of a criminal check, and neither are minor traffic violations like a speeding ticket. Knowing what’s included—and what isn’t—is crucial for setting the right expectations for your review process.

Can We Deny a Job Because of a Criminal Record?

The answer to this is a firm “no.” You cannot have a blanket policy that automatically rejects anyone with a criminal record. The EEOC is very clear on this: employers must conduct an individualized assessment for every candidate.

This means you have to carefully consider three key factors:

  1. The nature of the crime and how serious it was.
  2. How much time has passed since the offense.
  3. How the crime directly relates to the duties and responsibilities of the job in question.

If you’ve done that assessment and you’re still leaning toward not hiring the person, you have to start the formal adverse action process. This is non-negotiable. It gives the candidate a chance to see the report and clear up any mistakes. A criminal record can be a valid piece of the hiring puzzle, but it can’t be the only piece, especially when a modern employee’s background now includes their online life. You can learn more about the impact of your digital footprint on job opportunities from our in-depth guide.

Should We Check All Employees or Just Some?

Consistency is your best friend here and your strongest defense against discrimination claims. Your policy doesn’t have to mandate a background check for every role in the company. That might be overkill.

But for any specific role you do decide to screen for, you must screen every applicant for that role.

For example, if you determine that all “Senior Accountant” candidates need a criminal check because they’ll be handling company finances, then you have to run that same check on everyone who applies for that job. No exceptions. You can’t just pick and choose based on a gut feeling or an interview. This role-based consistency is what keeps your hiring process fair and legally sound.


A thorough, compliant screening process is foundational to protecting your organization. At Digital Footprint Check, we deliver in-depth pre-employment screening that goes beyond the basics, combining criminal record checks with education and employment verification to give you a complete picture of every candidate. Get started with Digital Footprint Check today.

Back to Blog

Related Posts

View All Posts »