SHRM Background Check Best Practices for HR Professionals

TL;DR

SHRM background check best practices center on building a documented, consistent, and legally defensible screening program that aligns with FCRA requirements, EEOC guidance, and applicable state fair-chance laws. The core principles: standardize your process across all candidates, tie screening criteria to job relevance, and maintain audit-ready documentation at every step. Organizations that follow these frameworks reduce adverse action disputes, hiring delays, and negligent-hire liability simultaneously.

What HR Teams Need to Know

SHRM doesn’t issue binding regulations, but its research, toolkits, and benchmarking data function as the de facto industry standard for how HR departments structure defensible screening programs. When compliance officers, plaintiff attorneys, or auditors evaluate whether your background check process was “reasonable,” they frequently reference SHRM-aligned practices as the baseline for what a competent HR function should have done.

This matters because background screening sits at the intersection of three legal exposure points: FCRA compliance (federal disclosure and adverse action requirements), EEOC guidance (disparate impact from criminal history policies), and a patchwork of state and local fair-chance laws that restrict when and how you can ask about criminal records.

Your screening workflow touches nearly every stage of the hire lifecycle — from the offer letter contingency language, to the timing of your background check request, to how your team documents individualized assessments before rescinding an offer. A gap at any point creates litigation risk, and inconsistency across hiring managers is the single most common driver of disparate treatment claims.

SHRM-aligned best practices give you a framework to standardize this workflow so it doesn’t depend on individual recruiter judgment calls.

Detailed Analysis

The Four Pillars of a SHRM-Aligned Screening Program

Most defensible programs are built around four operational pillars. Each maps to a specific compliance risk.

Pillar What It Requires Primary Risk If Missing
Standardized job-relevance criteria Written criteria tying screening scope to specific job duties EEOC disparate impact claims
Consistent disclosure/authorization process Clear, standalone FCRA disclosure forms; separate authorization FCRA statutory damages ($100–$1,000 per violation)
Documented adverse action workflow Pre-adverse notice, waiting period, individualized assessment, final notice Class action exposure under FCRA
Ongoing policy audits Annual review of screening matrix against state law changes State fair-chance violations

Benchmarking Your Program

SHRM’s talent acquisition benchmarking data consistently shows that organizations with formalized screening policies report fewer time-to-fill delays and lower new-hire turnover in the first 90 days compared to organizations using ad hoc, manager-discretion screening. The lesson for your team: consistency isn’t just a compliance requirement, it’s a retention and efficiency lever.

A well-structured program typically includes:

  • A written screening policy approved by legal counsel, distributed to all hiring managers
  • A standardized authorization form compliant with FCRA Section 604(b)(2) — no liability waivers embedded in the disclosure
  • A defined decision matrix for criminal history review, scored by job relevance, recency, and severity — not blanket disqualification
  • A centralized vendor relationship with your Consumer Reporting Agency (CRA) to ensure consistent turnaround and audit trails

Individualized Assessment Framework

When a criminal record surfaces, EEOC guidance recommends you evaluate three factors before making an adverse decision:

1. Nature and gravity of the offense
2. Time elapsed since the offense or completion of sentence
3. Nature of the job held or sought

Document this assessment in writing every time. If your team can’t produce this documentation during an audit or lawsuit, your “individualized assessment” defense collapses regardless of what your policy says on paper.

Practical Operational Implications

For your day-to-day team, this translates into a few non-negotiable operational habits:

  • Never let a hiring manager independently reject a candidate based on a raw background check result without HR/compliance sign-off.
  • Timestamp everything — disclosure signed, report received, pre-adverse notice sent, waiting period expired, final decision made.
  • Standardize your waiting period at a minimum of 5 business days between pre-adverse notice and final adverse action, even though FCRA doesn’t specify an exact number — this is the de facto industry standard most courts and CRAs recognize as reasonable.

Compliance Considerations

Federal Requirements (FCRA)

The FCRA governs any background check performed through a third-party CRA. Core obligations include:

  • Standalone disclosure — the disclosure document cannot be bundled with other application materials or contain extraneous liability language.
  • Written authorization — obtained before you initiate the check.
  • Pre-adverse action notice — provided before you take any adverse action, giving the candidate a copy of the report and a summary of FCRA rights.
  • Post-adverse action notice — sent after the waiting period if you proceed with the adverse decision.

EEOC Guidance on Criminal History

EEOC’s enforcement guidance doesn’t prohibit criminal history screening, but it flags blanket “no felons” policies as high-risk for disparate impact claims, since conviction rates vary significantly by race and ethnicity. Your policy should apply the individualized assessment framework outlined above rather than automatic disqualification.

State and Local Fair-Chance Variations

This is where most multi-state employers get exposed. Requirements vary widely:

Requirement Example States/Cities
Ban-the-box (no criminal question on application) California, Illinois, New York City, Philadelphia
Delayed inquiry (criminal history only after conditional offer) California, Colorado, Massachusetts
Credit report restrictions California, Colorado, Illinois, Connecticut, New York City
Salary history bans affecting screening scope Multiple states — verify before requesting prior compensation

If you operate in multiple jurisdictions, your screening policy needs a state-specific overlay matrix, not a single national policy. What’s compliant in Texas may trigger a violation in California or NYC.

negligent hiring liability

On the flip side of over-screening risk is under-screening risk. Courts have consistently held employers liable for negligent hiring when a reasonable background check would have surfaced information relevant to foreseeable harm — particularly in roles involving vulnerable populations, financial access, or driving responsibilities. Your screening scope should be defensible in both directions: not overly broad (EEOC risk) and not insufficiently thorough (negligent hiring risk).

Action Steps for Your Team

Immediate (quick wins):

  • Audit your current disclosure and authorization forms against FCRA Section 604(b)(2) requirements — this is a 30-minute legal review that closes one of the most common litigation gaps.
  • Confirm your CRA is FCRA-compliant and accredited — verify their audit trail, dispute resolution process, and turnaround SLAs.
  • Standardize your adverse action email/letter templates so every hiring manager uses the same language and timeline.

Near-term (30–90 days):

  • Build or update your job-relevance screening matrix, mapping specific roles to specific screening scopes (criminal, credit, driving record, drug screening, professional license verification).
  • Train hiring managers on what they can and cannot do independently — screening decisions should route through HR/compliance, not sit with the requesting manager.
  • Map your state-specific obligations if you hire across multiple jurisdictions, and assign ownership of quarterly regulatory monitoring.

Ownership:

Your HR compliance lead or Talent Acquisition Director should own the policy; your legal counsel should review it annually; your background check vendor should provide the operational infrastructure — automated adverse action workflows, audit-ready documentation, and ATS-integrated ordering — so your team isn’t manually tracking timelines across spreadsheets.

Longer-term:

  • Conduct an annual policy audit aligned with SHRM’s compliance calendar recommendations, particularly after any state legislative session that touches employment law.
  • Benchmark your turnaround times and candidate drop-off rates against industry standards to identify where screening friction is costing you qualified candidates.

FAQ

Does SHRM certify or accredit background check vendors?
No. SHRM provides research, toolkits, and educational resources, but it does not certify or endorse specific CRAs or screening platforms. Vendor accreditation for FCRA compliance typically comes from industry bodies rather than SHRM directly.

What’s the difference between FCRA compliance and SHRM best practices?
FCRA compliance is a legal floor — the minimum federal requirements for using consumer reports in hiring decisions. SHRM best practices go further, incorporating EEOC guidance, state fair-chance nuances, and operational consistency standards that reduce litigation risk beyond the federal minimum.

How often should we update our background check policy?
Review your policy at least annually, and immediately after any state or local fair-chance law changes in jurisdictions where you hire. Multi-state employers should assign quarterly monitoring given how frequently state-level screening laws shift.

Can a hiring manager reject a candidate based solely on a criminal record?
Not without an individualized assessment documented by HR or compliance. EEOC guidance requires evaluating the offense’s nature, time elapsed, and job relevance before making an adverse decision — a manager acting unilaterally creates significant disparate impact exposure.

What’s the biggest compliance gap SHRM-aligned employers typically have?
Inconsistent adverse action timelines across hiring managers and locations. Centralizing this workflow through automated, vendor-supported processes is the single highest-leverage fix most organizations can make.

Conclusion

Building a screening program that reflects SHRM background check best practices isn’t about chasing a certification — it’s about creating a documented, consistent, job-relevant process that holds up under EEOC scrutiny, FCRA audit, and state-law variation simultaneously. The organizations that get this right treat screening as an operational system, not a series of one-off manager decisions.

BackgroundChecker.com supports HR teams building exactly this kind of infrastructure: FCRA-compliant workflows, automated adverse action sequencing, dedicated account management, and direct integration with the ATS and HRIS platforms your team already uses. Whether you’re screening 10 hires a year or 10,000, our platform is built to scale your compliance program alongside your headcount, with transparent per-check pricing and no guesswork on turnaround times. Request a demo or start screening today to see how a standardized, audit-ready program can reduce your legal exposure and your time-to-hire at the same time.

—

This article is for informational purposes and does not constitute legal advice. Consult qualified legal counsel for compliance guidance specific to your organization.

Leave a Comment