The uncomfortable question background screening needs to ask in the age of AI
The future of screening may not be about knowing more. It may be about knowing what matters.
For decades, the background screening industry has become increasingly sophisticated at finding information as we have more databases, sources, geographies, way more data and now, increasingly, more artificial intelligence.
Technology has made it possible to find, connect and analyse information at a scale that would have been unimaginable when many of today’s screening processes were first designed but perhaps we need to pause and ask a slightly uncomfortable question:
Just because we can check something, should we?
The ability to find information doesn’t automatically make that information relevant and more information doesn’t necessarily produce a better hiring decision.
The industry’s natural instinct: check more
There is a natural logic behind expanding a screening programme.
If one check helps identify risk, surely another check can help identify more and another and yet another.
The problem is that screening isn’t an exercise in collecting the maximum amount of information about a person.
It is an exercise in understanding and managing risk. Those are very different objectives.
Imagine recruiting for a role where the principal risks relate to financial integrity, access to sensitive systems and regulatory obligations.
Now imagine adding a series of additional checks simply because they are available.
Have we necessarily made the organisation safer or have we simply created more information to process, interpret, store and eventually dispose of?
More isn’t automatically better, sometimes it is simply more.
Screening should follow risk, not curiosity
This is perhaps one of the biggest opportunities for our industry.
A financial services organisation, a healthcare provider, a technology company and a logistics business do not face exactly the same risks.
Even within the same organisation, two employees can have dramatically different risk profiles depending on:
- the role they perform;
- the information they access;
- their level of authority;
- their interaction with customers;
- regulatory requirements;
- geographic exposure; and
- the consequences if something goes wrong.
So why should their screening programmes necessarily look identical?
The better question isn’t: “What checks can we run?”
It is: “What could realistically go wrong in this role, and what evidence would help us manage that risk?”
That takes us from checklist screening to risk-based screening and I believe that is a much more mature way to think about our industry.
The “because the client asked for it” problem
There is another uncomfortable conversation worth having.
What should a screening provider do when a client requests a check that may not add meaningful value?
Is the role of the screening provider simply to say: “Yes, we can do that.”
Or should an experienced screening partner sometimes say: “I’m not sure you need that.”
I would argue for the latter.
A truly strategic screening provider shouldn’t necessarily be the organisation that sells the client the largest number of checks.
It should be the organisation that helps the client understand which checks actually matter and that requires expertise. It requires understanding the client’s risk environment and occasionally, it requires being willing to challenge the brief.
AI makes this question more important
This becomes particularly relevant as AI transforms what is technically possible.
AI can search, it can match, correlate, identify patterns and can even surface anomalies. It can potentially connect information across sources that a human reviewer would never have the time to examine manually.
That is incredibly powerful but it also creates a new temptation:
“If AI can find it, why wouldn’t we look at it?” because the question isn’t whether AI can find the information and is rather: What does that information actually tell us? Perhaps more importantly: Does it have anything meaningful to do with the risk we are trying to manage?
The danger of data overload
Imagine two screening reports.
Report A
Contains five highly relevant, verified findings directly connected to the requirements of the role.
Report B
Contains thirty pieces of information, five are relevant, ten require interpretation, eight are largely irrelevant and seven generate potential discrepancies that need investigation.
Which report gives the employer greater confidence?
We instinctively assume the second and I’m not convinced.
The second may simply give the decision-maker more noise to interpret and noise can be dangerous.
It can distract from genuinely important signals, create unnecessary candidate friction, increase false positives, lengthen turnaround times and create additional privacy and data governance obligations. It can encourage decision-makers to attach significance to information that was never particularly relevant to the role in the first place.
The quality of a screening programme shouldn’t be measured by how much information it produces.
It should be measured by how effectively it supports a sound decision.
What happens to the information we didn’t really need?
This also takes us back to a question we explored earlier in this series – once information has been collected, it has to be governed:
- Where is it stored?
- Who can access it?
- How long is it retained?
- What is the audit trail?
- When does the information become obsolete?
- When should it be securely purged?
- What happens to it when the candidate changes employer?
- What happens when AI systems have used that information to generate additional insights or risk signals?
The easier technology makes information collection, the easier it becomes to forget that data has a lifecycle. Just because information can be retained indefinitely doesn’t mean it should be, just because information can be reused doesn’t automatically mean it should be and just because information can be inferred doesn’t necessarily mean it belongs in a hiring decision.
The candidate isn’t a data set
This may sound obvious, but I think it gets lost surprisingly easily.
A candidate can become a collection of data points:
- Name
- Date of birth
- Address
- Education
- Employment
- Identity documents
- Criminal records
- Professional qualifications
- Digital signals
- Risk indicators
It is imperative to remember that behind every one of those data points is a person:
A name variation isn’t automatically suspicious, an employment gap isn’t automatically concerning, an unusual career path isn’t automatically a red flag, a discrepancy isn’t a verdict and rather it is a reason to ask a question.
Sometimes, the answer to that question completely changes the meaning of the original data and that is why context matters.
The screening provider’s role may need to change
This is where the industry has an opportunity to evolve as historically, the relationship has often looked something like:
Client → orders checks → screening provider → produces report
Perhaps the future looks more like:
Client → defines risk → screening partner advises → appropriate checks → contextual interpretation → proportionate decision
That is a different relationship.
The screening provider becomes less of a check supplier and more of a risk and trust adviser and that, in my view, is where genuine strategic value lies.
Not in saying: “We can check that too.” but sometimes in saying:
“Let’s first understand why you want to check it.”
The paradox of better technology
Here is the paradox I see coming.
The better our technology becomes at finding information, the more important human judgement becomes in deciding what deserves attention.
AI may eventually make it possible to uncover hundreds of potential signals about an individual but that doesn’t mean an employer should act on hundreds of signals.
The real expertise may increasingly lie in filtering and separating: signal from noise, relevance from curiosity, risk from difference, evidence from inference and perhaps most importantly information from meaning.
We should also be willing to say “no”
This is where I think the industry needs a cultural shift. A sophisticated screening professional shouldn’t only know how to run a check but should also know when not to run one.
They should be able to challenge unnecessary duplication, question disproportionate screening, identify irrelevant data collection, explain the implications of additional checks and help clients design screening programmes around actual risk rather than simply around everything that happens to be available.
Sometimes the most valuable advice a screening provider can give isn’t:
“Here’s another check you could add.”
It is rather:
“You probably don’t need this one.”
That is not reducing value but rather demonstrating expertise.
The AI question we should really be asking
We spend a lot of time asking: “What can AI do for background screening?”
I think there is a more important question. “What should AI be allowed to do in background screening?”
Alongside that:
- What information should it access?
- What should it ignore?
- What should it infer?
- What should it never infer?
- Which signals should trigger human review?
- Who is accountable for the final decision?
- How does a candidate challenge an outcome?
- How do we ensure the system doesn’t turn a weak signal into a strong conclusion?
These aren’t simply technology questions. They’re questions about governance, ethics, proportionality and trust and these questions will become more important, not less as the technology improves.
Perhaps the future is about knowing enough
I think we have spent decades becoming better at finding information.
The next stage of our industry’s maturity may be about becoming better at knowing when enough is enough, enough information to assess the relevant risk, enough verification to establish confidence, enough investigation to understand an anomaly, enough retention to satisfy legitimate requirements and then – stop as the purpose of background screening isn’t to build the most comprehensive dossier possible on a candidate.
It is to help an organisation make a better-informed and proportionate decision.
My Two Pence…
I’ve spent enough years around background screening to become slightly suspicious of simple words.
Verified. Discrepancy. Clear. Risk.
They sound definitive but often, they aren’t and I think we need to be equally careful about another word:
More – More checks, more data, more monitoring, more AI, more information.
None of these automatically mean better screening and perhaps the most sophisticated screening programme isn’t the one that checks the most, it’s the one that knows what not to check.
We have spent years becoming better at finding information and AI will make us extraordinarily good at it but finding information has never really been the hardest part. Knowing what is relevant, what is proportionate and what should simply be left alone, that’s where judgement comes in as a candidate doesn’t become safer because we’ve collected another ten pieces of information about them.
An employer doesn’t become more protected because its screening checklist is longer and a screening provider doesn’t become more valuable because it can search more databases.
The future of screening isn’t knowing more about people.
It’s knowing enough to make a better decision and having the discipline to stop there.
That’s my two pence.
Questions I’d Love the Industry to Answer
- Are we designing screening around risk, or simply around what technology makes possible?
- Should a screening provider ever challenge a client’s requested screening scope?
- At what point does additional information become noise rather than insight?
- How should AI distinguish between a relevant signal and an irrelevant anomaly?
- Who decides what information is genuinely proportionate to a particular role?
- As technology makes data collection easier, are we becoming disciplined enough about what we choose not to collect?
Just because we can check it, doesn’t mean we should.
Perhaps that is one of the most important conversations the background screening industry needs to have next.

