I have been reading HireRight’s 19th annual Global Benchmark Report, based on responses from more than 1,900 HR, risk and talent acquisition professionals worldwide.
The EMEA findings show that 39% of organisations experienced identity fraud in 2025, which is close to four in ten respondents.
AI-generated documents, synthetic identities and increasingly convincing fake candidate profiles are making an old problem much harder to detect. In response, the use of identity verification across EMEA has risen from 33% last year to 57% this year.
Nevertheless, 44% of EMEA organisations conducting identity verification still handle it internally, and 40% of those provide no specialist training to the people responsible.
I understand why businesses bring checks in-house. Cost, speed and control all count. But if fraud has changed and the capability has not, how much confidence should we place in the result?
TL;DR
- Identity fraud, candidate discrepancies and workforce trust now seem to be part of the same hiring-risk conversation.
- Identity verification confirms who is being assessed, while other checks are needed to understand the history and risk relevant to the appointment.
- Screening should reflect the access and responsibility attached to a role, before hire and at sensible review points afterwards.
- Traditional checks, identity verification and human-reviewed Digital Risk Screening each reveal a different slice of the risk spectrum. To be thorough, you need as many slices as possible.
Identity certainty is one layer of workforce confidence
Before assessing someone’s history, qualifications or suitability, you need confidence that you are assessing the correct person. Identity verification provides that assurance, while the remaining checks examine different parts of the appointment.
HireRight found that 90% of EMEA respondents uncovered candidate discrepancies during background screening in the previous 12 months. Employment and education verification remained the areas most likely to expose inconsistencies.
The report also found that 38% of EMEA respondents named potential misalignment with corporate values as one of the main risks they want employment screening to help reduce. This ranked ahead of the cost of a bad hire, workplace safety and security, and financial loss through criminal activity.
I find that shift interesting because it changes what screening is being asked to do.
Employers, of course, still need to verify identity, qualifications, employment history and formal records. Yet organisations are also trying to understand whether the available evidence supports the level of trust, access and responsibility they are about to grant.
As I see it, organisations still need to close the workforce confidence gap between confirming the facts a person has supplied and understanding the relevant risk signals around a high-trust appointment.
The screening perimeter should follow access
The HireRight report also found that 34% of EMEA respondents do not conduct any post-hire checks, despite the way people’s roles and access can change after appointment.
A person’s access rarely remains static after joining an organisation. They may be promoted, move into a regulated role, gain access to sensitive systems or data, take responsibility for vulnerable people, or become part of a critical supplier relationship.
The original screening decision may have been proportionate for the job they joined to do. Why should we assume it remains proportionate when their access changes?
The same principle applies to supply chain: contractors, freelancers and consultants who can hold access and responsibilities comparable to permanent employees, while being screened through a different provider or to a different standard.
I really think that the type of screening should mirror the consequence of the access being granted. Review points should be limited to genuine changes in trust, responsibility or exposure. Continuous monitoring would be neither necessary nor proportionate.
For example:
1️⃣ Before appointment to a high-trust role.
2️⃣ When someone moves into a position with greater access to people, systems, data or money.
3️⃣ When a contractor or supplier-side worker receives comparable access to an employee.
4️⃣ Where a defined event creates a legitimate reason to review the available evidence again.
Treating a pre-employment check as a permanent conclusion may be administratively convenient. I am not convinced it reflects how access changes in the real world.
Different checks answer different questions
I don’t think organisations should rely on one check as a complete assessment. Each part of the process covers a different slice of the risk spectrum, with its own defined evidence and limitations.
Identity verification helps establish that the candidate is who they claim to be.
Employment, education, criminal record and other traditional checks help verify formal history and known outcomes.
Digital Risk Screening, or DRS, adds a fairly thick slice: structured visibility into relevant digital exposure signals those checks were never designed to reach.
To be thorough, you need as many of these slices as possible.
Safehire’s AI supports discovery across lawfully accessible surface, deep and dark web sources within a defined scope. Human analysts then validate identity, relevance and context before anything is reported.
This distinction affects who remains accountable for the decision. AI is good at speed and coverage. It should not decide whether somebody is suitable, trustworthy or safe. That judgement belongs with people using relevant evidence, organisational policy and the wider circumstances of the role.
DRS is an additional intelligence layer. It supports safer recruitment, workforce risk and other high-trust access decisions while traditional checks and identity verification continue doing the jobs they were designed to do.
What I take from HireRight’s report
HireRight has put useful evidence behind something many employers can already feel: candidate fraud is becoming more sophisticated while the definition of workforce risk is expanding.
My reading of the evidence is this: screening cannot remain one event with one permanent answer. Things change. People and what they get up to changes. Nevertheless, the checks should be proportionate to the decision, and ownership of the judgement should be clear:
- verify identity;
- validate the formal history relevant to the role;
- add proportionate digital risk intelligence where access carries consequence;
- use human review before acting on a finding;
- define when a material change in role or access should trigger another review;
- apply comparable standards to employees and contingent workers where their access is comparable.
Accuracy and quality remained the leading priorities for employers choosing a screening provider in HireRight’s global findings, which is the correct emphasis. The volume of data tells us very little about its usefulness. Decision-makers need evidence that is relevant, validated, contextualised and usable.
The more trust, access or responsibility a role carries, the more deliberate the screening decision should be.
For HR, talent, safeguarding and risk leaders, I would use HireRight’s report to ask three questions:
1️⃣ Where does identity verification sit in our current process?
2️⃣ Do the people running it have the capability to recognise the risk we now face?
3️⃣ Does our screening still match the access people hold after they join?
If any answer is unclear, there is work to do.
Read HireRight’s 2026 Global Benchmark Report: www.hireright.com/benchmark2026
Read HireRight’s release and global findings: HireRight Releases 2026 Global Benchmark Report


.png)
.png)
.png)




.png)