I came across Veremark’s 2026 Screening Benchmark Report this week. It covers analysis from close to half a million background checks from 2025, so definitely worth a read.
There is a lot of data in there. The 81% of employers that reportedly do no post-hire screening resonated.
It resonated because it concludes that a check somebody completes before joining may be the last one they ever have, even if they stay for years or move into a role with more access and responsibility.
TL;DR
- Veremark analysed close to half a million background checks conducted during 2025.
- Its report says 81% of employers have no form of post-hire screening.
- Different checks answer different questions, and the checks used most frequently do not produce the most frequent discrepancies.
- Screening depth should reflect the access, responsibility and potential consequences attached to the role.
- A screening decision has a shelf life (obviously). Organisations need to start thinking more deliberately about reassessment. Top of mind should be fairness, lawfulness and proportionality.
A snapshot
Here is a line from the Veremark report that sums up the issue rather well:
“Screening follows hiring. Risk doesn’t.”
The monthly numbers tell much the same story. Financial Services checks were up 53% from January to December. Business Services dropped 62% between September and December. People get checked when organisations are hiring; once they are through the door, the activity seems to fall away.
A background check gives you information about a person at a particular moment. Some checks confirm identity or eligibility. Others look at criminal records, sanctions, employment history, qualifications or financial history.
Each check has value, although each is limited to a particular set of information.
According to Veremark, database checks such as sanctions, criminal records, identity verification, financial history and right-to-work checks account for 58% of screening volume across its dataset. In Financial Services, that figure reaches 80%. These checks reportedly flag discrepancies in fewer than 1% of completed checks.
Education verification flags discrepancies in 21.1% of completed checks. Employment verification flags them in 15.3%. CV-gap checks have the highest reported rate at 51.7%.
Across all of Veremark’s checks, the average discrepancy rate was 5.3%. Education checks were roughly four times higher; CV-gap checks were close to ten times higher. It’s stating the obvious, I know, but the checks you choose shape what you are likely to find.
Veremark uses “discrepancy” as a broad category. It may be a small difference in employment dates or a qualification that cannot be verified. The report does not separate minor administrative differences from material fabrication, so a discrepancy should never be presented as automatic evidence of dishonesty (good thing to remember when reviewing any candidate report).
Likewise, a low discrepancy rate does not make a database check unimportant. A sanctions match or relevant criminal-record finding may be rare and still have serious consequences. Some checks are legal or regulatory requirements. You run them because the risk environment requires them.
My view of the data is that organisations need to be clearer about the question each check answers:
- Database and registry checks ask whether somebody appears on a specified formal record.
- Employment and education checks test whether claims about a person’s history can be verified.
- Digital Risk Screening looks for relevant signals in available online information that formal records may not contain.
- Post-hire reassessment asks whether something material has changed since the original decision.
A larger package may still leave gaps if the checks do not reflect the role’s actual risk profile.
Across the report, the average was four checks per candidate. Capital Markets ran 13.1; Business Services and Healthcare ran 2.5. That is quite a big range…
Business Services processed the most candidates, but Financial Services ran far more checks from fewer requests. So a business can screen lots of people and still do relatively little screening on each one.
I do not think every employee needs the same large screening package. That would add unnecessary cost, delay and intrusion.
The depth of checks should parallel the role: what the person can access, who depends on them and what the impact is if the organisation gets the decision wrong.
Personal opinion is that the risk department should play a bigger role.
The shelf life
Recruitment processes generally treat screening as a gateway. The candidate completes the checks, receives approval and joins the organisation. The file is closed.
The person’s access, responsibilities and circumstances can continue to change after the recruitment file is closed.
Someone might join in a junior role and, a few years later, be running a team, handling much more sensitive information or working directly with vulnerable people. That is quite a different risk profile from the one they were hired into.
A check performed three years ago cannot account for something that happened last month.
Veremark makes the point:
“Every month that passes after the initial check, the gap between what was verified and what is currently true widens.”
This is where the 81% figure becomes difficult to gloss over. For those employers, the recruitment check may be the only verification conducted, regardless of how long somebody remains in the organisation or how much their role changes.
I understand why hitherto this has been the case. Re-screening raises legitimate questions about privacy, proportionality, cost and employee trust. Continuous monitoring of everybody all the time smacks of 1984.
However, we shouldn’t trade in absolutes. Doing nothing after onboarding implies that the original information remains sufficient for as long as the person stays in the organisation. Any casual observer would conclude that is a flawed - and possibly ignorant - assumption.
For some regulated roles, reassessment is already required. The Veremark report refers to the FCA’s annual fitness-and-propriety assessment under the Senior Managers and Certification Regime. Employers also have continuing right-to-work obligations for people with time-limited permission.
Other organisations need to set their own defensible triggers. These may include:
- appointment to a higher-trust role;
- a substantial increase in access or responsibility;
- renewal of a time-limited permission or professional qualification;
- a defined periodic review for a regulated position;
- credible information that creates a legitimate need for reassessment.
The purpose and legal basis should be clear. Employees should know what the organisation does and why. Findings should be verified before action is taken, with protected characteristics and irrelevant information excluded from the decision.
A screening decision - like buying a new car - starts to lose value as soon as you drive it off the lot.
The layers
A defensible screening programme must accept there are limitations with every measure you take.
- Run statutory checks because they are required and valuable.
- Verify employment and qualifications where those claims are relevant.
- Add digital-risk screening where online behaviour or associations could create a material safeguarding, security or reputational risk.
- Reassess when the role or circumstances justify it.
Then make sure the left and right hands are talking to each other. Simply put, there should be consistency in how people risk is managed from pre-hire to eventual offboarding.
Technology (read AI) can increase coverage and surface information quickly. Human analysts should validate identity, context and relevance. A human in the organisation must decide what is fair, proportionate and connected to the duties of the role.
Conveniently, this is the model we’ve built at Safehire. Our work complements established background checks by searching defined open, deep and dark web sources for relevant digital-risk signals. Potential findings are reviewed by experienced analysts before they are reported.
Technology can gather and organise evidence quickly; an accountable person must still assess it and make the decision.
So I would say do the following:
- run the checks required for the role (by law and your policies);
- identify blind spots and add further layers where the risk justifies them;
- document what was examined, how the decision was reached and when it should be reviewed.
What we must now start thinking about is to link screening depth to changes in access, authority and responsibility. Treat reassessment as part of people-risk management rather than an emergency response after something has gone wrong.
The Veremark report is worth a read because it gives leaders something quantitative to compare against. Be prepared to hear that while you may feel you are doing a good job at the pre-hire stage, you may still be relying a little too much on information that becomes less current with every passing month.
If somebody in your organisation was screened three years ago and now has greater access, greater authority or greater responsibility, what evidence are you relying on today?


.png)
.png)
.png)




.png)
.png)