A record 10,293 referrals were made to Prevent in England and Wales in the year ending 30 September 2025, relating to 9,957 people.

Where age was recorded, 36% of referrals involved 11 to 15-year-olds.

These figures need careful interpretation.

A referral records a concern for assessment. It does not establish wrongdoing. Rising numbers may also reflect greater awareness, changing reporting patterns and increased use of the system.

Still, the scale matters.

The latest Home Office figures show how heavily safeguarding concerns now involve children and young people.

The point is not that every safeguarding concern is a recruitment issue. It is that the risk environment around young and vulnerable people increasingly includes online behaviour, online communities and public digital signals.

Online spaces form part of that environment.

Grievance, violent fixation, misogyny and extremist ideas can develop within fragmented online communities. People find others who reinforce their views. Harmful interests can deepen. The warning signs may remain outside the formal systems used by schools, employers and safeguarding teams.

This creates a wider question.

How should organisations assess relevant online risk before giving someone access to children, vulnerable people, patients, sensitive environments or positions of trust?

Existing checks address only part of the picture

Prevent has an important role.

So do DBS, BPSS, references, interviews, professional registration and internal safeguarding procedures.

Each serves a defined purpose. Each remains essential.

Their evidence usually comes from formal records, declared information, known outcomes and regulated disclosures.

Relevant public online signals may sit outside those sources.

A person may have no criminal record, regulatory finding or adverse reference. Publicly accessible information may still raise legitimate questions about violence, discrimination, extremist associations, harmful sexual behaviour or suitability for a particular position of trust.

Those signals require careful handling.

A post may be old, misattributed, ironic, taken out of context or irrelevant to the role. A single comment may carry a different weight from a sustained pattern. Lawful expression remains protected.

The task is to establish identity, context, pattern and relevance before anyone reaches a conclusion.

Public online conduct can affect professional trust

A recent Nursing and Midwifery Council case provides a clear example.

The NMC considered social media posts and comments shared by a registered nurse between July 2024 and February 2025. The panel found that the material contained offensive, derogatory and discriminatory language relating to race, religion and immigration status.

The nurse received a six-month suspension order.

The NMC decision concluded that the conduct could cause members of the public to believe they might receive less favourable treatment.

This goes directly to professional trust.

A regulatory finding and a pre-employment screening decision carry different thresholds and responsibilities. They should be kept separate.

The operating lesson remains relevant: public online conduct can affect confidence in someone’s judgement, impartiality and suitability for a trusted role.

One poor post should never trigger an automatic career-ending decision.

Context matters.
Timing matters.
Authorship matters.
Pattern matters.
Role relevance matters.

A fair process must test each of them.

Informal searching creates its own risk

Too many organisations still handle online concerns informally.

Someone searches a name.
Someone scrolls through social media.
Someone takes a screenshot.
Someone forms a view.

The search may never be recorded. The identity may never be confirmed. The relevance threshold may change between candidates. Personal bias can shape what gets noticed and how it is interpreted.

The individual may have no opportunity to respond.

This leaves the organisation exposed.

A decision made through an undocumented online search is difficult to explain to a candidate, regulator, board or court. It also creates avoidable risks around privacy, discrimination, mistaken identity and inconsistent treatment.

Safeguarding and HR teams should not be left to improvise this work under time pressure.

They need a governed method.

What responsible Digital Risk Screening looks like

Digital Risk Screening gives organisations a structured way to assess relevant public online indicators.

A responsible process should include:

  1. A legitimate purpose connected to the role.
  2. Defined and proportionate risk categories.
  3. Clear limits on the public sources that may be used.
  4. Accurate identity matching.
  5. Context and corroboration checks.
  6. Review by trained human analysts.
  7. An opportunity to respond to material findings.
  8. A named decision-owner and documented audit trail.

Private accounts sit outside the scope.

Automated systems should not make the final suitability decision.

The screening output should present evidence, context and confidence clearly enough for a human decision-maker to understand and challenge it.

The organisation remains responsible for the outcome.

Fairness, proportionality and relevance must shape the whole process, from the initial search criteria through to retention and deletion.

Three questions every organisation should be able to answer

For a high-trust position, leaders should be able to answer:

  1. What did we check?
  2. What did we find?
  3. Why did we decide it was, or was not, relevant?

These questions matter when a concern emerges.

They matter even more before access is granted.

An organisation that cannot answer them has a gap in its assurance process.

Completing the standard checks may satisfy one part of the requirement. It may leave relevant public digital risk unexamined.

The level of screening should always match the access, responsibility and potential harm attached to the role.

Safeguarding must follow the risk environment

Safeguarding has always adapted as threats, behaviours and evidence change.

The online environment is now part of the operating picture.

Children can encounter harmful communities and content online. Adults can leave public signals that raise legitimate questions about judgement, conduct, discrimination, violence or suitability for trusted access.

Organisations do not need blanket monitoring.

They need a defined capability for those roles where the risk justifies it.

Clear scope.
Accurate identity matching.
Relevant evidence.
Human validation.
Proportionate judgement.
A recorded decision.

If a relevant online signal appeared tomorrow, who would see it, who would test it and who would own the decision?

That is the assurance gap Safehire.ai is built to help close: not through blanket monitoring, but through governed Digital Risk Screening that is proportionate, evidenced and human-led.

For organisations reviewing safer recruitment, safeguarding, regulated roles or positions of trust, this capability should now form part of the assurance conversation.

If risk is showing up online, safeguarding needs a responsible way to see it, assess it and decide what follows.

Continue reading