Annual vendor reviews put background screening under the compliance team's lens every year, and the Fair Credit Reporting Act (FCRA) gives that review a clear structure. The law sets defined steps for employers and defined duties for the screening companies they use.
The most useful way to review an FCRA-compliant background check program is to separate those two sets of responsibilities. The employer owns disclosure, authorization, and adverse action. The consumer reporting agency owns accuracy and its own notices. When each side is clear, the review becomes a straightforward checklist.
The FCRA is the federal law that governs how consumer reports are prepared and used, including background checks for employment. When an employer uses a report from a third-party consumer reporting agency to make a hiring, retention, promotion, or reassignment decision, the FCRA applies.
Two questions set the scope.
The FCRA assigns duties to both sides of a background check:
Employers: any employer using consumer reports for employment decisions must follow the FCRA's disclosure, authorization, certification, and adverse action steps, according to the Federal Trade Commission (FTC).
Consumer reporting agencies: screening companies must follow reasonable procedures to assure maximum possible accuracy of the information they report.
Newer data sources: the Consumer Financial Protection Bureau (CFPB) has confirmed that background dossiers and algorithmic scores from third parties, when used for employment decisions, are often consumer reports under the FCRA.
Checks an employer runs entirely in-house, with no third party involved, generally fall outside the FCRA's procedures, though other federal and state laws still apply.
The FCRA includes civil remedies for consumers. For willful noncompliance, a consumer may recover actual damages or statutory damages of $100 to $1,000, plus punitive damages as a court allows and attorney's fees. A documented, repeatable process is what keeps every check on the right side of those rules.
FCRA compliance for employers comes down to five steps, each with a clear owner and record. The FTC's guidance for employers sets out the requirements below.
Before ordering a report, tell the candidate in writing that you may use a consumer report for employment decisions. The notice must be in a stand-alone format and cannot sit inside an employment application. Then get written permission, which can appear in the same document as the disclosure.
Certify to the screening company that you notified the candidate and got permission, and that you will comply with the FCRA. You also certify that you will not misuse the information in violation of equal opportunity laws.
Before rejecting a candidate or taking any other adverse action based on the report, share it first. Give the candidate a copy of the report and A Summary of Your Rights Under the Fair Credit Reporting Act. The notice gives the candidate a chance to review the report and point out anything inaccurate.
After the pre-adverse notice, allow a reasonable period for the candidate to respond. The FCRA does not set a fixed number of days, and many employers use at least five business days. If you proceed, send an adverse action notice that includes:
The name, address, and phone number of the consumer reporting agency
A statement that the agency did not make the decision and cannot explain the reasons for it
Notice of the candidate's right to dispute the report and to get a free copy within 60 days
Keep a record that each report was obtained for employment purposes with the candidate's authorization. When you no longer need a report, dispose of it securely so the information cannot be read or reconstructed, as the FTC's disposal rules require.
The FCRA sets the federal floor, and many states add their own rules. The FTC advises employers to review their state's laws on consumer reports, noting that some states restrict the use of credit reports for employment. An FCRA-compliant background check program therefore maps each state where it hires to any added notice, timing, or content rules.
In an AI-powered workflow, the FCRA steps stay the same, and automation makes each one consistent and recorded. The platform handles the sequence, and people keep every decision.
Three capabilities matter most.
Automated consent works best as its own step, separate from the job application. TRACE, TraqCheck's AI verification agent, sends each candidate a branded, mobile-friendly consent link. The disclosure appears on its own screen, and the signed authorization is captured before any check begins. That design keeps the stand-alone requirement intact for every candidate.
Adverse action decisions stay with people, and the platform supports each notice. A strong workflow delivers the full report for the pre-adverse notice, tracks the waiting period, and records when each notice was sent. In TRACE, a human verification specialist reviews every result, and each report arrives with verified facts and clear flags that your team can share with the candidate.
An audit trail shows who ordered each check, when consent was captured, what was reported, and what the employer decided. TRACE is FCRA-compliant by design, and every report includes a full audit trail for compliance. The CFPB's view that third-party algorithmic scores are often consumer reports makes that record especially valuable when AI is part of the workflow.
For more on how compliance and risk teams use these records, see compliance and regulatory screening and the compliance risk employers cannot ignore.
For candidates in the EU, the GDPR governs how their personal data is processed, alongside or instead of the FCRA. The core principles overlap, while the mechanics differ.
Here is how the two frameworks compare directly.
Factor
FCRA (US)
GDPR (EU)
What it covers
Consumer reports used for employment decisions
Any processing of personal data of people in the EU
Basis to proceed
Permissible purpose and written authorization
A lawful basis under Article 6
Criminal records
Reportable within FCRA and state limits
Only under official authority or where EU or member state law authorizes it (Article 10)
Screening provider's role
Consumer reporting agency with accuracy duties
Data processor under a binding contract (Article 28)
Automated decisions
People make adverse action decisions
In summary, the FCRA focuses on the report and the notices around it, while the GDPR focuses on the lawful basis and safeguards for all processing. Global workforce verification programs apply the right framework for each country.
There is no official FCRA certification, so reviews of FCRA-compliant background check companies look at how each provider meets its duties in practice. Six questions cover the essentials:
Does the provider give you the Notice to Users of Consumer Reports and the Summary of Your Rights, as the FTC requires of screening companies?
What independent security attestations does it hold, such as SOC 2 Type II and ISO 27001, and does it offer GDPR processor terms for international hires?
Clear, specific answers to all six give your compliance team what it needs for the annual review.
Annual reviews move fastest when the evidence is gathered in advance. A complete file usually includes:
Your current stand-alone disclosure and authorization forms, with a sample of signed records
Your certifications to the screening provider
Pre-adverse and adverse action notice templates, with a log of notices sent
The provider's Notice to Users of Consumer Reports and its dispute-handling process
The provider's latest SOC 2 Type II report and ISO 27001 certificate
With these in one place, the review confirms what already works and highlights any updates for the year ahead. For a wider view of the market, compare background check software and read about AI in background screening.
FCRA compliance is a shared, well-defined process. Employers own disclosure, authorization, certification, and adverse action, and screening providers own accuracy, notices, and dispute handling. A platform that builds each step into the workflow, with human review and a full audit trail, turns the annual review into a confirmation rather than an investigation.
TRACE is FCRA compliant by design, SOC 2 Type II and ISO 27001 certified, and GDPR ready. To walk through how it fits your review, book a demo or get in touch with the team.
The FCRA requires employers to give a stand-alone written disclosure, get written authorization, and certify compliance to the screening company. Before and after any adverse decision, employers must send a pre-adverse action notice and an adverse action notice.
There is no official FCRA certification, so compliance shows in how a platform meets its duties: accurate reporting procedures, required notices, dispute handling, and support for employer steps. TraqCheck's TRACE is FCRA compliant by design, with human review of every result and a full audit trail.
A pre-adverse action notice is the notice an employer sends before taking adverse action based on a background report. The notice includes a copy of the report and A Summary of Your Rights Under the Fair Credit Reporting Act.
Yes. TRACE is FCRA compliant by design, and it is also SOC 2 Type II certified, ISO 27001 certified, and GDPR ready. Employers still complete their own FCRA steps, such as adverse action decisions and notices.
No. The FCRA does not create a certification program. Employers assess compliance by reviewing a provider's accuracy procedures, notices, dispute handling, and workflow support.
The FCRA does not set a fixed number of days and requires a reasonable opportunity for the candidate to respond. Many employers wait at least five business days, and some state laws set specific periods.


