Building a background check program from scratch means putting five pieces in order: a written policy, a provider you trust, the disclosure and authorization forms candidates sign, someone trained to actually run the checks, and an adverse action process for when a report comes back bad. Do them in that order and it's no fuss. Do them out of order, which is what most small companies do, and you end up fixing things after you've already made a hiring decision, which is a mess.
I ran background checks for almost 30 years at a manufacturing company in Ohio before I retired. Nobody handed me a manual. I built the program the hard way, by getting a few things wrong first. This is the order I'd do it in if I were starting over today.
Your policy is the internal document that says who gets checked, what you check for, and how you decide what to do with the results. Write this first. If you shop for a provider before you know what you actually need, you'll end up buying whatever the salesman is pushing that week.
We already wrote a full guide on this part, with a free template, so I won't repeat it here. Go read How to Write a Background Check Policy for a Small Business and come back. This article is about everything around that document, not the document itself.
One thing worth saying twice: your policy has to apply the same way to everyone in the same job category. If you run a criminal check on one warehouse candidate and skip it for another because you liked her better, that's not a policy, that's a lawsuit waiting to happen.
This is where I've seen the most money wasted. A five-person company doesn't need the same setup as a 500-person one, but sales reps will try to sell you the big package anyway.
Figure out three things before you call anyone: how many hires you make a year, what states you hire in, and what you're actually checking. Then ask providers to price against that, not their general rate card.
Ask every provider these questions directly:
Back when I did this, the vendor that impressed me most in the sales meeting was definately the worst one to actually work with. Slick presentation, three-week turnarounds once we signed. Ask current customers, not just the sales team, how support actually works when something goes wrong.
Federal law (the FCRA, which just means the Fair Credit Reporting Act) says you have to tell a candidate in a clear, standalone document that you're going to run a background check, and get their written okay before you run it. This isn't optional and it isn't a place to get creative.
The disclosure form has to be its own document. You can't bury it in the job application or tuck it into a longer employee handbook with other stuff on the same page. Courts have thrown out cases specifically because the disclosure had extra language mixed in that didn't belong there.
Most providers give you a compliant template as part of onboarding. Use theirs, or have a lawyer look at whatever you use. This is one spot where "close enough" isn't close enough, and I'd get it checked even if the provider says it's already compliant.
Somebody at your company will be the one who logs into the portal, orders the check, and reads the results. That person needs actual training, not just a login and a "figure it out."
They need to know how to read a criminal record without panicking over something irrelevant, what counts as a real problem versus something that doesn't matter for the job, and what not to say if a candidate asks about results before the process is finished.
I once watched a manager tell a candidate over the phone "you failed the background check" before the formal process had even started. That single sentence caused a bigger headache than the actual record ever would have. Train people to say nothing definite until adverse action (next step) has run its course.
Adverse action is the legal term for what you have to do if a background check comes back with something that makes you not want to hire the person. It's a two-step process, and both steps have to happen, in order, every time.
Most decent providers will hand you templates for both letters, and some will even send them for you automatically. Ask about this in step 2, not after you've already needed it and don't have one ready.
For a small company doing it seperately, not all at once, figure two to four weeks. Writing the policy takes a day or two. Comparing providers and signing a contract usually takes the longest, mostly because of internal back-and-forth, not the vendors. Forms and training are quick once you've picked a provider, since most of that comes from them.
Don't rush it to get hiring faster. A program built in two rushed days falls apart the first time a candidate disputes something, and then you're rebuilding it under pressure instead of on your own schedule.
Skip the policy and every manager makes their own call on what gets checked, which turns into inconsistent treatment fast. Skip training and someone says the wrong thing to a candidate. Skip adverse action and you've skipped a federal requirement, which is the expensive one to get wrong.
None of this is meant to scare you off running background checks. It's meant to get you set up right the first time, so the process runs quiet in the background instead of blowing up on you six months in.
And none of it replaces a lawyer's advice for your specific situation. State rules on top of the federal FCRA change often enough that what was fine last year might not be this year. When in doubt, ask one.