Compliance

How to Write a Background Check Policy for a Small Business (Free Template)

By Dale Whitfield · August 28, 2026

A background check policy needs six things written down: why you run checks, which roles get checked for what, how you handle consent, what happens if something bad turns up, how long you keep the records, and who's in charge of all of it.

Get those six things on paper before you order your first report. There's a full template below you can copy today.

I ran background checks for almost 30 years before I retired. The companies that got sued weren't the unlucky ones. They were the ones making the rules up as they went, one candidate at a time. A policy on paper is boring. Boring is exactly what keeps you out of trouble.

Why a five-person company needs this too

You don't need a legal department to write one of these. You need one page and about twenty minutes. Small companies skip this step more than big ones, which is backwards.

A big company has an HR department to catch a mistake before it turns into a lawsuit. A five-person team usually doesn't have that safety net.

Every time you check one candidate a certain way and skip a step for another, you've made a decision, even if you didn't mean to. A written policy takes that decision out of the moment and turns it into a rule you follow every time. That consistency is the whole point.

The six things your policy actually needs

Here's the template, stripped down to what matters. Fill in your own details under each heading and you've got a real policy, not just good intentions.

Background Check Policy Template

  1. Purpose and scope. Why your company runs background checks (safety, client contracts, insurance requirements) and who the policy covers: every hire, or just certain roles, plus whether it reaches contractors and interns.
  2. What gets checked, by role. A list of your actual role categories (office, warehouse, driving, finance, and so on) with the specific checks tied to each one. Tie every check to the job. Never to the person.
  3. Consent and disclosure process. The exact point in your hiring process where a candidate gets the standalone disclosure form, who sends it, and how their signed authorization gets recorded and stored.
  4. Adverse action process. The two-step notice you'll send if a report might change your decision: pre-adverse action first, then a waiting period, then a final notice. Name who reviews a dispute if one comes in.
  5. Record retention. How long you keep background check records and reports, where they're stored, and exactly who's allowed to open that file.
  6. Who's responsible. One person, by job title, who owns this policy, reviews every result, and updates the document when a law changes.

That's it. Six headings, filled in with your own company's real answers. Everything after this is me walking through each one so you're not guessing at what belongs under it.

Not sure which provider fits your team? Answer a few questions and get matched, free.
Find Your Match

Purpose and scope, in plain language

Start by writing down why you're doing this at all. Maybe it's a client contract that requires it. Maybe it's an insurance requirement, or just wanting to know who you're actually hiring. Whatever it is, put it in one sentence.

Then say who the policy applies to. Most companies check every employee the same way for the same role. Fewer companies also decide upfront whether contractors, interns, and volunteers get checked too, and that's a gap I see constantly. Decide it now instead of getting asked in the middle of an interview.

What gets checked, by role

This section is where most homemade policies fall apart. Don't write "we run background checks." Write down your actual roles and match checks to each one. A driver needs a motor vehicle record. A bookkeeper might need a credit check where your state allows it. Somebody answering phones probably doesn't need either.

The reason this matters isn't just cost. If two candidates for the same job get different checks, and one of them happens to be in a protected class, you've handed a lawyer an easy case.

Write the rule once, per role, and apply it every single time. No exceptions for a candidate you have a good feeling about.

Consent and disclosure, spelled out ahead of time

Federal law, the Fair Credit Reporting Act, requires a standalone disclosure telling the candidate you're running a check, plus a separate signed authorization. Standalone means its own page and its own signature. Not buried in your job application, not mixed into your at-will language.

Your policy should name who sends that form and when. Is it HR, the hiring manager, or your provider's portal doing it automatically? Pick one answer and write it down, so it doesn't get missed the one time your regular person is out sick.

What happens if something comes back

This is the part people rush, and it's the part that gets companies sued. If a report shows something that might change your decision, federal law requires a two-step process called adverse action. You can't just reject the candidate on the spot.

First, pre-adverse action: you send the candidate a copy of their report and a summary of their rights, then give them real time to respond before you finalize anything. Many companies use five business days as their own internal standard, though the law itself doesn't spell out one fixed number.

Check current guidance before you lock a specific figure into your policy. If they don't dispute anything, you send a final adverse action notice and you're done.

Skip either step and you're not being sloppy. You're breaking federal law.

How long you keep the file

Record retention is the section people forget entirely, and it shouldn't be. At minimum, keep background check records long enough to cover federal recordkeeping rules for employment decisions, generally at least a year.

Many employers keep them longer, because state deadlines for filing a claim can run past that. I'm not a lawyer, and retention rules genuinely shift by state, so get your specific number confirmed rather than copying mine.

Write down where the file lives (a locked drive, not somebody's email inbox) and who can open it. That last part matters more than people think. A report sitting in a shared folder that half the office can see is its own kind of problem.

Who's actually in charge

Name one person. Not "HR," a specific title. That person reviews every result, decides when adverse action applies, and updates this policy when a law changes, which happens more often than you'd guess.

Spreading that job across whoever happens to open the report first is how a policy quietly stops being followed.

I watched this go wrong at one of the companies I worked for. Nobody owned the policy, so nobody noticed it was three years out of date until a lawyer asked to see it. Dont let that be you.

A few things people ask me

Do I need a lawyer to write this? Not to write the first draft. You do need one to review your final disclosure, authorization, and adverse action language before a real candidate sees it. That review is cheap compared to what a mistake costs.

Can I just use my provider's template? Only after someone with legal knowledge has actually read it for your state. A generic template written for a different state can leave real gaps.

How often should I update this policy? At least once a year, and any time you hear a law changed in a state where you hire. It's more trouble to skip that check than it is to just do it.