You can get sued for screening a candidate too little. You can also get sued for screening a candidate too much, or doing it the wrong way. Those are two separate legal risks, they pull in opposite directions, and "run a deeper background check on everyone" doesn't fix either one by itself.
Most articles on this topic only cover one side. I want you to see why they conflict, not just what each rule says on its own.
Negligent hiring isn't part of the FCRA. It's not a federal rule at all. It's a state-law claim, and the details shift depending on where you're located. But the basic shape of it holds steady enough across states that I can explain it plainly.
Here's the idea. If you put someone into a job where they could foreseeably hurt another person, and you didn't take reasonable steps to screen for that specific risk before hiring them, and that person then hurts someone in a way connected to the risk you skipped, you can be found liable. Right alongside the person who actually caused the harm.
Three things have to line up for a claim like that to stick. The harm has to be reasonably foreseeable for that specific role. Your screening has to have fallen short of what a reasonable employer would have done for that role. And the shortfall has to actually connect to the harm that happened. All three, not just one.
Foreseeability is doing most of the work here, and it's entirely job-specific. A home health aide who enters a client's house alone carries a foreseeable risk that a warehouse packer working a loading dock with three coworkers around doesn't. Neither does an accountant who never leaves the building.
There's a nuance worth catching here too. Running more checks isn't the same as running the right check. A cheap, nationwide database search for a home health aide role can miss the local record that actually mattered, because those databases often lag behind what's sitting in the actual courthouse file. Quantity doesn't buy you the same protection accuracy does, and courts tend to notice the difference.
So to say that again a different way: negligent hiring isn't asking whether you ran a background check. It's asking whether you ran one deep enough for what the job actually exposes other people to.
I'm not going to hand you a finished list of which roles count as foreseeably risky and call it complete. That list looks different depending on your state's case law. Check the specifics with an employment lawyer before you build it into a policy manual. That part's not optional.
This tension shows up hardest in a specific handful of industries. Home healthcare and in-home caregiving. Transportation, anywhere someone drives as part of the job. Childcare and K-12 schools. Property management, where a maintenance worker gets a key to someone's apartment. Financial services, where someone gets real access to other people's money. Each of those roles carries genuine foreseeability built into the job itself, which is exactly why they tend to draw the most scrutiny in negligent-hiring litigation across this industry, even without me pointing to one specific case for you.
Now flip it. FCRA, the federal law that sets the rules for background checks, and Title VII, enforced by the EEOC, don't punish employers for running background checks. They punish employers for running them carelessly, or acting on what comes back the wrong way.
A blanket policy is the classic version of this. "No felons, no exceptions" feels safe because it treats every candidate the same. It's actually one of the more common ways employers end up in front of the EEOC, because conviction rates aren't spread evenly across every group of people. A rule that never mentions race can still screen out one group far more than another. That's disparate impact, and intent doesn't matter.
There's a second version of this that gets less attention: running a deep background check on a role that never called for one. Pulling credit history for a warehouse job. Running a ten-year criminal lookback on a part-time cashier. None of that makes anyone safer, because there was never a foreseeable risk there to screen for in the first place. It just adds disparate-impact exposure and paperwork obligations you didn't need to take on.
And mishandling the process itself is its own category, separate from what you screened for. Skipping the standalone disclosure form. Rushing past the adverse-action waiting period. Telling someone they're rejected before they've had a real chance to respond to what the report found. All of that is FCRA exposure, and it has nothing to do with whether your underlying decision was even correct.
None of this means you can't consider a criminal record. You can. It means you have to look at it for a reason connected to the actual job, not run it through a fixed rule and call that thorough.
Here's the trap. After something goes wrong, the instinct is almost always the same: we should have checked more. So the policy gets rewritten to screen deeper, for every role, across the board. That feels responsible. It also walks you straight into the other risk.
Screening more broadly, applied evenly across roles that don't share the same foreseeable risk, doesn't make the genuinely risky roles any safer. It just means you're running the same aggressive screen on your accountant as you are on your home health aide, and rejecting people from both groups using the same fixed criteria. That's the setup for a disparate-impact claim, not a defense against one.
| Risk direction | What actually triggers it | What it's really punishing |
|---|---|---|
| Negligent hiring | A role with foreseeable access to harm others, paired with screening that fell short of what that risk called for | Doing too little, for a role that needed real scrutiny |
| FCRA / EEOC exposure | A blanket policy, screening unrelated to the actual job, or a mishandled adverse-action process | Doing too much, or doing it carelessly, no matter the role's actual risk |
Depth and breadth aren't the same lever. Going deeper on a role that genuinely needs it is a negligent-hiring defense. Going broader across every role, whether it needs it or not, is an EEOC and FCRA problem waiting to happen. Confusing the two is where most of this goes wrong.
If you're the one person handling HR at a fifty-person company, this is exactly the kind of nuance that gets lost when you're moving fast. One rule is easier to manage than five. That's understandable. It's also how you end up exposed on both sides at once.
There's a real answer here, and it isn't "somewhere in the middle." It's individualized assessment, tied to genuine job relevance, applied the same way every time. That's what a court expects on the negligent-hiring side and what the EEOC expects on the discrimination side. Same discipline, pointed in two directions.
Start by mapping your roles honestly, by actual risk, not by job title. Does this person enter someone's home alone? Work unsupervised with children, older adults, or people with disabilities? Drive as part of the job? Handle money or sensitive financial access? Those answers tell you where deeper screening is genuinely defensible, not just cautious.
Picture two open roles at the same company. One is a home health aide who'll be alone in a client's house within her first week. The other is a marketing coordinator who works from the office and never meets a client unsupervised. Running the identical background check on both isn't consistency. It's a mismatch in both directions at once, too light for one job and too heavy for the other.
For roles that clear that bar, run a real, documented check that matches the actual risk. Criminal history at the right depth. License or credential verification if the job needs it. An MVR if they're driving. Write down why you chose that scope. That documentation is what "reasonable care" looks like if a negligent-hiring claim ever tests it.
For roles that don't clear that bar, don't run the same check anyway just because one policy is easier to manage than several. A standard that's too aggressive for the job in front of you isn't extra caution. It's extra exposure, with nothing gained on the safety side to justify it.
When a record does turn up, on any role, don't auto-reject and don't ignore it either. Run it through the same three questions every time. How serious was the offense. How long ago did it happen. How closely does it relate to what this specific job actually involves. Give the candidate a real chance to respond before you decide anything final.
That's the whole trick. Not screening more. Not screening less. Screening on purpose, for a reason you can write down.
One practical side note here. If you carry employment practices liability insurance, ask your broker how the policy treats a negligent hiring claim versus an FCRA or EEOC claim. Some policies handle those very differently. Finding that out after a claim gets filed is a worse time to learn it than now.
You won't get this right by instinct in the middle of a hiring rush, and you shouldn't try to. Build the risk map and the screening tiers before you're mid-req and under pressure, not while a hiring manager is waiting on you to move faster.
Keep the reasoning on file for every hire, not just the ones where a record showed up. "We reviewed the offense, the time passed, and how it related to this role" holds up if anyone ever asks you to explain a decision. "We ran the standard check" doesn't, even when the outcome would've been identical either way.
And when something does go wrong with a hire, resist the urge to fix it by cranking every screen up to maximum for every future role. Go back to the risk map instead. If the map was wrong for that role, fix the map. Don't throw out the whole idea of matching screening to risk because one case slipped through it.
None of this works if it only lives in one person's head, either. Train whoever actually makes the reject-or-move-forward call, not just whoever wrote the policy. A risk-tiered process that only one manager understands isn't really consistent, and inconsistency is its own kind of exposure on the EEOC side.
This is genuinely hard to hold in your head hire by hire, especially on a small team without in-house counsel sitting down the hall. That's exactly why it has to live in a written policy, built ahead of time, instead of getting decided fresh under pressure every time a report comes back with something on it.