Compliance

The CRA Made the Mistake, You Got Sued: Why Vendor Selection Is a Compliance Decision

By Marcus Odom · August 28, 2026

Here's a scenario I've seen play out more than once. An employer runs a background check through their screening company, the report comes back clean, or close enough, and they make an offer. Six months later they get a letter from a lawyer.

Turns out the report was wrong. Maybe it matched the wrong person. Maybe it was pulling an old record that should've dropped off years ago. And now the employer is a named party in a lawsuit, right alongside the vendor who actually made the mistake.

A lot of employers assume that once they hire a background check company, the compliance risk moves over to that company too. Pay someone else to run the check, let them own the legal exposure. That's not how it works. Not under the Fair Credit Reporting Act, and not in practice.

Let's go through why that assumption is wrong. I'll cover the specific ways a vendor's failure turns into your problem, how to verify a vendor's compliance claims before you sign anything, and what to do if you're already locked in and something's gone sideways.

That part's not a small side note. It's the whole point of this article.

Yes, you can be named in a lawsuit over your vendor's mistake

The Fair Credit Reporting Act doesn't put one party in charge of compliance. It creates two separate sets of obligations that run at the same time.

One set belongs to the consumer reporting agency, the CRA, the company that actually pulls the records and builds the report. The other set belongs to the "user" of that report. That's you, the employer.

Your vendor doing their job well doesn't excuse you from doing yours. And your vendor doing their job badly doesn't excuse you from yours either. So to say that again a different way: these are two separate report cards, not one shared grade.

Your part of the FCRA includes things that have nothing to do with the vendor at all. You need a proper standalone disclosure form and the candidate's written consent, separate from the job application, not buried in it.

You also need to follow the two-step adverse action process before you turn someone down based on a report: pre-adverse notice, a copy of the report, a copy of the candidate's rights, a waiting period, then a final notice if you go through with it.

And you need to actually be legally allowed to use whatever's in that report, which depends on your state and sometimes your city.

Here's the practical result. When a report error leads to a lawsuit, plaintiffs' lawyers often name the employer right alongside the CRA. Not always because the employer caused the underlying data error.

Usually it's because the employer is the one who actually took the adverse action. And a lawyer looking closely at one FCRA problem tends to check the employer's own paperwork at the same time. It's common to find a second, separate violation sitting right next to the first one.

I want to be careful here, because this is exactly the kind of thing that gets oversimplified. Whether choosing a bad vendor becomes its own basis for your liability, versus you just getting swept into a suit over your own separate mistakes, depends heavily on the facts and the state you're in.

That's a real legal question, not something I can hand you a flat rule for in an article. Talk to an employment lawyer about your specific situation. That part's not optional.

Three ways a vendor's failure becomes your legal problem

Let me walk through the three patterns I saw come up again and again when I worked on the operations side of a screening company. None of these are rare edge cases. They're the ordinary ways this goes wrong.

Stale or mismatched data

A criminal record search comes back with a hit. Except it's not actually your candidate's record. It belongs to someone else with a similar name, maybe the same birth year. Or the record is real, but it's years out of date, an expungement or a dismissal that never made it into the vendor's database.

I want to be careful not to hand you a specific court case here and tell you it's settled law. The details of any one case matter more than a quick summary can capture. But the general pattern is well established.

When a screening company's matching process is sloppy enough that it attaches someone else's record to your candidate, and that leads to a rejection, both the CRA and the employer that acted on the bad report can end up as defendants. That's not hypothetical. It's a documented category of case, even without me naming one for you.

Slow turnaround pushes you into your own mistake

This one's sneakier, because it's not really about the vendor's data at all. It's about what a slow vendor does to your own behavior.

Say a report takes three weeks longer than it should. The hiring manager is frustrated. The candidate's getting other offers. So someone skips the waiting period between the pre-adverse notice and the final decision. Or they tell the candidate verbally that it's a no before the process is actually finished.

The vendor's delay didn't violate the law. Your reaction to that delay did. That's a violation you created, entirely on your own, because a slow vendor put you under pressure.

Missing adverse-action paperwork

Some vendors don't generate a proper Summary of Rights document. Some don't keep up with state-specific disclosure language that a handful of states require on top of the federal minimum.

Here's the part people miss: you send the pre-adverse and final adverse action notices, not your vendor. If your vendor can't hand you the right documents on time, or the right documents at all, that gap becomes your paperwork problem, even when the actual background data was completely accurate.

I'll add one more thing here, because it matters. Both the FTC and the CFPB have general authority to bring enforcement actions over this kind of process failure, and adverse-action notice mistakes are a recurring theme in background-screening litigation.

I'm not going to hand you dollar figures or case names in this article. I'd rather be honest about what I can verify than make this sound more precise than it is. But don't read that caution as "this doesn't really happen." It happens often enough that it's worth building your process to avoid it, not something you should assume is a one-in-a-million risk.

What "FCRA compliant" actually means, and how to check it yourself

Here's something worth knowing before you read another vendor's homepage. There's no government seal that says "FCRA compliant." No agency hands that phrase out. Every screening company operating legally is already subject to the FCRA, the same way every driver on the road is subject to speed limits.

Putting the phrase on a website doesn't prove anything. It doesn't tell you a single thing about how carefully that company actually follows the law day to day.

So what should you actually look for instead? Two things, and they're genuinely different from each other.

PBSA accreditation is the closest thing this industry has to an independent, audited standard. PBSA, the Professional Background Screening Association, runs a voluntary accreditation program that requires a third-party audit across legal compliance, consumer protection, how the company sources its data, and information security.

It's not a one-time thing either. Vendors have to recertify roughly every five years to keep it. And it's genuinely selective. Industry estimates put accredited firms at a fairly small share of active screening companies out there, so don't assume every big name has it.

Ask for current, verifiable proof, not a badge graphic sitting on a marketing page.

SOC 2 Type II certification covers something different: how a vendor actually handles the sensitive personal information a background check requires. Social Security numbers, dates of birth, home addresses.

Type II matters more than Type I here, because Type I is just a snapshot of one day. Type II means an auditor watched how the company handled data security over a real stretch of time, usually six months or more.

Ask any vendor you're seriously considering to send you the accreditation certificate or a verification link, and the SOC 2 report itself, or at least a summary of it. Not a claim on a slide. The actual document. A vendor with nothing to hide will send it without much friction.

Not sure which provider fits your team? Answer a few questions and get matched, free.
Find Your Match

The pre-signature checklist

This is the part I'd actually print out and keep next to the contract. Go through it before you sign, not after something goes wrong.

  • Accreditation and certifications. Current PBSA accreditation, verified independently, and current SOC 2 Type II.
  • Data sourcing. Does the vendor confirm records at the actual source, courthouses, schools, past employers, or are they mostly matching against a database? Database-only is faster and cheaper. It also carries more of the stale-record risk I described above.
  • Turnaround time in writing. Get per-check-type turnaround commitments in the actual contract or order form, not a number a sales rep said out loud. A verbal promise gives you nothing to point to when a delay causes a real problem.
  • Adverse action support, built in. Confirm the platform generates state-specific disclosure and consent forms, plus the pre-adverse and final adverse action notices with the Summary of Rights, and that those forms actually get updated as state and local law changes.
  • Dispute and reinvestigation process. Ask their average time-to-resolution on a candidate dispute. The FCRA gives a 30-day reinvestigation clock. Ask how they keep both the candidate and you informed while that clock is running.
  • Data security and residency. Where is applicant data actually stored and processed, and what's their written breach notification commitment. In writing, not "we'll let you know."
  • Indemnification language. Does the contract say the vendor covers costs if litigation comes from their own data error or process failure? Or does the standard agreement quietly leave you holding that risk alone? This is worth sending to a lawyer before you sign, not something to accept in whatever boilerplate they hand you.
  • Proof of insurance. Ask for evidence of errors and omissions coverage, and cyber liability coverage while you're at it.

None of this is exotic. It's just work. And it's work most employers skip because the sales conversation moves fast and the contract feels like a formality. It isn't one.

Not sure which provider fits your team? Answer a few questions and get matched, free.
Find Your Match

Red flags that predict trouble down the road

Some of these are small on their own. Together, they tell you something.

  • No written SLA. Turnaround times only ever come up as something a sales rep mentioned in a call.
  • The vendor is slow or reluctant to produce accreditation proof, a SOC 2 report, or insurance certificates when you ask directly.
  • Disclosure and adverse action templates that are generic, not state-specific, or that look like they haven't been touched in years.
  • No named person for compliance or dispute questions. Everything routes through general sales or support instead.
  • Pricing that's hard to pin down, bundled fees you can't fully break apart. A vendor that isn't straight with you about pricing usually isn't straight with you about process either.

One of these alone might be nothing. Three or four of them together is a pattern, and patterns are worth walking away from.

If you're already locked into a vendor and something goes wrong

Maybe you're reading this after the fact, not before. That happens more than you'd think. Here's what to do.

Start writing down the timeline. When you ordered the report, when it actually came back, what the SLA promised versus what happened, and every step of your own adverse action process, with dates. You want this documented while you still remember it clearly, not reconstructed later from memory.

Don't let frustration with your vendor's delay push you into cutting your own corners. Skipping the waiting period, telling a candidate verbally before the process is finished, those mistakes are entirely within your control no matter what the vendor did on their end. A slow vendor is their fault. A skipped waiting period is yours.

The moment a report error or a dispute turns into an actual complaint or a demand letter from a lawyer, bring in employment counsel. Treat it like the legal matter it already is, not a customer service ticket you route to your vendor's support line.

And use it. A missed SLA, an unresolved dispute, a vendor that went quiet when you needed answers, write it down and bring it to your next contract renewal or RFP. A documented pattern of failure is leverage. It's also grounds to switch, and you shouldn't feel like you need permission to act on it.

Vendor selection belongs in your compliance process, not just procurement

Price matters. Integrations matter. How fast a report comes back matters. None of that is fake.

But accreditation, a documented process, and a written SLA aren't extras you get to if there's budget left over. They're gating criteria, because your own legal exposure is tied directly to them, whether you signed up for that or not.

Everything in this article, checking accreditation, comparing SLAs, actually reading the contract instead of skimming it, is real work. Most HR teams doing this alongside a full-time job don't have room to do all of it carefully for every vendor on a shortlist.

That's exactly the gap a structured matching process fills. It's already done the vetting you'd otherwise have to do yourself, one vendor at a time, on top of everything else on your plate.