Here's a scenario I've seen play out more than once. An employer runs a background check through their screening company, the report comes back clean, or close enough, and they make an offer. Six months later they get a letter from a lawyer.
Turns out the report was wrong. Maybe it matched the wrong person. Maybe it was pulling an old record that should've dropped off years ago. And now the employer is a named party in a lawsuit, right alongside the vendor who actually made the mistake.
A lot of employers assume that once they hire a background check company, the compliance risk moves over to that company too. Pay someone else to run the check, let them own the legal exposure. That's not how it works. Not under the Fair Credit Reporting Act, and not in practice.
Let's go through why that assumption is wrong. I'll cover the specific ways a vendor's failure turns into your problem, how to verify a vendor's compliance claims before you sign anything, and what to do if you're already locked in and something's gone sideways.
That part's not a small side note. It's the whole point of this article.
The Fair Credit Reporting Act doesn't put one party in charge of compliance. It creates two separate sets of obligations that run at the same time.
One set belongs to the consumer reporting agency, the CRA, the company that actually pulls the records and builds the report. The other set belongs to the "user" of that report. That's you, the employer.
Your vendor doing their job well doesn't excuse you from doing yours. And your vendor doing their job badly doesn't excuse you from yours either. So to say that again a different way: these are two separate report cards, not one shared grade.
Your part of the FCRA includes things that have nothing to do with the vendor at all. You need a proper standalone disclosure form and the candidate's written consent, separate from the job application, not buried in it.
You also need to follow the two-step adverse action process before you turn someone down based on a report: pre-adverse notice, a copy of the report, a copy of the candidate's rights, a waiting period, then a final notice if you go through with it.
And you need to actually be legally allowed to use whatever's in that report, which depends on your state and sometimes your city.
Here's the practical result. When a report error leads to a lawsuit, plaintiffs' lawyers often name the employer right alongside the CRA. Not always because the employer caused the underlying data error.
Usually it's because the employer is the one who actually took the adverse action. And a lawyer looking closely at one FCRA problem tends to check the employer's own paperwork at the same time. It's common to find a second, separate violation sitting right next to the first one.
I want to be careful here, because this is exactly the kind of thing that gets oversimplified. Whether choosing a bad vendor becomes its own basis for your liability, versus you just getting swept into a suit over your own separate mistakes, depends heavily on the facts and the state you're in.
That's a real legal question, not something I can hand you a flat rule for in an article. Talk to an employment lawyer about your specific situation. That part's not optional.
Let me walk through the three patterns I saw come up again and again when I worked on the operations side of a screening company. None of these are rare edge cases. They're the ordinary ways this goes wrong.
A criminal record search comes back with a hit. Except it's not actually your candidate's record. It belongs to someone else with a similar name, maybe the same birth year. Or the record is real, but it's years out of date, an expungement or a dismissal that never made it into the vendor's database.
I want to be careful not to hand you a specific court case here and tell you it's settled law. The details of any one case matter more than a quick summary can capture. But the general pattern is well established.
When a screening company's matching process is sloppy enough that it attaches someone else's record to your candidate, and that leads to a rejection, both the CRA and the employer that acted on the bad report can end up as defendants. That's not hypothetical. It's a documented category of case, even without me naming one for you.
This one's sneakier, because it's not really about the vendor's data at all. It's about what a slow vendor does to your own behavior.
Say a report takes three weeks longer than it should. The hiring manager is frustrated. The candidate's getting other offers. So someone skips the waiting period between the pre-adverse notice and the final decision. Or they tell the candidate verbally that it's a no before the process is actually finished.
The vendor's delay didn't violate the law. Your reaction to that delay did. That's a violation you created, entirely on your own, because a slow vendor put you under pressure.
Some vendors don't generate a proper Summary of Rights document. Some don't keep up with state-specific disclosure language that a handful of states require on top of the federal minimum.
Here's the part people miss: you send the pre-adverse and final adverse action notices, not your vendor. If your vendor can't hand you the right documents on time, or the right documents at all, that gap becomes your paperwork problem, even when the actual background data was completely accurate.
I'll add one more thing here, because it matters. Both the FTC and the CFPB have general authority to bring enforcement actions over this kind of process failure, and adverse-action notice mistakes are a recurring theme in background-screening litigation.
I'm not going to hand you dollar figures or case names in this article. I'd rather be honest about what I can verify than make this sound more precise than it is. But don't read that caution as "this doesn't really happen." It happens often enough that it's worth building your process to avoid it, not something you should assume is a one-in-a-million risk.
Here's something worth knowing before you read another vendor's homepage. There's no government seal that says "FCRA compliant." No agency hands that phrase out. Every screening company operating legally is already subject to the FCRA, the same way every driver on the road is subject to speed limits.
Putting the phrase on a website doesn't prove anything. It doesn't tell you a single thing about how carefully that company actually follows the law day to day.
So what should you actually look for instead? Two things, and they're genuinely different from each other.
PBSA accreditation is the closest thing this industry has to an independent, audited standard. PBSA, the Professional Background Screening Association, runs a voluntary accreditation program that requires a third-party audit across legal compliance, consumer protection, how the company sources its data, and information security.
It's not a one-time thing either. Vendors have to recertify roughly every five years to keep it. And it's genuinely selective. Industry estimates put accredited firms at a fairly small share of active screening companies out there, so don't assume every big name has it.
Ask for current, verifiable proof, not a badge graphic sitting on a marketing page.
SOC 2 Type II certification covers something different: how a vendor actually handles the sensitive personal information a background check requires. Social Security numbers, dates of birth, home addresses.
Type II matters more than Type I here, because Type I is just a snapshot of one day. Type II means an auditor watched how the company handled data security over a real stretch of time, usually six months or more.
Ask any vendor you're seriously considering to send you the accreditation certificate or a verification link, and the SOC 2 report itself, or at least a summary of it. Not a claim on a slide. The actual document. A vendor with nothing to hide will send it without much friction.
This is the part I'd actually print out and keep next to the contract. Go through it before you sign, not after something goes wrong.
None of this is exotic. It's just work. And it's work most employers skip because the sales conversation moves fast and the contract feels like a formality. It isn't one.
Some of these are small on their own. Together, they tell you something.
One of these alone might be nothing. Three or four of them together is a pattern, and patterns are worth walking away from.
Maybe you're reading this after the fact, not before. That happens more than you'd think. Here's what to do.
Start writing down the timeline. When you ordered the report, when it actually came back, what the SLA promised versus what happened, and every step of your own adverse action process, with dates. You want this documented while you still remember it clearly, not reconstructed later from memory.
Don't let frustration with your vendor's delay push you into cutting your own corners. Skipping the waiting period, telling a candidate verbally before the process is finished, those mistakes are entirely within your control no matter what the vendor did on their end. A slow vendor is their fault. A skipped waiting period is yours.
The moment a report error or a dispute turns into an actual complaint or a demand letter from a lawyer, bring in employment counsel. Treat it like the legal matter it already is, not a customer service ticket you route to your vendor's support line.
And use it. A missed SLA, an unresolved dispute, a vendor that went quiet when you needed answers, write it down and bring it to your next contract renewal or RFP. A documented pattern of failure is leverage. It's also grounds to switch, and you shouldn't feel like you need permission to act on it.
Price matters. Integrations matter. How fast a report comes back matters. None of that is fake.
But accreditation, a documented process, and a written SLA aren't extras you get to if there's budget left over. They're gating criteria, because your own legal exposure is tied directly to them, whether you signed up for that or not.
Everything in this article, checking accreditation, comparing SLAs, actually reading the contract instead of skimming it, is real work. Most HR teams doing this alongside a full-time job don't have room to do all of it carefully for every vendor on a shortlist.
That's exactly the gap a structured matching process fills. It's already done the vetting you'd otherwise have to do yourself, one vendor at a time, on top of everything else on your plate.