A real compliance audit checks five things: whether your disclosure form actually stands alone and is current, whether adverse action gets handled the same way every single time, whether old records get destroyed the way FACTA requires, whether your policy gets applied the same way to every candidate, and whether you're following the specific rules in every state you actually hire in. Not just your headquarters state. Every state.
You don't need a law degree to run this. You need an afternoon, a stack of your last twenty or so candidate files, and the willingness to actually look, not just assume it's fine because nobody's complained yet. If you don't have a written policy to audit against yet, start with our policy template article first. This one assumes you've already got a program running and want to know if it's actually being followed.
Because nothing going wrong yet isn't the same as nothing being wrong. Most FCRA problems don't show up as a lawsuit on day one. They sit quietly in a filing cabinet for two years, applying to fifty candidates the exact same broken way, until one of those fifty candidates talks to a lawyer.
I spent over a decade on the operations side of a background screening company. The employers who called us in a panic were almost never the ones who'd never had a policy. They were the ones who wrote a good policy once, three years back, and never checked whether anyone was still actually following it.
That's the real risk. Not the missing policy. The policy that quietly stopped matching what people do day to day.
An audit is just you catching that gap before someone else does. Do it once a year, minimum, and any time a law changes in a state where you hire.
Here's the whole thing in one place. Pull a sample of recent candidate files, at least ten, more if you hire a lot, and go through this list against each one. Don't just check your policy document. Check what actually happened.
Background Check Compliance Audit Checklist
Disclosure and authorization
Adverse action
Record disposal (FACTA)
Consistency across candidates
State-specific rules
Twenty-two boxes. If you can't check every one of them for your sample of files, you've found your real audit result. That's not a failing grade. That's the whole point of doing this.
Pull the disclosure form you're using right now. Read it on its own, nothing else. Does it say anything besides "we're going to run a background check on you"? If it mentions your at-will policy, a liability waiver, or anything from the job application, it's not standalone. That's a real problem, and it's one of the most litigated parts of the FCRA.
Now check the date on it. A form your company wrote four years ago and never touched again is a real risk, because the rules around what needs to be in it can shift, and a form nobody's reviewed since isn't going to catch that on its own.
Then check the files themselves, not just the template. Pull ten recent candidates and confirm each one actually has a signed authorization on record, signed before the report went out, not backdated or missing entirely because someone was in a hurry.
That part's not optional. A perfect template sitting in a folder means nothing if the actual signed copies aren't there when someone asks for them.
This is where most audits find their biggest gap, and it's rarely because nobody knows the rule. It's because the rule gets followed for the obvious cases and quietly skipped for the borderline ones.
Say a candidate has one thing on their report that's minor. Not disqualifying on its own, but it's part of why you passed on them along with two other factors. Did they still get a pre-adverse action notice? A lot of employers only send that notice when the report is the sole and obvious reason for a rejection. That's not what the law says. If the report played any role, even a partial one, in the decision, the notice is owed.
Go back through your last ten or so rejected candidates where a background check was part of the process. For each one, ask honestly: did the report factor in at all? If yes, is there a pre-adverse notice on file, sent before the final decision, with the report and the Summary of Rights attached? If you want the full two-step process laid out with sample letters, I walked through that in a separate article on handling adverse action.
So to say that a different way: this isn't about whether you followed the process for your obvious cases. It's about whether you followed it for the messy, in-between ones too. Those are the files a lawyer actually goes looking for.
Check your timing too. Did the waiting period actually happen, or did the final notice go out the same week as the pre-adverse one because the role needed filling? I get why that happens. It's still a violation every single time it does.
I covered this rule in detail in a separate article on the FACTA Disposal Rule, so I won't repeat the whole thing here. For this audit, the question is narrower: is it actually happening, on a schedule, or is it happening whenever someone notices the filing cabinet is full?
Go find your oldest background check files right now. How old are they? If you don't have a clean answer, that's the finding. A retention policy that exists on paper but isn't tied to an actual disposal date isn't really a policy. It's a hope.
Check the method too. "We deleted the file" isn't the same as "we destroyed the file" under FACTA. Hitting delete on a computer usually just removes the label, not the underlying data. If your process is a shredder truck once a quarter and an IT policy that actually wipes drives, you're in decent shape. If it's "someone probably threw that out at some point," it isn't.
That part's not optional, and it's one of the easiest things to fix once you actually see the gap.
This is the part of an audit most employers skip entirely, and it's the one I'd argue matters most. A policy that reads perfectly on paper can still be applied unevenly in practice, and that gap is where disparate treatment claims come from.
Here's the spot-check I'd actually run. Pull a sample of candidates for the same role, across different demographics if your numbers allow it, and lay their files side by side. Did they all get the same checks? Were similar records weighed the same way, or did one candidate get a pass on something another candidate got rejected for?
You're not looking for intentional discrimination, necessarily. Most of the time, it's not that. It's a hiring manager who liked one candidate enough to overlook something, and didn't extend that same grace to someone else. That's still a real problem, even when nobody meant it to be one.
The fix isn't complicated. Tie every check to the role, not the person, and write down how a given kind of record gets weighed before you're looking at an actual candidate's file. Deciding case by case, in the moment, is exactly how inconsistency creeps in without anyone noticing.
This one gets missed constantly, especially once a company grows past hiring only in its home state. Your policy might be airtight for where your office sits and still be missing something in three other states where you've got remote employees or candidates.
Make an actual list. Every state where you currently have candidates or employees, not just headquarters. For each one, check whether it has its own ban-the-box or fair chance timing rule, its own lookback limit on what can show up on a report, or its own restriction on credit checks.
I'm not going to hand you a master list of every state rule here, because that list changes, sometimes more than once a year, and a stale list is worse than no list at all if you trust it blindly. What I will tell you is that "we use one national process everywhere" is a phrase that should make you nervous, not confident. A process built for the average state usually isn't built for the strictest one.
If you're hiring across five or more states, this is the part of the audit worth having a lawyer or your background check company's compliance team actually walk through with you, rather than relying on an article, including this one, to catch every gap.
Whoever owns your background check policy should run this audit, and that should be one named person, not a shared responsibility that quietly belongs to nobody. If you don't currently have that person named, that's worth fixing before you even get to the checklist above.
Run it once a year at minimum. Run it again any time a law changes in a state where you hire, any time you start hiring in a new state, or any time you bring on a new background check provider. A provider switch is a bigger trigger than people expect, because your old process might not map cleanly onto the new vendor's forms and workflow.
An outside review from a lawyer or a compliance consultant is worth doing every couple of years even if your internal audits keep coming back clean. A fresh set of eyes catches things a person too close to the process stops noticing.
Something usually turns up. That's normal, and it's not a reason to panic. Write down exactly what you found, fix the process going forward, and don't try to quietly patch old files to make them look like they always followed the rule. That second part matters more than people think. A record that's honest about a past gap is defensible. One that looks retroactively cleaned up is not.
If the gap is small, like a form that's a year out of date but was still legally sufficient, fix it and move on. If the gap is bigger, like adverse action notices that were skipped for a chunk of candidates, talk to an employment lawyer before you do anything else. I'm not a lawyer, and a gap like that carries real legal weight I'm not going to pretend to resolve for you in an article.
Either way, don't let the audit be the last time you look. The whole reason this stuff drifts is that a policy gets written once and then nobody checks it again for years. Checking it once, thoroughly, is good. Checking it every year is what actually keeps you out of trouble.