
The 2026 ACFE Report to the Nations makes the point visually: executive/upper management, accounting and finance, and sales sit at much higher risk for occupational fraud than many other functions. That does not mean every hire in every department should face the same level of vetting, it means your screening policy should be proportionate to departmental risk and informed by the people who know those risks best.

- Risk is not uniform. Functions that handle cash, financial controls, vendor payments, or sensitive client data (finance, accounting, sales, execs) present different incentives and opportunities for misconduct than, say, facilities, R&D, or marketing.
- One‑size screening is inefficient. Over‑screening low‑risk roles wastes time and budget; under‑screening high‑risk roles leaves the business exposed.
- Culture and context vary. Some departments operate with decentralised decision-making or heavy external interaction (sales, procurement), that increases vulnerability in ways HR alone may not see.
How to build a sensible, department‑aware screening policy
- Start with a cross‑functional risk map
- Ask the risk/compliance team to map the organisation by fraud exposure, privilege level, and data
- Produce a simple heatmap showing which functions carry higher exposure and why.
- Involve department owners early
- Invite heads of Finance, Sales, IT, Operations, Legal, and any function with unique exposures to provide role‑level insight: authority levels, access, third‑party interactions, and common pain points.
- Capture role families (e.g., junior accountant vs. AP manager), screening depth should follow role risk, not just job title.
- Let HR translate risk into screening tiers
- Define screening tiers (e.g., standard, enhanced, executive) and map role families to tiers based on risk inputs.
- Standard: identity verification, reference checks.
- Enhanced: criminal/credit checks where lawful, employment verification, and professional license checks.
- Executive/High‑Risk: enhanced full due diligence, periodic re‑screening, and ongoing monitoring.
- Consult the risk/compliance team on controls and monitoring
- Screening reduces hiring risk but does not eliminate it. Risk should advise on background check frequency, post‑hire monitoring triggers, and how screening integrates with segregation of duties and approval workflows.
- Ensure legal and privacy alignment
- Work with Legal to confirm which checks are permissible in each jurisdiction and that consent, data retention, and adverse‑action processes meet local law.
- Communicate policy and exceptions clearly
- Publish a concise screening policy that explains tiers, rationale, and escalation paths for exception approvals. Transparency helps hiring managers and candidates understand expectations.
- Review, measure, and refine
- Track outcomes: time‑to‑hire, cost per screen, and incidents detected post‑ Use those metrics and periodic fraud/loss data to recalibrate tiers and focus.
HR should own employee‑screening policy administration, but the policy cannot be designed in isolation. The best, most defensible policies are created at the intersection of HR, department owners, legal, and risk. Use fraud research as a conversation starter, not a checklist: it signals where to focus effort and provides evidence to justify different tiers of screening across your organisation.
Contact iFacts if you would like assistance with drafting a short screening‑tier template and an email HR can send to department heads to collect role‑level risk inputs.
