
Too many organisations assume that a background check done at hiring is enough. But people’s circumstances change, roles evolve, and threats adapt. An employee who was low risk at hire can later face financial pressure, be targeted by criminal syndicates, or be promoted into a sensitive role, all of which can materially change their risk profile.
Why a one-time check is inadequate
- Life changes matter: financial distress, personal crises, or new outside business interests can create incentives to commit fraud or leak confidential data.
- Role changes increase exposure: promotions to procurement, finance, IT, or client-facing roles create new access to sensitive assets.
- Criminal syndicates adapt: organised groups actively target insiders, using coercion or social engineering to recruit or threaten employees.
- Time erodes information value: adverse media, legal actions, and undisclosed affiliations can arise after hire and remain undetected without monitoring.
What ongoing screening (monitoring) actually protects
- Data security and IP: early detection of changes that might expose secrets or systems.
- Reputation and regulatory compliance: reduces the risk of being unknowingly complicit in fraud or corruption.
- Operational resilience: helps detect insider threats, conflicts of interest, and fraud schemes before they crystallise.
- Employee wellbeing: monitoring programmes can flag staff under stress who may need support, reducing risk while helping people.
Barriers to making the ongoing screening standard
- Privacy and legal concerns: employers worry about overreach and must navigate labour and data protection laws.
- Cost and complexity: continuous checks are seen as expensive and technically demanding.
- Cultural resistance: screening is often perceived as distrustful or punitive, harming morale.
- Lack of governance: no clear policies on when, how, and for whom ongoing checks apply.
How companies can make monitoring a sensible, lawful standard
- Adopt a risk-based model: focus continuous monitoring on high-risk roles, vendors, and individuals with access to sensitive assets.
- Build clear policies and consent: establish transparent, written procedures; inform employees and obtain lawful consent where required. Ideally, this should be built into company policies, and employees should be well aware of these ongoing checks when they are employed.
- Use proportionate checks: mix passive monitoring (adverse media, PEPs) with periodic rescreening and targeted checks after role changes or incidents.
- Integrate with HR lifecycle: trigger checks on promotion, transfer, disciplinary action, or when new responsibilities are assigned.
- Protect privacy and fairness: limit data collection to what’s necessary, ensure secure handling, and provide appeal/remediation routes.
- Communicate benefits: frame monitoring as protecting the business, colleagues, and the individual, not as mistrust.
- Use a professional background screening company that will assist with all areas of compliance in the screening process.
- Train leaders and HR: ensure managers understand risk indicators, escalation paths, and how to support affected staff.
- Encourage HR and Risk to regularly meet and agree on the areas of risk for the various positions
A closing ask for leaders, if hiring is risk management, why stop there?
Ongoing screening, done fairly and lawfully, is an investment in trust, compliance, and resilience. What steps would your organisation need to take to move from one-off checks to continuous, risk-based monitoring?
If you have implemented this successfully, I’d welcome examples of what worked and lessons learned.
