Skip to main content

FAQs: Background checks: requirements, Secureframe setup, and common scenarios

Written by Brady Price

Secureframe: product setup and evidence

This article brings together common customer questions and practical answers based on typical Secureframe workflows, compliance situations and unique tech stacks.

It is meant as quick reference material for day-to-day use of the product.

For New hire screening test intervals, At Risk status, and upload tracking, see FAQs: Test uploads, tracking, and audit Testing tab.

How can I remove or disable background checks from my account or application?

  • Completed background checks are stored in the data room, and pulled reports can be archived via the three dot menu. For additional questions or help with this, please reach out to our support team!

How can one retract the initiation of a background check?

  • Currently, there is no direct way to cancel or retract a background check once it has been initiated. However, if you need to exclude a user from background checks you can move the user to a group that is exempt from background checks.

    This will effectively prevent the system from requiring or processing a background check for that user moving forward.

What if our employees completed their background check with a different email?

  • During employee onboarding, employees will provide the email used to consent to background checks. If completed with a different vendor, the system will pull the completed checks for the user.

What to do for background checks if there are no new hires during audit window?

  • If no new hires occur during the audit window, the client does not need to provide any evidence related to background checks.

Does this Initiate Background Check restart an existing background check process?

  • No, it does not restart an existing check. The Initiate Background Check button is only clickable when a check has not yet been started. If a check is already in progress or completed in the system, the option will be disabled or removed. For previously completed background checks, admins can instead upload the existing report manually to the Data Room for evidence.

An employee completed their background check, but the task is still greyed out or blocked in onboarding. What should I do?

  • First confirm whether the check was completed through Secureframe/Checkr or outside the platform (for example directly in Checkr or with another vendor).

  • If completed in Secureframe: open the user's Personnel profile and confirm the background check shows as complete. If it does but onboarding still shows grey, wait for the next sync and have the employee log out and back into onboarding.

  • If completed outside Secureframe: the onboarding task may remain grey until evidence is linked. Upload the report manually (How to Upload and Match Background Checks) or confirm the employee entered the same email used for the Checkr report during onboarding.

  • If the employee used a different email in Checkr than their Secureframe account, the completion may not match. Update or merge personnel records if needed, or contact Support.

  • Initiate Background Check is only available when a check has not started. If the button is grey because a check is in progress or complete, that is expected. The issue is usually a status sync or email mismatch, not a missing initiation step.

What email should I use for my background check?

  • Enter the email used during your background check. If you've completed a background check previously (with Checkr or Vetty), use the same email address to backfill the completed check.

If a client has previous background checks from a non-integrated vendor, do they need to re-run background checks?

  • No need to re-run background checks. Background checks not done with an integrated vendor can be used; they just need to be uploaded manually.

Why is the New hire screening test still failing after group exceptions or a Vetty re-sync?

  • Open the New hire screening test and confirm the evidence date range covers your audit window. Group exceptions only affect personnel included in the excepted groups; verify the employee is in the correct personnel group and not marked out of scope.

  • For Vetty or Checkr integrations, re-sync the background check connection under Monitoring → Integrations, then refresh the test. Confirm the employee used the same email in Checkr/Vetty as their Secureframe personnel record.

  • If evidence still does not populate, upload the report manually to the Data Room and link it to the employee, or contact [email protected] with the personnel name and test interval dates.

Where can I find the expected date range for New hire screening evidence?

  • Open the test detail page and review the test interval and guidance in the Evidence tab. The required coverage period is based on the test interval (typically aligned to new hires within the audit window). Set manual upload Completed on dates to when the background check was completed, not when you uploaded the file.

Why does personnel status show incomplete or failing tests even when onboarding shows 100% complete?

  • Onboarding completion and compliance test status are tracked separately. An employee can finish every onboarding task (policies, training, consent) while the background check or New hire screening test is still In progress, Not started, or missing linked evidence.

  • Open the employee's Personnel profile and confirm background check status. Open the New hire screening test and verify evidence covers the audit window. If Checkr/Vetty shows complete but Secureframe does not, check for an email mismatch or duplicate personnel records (merge users if needed).

  • If the check was completed outside Secureframe, upload the report manually (How to Upload and Match Background Checks) so the test can pass.

What steps are required to ensure background checks are properly initiated and processed through Checkr or Vetty?

  1. Connect the integration. Go to Monitoring → Integrations → Background Check and connect Checkr (or Vetty if you are an existing customer). See Integrate and Initiate background checks (Checkr).

  2. Configure onboarding settings. Open Personnel → Settings → Onboarding (or Onboarding settings). Select a Background Vendor and Background Check package. Both are required before Initiate Background Check becomes available.

  3. Employee consent. The employee completes background information and consent during onboarding. Until consent is submitted, the initiate option may be greyed out for admins.

  4. Admin initiation. From Personnel, use the three-dot menu next to the employee and select Initiate Background Check. Status moves to In progress while Checkr/Vetty processes the package.

  5. Sync and evidence. When complete, the report uploads to the Data Room and personnel status updates to Completed. Re-sync the integration if status is stale after several minutes.

Why is New hire screening showing At Risk when I do not see overdue or incomplete tasks?

  • The New hire screening test can show At Risk when required evidence is missing for personnel in scope during the test interval, even if individual onboarding tasks look complete. Common causes: background check not linked, wrong Completed on date, or evidence date range that does not cover the audit window.

  • Open the test detail page and review the Evidence tab and date range. Confirm group exceptions include the right personnel. For upload and interval troubleshooting, see FAQs: Test uploads, tracking, and audit Testing tab.

Can I track uploaded background checks without selecting a vendor, package, or integration?

  • Yes. If you use Checkr (or another vendor) outside Secureframe, or do not want automatic initiation, skip the integration and upload reports manually to the Data Room as Background Check Report evidence assigned to each employee. See How to Upload and Match Background Checks.

  • You do not need to select a vendor and package in onboarding settings for manual tracking. You still need in-scope personnel to have evidence linked before the New hire screening test can pass.

Where is the background check test or New hire screening control located?

  • Open Tests from the left navigation and search for New hire screening. This test evaluates background check evidence for in-scope personnel during the test interval.

  • Personnel-level status and initiation live under Personnel (background check column and three-dot menu). Policy scope for who needs checks is covered in Background check scope.

Where can I find background check status and reports for employees?

  • Personnel table: Use background check filters (Completed, In Progress, Not Initiated, Not Started) and open the employee profile for status.

  • Data Room: Completed Checkr/Vetty reports initiated through Secureframe are stored as Background Check Report evidence. Super Admins can export sensitive reports from the Data Room when needed.

  • Secureframe does not display the full Checkr report inline in Personnel. Use Checkr for live report detail; use Secureframe for compliance status, linked evidence, and audit tests.

How do I exclude contractors or non-US employees from background checks?

  • Open Personnel → Settings → Onboarding. Use personnel groups and exceptions to mark contractors or international employees out of scope for automated background checks.

  • For non-US employees, many organizations use resume and reference documentation instead of a formal check. Confirm requirements with your auditor and see Background check scope for in-scope vs out-of-scope guidance.

  • To remove the requirement for one person, move them to an excepted group rather than deleting the personnel record.

Why does Secureframe show a different background check status than Checkr or Vetty (for example Not started vs In progress)?

  • Not started in Secureframe usually means the employee has not completed onboarding consent, or an admin has not clicked Initiate Background Check yet, even if Checkr shows activity.

  • In progress on one side and Not initiated on the other often means the check was started in Checkr/Vetty directly, not through Secureframe. Re-initiate from Personnel if the button is available, or upload the completed report manually.

  • Also check for duplicate personnel records, email mismatches between Checkr and Secureframe, and stale integration syncs under Monitoring → Integrations.

Will background checks initiated outside Secureframe sync automatically?

  • No. Checks started directly in Checkr or Vetty (outside the Secureframe initiate flow) generally do not auto-associate with the correct personnel record, even when email and name match.

  • Upload the completed report to the Data Room and assign it to the employee, or initiate through Secureframe for new checks. See How to Upload and Match Background Checks.

  • Secureframe does not send a dedicated admin email for every consent submission. Admins should monitor the Personnel table for status changes (for example from Not started to ready for initiation) and use Personnel filters for background check state.

  • After consent, the admin must still click Initiate Background Check from the employee's three-dot menu unless your onboarding automation already triggers initiation.

Is Checkr the only way to run background checks in Secureframe?

  • Checkr is the supported integration for new customers. Vetty remains available for some existing customers. You can also upload third-party or prior background check reports manually without any integration.

What should an employee do if they never received the background check invitation email?

  • Check spam and confirm the email on the Personnel record matches where Checkr sent the invite. Employees can enter the email used for a prior Checkr check during onboarding to help backfill.

  • Non-admins should contact their Secureframe admin. Admins can verify consent status, correct the email on the personnel record, and re-initiate from the three-dot menu when available.

  • Timing depends on Checkr and the package ordered; Secureframe does not control how fast Checkr completes searches.

How can I clear overdue background check tasks when the check is already complete?

  • If Checkr/Vetty shows complete but Secureframe still shows overdue: confirm the report is linked in the Data Room, merge duplicate personnel if needed, and re-sync the background check integration.

  • There is no manual status override toggle. Passing the test requires correct evidence association. Upload the report manually if auto-sync did not link it.

  • Super Admins can export background check reports for auditor requests when direct auditor access is not available. See How to Upload and Match Background Checks.


Policy, timing, and retention

When do background checks need to be performed?

  • Background checks should be performed within accordance with the company's policy, typically within 30 days of hire.

How long should background check results be retained to comply with audit requirements, and what is the recommended policy?

  • Background check results should be retained at least through the duration of employment and in accordance with your organization-defined re-screening frequency. This allows you to demonstrate compliance with your policy during an audit.

    Organizations typically define re-screening intervals such as annually, or every 3-7 years. To meet audit requirements, you should be able to provide evidence that background checks were completed and refreshed based on your stated policy.

    Recommended policy:

    Define a clear re-screening frequency in your Background Check or relative Policy (e.g., every 3 years).

    Retain background check results for the length of employment plus the re-screening interval (e.g., 3 additional years after separation if that’s your re-screening period).

    Ensure secure storage with restricted access to these records.

    Always consult with your legal or HR team for additional guidance on applicable data retention laws in your jurisdiction.


SOC 2

Are background checks a requirement for SOC 2?

  • Since SOC 2 is forward-looking, only newly hired employees need to complete a background check. If a customer is performing a Type 1 audit and does not plan to hire in the near term, it's recommended to have one background check completed to provide evidence for that control. All in-scope contractors must have a background check performed. For non-US-based employees, uploading their resume and references can satisfy this control.

For SOC 2, what types of background checks are required?

  • SOC 2 does not specify the type of background checks. As long as background checks are performed, it is up to the organization to decide what type of checks to conduct on employees.

We previously relied on resumes instead of formal background checks, but we’re implementing background checks this cycle. For SOC 2, how should we handle minor or historic criminal violations (e.g., a small theft from several years ago)?

  • SOC 2 does not require organizations to automatically disqualify employees for minor or historic offenses. The key auditor expectation is that a background check is performed and that the organization follows a documented, risk-based decision process for how results are evaluated and handled.

    If a background check identifies a minor or older violation, this can typically be addressed through:

    Documented risk assessment and rationale

    Appropriate access controls or role restrictions (if needed)

    Increased monitoring where relevant

    Formal risk acceptance by management

    Auditors are primarily looking for evidence that the organization:

    Performs background checks consistently

    Evaluates results thoughtfully rather than punitively

    Aligns access and controls with assessed risk

    Moving from resumes to formal background checks is generally viewed as a maturity improvement, not a deficiency, even if historic checks were not performed previously.


ISO 27001 (and related)

Are background checks required for ISO 27001?

  • ISO 27001 does not mandate background checks, but it is a best practice to perform third-party background checks on employees in critical roles. Background screening prior to employment is recommended and may include verification of references, resume accuracy, identity, and criminal or credit history.

For ISO background check, 3a. “Is it correct that we do not need background checks if employees are based in a specific country and/or are contractors?”

  • Correct. ISO 27001 requires appropriate pre-employment screening based on local labor laws and organizational policy.
    If background checks are restricted or not customary in that jurisdiction, alternative methods such as résumé review, reference checks, or interview-based screening are sufficient.

We are aligned to both ISO 27001 and ISO 9001. Our organization began performing background checks in 2022, but some employees hired before that did not have a background check completed at the time of hire. Do we need to retroactively perform background checks on those employees?

  • No, retroactive background checks are not required.
    It is sufficient to have a documented background check policy in place and to provide evidence that background checks have been consistently performed since the policy was enforced (e.g., for all new hires after 2022).

    Auditors generally look for:

    A formally approved and enforced policy

    Evidence that the control is operating as designed going forward

    Consistent application from the policy effective date onward

    As long as background checks are completed for new hires per the policy and this can be demonstrated with evidence, this approach is acceptable for both ISO 27001 and ISO 9001.


HIPAA

Do personnel need to do background checks for HIPAA?

  • While HIPAA does not explicitly require background checks, it is recommended for all personnel, especially those with access to PHI, to undergo background checks. Some organizations may choose to bypass this requirement if it is not feasible.


International and contractors

Can a company require background checks for contractors not in the US?

  • Yes, but background check requirements vary by country. Some countries may have laws prohibiting background checks for contractors, so it's important to check local regulations.

Are background checks required in US and other countries?

  • Background checks depend on local laws. In countries like Canada, India, and China, background checks may be restricted or not required. In such cases, a resume or alternative proof may be acceptable.


Additional customer questions

How long does a background check take when using Checkr?

  • Timing is driven by Checkr and the check package your organization ordered (criminal scope, county searches, etc.), not by a fixed clock inside Secureframe. In practice, many employment packages complete in roughly a few business days, while some searches (for example, certain county records) can take longer when courts or agencies are slow to respond.

What is Vitally and why am I seeing a link from it?

  • Vitally is the tool we use to share and track your Secureframe implementation plan. You may receive links from a vitally.io domain that guide you through key onboarding steps. This is part of your Customer Success experience and helps ensure you stay on track with your compliance journey.

Did this answer your question?