How to evaluate a background verification provider
Sixteen questions, grouped by what they actually test, and the answers that should worry you. Written so it works against us as well as against anybody else, which is the only way a checklist like this is worth anything.
- Ask to see a case that went badly, not a case that went well. Every provider can show you a clean one.
- The two ways to be faster than the sources allow are both ways of not doing the check.
- A report without the source response behind each finding is a conclusion you cannot inspect.
- Certification answers the data-handling question. It does not answer the did-you-actually-check question.
Why the usual evaluation does not work
Most provider selections come down to price, turnaround and a demonstration. All three are easy to look good on and none of them tests the thing that matters.
Price is comparable only if the products are the same, and the largest cost difference in this industry is between contacting a record holder and reading a document the candidate supplied. Those produce identical-looking reports at very different costs.
Turnaround is worse, because being fast is mostly a matter of not waiting, and not waiting is mostly a matter of not asking. And a demonstration shows you a case where everything worked, which is the case where the differences between providers are smallest.
What follows is sixteen questions that are hard to answer well without actually operating properly. Ask them of us too.
Sourcing: did you actually check?
This group is the most important and the least often asked.
1. For each check in your proposal, who exactly do you contact?
Not "we verify employment" but which desk at which organisation. A provider who runs this work knows, immediately, that education goes to the awarding university and not the affiliated college, and that a large employer's request has to reach the correct legal entity.
Worrying answer: a general description of a process, or a reference to "our database" for a check that should go to a record holder.
2. Which of your checks are database lookups and which are direct contact?
Both have a place. A global database screen is legitimately a database. An employment verification should not be. What you are testing is whether they will tell you the difference unprompted.
3. What happens when a former employer will not respond?
The single most useful question on this page. Ask for the escalation path, and ask what the case looks like at the end if nobody ever answers.
Worrying answer: anything that ends with the check being marked verified. The correct answer is that it is reported as unanswered, with the attempts documented, and corroborated where possible through EPFO records.
4. Show me a case where a check could not be completed.
A redacted real one. How an "unable to verify" is written up tells you more about a provider than any number of clean cases.
Evidence: can I see what you saw?
5. Is the source document or response attached to each finding?
If the answer is that a summary is provided, you are being asked to trust a conclusion. The annexure is the difference between a report you can defend to an auditor in eighteen months and one you cannot.
6. How is a discrepancy presented?
You want both versions shown: what the candidate declared and what the source returned, side by side, unresolved. A provider who reconciles a mismatch on your behalf has made a decision that was yours to make.
7. Do you score or rate candidates?
A single score compresses away exactly the information you need. As the discrepancy anatomy shows, "payroll kept contributing for a month after exit" and "two concurrent employers for two years" are the same amber and completely different facts.
Worrying answer: a proprietary risk score presented as the main output.
8. Can a candidate see what was found and correct it?
Ask for the actual route. A provider without one has not thought about the candidate at all, and under the DPDP Act that is a gap that lands on you as well as on them.
Data handling: what happens to what I give you?
9. What is your retention period, per data type, and what triggers deletion?
A specific answer exists at a provider that has thought about it. "As long as required" is not one.
10. Where is candidate data stored, and who inside your organisation can reach it?
11. What certifications do you hold, and can I see the certificates?
ISO 27001 is the relevant one for information security management. It is worth having and it is not sufficient: it tells you a management system was audited, not that a check was run at source. Treat it as a floor.
12. How is consent captured, and does the record name the specific checks?
Consent to an employment check is not consent to a credit check. The consent record should name what it covers, and you should be able to produce it later. See the DPDP piece.
Failure: what happens when it goes wrong?
13. What is your process when a finding turns out to be incorrect?
Errors happen. What matters is whether there is a defined route to correct one, whether the correction is visible on the case alongside the original, and who is told.
14. Who do I speak to when a case is stuck, and will it be the same person?
A ticket queue is a reasonable way to run support and a poor way to run an escalation about a person's joining date.
15. What proportion of your cases involve a physical visit, and is the field network yours?
Relevant if you are buying address verification or anything outside metros. Sub-contracted field work is normal; not knowing whether it is sub-contracted is not.
16. Which checks in this proposal do you think we do not need?
A provider willing to talk you out of a check is telling you something about how they will behave for the next three years. One that agrees every role needs everything is selling a package rather than scoping one.
Question 3 and question 16 are the two that are hardest to fake. The first tests whether a provider does the work when nobody would notice if they did not. The second tests whether they will act against their own short-term interest. If you only have time for two, use those.
Answers that should worry you
| What you hear | What it may mean |
|---|---|
| "Guaranteed turnaround of X days for the full package" | Either the slow checks are not really being run at source, or the guarantee has exceptions that will apply to most of your cases |
| "We have a database of Indian criminal records" | There is no national criminal database open to employers. Ask exactly what the database contains and where it came from |
| "Our AI verifies documents automatically" | Document analysis is real and useful. It is not the same as contacting the issuer. Ask which one is happening |
| "We can check without informing the candidate" | Walk away. Checks run on consent, and this exposes you rather than them |
| "100% verification success rate" | Sources sometimes do not answer. A provider with no unanswered checks is closing them as something |
| "We'll flag anything suspicious" | Ask what "suspicious" means and who decides. You want facts and evidence, not somebody else's judgement about your candidate |
| A polished specimen document offered instead of a real case | Read it for what it does NOT contain: an unanswered check, a discrepancy left unresolved, an annexure. A pilot on your own difficult candidates tells you more than any prepared document |
Run a pilot, and choose what goes in it
The most informative thing you can do costs a small batch of cases.
Do not send an easy batch. Send the cases you expect to be difficult: a candidate whose previous employer has closed, one who has lived in several cities, one with a qualification from a smaller institution, one with a common name. Those are where providers differ, and a pilot of five straightforward metro candidates will tell you almost nothing.
Then read what comes back with three questions. Is there evidence behind each finding? Is anything reported as unanswered, and if not, is that plausible given what you sent? And is a discrepancy shown as two versions or as a resolved verdict?
Applying this to us
It would be dishonest to publish this and then be evasive about our own answers, so briefly: GVS annexes the source document or response to every finding, reports both versions of a disputed fact rather than resolving it, does not issue a candidate score, and reports an unanswered check as unanswered with the attempts shown. We hold ISO 9001:2015 and ISO 27001 and the certificates go to prospects on request. We state one turnaround figure, for identity, and decline to state one for checks whose pace is set by somebody else.
The things we would want a buyer to press us on are the same ones on this page. Ask for a difficult pilot batch, and ask which checks in a proposal you do not need. Both are in talk to sales, and the data-handling detail is in the Trust Centre.
Questions we get asked
What is the single most useful question to ask?
Should we choose the fastest turnaround?
Does ISO certification matter?
What should be in a report?
How should a provider handle candidate data?
Is a cheaper provider a worse provider?
Read next
What sets the pace, and why a guaranteed turnaround should raise a question.
Read the guide The anatomy of a discrepancyWhy a score destroys the information you actually need from a report.
Read the research Trust CentreOur own answers on consent, retention, access and certification.
Trust CentreBring the sixteen questions to the call
And send a difficult pilot batch, not an easy one. That is where providers differ.
Talk to sales