GVS - Genuine Verification Services
Talk to sales

How to evaluate a background verification provider

Sixteen questions, grouped by what they actually test, and the answers that should worry you. Written so it works against us as well as against anybody else, which is the only way a checklist like this is worth anything.

9 min readReviewed August 2026Research & analysis
Trusted by 500+ companies
Canara BankChannelplayTata AIG InsuranceMacgenceIndiaMARTOlive Green ConsultingPunjab & Sind BankZee MediaJobkartKazamAvalon Information SystemsMeruBTCQuytechGreat Eastern Energy CorporationGiginBharat BhushanPilot IndustriesShipex IndiaKW GroupWise FinServPTC NetworkOrcapodadaanSouthern TravelsElectricaBaby & Mom RetailSyscomLarkRoots DevelopersGMSCircleRightRudra ShieldEssential EnergyAviaxpert
In short
  • Ask to see a case that went badly, not a case that went well. Every provider can show you a clean one.
  • The two ways to be faster than the sources allow are both ways of not doing the check.
  • A report without the source response behind each finding is a conclusion you cannot inspect.
  • Certification answers the data-handling question. It does not answer the did-you-actually-check question.

Why the usual evaluation does not work

Most provider selections come down to price, turnaround and a demonstration. All three are easy to look good on and none of them tests the thing that matters.

Price is comparable only if the products are the same, and the largest cost difference in this industry is between contacting a record holder and reading a document the candidate supplied. Those produce identical-looking reports at very different costs.

Turnaround is worse, because being fast is mostly a matter of not waiting, and not waiting is mostly a matter of not asking. And a demonstration shows you a case where everything worked, which is the case where the differences between providers are smallest.

What follows is sixteen questions that are hard to answer well without actually operating properly. Ask them of us too.

Sourcing: did you actually check?

This group is the most important and the least often asked.

1. For each check in your proposal, who exactly do you contact?

Not "we verify employment" but which desk at which organisation. A provider who runs this work knows, immediately, that education goes to the awarding university and not the affiliated college, and that a large employer's request has to reach the correct legal entity.

Worrying answer: a general description of a process, or a reference to "our database" for a check that should go to a record holder.

2. Which of your checks are database lookups and which are direct contact?

Both have a place. A global database screen is legitimately a database. An employment verification should not be. What you are testing is whether they will tell you the difference unprompted.

3. What happens when a former employer will not respond?

The single most useful question on this page. Ask for the escalation path, and ask what the case looks like at the end if nobody ever answers.

Worrying answer: anything that ends with the check being marked verified. The correct answer is that it is reported as unanswered, with the attempts documented, and corroborated where possible through EPFO records.

4. Show me a case where a check could not be completed.

A redacted real one. How an "unable to verify" is written up tells you more about a provider than any number of clean cases.

Evidence: can I see what you saw?

5. Is the source document or response attached to each finding?

If the answer is that a summary is provided, you are being asked to trust a conclusion. The annexure is the difference between a report you can defend to an auditor in eighteen months and one you cannot.

6. How is a discrepancy presented?

You want both versions shown: what the candidate declared and what the source returned, side by side, unresolved. A provider who reconciles a mismatch on your behalf has made a decision that was yours to make.

7. Do you score or rate candidates?

A single score compresses away exactly the information you need. As the discrepancy anatomy shows, "payroll kept contributing for a month after exit" and "two concurrent employers for two years" are the same amber and completely different facts.

Worrying answer: a proprietary risk score presented as the main output.

8. Can a candidate see what was found and correct it?

Ask for the actual route. A provider without one has not thought about the candidate at all, and under the DPDP Act that is a gap that lands on you as well as on them.

Data handling: what happens to what I give you?

9. What is your retention period, per data type, and what triggers deletion?

A specific answer exists at a provider that has thought about it. "As long as required" is not one.

10. Where is candidate data stored, and who inside your organisation can reach it?

11. What certifications do you hold, and can I see the certificates?

ISO 27001 is the relevant one for information security management. It is worth having and it is not sufficient: it tells you a management system was audited, not that a check was run at source. Treat it as a floor.

12. How is consent captured, and does the record name the specific checks?

Consent to an employment check is not consent to a credit check. The consent record should name what it covers, and you should be able to produce it later. See the DPDP piece.

Failure: what happens when it goes wrong?

13. What is your process when a finding turns out to be incorrect?

Errors happen. What matters is whether there is a defined route to correct one, whether the correction is visible on the case alongside the original, and who is told.

14. Who do I speak to when a case is stuck, and will it be the same person?

A ticket queue is a reasonable way to run support and a poor way to run an escalation about a person's joining date.

15. What proportion of your cases involve a physical visit, and is the field network yours?

Relevant if you are buying address verification or anything outside metros. Sub-contracted field work is normal; not knowing whether it is sub-contracted is not.

16. Which checks in this proposal do you think we do not need?

A provider willing to talk you out of a check is telling you something about how they will behave for the next three years. One that agrees every role needs everything is selling a package rather than scoping one.

Question 3 and question 16 are the two that are hardest to fake. The first tests whether a provider does the work when nobody would notice if they did not. The second tests whether they will act against their own short-term interest. If you only have time for two, use those.

Answers that should worry you

What you hearWhat it may mean
"Guaranteed turnaround of X days for the full package"Either the slow checks are not really being run at source, or the guarantee has exceptions that will apply to most of your cases
"We have a database of Indian criminal records"There is no national criminal database open to employers. Ask exactly what the database contains and where it came from
"Our AI verifies documents automatically"Document analysis is real and useful. It is not the same as contacting the issuer. Ask which one is happening
"We can check without informing the candidate"Walk away. Checks run on consent, and this exposes you rather than them
"100% verification success rate"Sources sometimes do not answer. A provider with no unanswered checks is closing them as something
"We'll flag anything suspicious"Ask what "suspicious" means and who decides. You want facts and evidence, not somebody else's judgement about your candidate
A polished specimen document offered instead of a real caseRead it for what it does NOT contain: an unanswered check, a discrepancy left unresolved, an annexure. A pilot on your own difficult candidates tells you more than any prepared document

Run a pilot, and choose what goes in it

The most informative thing you can do costs a small batch of cases.

Do not send an easy batch. Send the cases you expect to be difficult: a candidate whose previous employer has closed, one who has lived in several cities, one with a qualification from a smaller institution, one with a common name. Those are where providers differ, and a pilot of five straightforward metro candidates will tell you almost nothing.

Then read what comes back with three questions. Is there evidence behind each finding? Is anything reported as unanswered, and if not, is that plausible given what you sent? And is a discrepancy shown as two versions or as a resolved verdict?

Applying this to us

It would be dishonest to publish this and then be evasive about our own answers, so briefly: GVS annexes the source document or response to every finding, reports both versions of a disputed fact rather than resolving it, does not issue a candidate score, and reports an unanswered check as unanswered with the attempts shown. We hold ISO 9001:2015 and ISO 27001 and the certificates go to prospects on request. We state one turnaround figure, for identity, and decline to state one for checks whose pace is set by somebody else.

The things we would want a buyer to press us on are the same ones on this page. Ask for a difficult pilot batch, and ask which checks in a proposal you do not need. Both are in talk to sales, and the data-handling detail is in the Trust Centre.

Questions we get asked

What is the single most useful question to ask?
Show me what a case looks like when a former employer refuses to answer. Every provider can show a clean case. How a provider handles a source that will not co-operate tells you whether they escalate and report honestly, or quietly close the check as verified.
Should we choose the fastest turnaround?
Be careful. For most checks the time is spent waiting for a third party, so there are only two ways to be materially faster: accept the documents the candidate supplied instead of going to the record holder, or close an unanswered check as verified. Both produce a fast report and neither produces a check.
Does ISO certification matter?
It is worth having and not sufficient on its own. ISO 27001 tells you an information security management system was independently audited, which matters when you hand over candidate data at volume. It says nothing about whether a check was run at source, which you have to ask separately.
What should be in a report?
Per-check status, the finding in words showing what the source said against what the candidate declared, and the source document or response annexed behind each finding. A report giving only a status, or a score, is asking you to trust a conclusion you cannot inspect.
How should a provider handle candidate data?
Under written consent that names the checks, with a stated retention period, access controls, and a route for a candidate to ask what is held and request a correction. Under the DPDP Act these are obligations rather than preferences, and they fall on the employer as well as the provider.
Is a cheaper provider a worse provider?
Not automatically, but ask where the saving comes from. Operating efficiency is fine. Reading documents instead of contacting sources, or closing unanswered checks, means you are paying less for something that is not the same product.

Read next

Bring the sixteen questions to the call

And send a difficult pilot batch, not an easy one. That is where providers differ.

Talk to sales