Scaut

Author: danielbutler6045b93171

  • Employee screening quickly and cheaply? Yes, you can!

    Employee screening quickly and cheaply? Yes, you can!

    What you pay for in recruitment

    Selecting a new employee is a complicated, and often lengthy, process. It costs time, effort, and money.

    What are all the costs to the employer?

    • Recruitment team (internal HR)
    • External agency
    • Advertising and marketing
    • Non-HR staff time and capacity
    • Verification of candidates and their professional history

    If we add it all up, we arrive at an amount of several tens of thousands even for ordinary positions. This is even if any of these elements are missing from the recruitment process. Like an external agency or, heaven forbid, a background check.

    Internal background check is expensive

    The importance of a background check and what the consequences of not vetting new employees the consequences, we’ve already said something.

    However, there are pitfalls to internal candidate vetting. It is often inefficient, expensive, and inaccurate. Onboarding can significantly slow down the process and, as a result, make it more expensive. And nobody wants that, and a hundred grand is a lot of money.

    Why is the self-verification of applicants expensive and complicated? For several reasons:

    • Lack of practical experience and knowledge on the part of in-house staff
    • Little experience in assessing information and documents
    • Necessary access to several paid databases that the average employer will use perhaps only a few times a year
    • Lack of a technical solution to quickly obtain and evaluate information
    • Little capacity, internal staff have to do this in addition to their other work
    • More frequent errors, leading to the need to introduce additional controls

    If it doesn’t work, we won’t use it

    Nobody enjoys a lengthy and complicated process, the results of which are not 100%. And if employees don’t enjoy it and don’t see the benefit, they won’t do it at all, or at least not properly. And the process will get worse and worse…

    What’s next?

    Recruiters will be thinking about how to improve candidate screening. They will hire external consultants to advise them and prepare presentations with suggestions for management. Employees who have worked well in the organization for many years will hardly see their HR. And their issues, problems, and questions will be dealt with belatedly.

    Similar unfortunate consequences arise when the responsibility for background checks of new employees is entrusted to other departments. If, for example, an organization has a fraud prevention team, then it is suggested that the agenda of applicant vetting should be added to that team. Unless capacity and resources are added along with it, which is certainly not automatic, the risk of an external attack on the assets of the organization or its client’s increases.

    6 reasons why background check as a service is better

    What about it? How to perform a background check quickly and with outputs that are easy to use?

    Use the services of those who specialize in employee background checks. Those who offer background checks as a service that you simply buy. Such as SCAUT.

    Will an external service work better than internal candidate verification? On the contrary, will it be more of a burden because the service will be complicated, expensive, and untrustworthy and provide complex outputs that no one inside the company will understand?

    Yes, background check as a service is better. Background checks on job applicants conducted by a specialist contractor can be more efficient, faster, and simply a better solution than a complicated and inefficient in-house process.

    An external candidate verification service is better for the following 6 reasons:

    1. She’s fast: Employees can be verified in a few hours, in complicated cases in a matter of days.
    2. It’s simple: a few clicks are all it takes to verify an applicant, no long paperwork or internet searches.
    3. It is reliable: Companies with a long track record of vetting candidates know what to check, what to look for, and don’t make mistakes.
    4. It’s up-to-date: The service is constantly evolving, responding quickly to new trends and threats, and engaging new data sources.
    5. It is professional: The responsible background check service provider guarantees the accuracy and completeness of the results and compliance with all legal requirements; both are guaranteed by contract
    6. It is easy to use: the output must be as simple as possible for internal HR and management. Semaphore, thumbs up, thumbs down, brief numerical rating. No long and unnecessary text.

    And you save twice

    Using an external job applicant verification service will help you save twice.

    How’s that?

    First: You’ll make your recruitment process cheaper.

    Using a simple service will make your onboarding faster and more efficient. And therefore cheaper, because time is the key factor in onboarding. If you keep a quality candidate waiting for a long time because you are tediously verifying their education and experience from abroad, your competitors will often reach for them. And you’re starting from scratch.

    And second: You reduce the risk of internal fraud, embezzlement, or other threats.

    A job applicant who lies to you during the hiring process may also lie about billing for a business trip. Or about what he was talking about with a competitor and why he downloaded a client database to a flash drive. If you don’t expose the liar at the beginning, it can hurt a lot more later.

  • The employee is stealing! Whose fault is that?

    The employee is stealing! Whose fault is that?

    Three risks of missing a background check

    If an employer does not properly vet a candidate, they may hire someone without the right qualifications and experience. And then he or she has to teach him or her what he or she (unverified) claims he or she should have known long ago.

    The employer may also decide to say goodbye to a less-than-truthful colleague. Then again, they have to spend time and money looking for a new person. In the meantime, someone else has to take his job.

    However, it can also happen that a candidate not only improves his/her classification and experience in his/her CV or tactfully keeps silent about some negative facts, but also applies for the position with the direct aim of harming others. To defraud the employer, to download a client database, to leak trade secrets, to gain unauthorized access to code, and to steal money.

    Sure, it doesn’t happen every day. But it does happen. According to many statistics, the costs associated with insider threats are steadily rising. The cost of dealing with insider threats and attacks is in the tens of millions of crowns in the average organization.

    If nothing major happens…

    The attack threatens everyone

    Even in our context, we have seen major attacks on the employer’s property and other interests from within. A phone carrier’s client database was copied and sold fraudulently, a large amount of cash was stolen, gift cards embezzled, and internal information negligently (or even intentionally) disclosed that affected the company’s value on the stock market or in negotiations with an investor. Examples abound.

    Do you think you are not at risk of such an attack because you are not an operator, a bank, or a large authority or fund managing billions of dollars of assets?

    According to a survey by the U.S. Chamber of Commerce, retail stores face a greater threat from their employees than from thieves or “street” robbers. Yes, internal employees steal more on average than “outside thieves.” Sad but true.

    Who’s to blame for the trouble?

    Who is responsible for the fraudster getting into the company? Who should have checked him, who is responsible for the selection process? Who is to blame for the organization incurring tens or hundreds of millions of dollars in damages because it failed to vet a new employee?

    In other words, who to punish for bad recruiting?

    At first glance, there are several culprits:

    • We can blame HR, which is responsible for recruiting
    • We can blame the compliance officer or the security director because they should have supervised the employees better
    • And if we have an external recruitment agency or headhunter helping us with recruitment, that’s also an ideal scapegoat.

    But firing the head of HR, the compliance officer, or terminating an outside agency will not be fair or effective. And it won’t in itself prevent similar problems from recurring in the future.

    The statutory officer is personally liable

    The first responsibility for the proper functioning of any organization lies with those who run it. Statutory, member of the statutory body, director, CEO, member of the board of directors.

    How should this somewhat general statement be understood in the context of vetting job applicants?

    It is the responsibility of the management of the organization to decide whether they intend to address applicant screening in recruitment at all, what resources they will devote to it, and whether the staff responsible will have the capacity, tools, and capabilities to do so.

    When an organization’s management underestimates the security of its staff or even resigns from vetting candidates altogether, the members of its statutory body put themselves at great personal risk. If this is judged to be a lack of responsibility in the exercise of their functions in breach of due care, they risk being held liable for any damage caused to the organization’s assets. And, in extreme cases, they may even be prosecuted.

    Due diligence and background check

    What does the somewhat archaic-sounding concept of “due diligence” mean in practice? Simply that a member of a statutory body or a member of an elected body is obliged to perform his or her duties with the necessary knowledge, due care, and loyalty. He or she must have sufficient information to make decisions and must put the interests of the organization ahead of his or her interests.

    What if a member of an elected body fails to act with due care and the organization suffers damage? For example, the stakeholder in question did not at all address the background checks of new employees, even though it must have been obvious to him that he was putting the company at great risk.

    In such a case, the member of the statutory body shall be liable for the damage to his entire property. Cash, movable and immovable property, simply everything that he or she owns alone or together with someone else, e.g. a spouse. And that’s where the fun really ends.

    Background check protects the employer and the statutory agent

    Candidate background checks are an important element in protecting employer assets. And, by extension, the personal assets of whoever runs the company.

    Certainly, not every insurance company, county, government office, school, manufacturing company, or business needs to screen its employees to the same extent. But at least a basic consideration of which job applicants an employer will screen, to what extent, in what manner, and using what sources of information and tools, should always be made by the statutory officer. This is the only way to adequately and consistently protect the employer’s assets and one’s own.

  • What Czech HR professionals don’t know: background screening around the world

    What Czech HR professionals don’t know: background screening around the world

    Do you accept the invisible?

    The coronavirus has changed work and HR trends forever. HR departments have to contend with home office employees and remote recruitment. It’s not easy to hire someone without actually seeing them. Verifying that he or she is truly trustworthy is even harder, and is often neglected. Who is hiding behind a small webcam? Does he have such a practice? And aren’t you giving access to sensitive data to a fraudster?

    Where the world trends are going

    Surveys among thousands of recruiters and HR professionals provide an overview of global trends in candidate screening in recent years. Individual respondents from companies across the globe revealed what information they verify about candidates and where they encounter the most common discrepancies.

    The most frequently verified information is the integrity of the applicant. This is followed by checks on identity, the truthfulness of references, suitability for the position, drug and alcohol testing, and a check on actual educational attainment. However, some places also require applicants to undergo fingerprint checks or have their social networks screened.

    And where do the screeners find the biggest discrepancies from what the candidates report?

    • In the EMEA region, i.e. Europe, Africa, and the Middle East, the survey revealed 66% of discrepancies in the candidate’s stated prior experience.
    • In the second place, with 64%, were misstatements in stated education.
    • 42% of candidates had different opinions about their integrity and 36% concealed overdue debts.
    • In Asia, the trends are similar, while in the US and Canada, the most significant problem uncovered is the criminal scruples of the people being screened.

    Some discrepancies, especially regarding past practice, may not be intended as fraud. However, it is always worth considering why a candidate does not, for example, want any of their previous employers to be contacted for reference checks.

    The unconverted and the wicked

    Those who do not verify information are guided only by their intuition. And that’s a poor guardian of data, money, or reputation. There are many cases where a good background check could have prevented the hiring of a person who caused considerable damage.

    You will remember the Czech theft of the century. A security agency hired an employee who had previously been fired on suspicion of stealing 23 million crowns. Maybe it’s better not to know, they thought…

    Did you know that Yahoo’s CEO had to resign because he lied about having an IT degree? Even in the US, where screening is absolutely common, someone neglected the verification process.

    And when the Strike Force comes for the CFO of a large clothing company because he has been wanted by Interpol for a long time, a red light should go on in all HR departments by now at the latest.

    Why HR departments love background checks

    The background check does not mean that every HR department should set aside time for detective work. Using automated employee screening systems, along with the right methodology, saves companies a lot of time and is much cheaper and more reliable than an in-house solution.

    Screening companies operate in compliance with legislation and GDPR, delivering objective reports in quick time, for example, scaut.com will prepare tailored screening packages for their clients on the SCAUT digital platform, where you often just enter the candidate’s name and date of birth and wait for the report.

    And what does a background check bring to HRists in terms of numbers?

    • 57% said that screening had improved the quality of recruitment,
    • 48% consider more rigorous security screening to be the biggest benefit,

    Better company reputation, elimination of risk, and, above all, peace of mind, are other answers that may inspire even hitherto hesitant companies in our country.

  • Economic crisis: Motivation for fraud is rising

    Economic crisis: Motivation for fraud is rising

    When money is missing…

    Opportunity makes a thief, they say. And so does motivation. The SCAUT platform is here to help ensure you never give the dishonest candidate that opportunity. Remember, with the economic and energy crisis, more and more people face financial difficulties. The opportunity to help make ends meet by taking from an employer can be a temptation for anyone who handles cash, has access to sensitive information or has decision-making power.

    The desire for a nice Christmas, lots of presents, or a spur of the moment decision to pay off a massive electricity bill. The risk of an employee falling victim to temptation is currently greater than ever. Limit this risk it by thoroughly screening job applicants so you have visibility into what kind of people you’re bringing on board.

    Disgruntled people do desperate things

    What is driving people who go on to defraud their own employers? The ACFE report, based on a sample of more than two thousand cases from around the world, identified the following trends associated with Covid and the emerging crisis. The main triggers behind dishonest behaviour include:

    • Fear of job loss
    • Denial of a raise or promotion
    • Cutting back on benefits
    • Pay cuts
    • Involuntary reduction in hours

    It is therefore more important than ever to screen job applicants. Candidates who do not provide truthful information or hidee important details about themselves should not be trusted. A dishonest employee is more likely to turn against his or her own company when feeling threatened. SCAUT gives you the tools you need to make the right decision.

    Peace of mind for a few crowns

    What is the real cost of peace of mind? For many staff positions it can be as low as 250 CZK. A basic pre-Interview check will save you time and cost and will flag up issues with a candidate before they even arrive for an interview. Has the individual been fined? Is he or she perhaps in insolvency or even under investigation? Is it really the person? SCAUT will provide quick answers.

    More responsibility, more risk

    The higher the position, the more damage a dishonest employee can inflict. SCAUT offers screening packages tailored for screening production staff, data specialists as well as managers and decision makers who have a direct influence on a company’s direction.

    Protect your reputation, money and data. While a basic integrity and [credibility check]](https://scaut.com/en/screening-detail/credit-basic) is often sufficient for entry-level positions, in the case of a managers SCAUT will also look for possible conflicts of interest, payment history and references to ensure you don’t accidentally put responsibility into the hands of someone who has dishonestly embellished their CV. Remember, you can’t trust someone who isn’t honest with you.

  • Background check: To avoid costing you money from unscreened candidates

    Background check: To avoid costing you money from unscreened candidates

    We trust each other, don’t we?

    Although almost every employee in the USA or Great Britain, for example, undergoes a so-called pre-employment screening, it is not standard in the Czech environment. Many HR managers find it unnecessary, expensive or time-consuming, and administratively demanding. We are not going to snitch, it has been done before, right?

    The use of a background check service is particularly recommended for people working in security-sensitive positions or requiring high qualifications or experience.

    Any loss of data, know-how, resources, or incompetent decisions will cost the company very dearly. Background check prevents this. It verifies the veracity of all data and the background of the candidate. And that can sometimes make you wonder whether you will be placed in an important position.

    Statistics are not boring, but a real scarecrow

    Adverts, phone calls, interviews, onboarding, training… But still, the poor recruiter has no peace of mind and in case of hiring an unsuitable person, he will have to go through the whole cycle again. According to a survey by The Risk Advisory Group of a sample of 5,000 CVs:

    • 80% of CVs contained inconsistencies
    • 21% of candidates exaggerated their previous experience
    • 12% of applicants lied about their education

    When you’re selecting an employee for your team, you want to make sure it’s the right one. Dishonest employees will not only cause financial losses for the employer but can also significantly damage the employer’s overall reputation. Yet research in the Czech Republic has shown us that:

    • 90% of employers do not verify that jobseekers are debt-free
    • 55% of employers rely on the truthfulness of the documents submitted for recruitment
    • 32% of employers are aware of the inadequacy of their control mechanisms

    The bottom line, recruiters can easily save themselves a lot of time, money, and sleepless nights with a professionally conducted screening.

    What does the background check check?

    Often HR staff does not know what a background check should look like, what information they can verify and how. At the same time, the mere information that a candidate passes the screening can serve to select the dishonest ones who will give up the selection process beforehand. Those who have nothing to hide have nothing to fear. The background check, which is automated by the SCAUT platform, focuses on the following areas:

    • Identity and documents of the applicant. Is the applicant who he/she presents himself/herself to be? Does he/she have valid documents, a work visa, or a residence permit? It is often darkest under the candlestick and the seemingly obvious can sometimes come as an unpleasant surprise.
    • Education or certification. Everyone has probably heard of forged university diplomas, certificates, or professional exams… The internet is full of them, just take your pick.
    • Professional references. They look nice on paper, but are you really in contact with such a quality worker? A background check will reveal any exaggerations or deliberate concealment of unsuccessful engagements.
    • Trade license and Directorship. Can the applicant’s business be a risk to the employer? Good to know before you let him or her in on your know-how. Alternatively, verify that the candidate has the necessary licenses and trades to carry out his or her business and you will not violate the law by engaging him or her.
    • Sanctions and watchlists. A criminal record, a wanted database, or even the status of points on a driving record are all essential factors for employers – often required by law.
    • Financial probity. Remember that desperate people do desperate things. The risk of being dishonest in a foreclosure is always a consideration. And a risk I don’t know about is a risk I can’t manage.

    From these types of screenings, the SCAUT platform will then mix the ideal packages of checks tailored to the individual positions you are currently filling:

    • Pre-Interview. A quick and basic check before your first interview to help you save time and costs.
    • Staff. For production, technical or administrative staff to minimize the risks of embezzlement and conflicts of interest.
    • Specialist. Suitable for anyone with access to internal data or client information. All of this should be in the hands of only the most trustworthy people.
    • Manager. For those with access to confidential information and decision-making authority. This will prevent any high losses.
    • Executive. Ideal for executives with access to, for example, trade secrets. Your brand will not lose its uniqueness or reputation.

    Outsource your background check, it pays off

    It’s expensive, it’s time-consuming, and GDPR prohibits it… These are just a few myths that circulate pre-employment screening. Background checks can be very quick, efficient, affordable and of course, legally sound.

    When outsourcing with SCAUT, which has developed a sophisticated digital platform for this purpose, you simply select the type of audit or choose from pre-selected packages and then just wait for the final report. This will give recruiters a guarantee and reassurance that the candidate is indeed trustworthy and suitable, instead of just a gut feeling.

    With professional screening, HR departments can save up to hundreds of hours, so take advantage of it. Remember, impressions are not enough. Only verified information will tell you who you’re working with. And remember, a person who isn’t honest with you is a person you can’t trust!

  • Do you need ISO certification? You can’t get it without a background check!

    Do you need ISO certification? You can’t get it without a background check!

    What is ISO?

    The International Organization for Standardization (ISO) brings together standardization bodies and authorities from different countries.

    The term standardisation has a rather ugly, or rather discredited, connotation in our experience. Let us therefore be clear that we are using the word in a technical sense to refer to the standardisation or the setting of objective criteria, i.e. standards for a certain activity.

    Food quality, information protection, environmental protection, occupational health and safety, but also, for example, a compliance system, protection of personal data or standardised requirements for certain types of products and protective equipment arer all areas, along with many more, for which the ISO issues standardised sets of requirements and rules to ensure quality and reliability.

    How do ISO standards work?

    ISO standards define generally established and recognised principles in a particular field, for example food safety or anti-corruption. They also contain specific requirements to ensure and demonstrate the application of these principles in the organisation’s activities.

    In practice, ISO standards can be approached in two ways:

    • Put the procedures of a specific ISO standard into practice to ensure that what is key to the organisation is done correctly and to a high standard, whether it is producing a specific product, protecting internal information or reducing the negative environmental impact of an activity.
    • An organisation may also choose not only to implement the requirements of the ISO standard, but to have them certified as being applied effectively and correctly. An independent third party will assess whether the ISO standard is actually applied in practice. If so, it will confirm this with a generally recognised certificate.

    Who are ISO standards suitable for?

    ISO standards can again be used in two ways: internally and externally.

    What does it mean to use an ISO standard internally?

    Management wants to make sure that it has its key processes under control, produces safe products, ensures the safety of employees in the workplace, has a good system in place to prevent bribery, meets the requirements of changing legislation, etc. Therefore, it will follow the examples of best practices summarised in the relevant ISO standard and implement them in its own internal processes, procedures and guidelines.

    However, for many organisations it is also important to demonstrate their compliance with the ISO standard externally. Being able to demonstrate clearly and quickly to their customers, business partners, parent company, regulators and anyone else that they are serious about production quality, information protection or bribery prevention. That’s what certification is for: an independent and trustworthy confirmation that an organisation actually follows the chosen ISO standard in practice.

    Standard ISO 27001:2022 and background check

    ISO also issues standards for information protection systems.

    In October this year, a new version of the relevant standard, ISO 27001:2022, was released, containing specific requirements and measures to ensure systemic information protection, cybersecurity and data protection.

    This is not a new issuance, but an update of a set of requirements issued in 2013. The requirements for security measures are organised differently in the updated standard (there are four categories instead of the previous 14), some of the requirements and controls are merged, and others are specified. The standard also introduces 11 new controls to demonstrate that an organisation is serious about protecting information.

    One of the requirements that has remained virtually unchanged in ISO 27001:2022 is the requirement to verify and screen job applicants.

    The ISO standard requires setting up a process for background check, i.e. verifying the professional history and credibility of all applicants before they become employees. The standard also requires periodic verification of findings during the employment relationship. All this, of course, taking into account the specific needs of the organisation, the relevant legislation affecting its activities as well as the the job and its associated risks.
    In other words, without an individualized and organizationally appropriate process for verifying the trustworthiness of applicants and employees, compliance with ISO/IEC 27001:2022 cannot be achieved. Processes for protecting information will not be complete either internally or externally, nor can they be supported by certification.

    Other standards and regulations

    The requirement to verify job applicants can also be found in other standards. And it is often important, if not necessary, to ensure compliance with generally binding legislation.

    A few examples:

    • ISO 37001:2016: this standard defines the requirements for a system to prevent corrupt behaviour. One of the key elements is the verification of new employees with respect to the subject of the standard and in relation to their previous behaviour, involvement in bribery cases, links to public officials, etc.
    • ISO 19600:2014: this standard defines the requirements for a compliance management system, which is an internal process for ensuring compliance with the legal and ethical requirements imposed on an organisation. Among the controls that support the achievement of the stated objective of compliance with legal and ethical requirements, it too includes a process for the verification of applicants for employment in the organization.
    • Cybersecurity: the Cybersecurity Act requires a number of private and public sector organisations to put in place sufficient technical and organisational measures to protect critical information systems. The forthcoming NIS2 Directive will both extend the scope of these measures (to other, supporting, information systems) and increase the number of organisations affected by these obligations by an order of magnitude. In a number of cases, in order to comply with the Cybersecurity Act, or its new wording after the NIS2 amendment, a process will also need to be established and documented for the vetting of job applicants. Are you ready for the new NIS2 cybersecurity regulation? Even when recruiting employees?
    • Data protection or GDPR is still alive: Rules for processing personal data should be set up as a process, with responsibilities, defined procedures, roles, security measures and appropriate documentation. Otherwise, the GDPR’s requirement for the so-called demonstrable responsibility of the controller or processor will not be met. This in itself can be an offence punishable in particularly serious cases by a fine of up to €20 million or 4% of the worldwide turnover of the group of companies to which the offender belongs. And of course, poorly set up internal governance can lead to data loss, unauthorised disclosure, misuse, unlawful alteration, etc., with all the negative consequences for the individuals concerned and the data controller as such. Personnel measures are an integral part of the measures to protect any personal and sensitive data processed. If an organisation experiences a data loss or leak or other security incident affecting personal data, it is its responsibility to document what security measures it has put in place, what it has not put in place and why. And it may not be easy to justify a lack of trustworthiness verification for employees who have direct access to sensitive personal data, and this can negligently or intentionally lead to a major problem.
    • Sector regulation: many organisations are required by sector regulations to address the trustworthiness of their employees. For example, the civil service law for civil servants, financial regulation for employees involved in offering and servicing certain financial products (consumer credit, insurance, etc.), or regulation to protect classified information.

    How to solve it?

    Internal information, personal data, cybersecurity, consumer protection, market confidence, parent company requirements, sector regulation… If any of these are important to your organization, you can’t avoid a background check.

    Or at the very least, you should think about it thoroughly and be able to justify why you are not conducting this important check. At best, you’ll justify it in an audit, a discussion with a parent company or business partner, at worst in a supervisory review or in court.

    It can be expensive, inefficient and ineffective to vet job applicants on your own. It is therefore a good idea to consider, and perhaps at least try, a specialist and professional service. Especially when it is easy, verified and available literally at a few clicks. Employee verification quickly and cheaply? Yes, you can!

  • Verify candidates in accordance with the law!

    Verify candidates in accordance with the law!

    In a nutshell, failing to conduct a background check on a job candidate’s professional history and qualifications can cost an organisation dearly when, for example, having to part with a newly hired colleague who has dishonestly embellished their CV, the company is forced to begin another costly hiring process. Worse still, a candidate with nefarious intentions may be inadvertantly hired. Someone who wants to steal from the organisation, misuse its resources, data, information, or cause damage.

    A systematic and appropriate process for vetting candidates is important not only for protecting an organization’s tangible and intangible assets, but also for meeting a range of regulatory obligations, ensuring due diligence by management, and obtaining or maintaining various ISO certifications.

    What are the limits of a background check?

    Everything has its limits. Even a background check.

    The vetting of job applicants and the screening and monitoring of existing employees inherently involves extensive processing of personal data and encroachment on privacy. We are guided therefore primarily by the General Data Protection Regulation (GDPR) and the Labour Code.

    Does this mean that background checks cannot actually be carried out? Absolutely not!

    It is perfectly legitimate to check prospective and current employees, their work histories and other facts. And it is even legal to do so. The important thing is to be aware of your obligations, the rights of applicants and employees, and to conduct the process from start to finish in a regulatory-compliant and completely transparent manner.

    What if we go too far in vetting candidates?

    We will address the main requirements of the GDPR and the Labour Code in a moment. But first, let’s answer the question: what is the risk to an organisation if it carries out the job applicant verification process in a haphazard, incorrect manner,, fails to inform applicants or uses illegally obtained data?

    There are several risks:

    • Penalty In extreme cases, violations of the GDPR are punishable by fines of up to EUR 20 million or 4% of the annual turnover of a company group, such as, for example, where massive illegal surveillance of employees has taken place.

    Is this threat only theoretical? I wouldn’t say so. Not far from us, in Germany, H&M has just been fined EUR 35.3 million by the local data protection authority for excessive monitoring, some would even say snooping, of its employees. Of course, in our country, the fine would probably be an order of magnitude less. But even a few million euros could be quite a high price to pay for wanting to know more about applicants and employees than is strictly necessary.

    • Changing internal processes backwards The consequences of a violation of the rules does not have to be limited to a fine. They may also require the organisation to change or cease certain processes, and to destroy any illegally processed information. This has been done several times by the Czech Data Protection Authority.
    • Unusability of illegally obtained outputs Information about job applicants obtained illegally are unusable in practice. And it can be very costly to reject an applicant or dismiss an existing employee on the basis of improperly gathered data. In addition to a fine, such an employer could face a claim for invalid dismissal or for compensation for non-pecuniary damage.
    • Damaged reputation of the employer Despite the turbulent economic and political situation in the Czech Republic, employees are still rather scarce, especially in some sectors. “Improving” your reputation as an employer by spying on job applicants or existing employees and finding out all sorts of things about them, and getting fined for it, will certainly notimprove your position on the labour market.

    Background check and GDPR

    How to proceed?

    How can you ensure that job applicant or employee screening is carried out in accordance with the GDPR?

    GDPR is a comprehensive regulation, so let’s highlight the most important ones:

    • Establish and clearly describe the purpose of processing applicants’ personal data.
    • Find sufficient legal authority for processing data in the context of a background check. Sometimes the legitimate interest of the employer is sufficient. In other cases (more extensive background checks, certain sources of information or categories of data) the consent of the candidate concerned is already required: informed, voluntary, and, above all, retrospectively verifiable consent.
    • Determine the scope, manner and duration of retention of personal data collected. For these rules, the GDPR likes to employ the vague concept of “necessity”. Personal data must be collected only to the extent necessary to achieve the stated purpose, retained only for the necessary period of time, etc. It may not always be easy to define and justify why a particular piece of data is actually necessary to verify an applicant for a particular job.
    • Demonstrably inform job applicants and employees about the processing of their personal data.
    • Take sufficient security measures, both technical and organisational, to ensure that the information obtained does not fall into unauthorised hands. Whether outside the organisation or inside.
    • In particular, in the case of more extensive screening or monitoring of individuals (multiple individuals, larger data volumes, advanced tools for recruiting and assessing applicants and employees), the organisation may be required to appoint a Data Protection Officer.
    • The entire process for processing personal data and protecting the rights of individuals needs to be documented so that the organisation can demonstrate its compliance with the GDPR requirements.

    Verification of job applicants from the perspective of the Labour Code

    The GDPR is not the only regulation that governs workplace privacy in employment relationships. The other, no less important, is the Labour Code. In fact, the Labour Code regulates some specific aspects or details that are not in the general regulation, the GDPR. And as a specific legal regulation, it even takes precedence over the GDPR in these parts.

    By the way, did you know that the control of privacy protection in the workplace is not carried out by the Data Protection Authority (DPA), but by labour inspectorates? There are many more of them, they have local branches and more capacity. While the OOOO carries out a total of 50 inspections per year (offices, hospitals, banks, e-shops, municipalities, schools), the Labour Inspectorate found 26 violations of legal rules for monitoring employees and job applicants last year alone? And it can also immediately issue a fine for such violations.

    What does the Labour Code say about employee privacy?

    First, it defines the categories of data that an employer may not request from job applicants or employees, nor obtain through third parties. This typically includes data on sexual orientation, church membership, trade union membership or political beliefs.

    Certain other categories of data may be used by the employer, but** only if the employer can justify** its necessity in relation to a specific job,for example, information relating to family and financial circumstances or a criminal record.

    The Labour Code also protects employees from unreasonable surveillance at work by, for example, cameras, monitoring of communications and internet activity, use of equipment on the job, etc. If an employer wishes to implement any of these practices, it must again be able to justify and document why it is necessary in the particular circumstances of the workplace. And it must directly and demonstrably inform the employees concerned.

    Background check quickly, efficiently… and legally!

    There is no shortage of legal requirements and conditions for performing a background check. Complying with and documenting these requirements in practice is not an easy task. This is especially true in companies where there is not much experience of HR compliance, or candidate screening, or where there are insufficient resources for doing so.

    What to do?

    Outsource these worries along with the entire background check. Engage the services of an experienced professional who specializes in job applicant verification and** can effectively deal with the requirements of the law**, and can also document his client’s compliance with the relevant legal requirements.

  • Everything begins and ends with employees

    Everything begins and ends with employees

    The number of attacks on property and sensitive information is steadily increasing, both in the private sector as well as the public. The importance of protecting them should therefore also rise against insider threats and employee fraud. Not because everyone steals and everyone is a fraudster, but because several objective factors will continue to increase the risk of internal attack in the years ahead.

    What are they?

    • The looming recession will worsen living conditions for many people, bringing some to the brink of existential problems
    • Financial difficulties, restructuring, and resource constraints in many businesses will lead to higher labor market turnover
    • The sudden loss of a job may lead to a desire to get a new job at any cost, even at the cost of ‘improving’ one’s CV, education, or experience
    • Existential problems can drive even a previously trouble-free employee to try to solve these problems at the expense of the employer
    • Despite the economic recession, there is a continuing shortage of certain specialisms in the labor market, even those that can easily be performed remotely
    • Remote working, including purely online recruitment, is still on the rise, but the risk of hiring someone online who has never actually been seen in the company is not always fully appreciated
    Internal risks, the threats associated with our employees, will become increasingly tangible. We may not like it, and we may say for the hundredth time that there is no such threat in our company, but that is the reality.

    František Nonnemann

    Compliance and Operational Risk Consultant

    Protecting money or information? Both!

    When an employee steals money, the damage is clear. We’re not just talking about a small addition to the household in the form of “moving” work tools or office supplies. That too can hurt an employer, especially when it becomes a sport among employees. But even more serious can be fraudulent cost accounting, false invoicing, or even misrepresenting a bank account to customers. And the classic “reaching into the treasure chest” remains a threat when a previously exemplary employee “resolves” a complicated personal situation in a truly unfortunate way.

    In the event of a loss or leak of internal information, the financial loss may not be so visible at first glance. But the damage can be even greater as a result.

    Misuse of internal information against the employer’s interests, disclosure of production processes, leaking the source code of a customer application, selling a client list, premature disclosure of information important for stock markets… We can imagine many such black scenarios. And often there’s no need to strain the imagination too much, just scan the news from home and the world. Financial losses can run into hundreds of millions, not to mention problems with reputations, watchdogs, and the courts.

    When thinking about fraud protection, we should strive to prevent direct attacks on property as well as to consistently protect sensitive and confidential information. One without the other does not make sense. Setting up measures to ensure the physical security of branches and not addressing, for example, the protection of trade secrets or client tribes, is necessarily incomplete. Such a half-hearted solution can ultimately be detrimental, as it gives a false sense of security to the organization’s management.

    You can’t do it without personnel security. But what is it?

    Whether we are dealing with the protection of plant know-how, cybersecurity, personal data, or ISO standards, personnel security is an integral part of the measures implemented. Or at least it should be.

    But what is it? Personnel security, human resources security, internal risks, “people risk”?

    In practice, the issue of personnel security is often seen as a training issue for employees. Employees have to be trained on how to work, how to protect internal information, and what regulations to follow. Within a few dozen minutes, they should process a lot of information, read dozens of internal directives and sign a confirmation that they know everything, understand everything, and will follow it.

    From a technical point of view, HR security is sometimes limited to defining the correct roles and user rights for employees and setting access and password policies. When there are sufficient resources, data leakage prevention (DLP), CCTV, or other security devices are put in place.

    Take action before the new employee starts!

    For HR security measures to be truly functional, they must begin before a potential attacker ever enters the organization.

    Why?

    The most advanced and expensive technical measures will not stop a truly determined attacker. It’s always just a question of money, capacity, and will. If someone enters your company or office with the intent and plan to misuse confidential information, technical measures alone will usually not stop them.

    Modern, interactive, and well-designed training will not reveal who lied at the interview and who is hiding something from their past. And it certainly won’t prevent an employee in a problematic personal situation from reaching into your coffers.

    It is therefore always better to start one step earlier and try to keep attackers, fraudsters, and other people who can cause very real and tangible problems for the employer out of the organization altogether. Better in the sense of being more efficient, conceptual, and ultimately cheaper.

    What does it mean to start early? Establish a process for a background check. This means checking the credibility and reliability of new employees or job applicants. After all, their past is your future. Checking to see if they are lying on their resume, improving their education, experience, or skills, or hiding other skeletons in their closet will save any employer a lot of future problems.

    Five conditions for a smart and effective background check

    Therefore, for a background check to work, and not just become another annoying paper exercise, it is advisable to choose a solution that will be:

    • Quick and easy for employers and candidates
    • Clear and transparent, with clear outputs for management
    • Reliable and comprehensive, including all relevant resources
    • Customizable, tailored to the employer’s conditions and the sensitivity of the position being filled
    • Fair and lawful, in line with data processing and privacy regulations for employees and job applicants

    More flies with one shot

    Setting up a reasonable, efficient, and smart process for vetting job applicants will help prevent internal fraud and misuse of information. However, quality tools for verifying the reliability of job applicants are also important in other areas. For example, they can greatly assist an organization in the:

    • Compliance with legislation that requires us to verify the trustworthiness of employees and protect sensitive information. From GDPR, a cybersecurity law that will soon affect thousands of companies, to financial market regulation, to state and local government. Everywhere we find requirements to secure information, and assets, ensure the functionality of the services provided and the trustworthiness of key employees or officials.
    • Meeting the requirements of the parent company, the founder, shareholders or voluntarily accepted ethical commitments
    • Protecting members of the statutory body from material liability for failing to take reasonable care of assets under management
    • Increasing the value of the company, whether on the stock exchange or in negotiations for a potential merger or sale
    • Obtaining certification when, for example, ISO standards in the area of information protection, as well as others, require a demonstrable and documentable process for verifying the trustworthiness of employees

    In other words, a well-constructed process for vetting job applicants can help an employer respond to multiple challenges and requirements. And it pays off!

    Personnel security is the topic of the future

    Attacks on private and public organizations, their property, assets, and information will increase. Attacks will be amateur, partly organized, and fully professional.

    Unauthorized access to and compromise of data can be relatively easy, and an attack can often be carried out quickly and cheaply. And effectively. Efficient in a negative sense for employers, of course. Indeed, the consequences of a successful attack on sensitive information can lead to the interruption or shutdown of its operations, leakage of confidential production processes, and loss of client trust. As well as fines and damages.

    Everything begins and ends with people. If an organization is not concerned with personnel security, it is simply not protecting its interests.

    František Nonnemann

    Compliance and Operational Risk Consultant

  • Two out of three frauds are caused by a company’s employees

    Two out of three frauds are caused by a company’s employees

    „From the available statistics, it is clear that two out of three investigated frauds are caused by employees or they are directly involved,” stated Michal Moroz, Chief Business Development Manager at Securitas, a security agency operating in 58 countries around the world. Properly implemented security measures can protect businesses from many criminal acts and property losses.

    Petr Moroz from Screening Solutions reminded us of psychological studies that divide the public into three groups based on character: Roughly 25 percent are people with a strong tendency towards unethical behavior and fraud whenever possible. Another 25 percent are individuals who are honest under all circumstances. The remaining half adapts their behavior according to life situations, established rules, and opportunities.

    Who is a typical thief?

    „You don’t want employees from the first group in your company at all. Therefore, it is crucial to verify the honesty of potential colleagues at the moment they apply for a job, for example, by using references or checking the truthfulness of their resume. Today, this can be easily achieved and, thanks to electronic tools, it is also cheap and fast. With the majority of the group of people who are characteristically unremarkable, you can work in the company with the help of well-established compliance processes and functioning risk management,” said Moroz.

    According to surveys, the typical perpetrator of a crime in the workplace is a man aged 35 to 55, who has been with the company for six or more years. One-third of them are people in executive and managerial positions, and in two-thirds of cases, they collaborate with someone else as an organized group.

    In the Czech Republic, unlike Slovakia and other European countries, legal protection for so-called whistleblowers, i.e. persons reporting offenses, is currently lacking, according to experts. However, surveys by multinational organizations show that up to 40 percent of criminal offenses were first detected with the help of a tip from someone. Internal audit came in second place with 20 percent of detecting crime. Therefore, companies should have internal rules for reporting offenses that allow for immediate and discreet detection and resolution of incidents.

    Protection is improving

    The SSI Group, which provides security services for several hundred sites, including shopping centers in the Czech Republic and Slovakia, also admitted that most stores are well prepared for customer theft. However, problems arise with losses that come from within their own ranks. Companies and store owners are therefore forced to continually improve their internal procedures and control mechanisms to prevent damage caused by their own employees.

    Thieves mainly target goods that can be quickly cashed in at pawn shops or on the black market. “These include mobile phones, tablets, gaming consoles, as well as fashion, beverages and food, perfumes, and cosmetics,” said Michal Cícer from SSI Group.

    Earlier this year, a young employee at the Škoda Auto plant in Kvasiny, Rychnov, was caught stealing dozens of steering wheel airbags and several steering wheels from newly manufactured luxury models, causing damage worth over 400,000 crowns. According to the police, the young man stole auto parts from December of last year to the middle of this January and then sold them personally or through the internet. The police solved the case in collaboration with the automaker’s security department.

    Such frauds and thefts are not only prevalent in the Czech Republic and other former Eastern Bloc countries. According to a report by the American Chamber of Commerce, at least 75 percent of employees commit at least one workplace theft during their lifetime, with 37.5 percent doing so regularly.

    Estimated loss

    Retailers may be doing their best to fight theft, but they also factor it into their business plans. Based on their past experiences and statistics, they calculate what is known as “shrinkage,” which is the expected value or volume of merchandise that will be stolen.

    “Retailers fight theft as best they can, but they also factor it into their business plans. Based on their previous experiences and statistics, they calculate the so-called “shrinkage,” i.e. the expected value or volume of stolen goods,” says Jaroslava Hanková, a partner at the consulting group Apogeo. “The amount of shrinkage determined in internal policies must be economically justified, and in the event of a tax administrator’s inspection, it must be properly documented,” warns Hanková.

    “When a retailer finds, based on inventory, that the physical condition of the goods does not correspond to the recorded condition, i.e. it is lower, then we are talking about a shortfall. The store must determine how the shortfall occurred and, if necessary, prescribe the responsible employee the appropriate compensation according to internal procedures,” describes Hanková. She says that further complications arise if the store operator claimed a VAT deduction on the stolen goods. In that case, they are obliged to adjust this deduction.

  • Inconsistent background checks of job applicants will cost companies dearly.

    Inconsistent background checks of job applicants will cost companies dearly.

    While the “heist of the century” may be an extreme example, domestic companies lose hundreds of thousands, or even millions of Czech crowns each year due to hiring managers with a hidden dark past.

    According to the study, “selecting an unsuitable candidate for a job position, especially for a top managerial role, costs a company ten to fourteen times the candidate’s annual salary,” claims Tomáš Drážný, the founder of Executivejob.cz, an online platform specializing in filling top managerial positions.

    Without proper checks in the selection process, job candidates who may later sell their employer’s marketing databases or damage business relationships can more easily get into companies.

    “Such individuals often break up the team because they have done the same thing in other companies,” adds Drážný. In the Czech Republic, only a small percentage of job applicants go through some form of screening, estimated to be in the single digits, whereas in the United States, it’s as high as 85 percent.

    Still feared screening

    However, the verification process is often very superficial and inconsistent. Overloaded recruitment department employees can easily overlook or miss a significant fact from a candidate’s past. A solution to this can be the so-called screening, which involves verifying the truthfulness and completeness of job applicants’ information by an external specialized company.

    “Screening is a somewhat feared topic in the Czech Republic because it is often mistaken for detective work. However, we always verify the facts based on the job applicant’s consent,” explains Petr Moroz, founder and managing partner of the Czech company Screening Solutions.

    A mistake in hiring an employee can be costly for a company, up to fourteen times the employee’s annual salary.

    Screening primarily verifies the truthfulness and completeness of what the job applicant has disclosed about themselves, as well as whether they have omitted or concealed anything. Employers often have the candidate’s criminal record and credibility checked, especially to see if they are not in insolvency or if there is no execution imposed on them.

    At higher positions, the candidate’s “trustworthiness” is also examined in banking or non-banking registers or their indebtedness to the state (for example, not paying taxes to the financial office). In addition to companies themselves, screening agencies are also used by personnel agencies, headhunters, and consulting firms.

    “We provide companies with a service where we guarantee that the candidate is clean. We cannot afford to tarnish our reputation by revealing something negative about such a person,” explains Drážný from Executivejob.cz.

    They are reading between the lines

    Screening companies are able to evaluate candidates very quickly and reliably thanks to access to many databases. They use both automated search systems and personal questioning of the candidate or verification of references. “We look for something between the lines,” says Petr Moroz.

    Even in the USA, one of the countries with the highest prevalence of screening, mistakes can happen. The most glaring failures then make it into the media. For example, the CEO of the internet company Yahoo had to step down from his position because he lied in his resume about having studied IT.

    Scandals also happen in Western European countries, where screening is also much more widespread than in the Czech Republic. In Germany, there is currently an affair involving the global payment operator Wirecard, whose former management allegedly embezzled up to 80 billion crowns. In the Czech Republic, a special unit once came to arrest the financial director of a clothing trader directly at a board meeting because he had been wanted by Interpol for a long time.

    The obstacle is a lack of education

    In recent times, the trend is clear: the interest in employee screening is increasing in the Czech Republic and the complexity of its execution is also rising. “We are growing rapidly. Companies have begun to realize that they cannot just hire based on a polished resume and references from friends,” says Moroz.

    According to Drážný, however, a barrier to even further development of screening is the low level of education among employees of the recruitment departments of Czech companies. “Employees in HR departments often don’t even know what screening should look like and that it exists. Verification is still very limited,” he believes.

    Recruiting departments of companies are also struggling with the coronavirus crisis. Not only are there more employees working from home, but there are also remote recruitments where recruiters often don’t even meet the candidate. This can make the verification process difficult.

    “For companies, it’s a burden. Either they give up on screening, or they find someone who is capable of doing it for them, even on a global scale,” says Moroz. His Screening Solutions company, in fact, provides such services. The company currently covers 158 countries, where it is usually able to provide screening in collaboration with local firms. “We work for global companies. For example, we have recently won a $700,000 contract for a US company for four years. We need to screen about 300 to 400 people per year, who, however, are joining from all over the world,” Moroz says.

    The rise of automated systems

    Five employees of the company perform approximately 10,000 screenings per year, ranging from simple identity verification of applicants to complex ones for which corporate clients pay up to 15,000 crowns. “For example, we find hidden information from criminal records in about three percent of candidates,” Petr Moroz says.

    During screening, companies often use automated verification systems. Especially for verifying databases such as business registers, monitoring negative media mentions, or sanction lists of individual countries and the EU.

    According to Petr Moroz, there are two basic groups of clients. The first are so-called “gig economy” companies, often technology companies in the sharing economy, startups or some IT companies. They mainly require automated and cheaper candidate screening and need an answer by the next day.

    In contrast to tech firms, the typical representative of the second group is a renowned financial institution with a long history operating in a heavily regulated industry. Here, it is not so much about speed but about the thoroughness of the verified information.

    The position of screening in the Czech Republic is also made difficult by the practice of many companies, which would rather part ways with an employee they would terminate for a serious offense on good terms, as they are afraid of legal disputes. “The risk for such a dismissed person then passes on to another company,” says Petr Moroz.

    The use of screening is also problematic in state or semi-state-owned companies. According to Moroz, people who do not meet the necessary parameters often sit in their boards of directors and supervisory boards. “They are there and nobody addresses it, we do not have a single customer from state-owned companies,” he says.