IndiciumIndicium
Log in
← Back to blog
Background checks for HR, Legal and Compliance

Turn public-source risk signals into audit-ready decisions.

Indicium helps regulated teams screen candidates, counterparties and sensitive hires — with dated sources, human review and reports your Legal team can defend.

With Indicium's 6-month satisfaction promise, you test audit-proof reports with dated sources before committing to a screening model.

Continuous Compliance Monitoring or One-Time Check?

One-time check or continuous monitoring? When the point-in-time check is no longer enough: GwG duties, GDPR limits and a decision matrix.

A background check is a snapshot: it evidences the findings as of the check date — nothing more. Sanctions lists change daily, adverse media emerges continuously, and a person’s financial circumstances can turn within months. For entities obliged under the GwG (German Anti-Money Laundering Act), continuous monitoring of the business relationship is mandatory anyway (§ 10 para. 1 no. 5 GwG); for your own staff, by contrast, the principles of the GDPR set limits on indiscriminate permanent screening. The right answer is therefore not an either-or, but a decision matrix: one-time, event-driven or continuous — depending on the role and the legal regime.

Why the snapshot ages

The point-in-time check answers the question “Was anything known as of the reference date?” — not the question “Is anything known today?”. Three examples show how quickly a check result becomes outdated:

  • Sanctions lists: The EU sanctions regulations (including Regulation (EU) No 269/2014) are continuously expanded with persons and organisations — a hit can arise one day after the check.
  • Adverse media: Reporting on investigations, insolvencies or conflicts of interest emerges continuously and is by nature unpredictable.
  • Personal circumstances: Secondary occupations, shareholdings and financial distress develop after hiring — that is, after the only check date many companies ever use.

What the law requires — and where it differentiates

For business relationships, the legal position for obliged entities is clear: § 10 para. 1 no. 5 GwG requires continuous monitoring, including keeping the underlying documents and information up to date. Anyone who screens customers and business partners only at onboarding does not fulfil the due-diligence obligations.

For personnel, the picture is more nuanced: the reliability of employees at obliged entities must be ensured not only at hiring but on an ongoing basis — what that looks like in substance is explained in our article on employee reliability checks under the GwG. At the same time, there is no general obligation to permanently vet every employee — and under data protection law that would not be tenable either. For internal audit and supervisors, what counts is less the individual hit than the evidence that your screening model was consciously chosen, justified in writing and applied consistently.

Where the GDPR sets limits

Indiscriminate permanent screening of the entire workforce collides with the principles of Art. 5 para. 1 GDPR: purpose limitation (lit. b), data minimisation (lit. c) and storage limitation (lit. e) require that repeat checks have a defined purpose, a limited scope and a deletion concept. As legal bases, Art. 6 para. 1 lit. c GDPR (statutory screening duties of obliged entities) and lit. f (legitimate interest with a balancing test) come into consideration — the riskier the role, the more readily the balancing also supports a shorter cycle. The underlying system is laid out in our article on the GDPR legal bases for screening.

Decision matrix: one-time, event-driven, continuous

In practice, a three-tier model has proven itself:

  1. One-time (hiring): All positions — identity, CV, position-relevant registers. The baseline check remains the foundation of every personnel decision.
  2. Event-driven: Role changes into sensitive functions, concrete indications, regulatory triggers (such as an upcoming appointment notification). External workers also belong here — why is shown in our article on screening interim managers and external contractors.
  3. Continuous: Key roles with access to money, customer data or critical systems, as well as constellations subject to a statutory monitoring duty — here above all sanctions-list and adverse-media monitoring, that is, the categories that can change daily.

What matters is the documented assignment: which role falls into which tier, with what justification and what cycle? The cycle itself also needs justification — an annual rhythm for key roles is regularly defensible, a tighter one only for sources that change daily, such as sanctions lists.

Classify your roles along the three tiers, justify the assignment in writing, and define for each tier the scope of screening, the cycle and the deletion periods. Start with the key roles — that is where the gap between a one-time check and reality is most expensive. Indicium delivers audit-proof reports with dated sources and human final review (Art. 22 GDPR) from €79 per report; the 6-month satisfaction promise bridges the two worlds — you start with individual checks and develop them into a recurring programme without committing upfront. Details on the models can be found under pricing, the scope of screening in the software report.

This article provides general information and does not constitute legal advice.

Ready to move from reading to doing?

See how a reviewable risk report is built — from name to verdict in minutes, not weeks.

Book a demo See a sample report