IndiciumIndicium
Log in
← Back to blog
Background checks for HR, Legal and Compliance

Turn public-source risk signals into audit-ready decisions.

Indicium helps regulated teams screen candidates, counterparties and sensitive hires — with dated sources, human review and reports your Legal team can defend.

Test the Indicium report directly against this requirements catalogue — seven review categories, dated sources and final human review included.

Background Check Software for Banks: Requirements Catalogue

Requirements catalogue for background check software in banks: review categories, DACH sources, data protection concept and audit-proof documentation.

Background check software for banks must deliver five things: defined review categories, robust source coverage in the DACH region, a sound data protection concept, audit-proof reports, and support for both one-off and recurring checks. The benchmark is not the vendor’s feature sheet but the law: § 6 (2) no. 5 GwG (the German Anti-Money Laundering Act) requires the reliability check of employees, and § 1 (20) GwG defines what reliability means in legal terms. Structuring the selection along these obligations produces a decision that will also hold up before internal audit.

Why Manual Checks Do Not Scale

As long as only individual key positions are checked, manual work is manageable. But as soon as the entire AML-relevant workforce is to be covered — at hiring and on a recurring cycle — the manual approach collapses at three points: review depth varies depending on who checks; sources are not documented; and results lie scattered across inboxes and HR folders. It is exactly these three weaknesses that stand out in a special audit. Reliability within the meaning of § 1 (20) GwG is a uniform statutory standard — it does not tolerate review quality that depends on the day-to-day workload of whoever happens to be checking. Repeatability and documentation are therefore not convenience features but the actual reason to systematise screening — for the end-to-end process, see our process guide for anti-money laundering officers.

The Requirements Catalogue: Five Criteria for the Evaluation Matrix

Anyone comparing vendors should assess every solution against the same five criteria — in writing, in an evaluation matrix that will later also document the selection decision to internal audit and management:

  • Defined review categories: identity, career history, registers, sanctions and watchlists, adverse media — the scope must be configurable per risk class and reproducible identically per report.
  • DACH source coverage: German and Swiss registers, insolvency and gazette sources, and German-language media; international databases alone are not sufficient for checks in this region.
  • Data protection concept: clear legal-basis mapping per category, necessity logic under § 26 (1) and (8) BDSG (the German Federal Data Protection Act), and defined retention and deletion concepts.
  • Documentation format: every report with date, source and reference per finding — such that it can go to internal audit or the supervisor unchanged.
  • One-off and ongoing: support for pre-employment checks, event-driven checks and recurring re-screening, without setting up a new project each time.

Data Protection and MaRisk as Knock-Out Criteria

Two criteria are non-negotiable. First, data protection: a tool that uses sources which cannot be traced back to the necessity standard of § 26 BDSG shifts the legal risk onto the bank. Second, the supervisor’s requirements on staffing: MaRisk (BaFin Circular 06/2024 (BA), the German minimum requirements for risk management) require in AT 7.1 that the quantity and quality of personnel correspond to operational needs — employee suitability is thus explicitly part of the supervisory framework, not merely an HR matter. A screening tool that does not deliver its results in a form that fits into this supervisory logic creates duplicate work: compliance must rework every report before it can go into the file. For the question of one-off versus ongoing checks, our comparison one-time check vs. continuous monitoring is worth a look.

Reference Architecture: The 7-Category Report

What such an architecture looks like in practice is shown by the Indicium report: seven defined review categories, every finding backed by a dated source, and a final human review before delivery (Art. 22 GDPR) — from €79 per report. You will find the structure in detail under software report and the terms under pricing.

Before your first vendor conversation, create your own evaluation matrix along the five criteria and weight the data protection concept and documentation format highest — review categories can be extended, a weak documentation format cannot. Ask every vendor to show you a real sample report, not just slides — and use that report to check specifically whether date, source and reference are stated per finding and whether you could pass it on to your internal audit without rework. You can get exactly this look at the Indicium report in a demo.

This article provides general information and does not constitute legal advice.

Ready to move from reading to doing?

See how a reviewable risk report is built — from name to verdict in minutes, not weeks.

Book a demo See a sample report