Candidate fraud is real. So is the risk of building a hiring process that treats legitimate candidates as suspicious because their technology, location, communication, disability, or life circumstances do not fit a narrow pattern.

The FBI has documented remote-work schemes involving stolen identities, pseudonymous accounts, false websites, proxy computers, and U.S.-based facilitators. Hiring teams need stronger controls, especially for roles with access to sensitive systems or data. At the same time, the EEOC has warned that software and AI can unlawfully screen out people with disabilities when safeguards and accommodation processes are missing.

Separate a risk signal from a verdict

A VOIP number, VPN, location mismatch, new email domain, shared device, unusual interview behavior, or inconsistent record can justify review. One signal rarely proves intent. Greenhouse’s current Real Talent materials similarly frame fraud detection around digital risk signals and identity verification, while keeping employers responsible for the decision.

Application integrity is the confidence to ask the next question, not permission to skip human judgment.

Use progressive controls

  1. Low-risk stage: validate basic contact quality, consent, and submission patterns.
  2. Elevated-risk stage: request additional confirmation or structured review when multiple signals conflict.
  3. High-risk role or late stage: use stronger identity verification, security involvement, or role-specific checks where proportionate.
  4. Resolution: document the decision, retain only necessary data, and provide a route for legitimate candidates to correct errors or request accommodation.

Keep four concepts separate

  • Authenticity: Is the person represented accurately?
  • Intent: Did the person knowingly pursue this role or employer?
  • Eligibility: Does the person meet non-negotiable requirements?
  • Viability: Should the person advance based on agreed job criteria?

A candidate can be authentic but unqualified, qualified but low-intent, or suspicious on one digital signal while entirely legitimate. Combining the concepts into one “quality” score creates bad decisions and weak explanations.

Controls to review

  • Clear role-level consent and confirmation.
  • Candidate-facing explanations for identity checks.
  • Accommodation and alternate-process routes.
  • Human review before adverse action based on risk signals.
  • Access limits, retention rules, and audit logs for sensitive data.
  • Escalation rules that involve HR, security, privacy, and legal only when warranted.

The goal is not maximum friction. It is enough verification to protect the organization without making every candidate prove innocence.

Design around the risk of the role

A remote software engineer with access to production systems may justify stronger identity and security controls than a low-access seasonal role. Applying the most intrusive process to every applicant creates cost, abandonment, privacy exposure, and inequity without necessarily improving protection.

Build tiers based on access, sensitivity, fraud history, geography, employment arrangement, and the stage of the process. Verification closer to an offer may be appropriate for many roles. Earlier checks may be justified when the risk is high and the candidate impact is understood.

Explain what you are asking and why

Candidates are more likely to trust a verification step when the employer explains its purpose, the provider involved, the data collected, how long it is retained, and what alternative exists if the process does not work for them. Silence makes a legitimate control feel arbitrary.

Build a resolution path

False positives will happen. A candidate may be traveling, using a corporate VPN, sharing a device, changing phone numbers, or requesting an accommodation. The system needs a person or team that can review the evidence, contact the candidate appropriately, correct records, and document the decision.

Without a resolution path, a risk score becomes an unappealable verdict. That is dangerous for candidates and for the employer.

Measure whether the control is working

  • How many candidates are flagged at each stage?
  • How many flags are confirmed, cleared, or unresolved?
  • Does the control reduce recruiter or security time?
  • Where do legitimate candidates abandon?
  • Are certain groups or accommodation needs affected disproportionately?
  • Are the retained data and access proportionate to the value?

Application integrity is not a product you switch on and forget. It is a governed operating practice that has to protect both the organization and the legitimacy of the hiring process.

Related: The true cost of a “cheap” application and The Evidence Chain.