A candidate receives a rejection email and replies with a sentence that should stop the room: “I never applied for this job.”

The fastest response is to assume fraud. The second-fastest is to blame the campaign source. Both may be wrong. A disputed application is a signal that the event chain needs to be reconstructed, not a verdict about the person, platform or partner.

An ATS record can have several origins

The record may have come from a completed application, a partially completed workflow, a lead conversion, a recruiter import, a rediscovered profile, a vendor integration, a duplicate-merge process or an automated apply tool. The candidate may have authorized one action and not understood that it would create another. A third party may have used their information. A system may have attached the wrong source or triggered a message before the organization had verified the record.

This is why the question “Is the record in the ATS?” is not enough. The ATS can accurately show that a record exists while remaining unable to prove how the person’s information entered the workflow.

Start with evidence, not blame

  1. Preserve the original ATS record and audit history.
  2. Identify the creation timestamp, source field and integration user.
  3. Check whether an application form was completed and whether required consent was captured.
  4. Compare click, session and conversion records from the media or career-site layer.
  5. Review duplicate records and prior candidate history.
  6. Confirm which automation sent the rejection or status message.
  7. Contact the candidate with a neutral request for clarification when appropriate.
A disputed application is not only a candidate-integrity issue. It can be an integration, consent, workflow or attribution issue.

What not to do

  • Do not accuse the candidate of dishonesty based on one system record.
  • Do not declare the source fraudulent before confirming the source assignment.
  • Do not delete the record before preserving the audit trail.
  • Do not let an automated disposition continue while the event is under review.
  • Do not treat one case as proof of a systemic pattern, or dismiss repeated cases as isolated exceptions.

Look for the pattern behind the complaint

One disputed record may be an error. Ten records with the same source, timestamp pattern, integration user or workflow path are an operating pattern. Group the cases by job, source, device, IP risk signal, email domain, creation method and message automation. You are looking for concentration, repetition and timing that can explain where the process changed.

Be careful with identity and network signals. Shared devices, VPNs, public networks and unusual locations do not automatically indicate fraud. NIST’s AI risk guidance emphasizes governance, measurement and context rather than blind reliance on automated risk scores. The same discipline belongs in hiring operations.

The candidate-facing response matters

A person whose information appears in a hiring system without their understanding may feel violated, confused or angry. A defensive response compounds the problem. A better response acknowledges the concern, pauses unnecessary communication, explains that the organization is reviewing how the record was created and gives the person a clear way to request deletion or correction.

The decision standard

Do not ask only whether the record is real. Ask whether the application was intentional, whether the data was authorized, whether the source assignment is defensible and whether the workflow behaved as designed. Those four answers will tell you what needs to change.