Log in Contact

In-employment screening for the people already on your payroll

Screening does not end on someone's first day. People change roles, take on budget authority, gain access to systems they could not reach before. In-employment screening re-checks the things that actually change, at the moments that matter, without treating your team as suspects.

Pescheck runs periodic and event-driven re-screening through the same platform and the same audit trail as your pre-employment checks. You set the cycle per role group, we handle consent, evidence and reporting.
In-employment screening for the people already on your payroll
Pre-Employment
Identity verified
References checked
Ready to hire

What is in-employment screening?

In-employment screening is a background check on someone who already works for you. It is the counterpart to pre-employment screening: the same checks, applied during the employment relationship rather than before it. The reason it exists is simple. A pre-employment check is a snapshot taken on one day. Circumstances move on. Someone is promoted into a role with payment authority, a professional registration lapses, a director takes a board seat elsewhere, a sanctions list is updated. None of that is visible in a check you ran three years ago.

When should you re-screen?

Three triggers cover most of it. Role change, where someone moves into a position that would have justified different checks at hire. A fixed cycle, where a regulator, a certification or your own policy sets an interval. An event, such as an incident, an audit finding or an alert from ongoing monitoring. What you should not do is re-run everything on everyone. Screening an existing employee is more intrusive than screening a candidate, because the relationship is already there and refusing is harder. Proportionality does more work here, not less.

Pre-employment and in-employment are not the same job

Both verify a person, but the balance of interests differs. A candidate can walk away from a hiring process. An employee has a contract, an income and a manager, so consent carries less weight as a lawful basis and your justification has to be stronger.

That is why in-employment screening works best when the rules are written down before you need them: which roles are in scope, which checks apply, how often, and what happens if something surfaces. Decide it once as policy, apply it consistently, and the individual screening stops being a judgement call about a specific person.

Set the cycle per role group

Screening every employee on the same interval is expensive and hard to justify. Pescheck lets you define role groups and give each one its own package and cadence, so a treasury team on an annual cycle and a warehouse team on no cycle at all can coexist in the same policy.

You keep the audit trail centrally: who was screened, when, on what basis, and what the outcome was. That is the record an auditor or a regulator asks for.

Catch what changes after the hire

Re-verify professional registrations, directorships, sanctions and PEP status, adverse media and, where the role justifies it, a fresh criminal record certificate. The checks are the same ones you already trust from pre-employment screening.

One audit trail for hire and re-check

Pre-employment and in-employment screenings sit in the same record, so you can show an auditor the full history for a role rather than two disconnected systems. Retention is set per check, and access stays limited to the people you name.

Checks commonly used for re-screening

Which checks belong in a re-screening cycle depends on what can realistically change and on what the role touches. Registrations expire, sanctions lists move, directorships and insolvencies appear in public registers. Qualifications, by contrast, rarely need checking twice.

We help you pick a package per role group that is defensible rather than exhaustive, so you are not collecting personal data you cannot justify holding.

How in-employment screening works

1

Write the policy

Define role groups, the checks for each, the trigger (cycle, promotion or event) and who decides on the outcome. We help you shape it so it holds up to an audit.

2

Inform your people

Employees are told in advance what is checked and why, and give consent through the platform. Transparency here is both a legal requirement and the difference between a policy people accept and one they resent.

3

Run and record

Screenings run on schedule or on trigger. Results land in the dashboard with a full audit trail, and only the people you authorise can see them.

Do I need consent to screen an existing employee?
You need a lawful basis, and consent is a weak one in an employment relationship because an employee is rarely free to refuse. Most employers rely on a legal obligation where one exists, or on legitimate interest supported by a documented policy and a proportionality assessment.

Regardless of the basis, you must inform the employee in advance about the screening and its scope. That obligation is separate from the basis and applies in every case.
How often should we re-screen?
Only as often as the risk justifies. Where a regulator or certification sets an interval, follow it. Where nothing external applies, most organisations settle on an event-driven approach for the majority of roles and a fixed cycle only for a small group with financial authority, privileged system access or contact with vulnerable people.

An interval you cannot justify is worse than no interval, because it creates a data-processing habit without a reason behind it.

The rules that apply to screening your own staff

Everything that governs pre-employment screening still applies: a valid legal basis, proportionality to the role, and telling the person in advance. In-employment screening then adds a complication, because the power imbalance is larger. A candidate can withdraw from a process. An employee risks their livelihood, so consent freely given is largely a fiction and regulators treat it that way.

The practical consequence is that your justification has to sit in policy rather than in an individual decision. Write down which roles are re-screened, on what trigger, with which checks and why those checks fit those roles. Consult the works council where your jurisdiction requires it. Then apply the policy consistently, because inconsistent application is what turns a defensible programme into a discrimination complaint.

Reasonable to re-check

  • Professional registrations and licences that expire

  • Sanctions and PEP status, which change without notice

  • Directorships and company officerships in public registers

  • Insolvency and bankruptcy filings, for roles with financial authority

  • Adverse media, where the role carries reputational exposure

  • A fresh criminal record certificate, where law or the role requires it

  • Right to work, where a permit has an expiry date

Still off limits

  • Health data and sickness absence

  • Religion, political opinion or trade union membership

  • Sexual orientation and ethnic origin

  • Private social media and personal life without a role-related reason

  • Continuous covert monitoring of employees

  • Re-running the full package on everyone by default

The last item is the one organisations get wrong most often. Buying a broad package and applying it to the whole workforce feels thorough, but it inverts the test: you are meant to start from the risk in the role and work towards the checks, not start from the checks and apply them everywhere. A screening you cannot justify for a specific role is personal data you should not be holding.

Where re-screening is expected of you

Few laws name in-employment screening directly. Several frameworks require it in substance, by asking you to keep assurance current rather than to verify once at hire.

ISO 27001

Annex A personnel security expects screening proportionate to the information a person can access, reviewed as roles and access change. Certification auditors look for the policy and the evidence, not just a pre-employment check on file.

Financial services

Fitness and propriety obligations for regulated roles are ongoing rather than one-off. A change in relevant facts, such as an insolvency or a directorship, is expected to trigger reassessment.

Critical infrastructure

Operators are increasingly required to run a continuous personnel security programme covering pre-employment screening, periodic re-screening cycles and checks on external suppliers, rather than a single check at hire.

Work with vulnerable groups

Several countries operate continuous monitoring rather than periodic re-checks, so a new relevant conviction surfaces during employment without the employer re-requesting anything.

What re-screening costs

Per screening, roughly the same as the equivalent pre-employment check, since the underlying checks are identical. The variable is volume: a cycle applied to a large role group multiplies quickly, which is another reason to scope by risk rather than headcount.

The cost that is easy to miss is administrative. Tracking who is due, chasing consent and keeping evidence together is where re-screening programmes usually fail, and it is the part automation actually solves.

Connect Pescheck to the HR stack you already use

Explore 100+ integrations
Pescheck integrations overview

Governance & Security:

FAQ

Questions and answers

Can't find what you're looking for? We're here to help.Contact us