In-employment screening for the people already on your payroll
Pescheck runs periodic and event-driven re-screening through the same platform and the same audit trail as your pre-employment checks. You set the cycle per role group, we handle consent, evidence and reporting.
What is in-employment screening?
When should you re-screen?
Pre-employment and in-employment are not the same job
Both verify a person, but the balance of interests differs. A candidate can walk away from a hiring process. An employee has a contract, an income and a manager, so consent carries less weight as a lawful basis and your justification has to be stronger.
That is why in-employment screening works best when the rules are written down before you need them: which roles are in scope, which checks apply, how often, and what happens if something surfaces. Decide it once as policy, apply it consistently, and the individual screening stops being a judgement call about a specific person.
Set the cycle per role group
Screening every employee on the same interval is expensive and hard to justify. Pescheck lets you define role groups and give each one its own package and cadence, so a treasury team on an annual cycle and a warehouse team on no cycle at all can coexist in the same policy.
You keep the audit trail centrally: who was screened, when, on what basis, and what the outcome was. That is the record an auditor or a regulator asks for.
Catch what changes after the hire
Re-verify professional registrations, directorships, sanctions and PEP status, adverse media and, where the role justifies it, a fresh criminal record certificate. The checks are the same ones you already trust from pre-employment screening.
One audit trail for hire and re-check
Pre-employment and in-employment screenings sit in the same record, so you can show an auditor the full history for a role rather than two disconnected systems. Retention is set per check, and access stays limited to the people you name.
Checks commonly used for re-screening
Which checks belong in a re-screening cycle depends on what can realistically change and on what the role touches. Registrations expire, sanctions lists move, directorships and insolvencies appear in public registers. Qualifications, by contrast, rarely need checking twice.
We help you pick a package per role group that is defensible rather than exhaustive, so you are not collecting personal data you cannot justify holding.
Insolvency check
Check if a candidate is in a bankruptcy or insolvency register.
Learn moreDutch Criminal Record (VOG)
A declaration of conduct (VOG) showing that past behavior poses no objection.
Learn moreID Check
Automated ID Checker verifies over 31,000 global identity documents
Learn moreIntegrity Check
A series of questions regarding the candidate's integrity.
Learn moreWork Reference Check
Verify an individual's work history, job performance, and other qualifications
Learn moreAdverse Media
Scanning search engines for possible risk indicators regarding your candidate.
Learn moreHow in-employment screening works
Write the policy
Define role groups, the checks for each, the trigger (cycle, promotion or event) and who decides on the outcome. We help you shape it so it holds up to an audit.
Inform your people
Employees are told in advance what is checked and why, and give consent through the platform. Transparency here is both a legal requirement and the difference between a policy people accept and one they resent.
Run and record
Screenings run on schedule or on trigger. Results land in the dashboard with a full audit trail, and only the people you authorise can see them.
Do I need consent to screen an existing employee?
Regardless of the basis, you must inform the employee in advance about the screening and its scope. That obligation is separate from the basis and applies in every case.
How often should we re-screen?
An interval you cannot justify is worse than no interval, because it creates a data-processing habit without a reason behind it.
The rules that apply to screening your own staff
Everything that governs pre-employment screening still applies: a valid legal basis, proportionality to the role, and telling the person in advance. In-employment screening then adds a complication, because the power imbalance is larger. A candidate can withdraw from a process. An employee risks their livelihood, so consent freely given is largely a fiction and regulators treat it that way.
The practical consequence is that your justification has to sit in policy rather than in an individual decision. Write down which roles are re-screened, on what trigger, with which checks and why those checks fit those roles. Consult the works council where your jurisdiction requires it. Then apply the policy consistently, because inconsistent application is what turns a defensible programme into a discrimination complaint.
Reasonable to re-check
-
Professional registrations and licences that expire
-
Sanctions and PEP status, which change without notice
-
Directorships and company officerships in public registers
-
Insolvency and bankruptcy filings, for roles with financial authority
-
Adverse media, where the role carries reputational exposure
-
A fresh criminal record certificate, where law or the role requires it
-
Right to work, where a permit has an expiry date
Still off limits
-
Health data and sickness absence
-
Religion, political opinion or trade union membership
-
Sexual orientation and ethnic origin
-
Private social media and personal life without a role-related reason
-
Continuous covert monitoring of employees
-
Re-running the full package on everyone by default
The last item is the one organisations get wrong most often. Buying a broad package and applying it to the whole workforce feels thorough, but it inverts the test: you are meant to start from the risk in the role and work towards the checks, not start from the checks and apply them everywhere. A screening you cannot justify for a specific role is personal data you should not be holding.
Where re-screening is expected of you
Few laws name in-employment screening directly. Several frameworks require it in substance, by asking you to keep assurance current rather than to verify once at hire.
- ISO 27001
Annex A personnel security expects screening proportionate to the information a person can access, reviewed as roles and access change. Certification auditors look for the policy and the evidence, not just a pre-employment check on file.
- Financial services
Fitness and propriety obligations for regulated roles are ongoing rather than one-off. A change in relevant facts, such as an insolvency or a directorship, is expected to trigger reassessment.
- Critical infrastructure
Operators are increasingly required to run a continuous personnel security programme covering pre-employment screening, periodic re-screening cycles and checks on external suppliers, rather than a single check at hire.
- Work with vulnerable groups
Several countries operate continuous monitoring rather than periodic re-checks, so a new relevant conviction surfaces during employment without the employer re-requesting anything.
What re-screening costs
Per screening, roughly the same as the equivalent pre-employment check, since the underlying checks are identical. The variable is volume: a cycle applied to a large role group multiplies quickly, which is another reason to scope by risk rather than headcount.
The cost that is easy to miss is administrative. Tracking who is due, chasing consent and keeping evidence together is where re-screening programmes usually fail, and it is the part automation actually solves.
Connect Pescheck to the HR stack you already use
Explore 100+ integrations
Questions and answers
Timing and balance of interests. Pre-employment screening happens before someone joins, while the hiring decision is still open. In-employment screening happens during the employment relationship, on an existing colleague.
The checks themselves are largely the same. What differs is the justification: an employee cannot walk away from the process as easily as a candidate, so your legal basis and proportionality assessment have to be stronger, and your policy has to be written down before you rely on it.
You can include a clause committing employees to cooperate with screening where it is proportionate and lawful, and many employers in regulated sectors do. A clause does not by itself create a lawful basis for any check you like, though.
Each screening still has to be proportionate to the role at the time it is run, and the employee still has to be informed. Treat the clause as setting expectations, not as blanket permission.
Decide the process before you need it. A finding is information, not a verdict. The employee should have the opportunity to respond and to correct inaccurate data, and the outcome should be assessed against the requirements of the role rather than in the abstract.
Who decides, who is informed and what the escalation path looks like all belong in the policy. Improvising this after a hit is how organisations end up with an unfair dismissal claim on top of the original problem.
Often yes, and it is regularly overlooked. Where a rule attaches to a role rather than to a contract type, contractors, agency workers and seconded staff in that role fall within scope. In financial services the reliability requirement is explicit about covering non-employees.
Practically, this is where most gaps sit: the permanent workforce is covered by an HR process, while the contractor population sits outside it.
Related but not identical. Continuous monitoring watches specific data sources, typically sanctions, PEP and adverse media, and alerts you when something changes. In-employment screening is a deliberate re-check of a defined package at a defined moment.
Monitoring suits data that changes unpredictably. Scheduled re-screening suits everything else. Many organisations combine the two: monitoring on a small high-risk group, cycle-based re-screening on a slightly wider one.
Explain it before you run it, and explain the reasoning rather than just the requirement. In-employment screening lands badly when it appears without warning and looks targeted at an individual.
Announce it as policy, cover a defined role group rather than named people, tell employees what is checked and what is not, and be clear that the process applies to everyone in that group including leadership. Screening that visibly stops at the management layer is the fastest way to lose the room.