Version 1.0 · UK recruitment resource

AI Candidate Identity & Recruitment Fraud Control Checklist

A source-led control framework for connecting the person who applies, interviews, verifies, onboards and starts work—without allowing an automated fraud signal to become an unchallengeable decision.

Owner: SOS Global AIJurisdiction focus: UKPublished: 19 September 2026
Discuss implementation
Control classifications

Know which rule you are applying before you collect evidence.

LEGAL REQUIREMENT

Applicable law

Confirm the current duty, lawful route and accountable employer or controller.

REGULATORY / SECTOR REQUIREMENT

Role or setting

Use the authoritative regulator, register, safeguarding or professional source.

CLIENT-SPECIFIC REQUIREMENT

Placement rule

Record what the hirer requires, what evidence it accepts and who can resolve exceptions.

SOS RECOMMENDED CONTROL

Operational safeguard

Preserve identity continuity, evidence status, challenge and accountable progression.

Identity continuity

One candidate identity from application to onboarding.

CheckpointEvidence and controlException requiring human review
1. Application identityRecord the candidate-supplied identity, contact route, source, consent/privacy information and material changes.Conflicting names, contact routes, unexplained duplicate profiles or material record changes.
2. Application materialKeep the submitted CV, answers, portfolio and declared use of permitted AI tools as separate evidence.Contradictory chronology, unverifiable claims or content that cannot be explained by the candidate.
3. Interview identityDefine how the interviewer connects the person present to the applicant record without relying on appearance alone.Unexpected participant, suspected prompting, voice/video inconsistency, substituted device or unexplained interruption.
4. Remote impersonation and deepfake riskUse proportionate liveness, challenge and escalation controls appropriate to the role and risk; document limitations.Failed or inconclusive checks must stop progression rather than create an automatic accusation.
5. Evidence integrityRecord issuer, source, date, document status and verification route separately from uploaded files.Alteration indicators, mismatch, expired evidence or inability to validate against an authoritative source.
6. Right-to-work interactionUse the current Home Office route. A digital identity check does not remove the employer’s responsibility to follow the prescribed process.No valid route, mismatch between result and candidate, time-limited permission or follow-up requirement.
7. Pre-onboarding continuityReconnect the verified person, accepted offer, worker record, bank/contact changes and access provisioning.Late identity or payment-detail change, new device/contact route or inconsistency with verified evidence.
8. Human decision and auditName the reviewer, evidence considered, challenge made, exception outcome, decision, date and retention rule.No consequential fraud or suitability conclusion should rest only on an AI flag or opaque score.
Practical response

Detect, pause, verify, decide and retain the basis.

01

Detect a discrepancy

Record the signal and source without prematurely labelling the candidate fraudulent.

02

Pause the affected progression

Protect the process and candidate while preventing a questionable identity or document from advancing.

03

Use an approved verification route

Recheck against the authoritative source or proportionate identity method.

04

Human review and recorded outcome

An authorised person considers the context, correction route, evidence and next action.

Turn the controls into a workflow

Keep identity evidence and human authority connected.

SOS can implement customer-specific identity and fraud-control workflows around approved providers, risk policy and accountable review.