Same frame as last time before we get into it, because this is running on our public site and not everyone reading it is inside the panel.
CXR runs research panels a few times a year. Small group, closed forum, several weeks of structured async discussion on one topic, then a closing call. This one is on candidate fraud in hiring - roughly two dozen TA leaders and heads of talent, plus a handful of identity and verification specialists to keep us honest on the tech side.
Co-facilitating with me is CXR member @Alex Murphy, CEO of JobSync, and his fingerprints are on this week's prompts as much as mine. Full disclosure, same as always: Alex and JobSync helped shape the framing on this panel, and JobSync sits in the talent tech market. Panelists aren't paid to participate. Never have been. That's how CareerXroads runs these. For additional resources and information, the panel and available downloads live at www.cxr.works/research.
Week 1 was defining the problem, and that recap is here. Week 2 moved to detection: what organizations actually have in place, how they're thinking about risk, and how the speed-versus-scrutiny fight is playing out inside real companies.
I said at the end of the Week 1 recap that I thought Week 2 was where this panel would get uncomfortable. It did. This was the week the group started admitting what's held together with tape. What follows isn't a tour of any one company's program - the specifics stay in the room (that's how we operate.) These are the patterns that showed up across two dozen organizations when nobody was performing for an analyst.
Opting out of the arms race is a strategy. So is arming up.
The widest split in the panel isn't between mature programs and immature ones. It's between two deliberate philosophies.
One camp is refusing to fight AI with AI, full stop. @Adela Schoolderman at Edwards Lifesciences made the case for it better than anyone I've heard so far: the moment you deploy detection AI, the fraudsters deploy counter-AI, and you're in an escalation loop with no finish line. Her alternative isn't inaction but rather it's refusing to build (in her words) a highspeed train station around a horse and buggy. Look inside first. Rigorous interviews, human judgment, disciplined process, and telling candidates plainly where AI is and isn't welcome in your hiring. She described her regulated, slower-moving environment as something she used to resent and now appreciates. It forces thinking over reacting.
The other camp is buying the full stack. Identity verification with biometrics. Application-level fraud scoring. IP monitoring wired into security operations. Deepfake detection on the roadmap. And here's the part that should stop you in your tracks: the sharpest voice in that camp doesn't disagree with Adela at all. @Sarah Smart at Appian opened her response by agreeing with Adela 100 percent - then laid out one of the more comprehensive detection approaches in the panel, and explained the gap between her philosophy and her actions in a sentence I've been repeating all week:
I am in a battle for quality signal.
She agrees with the opt-out argument. She's arming up anyway.
Sit with that for a few moments. Two thoughtful reads of the same threat producing opposite strategies. That's not confusion. That's a market that hasn't decided yet what the next few years look like, and it's exactly what we're taking into Week 3.
The industry is buying signal without buying decisions
Here's the pattern that snuck up on us mid-week, and I think it's one of the most important findings so far.
Fraud detection features are landing inside the major ATS and hiring platforms right now. Multiple panelists have them switched on - IP anomaly flags, risk scores, tiered fraud signals. Legal teams have approved the data use. The technology works, more or less.
Then a score comes back "elevated" and everything stops being a system and starts being a judgment call.
When I pushed on what actually happens next, the honest answer across nearly every organization was the same: the recruiter decides. On the spot, with no defined protocol, no calibration guidance, and no documentation standard. One leader told me a formal protocol is "a this year thing, hopefully a Q3 thing." He was one of the further-along ones.
The vendors are reporting to have shipped the signal. Almost nobody has shipped the playbook.
Exactly one organization in the panel described a working escalation model: flagged cases route to an ethics and compliance function that does the deeper investigation and hands back a recommendation, so recruiters are never asked to weigh fraud-risk factors themselves. High touch, expensive, and right now it's the exception.
Why does this matter beyond workflow hygiene? Because another panelist named the legal exposure directly: detection that relies on individual human judgment creates risk. Every inconsistent gut call on a fraud flag is a decision your company may someday have to defend. And the darker version is already here - I know of two companies running out-of-the-box AI against interview recordings, no TA customization at all, and dispositioning candidates as not qualified whenever it flags suspected fraud. No details recorded. No second look.
Give that another minute or two to settle in...
Fraud landed in TA's lap. The money didn't come with it.
We asked whose budget detection comes out of, and the panel produced at least four different answers. @Linellis Santiago at Land O'Lakes drew the cleanest line in the room, and I'd steal it if you have nothing in play today: pre-employment sits on TA's budget, identity and security measures post-hire sit under Cyber. Ownership follows where the risk lives. Others described the mirror image where security is funding it while TA operationalizes it - or a spend split with IT while chasing executive funding for the rest. And most common of all: TA driving vendor evaluation with no dedicated budget line anywhere, because waiting costs more than moving. One systems leader called that arrangement exactly what it is: backwards.
The framing that resonated most came from @John Gotham at Newell Brands, and it's an argument I'd hand any TA leader walking into a budget conversation: this is an enterprise risk issue with TA on the front line. Not a TA line item. Fund it like the former, staff it like the latter.
@John Hassett, who talks to hundreds of TA teams a month from the verification side, offered the historical rhyme to go with it. TA and the CISO are becoming the new power couple, the way TA and Marketing became one when employer branding got serious a decade ago. That earlier partnership took years and a lot of awkward meetings before it got real. I think we can expect the same here.
And one number is still missing from every business case in the thread so far... I asked the group what a single fraudulent hire actually costs - your company's number, not a vendor's slide. Nobody had one.
Still asking.
Everyone believes in risk tiering. Almost nobody has written it down.
The second question of the week asked how organizations tier fraud risk by role. The finding: risk tiering exists almost entirely in people's heads.
Several panelists admitted to "subconsciously ranking" (IT and system-access roles at the top, remote next, frontline at the bottom) without a single documented framework among them to date. A couple of organizations are deliberately not tiering at all, betting on strong, consistent controls for every candidate rather than variable scrutiny. That's a defensible position, and notably it came from the same disciplined-process camp described above.
But one story in our conversations broke the frame entirely, and it's the insight a few said they'll put in front of security teams this quarter. A large manufacturer is in the middle of extending email accounts and system access to thousands of frontline production workers who never had it (a good move for the employee experience) without changing the screening depth those hires receive. The leader who shared it said it plainly: they're increasing and decreasing risk at the same time.
Think about what that does to the tidy pyramid. When an entry-level assembler gets company system access, "high-risk roles" stops being a short list at the top of the org chart. The access floor is rising across corporate America, driven by digital workplace initiatives that have nothing to do with hiring. Risk tiering as most of us picture it may be obsolete before most organizations finish writing it down.
The real tension isn't speed versus scrutiny. It's deliberateness versus slowness.
I think that the best reframe of the week came from Adela, in her second big contribution of the panel. Hiring managers experience any added verification step as slowness. But slowness and deliberateness are different things, and the difference is whether TA has earned the standing to explain the tradeoff before the req is on fire.
Her organization gets visibility into hiring needs before plans are even approved, which has them filling roles weeks ahead of schedule without changing methods. That earned trust is what lets TA draw a hard line when it matters: we will not compromise on deliberateness to protect the business, the patients, and the candidate. Hiring managers run on assumptions about how TA works. They won't know differently unless we tell them.
The practical version of deliberateness showed up all over the thread, and it kept coming back to a phrase @Amy Ho at Adobe gave this panel back in Week 1: friction on purpose. Targeted friction at the highest-risk points, rather than blanket mandates everywhere. Video required where audio used to do. Identity checkpoints placed so that later interviewers can confirm the same person keeps showing up. Verification expectations stated up front in the job posting itself.
On that last one, a genuinely useful data point. @Shuree Sockel at Enterprise Mobility added identity-verification language directly to job postings and watched for a drop in apply completion. It never came. Candidates reportedly appreciate the transparency. If fear of deterring good candidates is what's holding you back from setting expectations early, the early evidence says the fear is bigger than the risk.
There's a hiring manager version of this too. @Kevin Granger at Trane Technologies educates his managers by showing them the evidence - two resumes side by side, same jobs listed in shuffled order, A-B-C on one and C-A-B on the other - so they see for themselves why the extra review time exists. Managers who go through hiring once a year don't know what TA is up against. Show them.
And @Jessica Gray described the most complete operating model in the panel so far: a cross-functional group spanning Legal, Physical Security, Onboarding, TA, and HR Ops that mapped exactly where fraud flags appear in their process, keeps a living playbook the team reviews monthly, and even triggers an alert when new-hire equipment ships to an address that doesn't match the one on file. Her team's motto is the one I'd put on the wall if recruiting was full RTO: increase our posture of caution.
Meanwhile, the blanket-mandate approach keeps failing in the wild. An "everyone onsite Day 1" edict from a business leader collapsed at one company for the simplest reason - HR never agreed to it, so it couldn't be enforced. Friction on purpose beats friction by decree, again.
I'll add one more thing from this thread, carefully, because it took real courage to share. At least one team admitted to using informal deterrence tactics that work - suspected fraudulent candidates withdraw almost immediately - but that the team itself isn't comfortable with, because the tactics aren't transparent and could burn legitimate candidates. That admission is the panel working as intended. The pressure to do something is producing improvised defenses ahead of principled ones, and the practitioners know it. That gap between what teams are doing and what they'd defend out loud is exactly what Week 4 exists for.
The frontline reality driving all this improvisation is not subtle. One recruiter encountered three fraudulent candidates in a single week - remote-work demands on an onsite role, a conveniently dropped call when the answer was no, duplicate LinkedIn profiles, oddly probing questions about security during a screen.
This is a Tuesday now.
The shelf is empty, and everyone is reaching for it
Listen to what the panel asked for this week, unprompted and independently. A vendor cheatsheet with real tradeoffs and costs. A one-page executive summary that helps Legal and Privacy see the risk of not acting. Documented implementation pitfalls from teams that have already been through it. And a recruiter quick-reference guide with red flags, real scenarios, and talk tracks - which @Laura Carver at Dell Technologies and Kevin Granger didn't just request, they spent half a thread designing out loud between them, down to whether it should be scenario-based or example-based. (Her answer: both, plus talk tracks. She's right.)
Five senior leaders, describing the same missing shelf.
Nobody is asking for more thought leadership on whether fraud is real. That question is settled. They're asking for working artifacts, and the artifacts don't exist yet - not from vendors, not from analysts, not from anyone.
Noted. I'm not letting it drop.
Where Week 3 goes
The AI Complication. Prompts are up.
This is where the Adela-and-Sarah tension from the top of this post gets tested directly. AI on both sides of the hiring table, deepfake detection, screening IN the AI skills you want while screening OUT the bots you don't, and whether Legal and Compliance are actually in the room when these decisions get made.
If you're a panelist and haven't posted in Week 2 yet, the threads are still open - even a couple of sentences from your seat helps the whole group. And if you're reading this from the wider CXR community or just within our industry and your company has put a real internal number on the cost of one fraudulent hire, I want to hear from you. That number is the missing piece of every business case in this research so far, and somebody out there thinks they have it, I'm sure.
#CandidateFraud#candidateexperience#leadership#research