Blogs

Fraud Panel, Week 4: The Receipts, and the One Thing

By Chris Hoyt (he/him) posted 2 hours ago

  

For the last week of the panel, I asked everyone to show their receipts. What have you actually changed in the last year because of fraud risk, what did it cost you, and what would you tell a peer who hasn't made that move yet.

A quick frame first, as we do, because this runs on our public site and not everyone reading it was inside the panel. CXR runs research panels a few times a year. Small group, closed forum, four weeks of structured async discussion on one topic, then a closing call. This one we've been working on is candidate fraud in hiring, with a couple dozen TA leaders and heads of talent in the room and a handful of identity and verification specialists to keep us honest on the tech side. The four weeks ran Landscape, Detection, The AI Complication, and What Needs to Change. We just closed our final week as we prepare the larger report, and this recap covers it.

Co-facilitating with me is CXR member @Alex Murphy, CEO of JobSync. Full disclosure the same way I'd give it inside the forum: Alex and JobSync helped shape the framing, and JobSync sits in the talent tech market. Panelists aren't paid to participate. Never have been. That's how we run these.

The change most people made is a stopgap, and they know it

Most of what's actually in place today is low-tech, and the people running it will tell you so themselves. Interviews moved off the phone and onto video. A recruiter comparing a driver's license photo against the face on the webcam. Nobody built a five-year strategy around that and it's catching people anyway.

One story from our conversations on this stuck with me. A team moved every interview to camera and added a manual ID check at the interview stage, knowing it would cost them a day of time-to-offer. They took the day. What they got back was suspicious candidates dropping out of the process on their own, once it was clear a human would actually look. @Andrea Johnson at Assurant described the same shift at her shop in a line the group kept borrowing all month: her recruiters are "no longer trying to be detectives."

The best change-management move of the week came from @Laura Carver at Dell. When someone asks whether they can skip a new verification step, she doesn't quote policy at them but instead tells them about a candidate the step actually caught. We've found that even for some leadership, fraud stays an abstraction to most teams until it has a face, and she's decided the fastest way to give it one is a true story.

Past that, the range in the room was wide. Some organizations have re-sequenced entire roadmaps to get enterprise identity verification live. Others told us the most valuable first move was getting the risk onto leadership's radar before anything happened, and the advice that came out of those threads was the bluntest of the month: don't wait for an incident. Reading it all together, what struck me is that nobody can say where the industry baseline sits. Because there isn't one. Each of us is guessing at where we stand.

The I-9 was never built for this

Halfway through the week I asked the question we'd been circling since July. Between photo capture, IP flags, digital wallet checks and NIST certifications, this group has assembled a pile of workarounds, and a pile of workarounds usually means the underlying standard has quit doing its job. So: does hiring need a new identity standard, and if so, who builds it, who owns it, and who makes anyone use it?

@Taylor Liggett of ID.me reframed the whole thing for me. The I-9 was never an identity check. It exists to establish your right to work in this country. Identity rides along only as a means to that end. The form is about forty years old, E-Verify about thirty, and both verify that documents and numbers are real rather than that the person holding them is who they claim to be. Most bad actors today are working with genuine PII that belongs to someone else, so they pass. He also pointed out that strong identity proofing standards already exist. NIST wrote them down years ago. And he gave us one number I haven't stopped thinking about since the discussion: in a single recent week, ID.me's early I-9 program caught more than forty fraud incidents, two of them confirmed North Korean operatives. One vendor, one week, and an early-stage product. I wouldn't quote that as an industry statistic but I'll absolutely quote it as a reason to stop assuming this is rare.

Where the group landed on who builds the replacement: a public-private partnership, and the agreement was nearly unanimous. Government sets the requirement, vendors build to it, employers enforce it in hiring. I think that's right and I'd also note it's the easiest possible thing to agree on, since it hands the homework to nobody in the room. The technology exists. The standards exist. The unclaimed job is enforcement, and every time the conversation gets there, it just stalls.

The one thing

I closed the panel by asking for a single commitment. One thing, not three, that the TA community should do differently in the next twelve months, specific enough that we could check back in a year and score it.

Most of the answers were some version of train the recruiters. @John Gotham at Newell made the fullest case: teach people what to look for, and write down where acceptable AI use ends and misrepresentation begins, rather than pretending you can ban the tools. Another thread added a wrinkle I hadn't considered, which is that guidance handed to a hiring manager very rarely survives the trip to the actual interviewers. Training is a fine answer and it's also the one that doesn't require a budget fight (which I suspect is part of why it led the voting.)

The commitment I'd put my own money on came from @Ryann Wingeier at Assurant: stop treating identity as a checkpoint and verify it continuously, from application through onboarding and into the job itself, and if your workforce is remote, let that reshape your roadmap this year. Twelve months ago this group was taking meetings with identity startups without being able to name the actual weak spot. Now we can. It's the handoff from candidate to employee, the moment everyone assumes the checking is finished and stops. Fewer people signed up for her version, I suspect, because it costs more and takes longer. But I'd still rather see this industry chase it than settle for a training module.

The piece nobody resolved is pace. @Adela Schoolderman at Edwards wants the process designed before any new tool goes live, because a tool you turn on in a hurry becomes a process you're stuck with. @Sarah Smart is done waiting, because the fraud isn't waiting either. I've flipped between those two positions a few times myself this month, and I'm not going to pretend the panel settled it. It depends on what you're protecting and how exposed you already are, and the best way I know to figure that out is to find a peer a year down either road and ask them what broke.

The closing call: we still don't have the right word

We spent a surprising amount of the closing call arguing about vocabulary, and it turned out to be the most productive argument of the hour.

Nobody on this panel ever loved "candidate fraud" as a label, and the call finally produced better options. One frame that landed with the group: little-f fraud versus big-F fraud. Resume padding and interview cheating on one side, organized rings and nation-state infiltration on the other, and one label stretched across both, which is a fair summary of why so many internal conversations about this go sideways. There was a push for "fraud in recruitment" over "recruiting fraud," since the latter sounds like the recruiters are the ones running the con. And one company has dropped the word fraud internally altogether. They call the work Employee Verification and frame it as protection for the people already on the payroll, which changes the politics of the entire program. "Workforce integrity" and "talent integrity" had their partisans too.

For consideration in your org: the label assigns the owner. Call it candidate fraud and it files itself under recruiting, which is how recruiters ended up holding the detective work in the first place. Call it workforce integrity and it belongs to security, ethics and legal as much as to TA, which is where most of the room thinks the work should have been sitting all along.

The unfinished business is what happens after a signal fires. Ethics team? Security? Legal? All three answers exist in the wild, and plenty of companies are still deciding case by case because there's no protocol to lean on. Nobody could price the risk either. The room's instinct is that one bad hire in a sensitive seat gets expensive fast, possibly into the billions across the industry and a double digit percentage of the stock price, but that's an instinct, not a figure. Somebody has to do that math before this work gets funded properly.

What to do with this

Three things, then I'll get out of your way.

  1. Pull your last ninety days of flagged candidates and trace each one. Who made the call, and what happened next? If the honest answer is that a recruiter sorted it out alone, you've found your gap.
  2. Decide how you're going to handle identity and commit for a year. Train your people, or build verification that runs the whole way through. Half of each, done without conviction, is the weakest position available.
  3. Take your recruiters out of the detective business. Four weeks of discussion kept arriving back at this. The tools have outrun the protocols, and the recruiter is the one left holding the difference. Closing that gap is a leadership decision. It will not happen from the recruiter's chair.

The structured discussion is closed although our member forums are still open and our meetings are buzzing with conversations on this topic, of course. Alex, the CXR team and I are pulling all four weeks into a longer report, and I'll be tagging panelists as it publishes. To everyone who spent a month putting what isn't working on the table next to what is: thank you. That candor is rarer than it should be in our industry but thankfully a familiar friend within our community.

If you want a seat at the next panel, the way in is the same as it's always been. Answer the polls. Show up in the forums. Come to a Colloquium. That's the pool we pull from. Learn more about previous research and download all the reports for free at www.cxr.works/research.


#CandidateFraud
#research

Community Events

Recent Headlines

Permalink