How to Evaluate a Background-Screening Proposal: A Procurement Scorecard

Published: 22 September 2026  |  Last updated: 22 September 2026

Selecting a background-screening provider is not simply a price comparison. The provider may handle identity documents, employment histories, education records, criminal-record information, financial information and other sensitive personal data across multiple jurisdictions.

Executive Summary

A defensible procurement process should answer three questions: can the provider lawfully and reliably deliver the checks required in every relevant country; can it protect candidate data and control its supply chain; and can it meet operational needs at the quoted price rather than simply present the lowest headline fee?

This guide provides a practical 100-point scorecard for procurement, HR, compliance, security and legal teams evaluating background-screening proposals or running an RFP.

The central principle: evaluate evidence, not assurances. Unsupported statements such as “global coverage”, “fast turnaround”, “compliant” or “secure” should not receive the same score as documented and independently verified capability.

For related guidance, see eeCheck’s Background Screening Vendor Questions in Asia, In-House vs Outsourced Screening in Asia, Compliant Background Screening Policy in Asia and Background Screening Policy Template for Asia-Pacific.

Important: This framework supports procurement and risk assessment. It is not legal advice. Screening scope, consent, permitted sources, reportable information and retention requirements differ by jurisdiction and role.

1. Establish Pass / Fail Requirements Before Scoring

Some failures should not be offset by a low price or polished presentation. Set minimum requirements before reviewing commercial proposals.

Typical Procurement GateWhy It Matters
Lawful delivery of every mandatory check in required jurisdictionsA broad country list is not useful if the required check cannot lawfully or reliably be delivered.
Acceptable DPA and cross-border transfer mechanismCandidate information may move across entities, systems and jurisdictions.
Disclosure of material subcontractors and data sourcesBuyers need visibility over who can access data and how delivery is controlled.
Minimum security controlsEncryption, MFA, access control, logging, vulnerability management and incident response should be evidenced.
Adequate insurance and financial stabilityThe provider should be able to support the programme throughout the contract term.
Breach-notification, audit, deletion and exit obligations acceptedThese protections should be contractual.
No material misrepresentationMisleading capability claims are themselves a procurement risk.
Legal, privacy, security and compliance review passedHigh-risk issues should be resolved before award.

2. The 100-Point Procurement Scorecard

Evaluation CategoryWeight
Legal, regulatory and screening methodology18
Geographic coverage and source quality14
Information security, privacy and data governance18
Service delivery, turnaround and quality assurance14
Technology, integration and reporting10
Candidate and client experience8
Implementation, governance and resilience8
Commercials and total cost of ownership10
Total100

3. Use a Consistent Scoring Scale

Weighted score = (vendor score ÷ 5) × category weight

ScoreMeaningEvidence Standard
0UnacceptableRequirement not met, omitted or material risk identified
1Major weaknessLargely manual, unproven or dependent on future development
2Partially meetsSome capability exists, but important gaps remain
3Meets requirementAdequate capability supported by relevant documentation
4Exceeds requirementStrong, mature capability supported by performance evidence
5Leading capabilityDemonstrably superior, independently assured and contractually committed
Scoring rule: score the provider’s current capability—not a roadmap item or a capability promised after contract signature.

4. Legal, Regulatory and Screening Methodology — 18 Points

What to assess

  • Permissible screening scope by jurisdiction and role
  • Consent or other required authorisation
  • Identity and name-matching methodology
  • Sources and verification routes
  • Distinction between verified facts, source responses, database matches and observations
  • Discrepancy, clarification and correction process
  • Review of adverse findings
  • Legal and regulatory change management
  • Support for regulated-sector requirements

Evidence to request

  • country-level methodology statements;
  • sample redacted reports;
  • consent workflows;
  • reinvestigation procedures;
  • regulatory change records;
  • reporting rules; and
  • source limitations and disclaimers.

Warning signs

  • “Global criminal check” is presented as a single uniform product.
  • The underlying source or verification route cannot be identified.
  • Database searches are presented as equivalent to primary-source verification.
  • The proposal guarantees that no record exists rather than describing the search actually performed.
  • Compliance responsibility is pushed entirely onto the employer.

See eeCheck’s Risk-Based Background Screening in Asia and Role-Based Background Screening in Asia.

5. Geographic Coverage and Source Quality — 14 Points

Coverage should be evaluated at the country-and-check level, not by country count alone.

What to assess

  • Can the provider deliver every required check in each hiring country and candidate-history country?
  • Is delivery performed through an owned team, affiliate, vetted local partner or aggregator?
  • What source type is used for each check?
  • Are source limitations, access restrictions and record coverage explained?
  • Does the provider support local languages, scripts, name conventions and documentary requirements?
  • Can it manage institutional fees, notarisation, translations and candidate-supplied documents?
  • Are country-specific turnaround times based on actual performance?
  • How are countries with decentralised or non-digitised records handled?

Evidence to request

Ask for a country-and-check coverage matrix containing, at minimum:

Coverage Matrix FieldRequired Detail
CountryJurisdiction in which the check is performed
Check typeEmployment, education, criminal, credit, regulatory, identity, etc.
Verification routeDatabase, government source, institution, referee or local researcher
Source typePrimary, authoritative or secondary
Standard TATMedian and 90th percentile, not just a broad range
Candidate actionDocuments, consent, fingerprints, in-person visit or none
Additional feesInstitution, court, government, translation or access fees
Key limitationCoverage period, geography, source availability or reportability
Delivery modelIn-house, affiliate or subcontractor

Warning signs

  • Coverage is stated only as a country count.
  • The provider will not disclose whether delivery is subcontracted.
  • One turnaround promise is applied to all countries and check types.
  • Reports omit the source searched, date searched or material limitations.

For country-specific context, see the Asia Background Check Guide, Hong Kong Background Check Guide, Singapore Background Checks Guide and China Background Check Process.

6. Information Security, Privacy and Data Governance — 18 Points

Security and privacy should carry at least as much weight as commercial terms.

What to assess

  • Current ISO/IEC 27001 certification or equivalent assurance
  • Certification scope
  • Encryption in transit and at rest
  • MFA, least privilege and role-based access
  • Logging, vulnerability scanning, penetration testing and patching
  • Production/test separation
  • Data storage and backup locations
  • Cross-border and onward transfers
  • Subprocessor access
  • Retention and deletion
  • Incident response and notification
  • Applicable data-subject rights
  • AI use and human oversight

Evidence to request

  • certificates and scope;
  • penetration-test summary;
  • security architecture;
  • subprocessor register;
  • data-location schedule;
  • incident response procedure;
  • retention/deletion standard;
  • BCP/DR test results; and
  • cyber/privacy insurance.

Warning signs

  • The provider relies solely on a cloud host’s certification.
  • Certification scope does not cover screening operations.
  • Subprocessors or data locations are undisclosed.
  • Candidate data is retained indefinitely “for future use”.
  • AI is described broadly without clear boundaries, validation or human review.

See eeCheck’s Asia Background Check Compliance Guide and AI Background Checks & Automation Risks.

7. Service Delivery, Turnaround and Quality Assurance — 14 Points

What to assess

  • Define when the TAT clock starts.
  • Separate provider-controlled from source/candidate-controlled delays.
  • Review median, 90th percentile and completion-within-SLA measures.
  • Segment SLAs by country and check type.
  • Review incomplete-information and non-response handling.
  • Understand QA before report release.
  • Review adverse-result escalation.
  • Ask for error, rework, complaint and correction rates.
  • Confirm named escalation roles and response times.

Evidence to request

  • at least six to twelve months of comparable performance data;
  • SLA definition and sample monthly service report;
  • quality-assurance methodology and sampling rates;
  • escalation matrix;
  • staffing and capacity plan;
  • business-continuity arrangements; and
  • anonymised examples of delayed-case communication.

Warning signs

  • Only “average TAT” is supplied.
  • The SLA clock stops for broad or poorly defined exceptions.
  • Extremely fast completion is promised despite reliance on slow primary sources.
  • Quality is described as “100% accurate” without a methodology or correction process.

Related reading: Background Check Turnaround in Asia and Why Fast Is Not Always Accurate.

8. Technology, Integration and Reporting — 10 Points

What to assess

  • Secure ordering and candidate data collection
  • Status tracking, document exchange and reporting
  • Role-based access, SSO, MFA and audit trails
  • Package and approval configuration
  • Production-ready ATS/HRIS/API integration
  • API authentication, retries, errors and change management
  • Consolidated and entity-level reporting
  • Report and audit-record export
  • Mobile, accessibility and multilingual support

Practical test

Require a scripted demonstration using realistic scenarios. Ask the provider to:

  1. create a candidate in one jurisdiction;
  2. trigger a missing-information workflow;
  3. show a delayed source response;
  4. escalate a potential discrepancy;
  5. restrict report access by role;
  6. display the audit history; and
  7. export management information.

This reveals operational capability more effectively than a generic sales demonstration.

See eeCheck’s ATS Background Check Integration Workbook.

9. Candidate and Client Experience — 8 Points

What to assess

  • Clear, mobile-friendly candidate journey
  • Transparent explanation of why information is requested
  • Country- and check-specific document requests
  • Save-progress and reminder functionality
  • Suitable support hours and channels
  • Secure correction/challenge process
  • Proactive client updates
  • Measured complaint and escalation performance

Evidence to request

  • candidate journey demonstration;
  • supported-language list;
  • support response and resolution statistics;
  • candidate satisfaction results and methodology;
  • complaint categories and trend data; and
  • sample candidate communications.

10. Implementation, Governance and Resilience — 8 Points

What to assess

  • Named implementation manager and credible work plan
  • Clear responsibilities and acceptance criteria
  • Pilot, UAT and controlled rollout
  • Migration of packages, workflows, users and historical cases
  • Training and change support
  • Ongoing governance cadence
  • Financial stability and capacity
  • Continuity and recovery arrangements
  • Exit plan covering data export, transition assistance and deletion

Evidence to request

  • implementation plan and RACI;
  • sample risk and issue log;
  • governance and reporting calendar;
  • continuity and disaster-recovery test summary;
  • financial information or credit assessment appropriate to the contract;
  • client references for comparable implementations; and
  • exit-assistance schedule.

For governance planning, see eeCheck’s Background Check SLA Template for Asia.

11. Commercials and Total Cost of Ownership — 10 Points

The cheapest unit price can become expensive when essential items are excluded.

What to assess

Commercial AreaWhat to Clarify
Package contentWhat is included in each check and package?
Fixed feesMinimum commitments, platform, account and implementation fees
Third-party costsCourt, institution, government, translation, courier and cancellation fees
ExceptionsUnable-to-verify, duplicate, reopened and supplementary checks
TechnologyIntegration, configuration, training and reporting
Pricing basisCountry, currency, contract year and volume assumptions
Price changesFX, inflation and pass-through increases
ExitTransition and termination costs

Estimated annual cost = unit charges + mandatory third-party fees + platform/account fees + implementation/integration + expected exception charges + internal operating cost.

Warning signs

  • Large parts of pricing are marked “at cost” without an estimate or cap.
  • Low base prices exclude common source fees.
  • The proposal assumes volumes or contract terms not stated in the RFP.
  • Price-adjustment mechanisms are unclear or open-ended.
  • Service credits are the sole remedy for serious security or compliance failures.

12. Ready-to-Use Evaluator Worksheet

CategoryWeightVendor Score (0–5)Weighted ScoreEvidence / ReferenceEvaluator Comments
Legal, regulatory and methodology18
Geographic coverage and source quality14
Security, privacy and data governance18
Service delivery, TAT and quality14
Technology, integration and reporting10
Candidate and client experience8
Implementation, governance and resilience8
Commercials and total cost10
Total100

13. How to Run a Fair Evaluation

  1. Use a cross-functional panel. Include HR/TA, procurement, privacy/legal, information security, compliance, HR technology and representative business users.
  2. Separate technical and commercial evaluation. Assess capability and risk before price dominates the process.
  3. Moderate scores as a group. Discuss material differences and retain the final rationale.
  4. Validate high-risk claims. Use due diligence, references, scripted demonstrations and, where appropriate, a pilot.
  5. Convert winning claims into the contract. Material promises should become contractual or implementation obligations.

14. Suggested Decision Thresholds

ResultSuggested Treatment
Any mandatory gate failedDo not proceed unless the risk owner formally accepts a documented remediation plan before award
Below 60/100Material capability or control gaps; normally exclude
60–69/100Potentially viable only with defined remediation and stronger contractual controls
70–79/100Meets requirements; compare risks, references and total cost carefully
80–89/100Strong proposal with good supporting evidence
90–100/100Exceptional; validate that scoring is evidence-based and not inflated

Consider category floors as well—for example, no shortlisted provider may score below 3 out of 5 in legal/methodology or security/privacy.

15. Common Procurement Mistakes

MistakeBetter Approach
Giving price too much weightConsider delays, rework, breaches and unreliable results as part of total value.
Treating all checks as commoditiesCompare sources, permissions, limitations and TAT like-for-like.
Scoring policies without testing implementationUse demonstrations, audit evidence and operating records.
Accepting global claims without country detailRequire country-specific methodology, source, TAT, candidate requirements and fees.
Ignoring the provider supply chainUnderstand which institutions, databases, researchers and partners can access data.
Leaving exit planning until the endDefine data export, open-case transition, secure deletion and assistance before award.

16. How eeCheck Can Support a Procurement Evaluation

eeCheck provides background-screening services across Asia and internationally, including employment and education verification, identity, criminal and court-related searches where legally available, sanctions and PEP screening, adverse media and other role-appropriate checks.

For procurement exercises, eeCheck can provide country-level service information, implementation planning, security and quality documentation, sample reporting and a structured response aligned with the buyer’s evaluation framework.

Organisations should assess eeCheck using the same evidence-based standards set out in this guide and select the provider that best fits their legal, risk, operational and candidate-experience requirements.

Related reading: Asia Background Screening Intelligence Report, Asia Background Screening Executive Briefing, Top Background Check Firm in Asia and MNC Background Screening in Asia.

Frequently Asked Questions

What is the most important principle when evaluating a background-screening proposal?

Evaluate evidence, not assurances. Unsupported claims should not receive the same score as capabilities backed by current documentation, independent assurance, service data, demonstrations or contractual commitments.

Should the lowest-price background-screening provider win?

Not necessarily. Price matters, but buyers should compare total cost of ownership, including third-party fees, integration, exception charges, internal workload, delays, rework and risk exposure.

How much weight should security and privacy receive?

This framework assigns 18 points to information security, privacy and data governance—equal to legal, regulatory and methodology considerations.

How should country coverage be evaluated?

At the country-and-check level, including source type, verification route, candidate requirements, TAT, fees, limitations and delivery model.

How should a provider’s turnaround time be assessed?

Review the SLA clock, exclusions, median and 90th-percentile performance, completion-within-SLA measures and country/check segmentation.

What score is generally acceptable?

The framework suggests 70–79 as meeting requirements, 80–89 as strong and 90–100 as exceptional, while mandatory gate failures should be addressed separately.

Why should proposal claims be written into the contract?

A proposal score has limited value if material commitments on scope, methodology, security, service levels, pricing, implementation, transition and deletion do not become contractual obligations.

Final Takeaway

The right provider is not necessarily the bidder with the longest country list, fastest headline turnaround or lowest unit price.

A strong procurement decision identifies the provider that can demonstrate lawful methodology, reliable sources, effective data protection, measurable service delivery and a workable operating model.

A documented scorecard makes the decision more consistent and defensible—and forces the buying team to define its true requirements before marketing claims and price pressure take over.

This guide provides general procurement and risk-management information and does not constitute legal advice.

KoreaEnglish