Accreditation is a voluntary review of a CRA’s operations against a published set of industry standards, conducted by an independent auditor. It is a trade credential rather than a regulatory requirement, and a CRA is not required to be accredited in order to operate.
Many CRAs pursue accreditation because clients request it, larger procurement processes may consider it, and preparing for the audit can identify gaps in policies and operations.
PBSA Accreditation
The Professional Background Screening Association (PBSA), formerly the National Association of Professional Background Screeners, operates an accreditation program for background screening organizations in the United States.
The program is administered by the Background Screening Credentialing Council. Formerly known as the Background Screening Agency Accreditation Program (BSAAP), it is now called the Background Screening Organization Accreditation Program (BSOAP). CRAs may still encounter the former name in published materials.
- Understand what the standard covers. The US employment screening standard is organized into six areas: information security, legal and compliance, client education, researcher and data standards, verification services standards, and business practices.
- Work from the current version of the standard. PBSA publishes the standard and its audit criteria, and both are revised periodically. A CRA preparing for audit should confirm which version applies to its review rather than working from an earlier copy.
- Expect an independent audit. Conformity is assessed by a third-party auditor through documentation review and interviews rather than by a self-certification.
- Understand the accreditation cycle. PBSA accreditation currently operates on a 5 year cycle. CRAs should confirm the current renewal and interim review requirements that apply to their accreditation.
- Check which program applies. PBSA maintains a separate general standard for organizations delivering screening services outside the United States. An organization operating in both may consider accreditation under each.
Worth Knowing: Accreditation is an industry credential. It is not a regulatory approval, a requirement to operate, or a guarantee of FCRA compliance. It demonstrates that an independent auditor found that the organization conformed to the applicable accreditation standard at the time of the review. Accreditation also carries application and audit costs, and many CRAs that operate properly and lawfully are not accredited.
Industry Standards and Certifications
Accreditation may be one part of a CRA’s broader compliance and information security program. Other certifications, audits, licenses, and provider requirements may apply depending on the services the CRA provides.
- Information security. Accreditation standards may include requirements for protecting personally identifiable information and demonstrating that appropriate security controls are in place. CRAs should confirm the current security documentation or independent assessment required by the applicable standard.
- SOC 2. A SOC 2 Type II report evaluates specified controls over a period of time and may be requested by clients evaluating a CRA’s information security and operational controls.
- ISO 27001. This certification evaluates an information security management system against an international standard and may be relevant to CRAs with enterprise clients or international operations.
- State licensing. A small number of states require a private investigator license or similar registration for some background screening activity. Licensing is a legal requirement where it applies, unlike accreditation.
- Data provider credentialing. Credit bureaus and other data sources maintain their own credentialing and inspection requirements, which operate independently of any accreditation.
See Policies, Training & Audits for data provider audits and other external reviews.
Preparation and Self-Assessment
Successful accreditation preparation begins well before the formal audit.
- Read the standard clause by clause. Each clause states a specific requirement, and the audit criteria describe what the auditor will accept as evidence of conformity.
- Assess the organization against each clause. Identify where the CRA conforms, where it conforms but lacks documentation to demonstrate it, and where it does not yet conform.
- Assign each gap an owner and a date. Remediation that is not assigned tends not to be completed before the audit window.
- Begin with the clauses that take longest to complete. Security assessments, new policies and procedures, training programs, and other requirements that need a history of implementation should be addressed early in the preparation process.
- Involve the people who perform the work. Auditors may interview staff to confirm how procedures are actually performed. Employees should understand the procedures that apply to their responsibilities and be able to explain how they follow them.
- Allow time between remediation and audit. Newly implemented procedures should have time to operate so the CRA can demonstrate that they are being followed and produce supporting records.
Good Practice: Treat the self-assessment as an operational review rather than an application exercise. The clauses cover areas a CRA should be able to demonstrate whether or not it seeks accreditation, and the gaps identified are worth closing even if the organization decides not to proceed.
Documentation Requirements
Accreditation requires a CRA to demonstrate that its established practices are actually being followed. Policies describe what should happen, while completed records help show what occurred in practice.
Documentation typically requested includes:
- Written policies and procedures covering the areas the standard addresses
- Client agreements and permissible purpose certifications
- Client credentialing files and site inspection records
- Vendor agreements, due diligence, and oversight records
- Information security policy and current certification or audit evidence
- Training materials and completion records
- Quality control procedures and results
- Dispute handling procedures and completed dispute files
- Records retention schedule and disposal procedures
- Insurance certificates
When preparing documentation for the audit:
- Map each document to the applicable requirements. An evidence index can identify which policy, record, or sample supports each requirement and make documentation easier to review.
- Provide samples that show the procedure operating. Completed files demonstrate conformity in a way that a policy document cannot.
- Confirm the documents are current. An expired certificate or a policy dated three years ago raises a question the auditor will pursue.
See Records & Documentation for what to retain and how long to keep it.
Maintaining Accreditation
Accreditation requires ongoing attention after the initial audit. Policies, procedures, documentation, and other program requirements should continue to be maintained throughout the accreditation term.
- Track renewal and review dates. Maintain accreditation renewal dates and any required interim reviews on the same compliance calendar used for other audits, inspections, and recertifications.
- Keep documentation current throughout the term. Maintaining records as the program operates makes renewal preparation easier and provides ongoing evidence that established procedures are being followed.
- Reassess when the standard is revised. A revised standard may add clauses the CRA has never been assessed against.
- Reassess after a significant change. New services, an acquisition, a platform migration, or a change in data providers can affect conformity in areas that were settled at the last review.
- Follow the program’s rules on displaying the mark. Accreditation programs set conditions on how the credential may be used in marketing, and those conditions apply for as long as the CRA displays it.
- Report changes the program requires. Ownership changes and other material events may need to be reported during the term rather than at renewal.
Good Practice: Assign responsibility for maintaining accreditation between audits. A designated owner can track changes to the standard, maintain required documentation, and identify gaps as procedures or operations change.
Records to Keep on File
Accreditation records document the review itself, separately from the operational records the review examined.
Maintain, as applicable:
- The version of the standard the CRA was assessed against, with its effective date
- Self-assessment results and the gaps identified
- Remediation plans, owners, and completion dates
- The evidence index mapping documents to clauses
- Correspondence with the accrediting body
- Auditor reports and findings
- Responses to findings and evidence of remediation
- The accreditation certificate and its term dates
- Interim review results, where the program includes one
- Current information security certification or audit report
Retain records from prior accreditation cycles. They establish how long the CRA has held the credential and what was examined in each review.
Worth Knowing: Accreditation is most valuable when the standards become part of the CRA’s ongoing operations rather than something reviewed only before an audit. Maintaining those practices throughout the accreditation term makes the credential more than a point-in-time review.
Download the Accreditation Readiness Checklist
What the standard covers, what to assess, and what documentation to assemble.
