IndiciumIndicium
Log in
← Back to blog
Background checks for HR, Legal and Compliance

Turn public-source risk signals into audit-ready decisions.

Indicium helps regulated teams screen candidates, counterparties and sensitive hires — with dated sources, human review and reports your Legal team can defend.

Understanding each phase of the screening process helps compliance teams scope onboarding workflows and align internal SLAs with external due-diligence support.

From order to report: the screening implementation timeline

A step-by-step walkthrough of how a background-check order moves from intake to final report, including typical duration buckets per phase.

When a compliance team commissions a background check, the question that follows is rarely just about content — it is about timing. How long does it take from the moment an order is placed until a reviewed, decision-ready report lands in the inbox? The answer depends on the scope of the screening, the jurisdictions involved, the availability of registry data, and the depth of human review required. For banks, insurers, private equity firms, and KRITIS operators in the DACH region, understanding the individual phases of a screening implementation helps set realistic expectations with internal stakeholders and external partners alike.

This article walks through the screening process step by step — from order intake to final report — and maps each phase to a qualitative duration bucket so that compliance and risk teams can plan around the process rather than be surprised by it.

Step 1: Order intake and scoping

Every screening engagement begins with an order. At this stage, the requesting party — typically a compliance officer, onboarding manager, or investment professional — defines what needs to be checked and on whom. The subject may be a natural person (a prospective board member, a beneficial owner, an executive candidate) or a legal entity (a target company, a counterparty, a fund structure).

The intake phase covers several dimensions: the type of screening required (registry verification, sanctions and adverse-media screening, UBO identification, or a combination), the jurisdictions in question, the risk classification of the subject, and any specific regulatory triggers that prompted the request. In the German market, this often ties back to the requirements of the Geldwäschegesetz (GwG), particularly the risk-based approach for customer due diligence. In Switzerland, comparable obligations arise under the Anti-Money Laundering Act and FINMA guidance.

A well-structured intake reduces friction downstream. If the subject’s identifying details are incomplete — a missing date of birth, an ambiguous entity name, an outdated registered address — the subsequent data-gathering phase slows down. Conversely, a precise order with clear scope boundaries allows the screening provider to allocate the right data sources and reviewers from the start.

Step 2: Data source retrieval

Once the order is scoped, the screening provider begins retrieving data from the relevant sources. This is the most variable phase of the entire timeline, because it depends on external data availability rather than internal processing capacity.

For corporate due diligence, the primary sources are commercial registers — in Germany the Handelsregister, in Switzerland the Zefix commercial register, in Austria the Firmenbuch. These registers provide registered office, legal form, managing directors, share capital, and in some cases shareholder structures. For UBO identification, register retrieval is often supplemented by additional document requests, particularly when ownership chains cross multiple jurisdictions or when nominee structures obscure the ultimate beneficial owner.

For sanctions and adverse-media screening, the data sources shift to watchlists, PEP databases, and structured media monitoring. Sanctions lists are generally machine-readable and can be queried quickly, but meaningful adverse-media screening requires human judgment to distinguish relevant findings from noise — a name match in a local news article is not the same as a substantiated report of regulatory action.

The duration of this phase depends heavily on the number of jurisdictions involved, the responsiveness of foreign registries, and the complexity of the ownership structure. A single-jurisdiction entity check with a clear register trail is substantially faster than a multi-tier holding structure spanning three or more countries.

Step 3: Human review and quality control

Raw data is not a report. The review phase is where a screening provider adds the analytical layer that distinguishes a due-diligence product from a simple data export. Trained analysts examine the retrieved material, reconcile discrepancies, and assess the relevance of each finding.

Several tasks typically occur during review. Name matches from sanctions screening are evaluated for false positives — does the matched individual plausibly correspond to the subject, or is it a common-name collision? Adverse-media hits are read in context and classified by severity and source reliability. Ownership chains are traced step by step, with each level documented and cross-checked against the available register evidence. Where documents are in a foreign language, translation or summarisation may be required.

Quality control is an integral part of this phase, not an afterthought. A second reviewer or a senior analyst commonly validates the findings before the report is finalised, particularly for enhanced due-diligence engagements or subjects classified as high-risk. This internal checkpoint exists to catch errors, ensure consistency in assessment language, and confirm that the scope defined at intake has been fully addressed.

The review phase is where the screening provider’s expertise becomes most visible. Two providers may retrieve the same register data, but the quality of the analysis — the clarity of the UBO trace, the precision of the adverse-media assessment, the soundness of the risk classification — is what determines whether the report is genuinely useful to the requesting compliance team.

Step 4: Report assembly and delivery

After review, the findings are compiled into a structured report. The format varies by provider and by client preference, but a due-diligence report typically includes a subject summary, a description of the sources consulted, the factual findings organised by screening type, an assessment section, and where applicable a risk classification or recommended next steps.

For ongoing monitoring engagements — common in banking and insurance contexts where customer relationships are periodically re-screened — the report may also flag changes since the last screening cycle, allowing the compliance team to focus on deltas rather than re-reading the entire file.

Delivery is typically handled through a secure portal, an API integration, or an encrypted email channel, depending on the client’s infrastructure. The report is the deliverable, but from a process perspective it is also the handoff point: the requesting team now owns the decision based on the findings.

Mapping phases to duration

The table below provides a qualitative orientation. Actual durations depend on scope, jurisdictional complexity, and data availability, and should not be read as service-level commitments.

Phase Typical duration Key variables
Order intake and scoping Short Completeness of subject data, clarity of screening scope
Data source retrieval Short to extended Number of jurisdictions, register responsiveness, ownership-chain depth
Human review and quality control Short to extended Volume of findings, false-positive rate, need for translation or second-level review
Report assembly and delivery Short Report format, delivery channel, client-specific templates

The dominant driver of overall timeline is almost always the data retrieval phase, followed closely by review when adverse-media findings are numerous or ownership structures are opaque. Intake and delivery are comparatively predictable.

Practical considerations for compliance teams

For teams planning screening workflows, a few observations are worth keeping in mind. First, the quality of the order directly influences the speed of the outcome. Providing complete subject data and a clear scope statement at intake reduces back-and-forth and prevents avoidable delays during retrieval. Second, multi-jurisdiction cases should be planned with buffer time, because foreign register responses are outside the screening provider’s control. Third, enhanced due-diligence engagements — those involving PEPs, complex ownership structures, or adverse-media deep dives — should not be benchmarked against standard KYC checks, as the review effort is materially different.

Finally, it is worth distinguishing between one-time screening and ongoing monitoring. A one-time report has a defined endpoint, while a monitoring engagement introduces a cyclical rhythm in which the same phases repeat at agreed intervals. Understanding both models helps compliance teams align their internal processes with the screening provider’s workflow.

This article provides general information and does not constitute legal advice in individual cases.

Ready to move from reading to doing?

See how a reviewable risk report is built – from name to verdict in minutes, not weeks.

Book a demo See a sample report