IndiciumIndicium
Log in
← Back to blog
Background checks for HR, Legal and Compliance

Turn public-source risk signals into audit-ready decisions.

Indicium helps regulated teams screen candidates, counterparties and sensitive hires — with dated sources, human review and reports your Legal team can defend.

With the Indicium report, you close the gaps that the state security clearance leaves open — documented with dated sources and human final review.

State Security Clearance vs. Employer Screening: Who Checks What?

Security clearance vs. own screening: what SÜG, LuftSiG and AtZüV cover — and what employers must check themselves under KRITIS-DachG and BSIG.

The state security clearance does not replace an employer’s own screening — the two instruments serve different purposes, with different depths of review and different areas of responsibility. The state vets on specific occasions and within narrow limits, focused on sovereign protected interests; the employer receives the outcome only as an approval or a rejection. CV integrity, economic conflicts of interest and ongoing monitoring are covered by none of the state procedures — and it is precisely these areas that the employer must, in many cases, take responsibility for itself under the KRITIS-DachG (German act on the resilience of critical infrastructure) and the BSIG (German act on the Federal Office for Information Security).

What the state checks: SÜG, LuftSiG and AtZüV

Three state vetting regimes shape practice:

  • Security clearance under §§ 7–10 SÜG (German Security Clearance Act): for security-sensitive activities with access to classified information, in three levels (Ü1 to Ü3). Since the January 2026 amendment with extended depth of review — details in the article SÜG Modernisation 2026.
  • Reliability check (ZÜP) under § 7 LuftSiG (German Aviation Security Act): for persons with access to security-restricted areas of airports and in air cargo.
  • Nuclear-law reliability check under § 12b AtG (German Atomic Energy Act) in conjunction with the AtZüV: for activities in nuclear installations, in decommissioning and in the transport of nuclear fuel.

All three procedures have one thing in common: they protect sovereign legal interests — the protection of classified information, aviation security, nuclear security. They draw on sources that are legally closed to the employer, in particular queries to the domestic intelligence authorities (Verfassungsschutz) and the Federal Central Criminal Register (Bundeszentralregister). These sovereign query channels are reserved to the state and cannot and must not be replicated by private screening.

What the state review structurally does not deliver

For the employer, the state clearance has three systemic limitations:

  • Opacity of the outcome: As a rule, the employer learns only the result — “reliable” or “not reliable”. The underlying findings remain with the authority. An independent risk assessment is not possible on this basis.
  • Narrow scope of review: What is assessed is reliability with respect to the specific sovereign protected interest. Whether the CV is accurate, whether degrees exist, whether economic entanglements or conflicts of interest are present — none of that is part of the procedure.
  • Snapshot in time: The clearance is valid for a period of several years. No ongoing monitoring captures what happens between cycles. For aviation security, the article What the ZÜP under § 7 LuftSiG does not check examines this gap in detail.

What employers may check themselves — and increasingly must

Beyond the sovereign queries, the employer may conduct its own checks, provided they are role-related and proportionate: identity and career history, degrees and references, publicly accessible registers, sanctions lists, media reports. The legal framework is set by the general data protection requirements of the GDPR (in particular Art. 6 and Art. 88 GDPR) and § 26 BDSG (German Federal Data Protection Act); the decisive standard is necessity in proportion to the position.

For many operators, this “may” is becoming a “must”: § 13 KRITIS-DachG and § 30 BSIG (as amended) oblige operators of critical facilities and NIS2 entities to implement personnel security measures; at EU level, Art. 13(1)(e) and Art. 14 of the CER Directive (EU) 2022/2557 expressly anchor background checks in the catalogue of duties. These obligations are addressed to the operator itself — they are not fulfilled by a parallel state clearance of individual employees. For an overview, see the articles on the KRITIS umbrella act and on personnel security under § 30 BSIG.

A practical problem sharpens the demarcation question: state procedures take time. Until clearance is granted, the employer faces the choice of keeping the person waiting or deploying them already. An own, documented screening before the start of work is the legally sound middle path: it does not replace the state decision, but it demonstrates that the employer has not delegated its own duty of care to the authority — and it delivers the risk assessment that the official procedure structurally withholds from it.

Map your roles along three questions: Which positions are subject to a state clearance (SÜG, LuftSiG, AtZüV)? Which positions are security-critical without being covered by a state procedure? And where do KRITIS-DachG or BSIG oblige you to ensure personnel security yourself? For the second and third groups, you need your own documented screening concept — an implementation guide is provided in the article Background checks as an operator obligation. Indicium delivers audit-proof software reports for this purpose, with dated sources and human final review (Art. 22 GDPR) — from €79 per report; industry examples can be found under Industries.

This article provides general information and does not constitute legal advice.

Ready to move from reading to doing?

See how a reviewable risk report is built — from name to verdict in minutes, not weeks.

Book a demo See a sample report