IndiciumIndicium
Log in
← Back to blog
Background checks for HR, Legal and Compliance

Turn public-source risk signals into audit-ready decisions.

Indicium helps regulated teams screen candidates, counterparties and sensitive hires — with dated sources, human review and reports your Legal team can defend.

Reading about background checks? Indicium turns public-source risk signals into audit-ready reports for HR, Legal and Compliance.

What is a background check and why it matters for KYC compliance

A practical breakdown of what background checks actually cover, how they differ from simple database lookups, and why they're essential for meeting KYC obligations under the GwG and EU AML directives.

A background check is the structured, methodical collation and assessment of information about a person or organisation that is relevant to a specific decision — hiring, contracting, a business relationship, or a regulatory obligation. It is not a single database query, but a process: collect, verify, assess, document.

What a proper background check covers

A modern background check for regulated institutions runs across at least six categories:

  1. Sanctions and watchlists — EU, OFAC, UN, HMT, SECO, and other relevant regimes. Are you dealing with a sanctioned person or entity?
  2. Personal data verification — Does the claimed identity hold up? Multiple addresses, email addresses, phone numbers, and their consistency over time.
  3. Adverse media screening — Has the person or entity appeared in press reports, regulatory filings, or court records in a negative context?
  4. Corporate network analysis — What companies is the person linked to? Are there connections to sanctioned entities, shell companies, or high-risk jurisdictions?
  5. CV and credential verification — Do the claimed qualifications, positions, and timelines match public records?
  6. Social media assessment — Limited to professionally relevant, publicly available content, assessed for reputation, conduct, and risk indicators within data-protection boundaries — not monitored, but checked.

Why it matters for KYC compliance

Know Your Customer (KYC) is not optional. Under the German Money Laundering Act (GwG), the EU’s 5th and 6th AML Directives, and equivalent legislation across Europe, obliged entities must identify their customers, understand the business relationship, and assess the risk of money laundering or terrorist financing.

A background check is the operational backbone of KYC. It answers the three questions every compliance officer must be able to answer:

  • Who am I dealing with? — Identity verification beyond the ID card.
  • What is the risk? — PEP status, sanctions hits, adverse media, and structural risks.
  • Can I document this decision? — An audit trail that holds up before the regulator and in court.

Database lookup vs. background check

A database lookup says: “Name appears on list X.” A background check says: “Name appears on list X; the entry dates from 2019; it concerns a subsidiary that was sold in 2020; the current UBO structure shows no connection; the risk is assessed as low — here are the sources.”

The difference is context and assessment. Regulators expect the latter. The GwG explicitly requires a risk-based approach — risk management and risk analysis under §§ 4–5 GwG — so you cannot outsource judgment to a boolean flag.

When due diligence is mandatory

  • Customer onboarding — GwG § 10: general due diligence requirements for new business relationships.
  • High-risk customers — GwG § 15: enhanced due diligence for PEPs, high-risk third countries, or unusually complex transactions.
  • Occasional transactions — GwG § 10 Abs. 3: above statutory thresholds that vary by sector (€15,000 as the general mark; lower thresholds apply, for example, to goods traders, precious metals and gambling).
  • Suspicious activity — Where facts indicate that assets may stem from money laundering or terrorist financing, a report under § 43 GwG must be filed without delay — not only after internal confirmation.

The Swiss and EU context

In Switzerland, the obligations flow from the Anti-Money Laundering Act (AMLA/GwG) and FINMA regulation. In the EU, the regulatory framework tightens with every iteration — the new EU Anti-Money Laundering Authority (AMLA) took up operations in 2025 and will assume direct supervision of selected obliged entities from 2028.

The direction is clear: more depth, more documentation, more personal accountability. A background check that is not reviewable is not a background check — it is a risk in itself.

How Indicium approaches it

Indicium runs seven check categories in parallel, every source dated and reproducible as of the cut-off date. Where the software reaches its limits — interpretation, context, edge cases — an analyst takes over. The result is a reviewable risk report: not a list of hits, but a reasoned assessment.


This article is for informational purposes and does not constitute legal advice. For specific compliance obligations, consult your legal department or external counsel.

Ready to move from reading to doing?

See how a reviewable risk report is built — from name to verdict in minutes, not weeks.

Book a demo See a sample report