Screening for the Offer That Comes Later: An Insider-Risk Playbook for HR

Screening for the Offer That Comes Later: An Insider-Risk Playbook for HR
Screening for the Offer That Comes Later: An Insider-Risk Playbook for HR

The companion piece made an uncomfortable case. The most dangerous moment in an employee’s tenure may not be the day they’re hired, but the day someone else offers them money for what they can reach.

No screening programme can predict which employee will say yes. That isn’t the goal.

The goal is to make your organisation expensive, awkward and risky to buy from. TrendAI frames the defence the same way: prepare staff for the possibility of being approached, and prepare systems to spot unusual behaviour if someone gives in.

What follows is the HR and screening side of that defence, in the order most organisations can realistically build it.

Start With the Access Map, Not the Org Chart

Most screening programmes are organised by job family or grade. The insider market is organised by capability.

Buyers target the people who can authorise payments, restore accounts or bypass fraud checks. Add to that anyone who can port a phone number, approve a refund or change a shipping record.

So begin with a joint exercise between HR, security and the business. List every action in your organisation that would be worth paying for. Then find every role that can perform it, including contractors and vendor staff.

The result is usually surprising. The list tends to include very few executives and a great many support, operations and trust and safety roles.

Sort those roles into tiers. A simple three-tier model works well: roles whose access could cause severe, direct harm to customers or funds; roles with meaningful but bounded access; and everyone else.

From here on, the tier drives everything. Not the job title, not the salary band, not the location.

Screen the Doors That Matter, Properly

For top-tier roles, the standard package usually isn’t enough, and the gaps are rarely exotic.

Verify identity at source, with liveness or in-person confirmation, because identity fraud remains the simplest way to put the wrong person in a sensitive seat. Verify employment against authoritative records where they exist, rather than referee phone calls.

Search court records in every jurisdiction where the person has lived or worked, not just the current one. Run adverse media and sanctions screening.

For roles where undisclosed outside work creates real risk, check for dual employment. Someone quietly working for a competitor or a second employer is showing precisely the divided loyalty the insider market exploits.

Financial checks deserve care. Financial pressure is a documented driver of insider activity, and Mimecast links the recent surge partly to layoffs, wage stagnation and cost-of-living strain.

But in the United States, employment credit checks fall under the FCRA and are restricted further in several states and cities, including California, Illinois and New York City. Elsewhere, they raise real proportionality questions.

Where lawful and genuinely relevant to a top-tier role, a financial check can be one input among several. It should never become a way of excluding people simply for having debt, which is both unfair and a poor predictor on its own.

Re-Verify When Access Changes, Not When the Calendar Does

The biggest gap in most programmes is that screening stops at the front door. People move into more sensitive roles through promotion or transfer, and nobody looks again.

The fix is trigger-based re-verification. Run a proportionate refresh when someone moves into a top-tier role, receives new privileged access, joins a sensitive queue, or returns after a long absence.

A refresh doesn’t need to repeat everything. Court records, adverse media, dual employment and any role-specific checks usually cover what could have changed.

Tie the refresh to the access request itself, so the permission isn’t granted until the check is complete. That turns re-verification into a normal part of career progression, rather than a signal of suspicion.

Build the legal basis properly.

In the US, a refresh run through a consumer reporting agency is a new consumer report under the FCRA, so the authorisation you hold must clearly cover checks during employment, or you need a fresh one.

In India, the DPDP Act treats processing for employment purposes, including safeguarding the employer against loss or liability such as corporate espionage, as a legitimate use. Notice, purpose limitation and proportionality still apply.

In the UK and EU, re-screening needs a documented lawful basis and a proportionality assessment.

Across all of them, tell employees at hire that re-verification happens when access changes. Transparency is a legal requirement, and it is also a deterrent.

Hold the Outsourced Seat to Your Standard

The Coinbase breach happened at a vendor’s desk, under a vendor’s hiring process, when support agents at an outsourcing firm in Indore were offered bribes to copy customer data.

Flashpoint’s data suggests buyers are increasingly probing supply chain partners and specialist service providers for exactly this reason.

Your screening standard should follow the access, not the employment contract. For every vendor whose staff touch top-tier capabilities, write the standard into the contract:

Screening equivalent to your own for the same tier. Evidence of completed checks, auditable on request. Re-verification when vendor staff move onto your account or into higher-access work. Prompt notification of any suspected insider incident or reported approach. No substitution of staff without the same checks.

Then actually audit a sample. A clause nobody tests is a hope, not a control.

This is also where genuine in-country capability matters. A delivery centre in India, the Philippines or the Gulf needs local court, address and employment verification to the same depth as a head-office hire. A screening programme that is rigorous in London and cursory in Indore has simply moved the risk to where the access is.

Make the Approach Reportable, and Protect the Reporter

The BBC case ended well because the target reported the approach. Most employees don’t know they should, or fear what happens if they do.

Build a clear, low-friction channel for employees to report being approached, whether on Telegram, Signal, LinkedIn or in person. Route it to a joint HR and security team, not a generic inbox.

Train people on what approaches actually look like. Recruiters often start with a small, grey-area favour, then escalate, and evidence of the earlier task later becomes leverage to blackmail the employee into more.

Say explicitly that reporting an approach will never count against the employee. Consider an amnesty for anyone who comes forward after an initial small step. The sooner the organisation knows, the cheaper the problem.

Then measure it. A rising number of reported approaches is good news. It means the channel works.

Treat Financial Distress as a Support Problem First

TrendAI suggests the shift towards selling out may be driven by workplace culture, personal financial pressure or general dissatisfaction, and that this human vulnerability is exactly what the market is built to exploit.

If that’s what makes employees receptive, the cheapest control is to reduce it where you can.

That means employee assistance programmes that include financial counselling. It means hardship funds or salary advances for genuine emergencies. It means managers trained to respond to visible stress with support rather than suspicion.

None of this is soft. An employee who can get help from their employer is far less likely to accept help from a buyer.

Pair it with structural controls that HR can influence. TrendAI recommends reducing single-person authority through dual approval for high-risk transactions, and treating workflow exceptions, such as unusual volumes of account recoveries, as security events.

Role design is an HR lever. A role that can’t move money alone is worth less on the market.

Close the Exit Cleanly

The Cifas research has a detail worth rereading: the logins in question were being sold to former colleagues.

The exit is a live risk window, and often the least governed one.

Revoke access on the last working day, not the following week. Recover devices and verify the recovery. Remind departing staff of their continuing confidentiality obligations. For top-tier roles, review access activity during the notice period.

Make sure contractor and vendor offboarding runs to the same timetable. Stale vendor accounts are among the easiest things in any organisation to sell.

Measure the Programme, Not Just the Checks

Screening programmes usually report volume and turnaround time. An insider-risk programme needs different numbers.

Track the share of top-tier roles re-verified at the point of access change. Track the share of vendor staff in top-tier work with auditable checks. Track the number of approaches reported, and how quickly they were escalated. Track the time between an exit and full access revocation.

These tell you whether the organisation is getting harder to buy from, which is the only outcome that matters.

The payoff is measurable too. Ponemon’s 2026 research found that organisations with an insider risk management programme avoided an average of seven incidents and saved $8.2 million.

Be the Company That Is Expensive to Buy

The insider market runs on the same logic as any market. Buyers go where access is valuable, easy to acquire and unlikely to be noticed.

Screening can’t change what your access is worth. It can change the other two.

A company that knows which seats are worth buying, verifies the people in them when their keys change, holds vendors to the same line, hears about approaches early and helps its people before a stranger does is simply a worse place to shop.

The employees it has are also, overwhelmingly, the ones who report the offer rather than accept it. The work of verification is to keep that true long after the first check comes back clean.

Scroll to Top