An applicant tracking system is the software used to manage job applications, candidate records, and recruiting workflows. In identity security contexts, it also becomes a control point where fraudulent applicants can be detected before onboarding, provided security teams can assess contact data, patterns, and linked threat intelligence.
Expanded Definition
An applicant tracking system, or ATS, is the workflow layer that collects applications, routes approvals, stores candidate records, and standardises recruiting activity. In security and identity terms, it is not just an HR tool. It is a trust boundary where identity evidence, contact data, résumé claims, device signals, and referral patterns can be compared before a person reaches onboarding. That makes it relevant to fraud detection, insider-risk screening, and early-stage identity verification.
Definitions vary across vendors because some products focus narrowly on recruitment operations while others include screening, scheduling, and compliance workflows. NHI Management Group treats the ATS as a decision-making system that can either strengthen or weaken the integrity of the hiring pipeline. Its security value increases when it is connected to threat intelligence, data validation, and identity governance rather than treated as a standalone database. The control logic often maps to access, logging, and integrity expectations described in NIST SP 800-53 Rev 5 Security and Privacy Controls.
The most common misapplication is treating the ATS as a passive record system, which occurs when recruiting teams assume every applicant record is authentic and never verify suspicious patterns before downstream access is granted.
Examples and Use Cases
Implementing ATS controls rigorously often introduces review overhead, requiring organisations to weigh candidate experience and recruitment speed against stronger fraud detection and data integrity.
- A recruiting team flags duplicate applications that reuse the same phone number, email domain, or résumé language across multiple identities, then escalates them for manual review.
- A security team enriches applicant contact details with threat intelligence to identify addresses linked to known mule recruitment campaigns or synthetic identity activity.
- An organisation verifies that candidates for sensitive roles complete extra identity checks before interview scheduling, reducing the chance of impersonation or automated fraud.
- An HR operations team reviews ATS audit logs to confirm who changed candidate records, closed requisitions, or advanced applications into onboarding.
- A governance team uses the ATS to preserve an evidentiary trail for hiring decisions, supporting privacy, compliance, and defensible screening practices aligned with NIST Digital Identity Guidelines.
Why It Matters for Security Teams
Security teams care about the ATS because hiring systems are increasingly attractive to adversaries who exploit speed, trust, and distributed review processes. A weak ATS workflow can allow fake applicants, résumé-padded insiders, or automated identities to enter the organisation before background checks or onboarding controls catch the issue. Once that happens, the ATS ceases to be a convenience layer and becomes part of the attack surface.
The identity connection matters most where applicants become employees, contractors, or non-human operators with system access. If the ATS is not tied to evidence quality, case management, and access governance, downstream identity proofing can be built on unreliable data. For organisations using automated screening or AI-assisted recruiting, the risk extends to model-driven decisions that may amplify bad inputs, which is why governance expectations from NIST AI Risk Management Framework are relevant when ATS workflows are augmented by AI. Organisations typically encounter the impact only after a fraudulent hire, credential abuse, or audit finding exposes the weakness, at which point the ATS becomes operationally unavoidable to secure.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST CSF 2.0, NIST SP 800-53 Rev 5, NIST SP 800-63 and NIST AI RMF set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | PR.AA-01 | ATS workflows affect identity assurance, authentication, and trust in candidate records. |
| NIST SP 800-53 Rev 5 | AU-2 | ATS auditability aligns with logging and traceability expectations for record changes. |
| NIST SP 800-63 | IAL2 | Applicant identity proofing can map to assurance expectations when hiring sensitive roles. |
| OWASP Non-Human Identity Top 10 | ATS data can seed downstream non-human accounts and onboarding trust decisions. | |
| NIST AI RMF | AI-assisted screening in ATS tooling needs governance for validity, bias, and accountability. |
Treat applicant records as trust-bearing data and validate identity evidence before access is granted.