Join our Newsletter — 33% off our NHI Course
Home› FAQ› Governance, Ownership & Risk› How should employers reduce fraud in online reference…
Governance, Ownership & Risk

How should employers reduce fraud in online reference checks without slowing hiring down?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 29, 2026 Domain: Governance, Ownership & Risk

Employers should verify the identity of both the candidate and the referee before accepting a reference submission, then keep the workflow as short as possible. A strong process combines identity proofing, verified contact details, and a structured portal for responses. That reduces spoofed references, cuts manual chasing, and gives recruiters a faster, more reliable view of the candidate’s history.

Why reference fraud is mostly an identity problem, not a hiring-volume problem

Online reference checks fail when the employer trusts the message, rather than the person behind it. The practical issue is spoofing: a candidate can submit a fake referee, a real referee can be impersonated, or a reference can be answered by someone with no authority to speak for the candidate. The fastest safe process verifies who is participating before collecting the reference.

That is why speed and control need to be designed together. A short workflow that uses verified contact details, identity proofing for both parties, and a structured response path usually beats a long manual process because it removes rework instead of adding more review.

How to keep the process short while making fraud harder

Employers should standardise the reference journey so recruiters are not improvising each time. Ask for the referee’s contact route from a trusted source, not only from the candidate, and use a portal or controlled callback flow that records who submitted the answer and when. The goal is to make the honest path the easiest path.

That process works best when it is lightweight at the point of use. A few targeted checks, such as matching the referee identity to the stated employer relationship and requiring structured answers, usually catch more fraud than an open email thread or a free-form phone conversation that can be easily spoofed.

Where there is a strong suspicion of impersonation, the check should stop being informal. In those cases, a callback to a separately verified number or a second channel confirmation is usually faster than trying to untangle an unreliable reference after the fact.

What should be verified before a reference is trusted?

Three things matter most: the candidate’s identity, the referee’s identity, and the referee’s authority to give the reference. If any one of those is weak, the reference can be genuine in form but unreliable in substance. Employers get the best signal when identity verification is paired with a clear, structured questionnaire.

Verified contact details are more useful than broad trust in a domain name or a social profile. A portal-backed workflow also helps because it preserves an audit trail, reduces off-platform persuasion, and makes it easier to spot repeated patterns of suspicious submissions across roles or applicants.

For this reason, reference checking should be treated as a fraud-control step inside hiring, not as a courtesy conversation. That framing helps recruiters understand why speed comes from removing uncertainty early, rather than from allowing more unverified inputs into the process.

Risk and Threat Considerations

Reference fraud creates two risks at once: false confidence in a hire and wasted recruiter time. Attackers and dishonest applicants usually exploit the weakest point in the process, which is unverified contact details, informal callbacks, or answer channels that do not prove the referee is real.

Failure mechanism: A spoofed referee, compromised inbox, or lookalike contact channel can supply a credible but false employment history, and manual follow-up often confirms the fraud only after the hiring decision has already been influenced.

Impact: The employer may hire someone on the basis of fabricated experience, miss a conduct warning, or spend extra cycle time chasing and re-checking references, which slows hiring instead of accelerating it.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-53 Rev 5 and CIS Controls v8 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST SP 800-53 Rev 5IA-8 — Identification and Authentication (Non-Organizational Users)Reference checks involve external people whose identity must be verified before trust is placed in their statements.
IA-12 — Identity ProofingThe process depends on proofing the identity of candidates and referees to prevent impersonation.
AU-2 — Event LoggingStructured portals create traceable records of who submitted the reference and when.
Recommendation — Verify external participants before accepting reference submissions. Apply identity proofing before trusting reference responses. Log submissions and verification steps for auditability.
ISO/IEC 27001:2022A.5.16 — Identity managementHiring references require controlled identity verification and ownership of the checking process.
Recommendation — Assign clear ownership for identity verification in the hiring workflow.
CIS Controls v8CIS-5 — Account ManagementThis is a user-identity verification and lifecycle control problem for an external hiring workflow.
Recommendation — Standardise verification steps for external reference accounts and contact paths.

Practitioner Guidance

What to prioritise: Put the verification step at the start of the reference workflow, not after the reference is received. If the referee cannot be tied to a trusted contact path, treat the response as untrusted until it is independently confirmed.

What to verify: Confirm that the contact channel, the referee identity, and the claimed employment relationship all line up before relying on the content of the reference. A clean answer is not enough if the sender is not trustworthy.

What good looks like: Recruiters should be able to complete the check quickly with minimal back-and-forth, while the employer still has evidence of who responded, through which channel, and under what verified relationship.

Practitioner takeaway: The right balance is not maximum scrutiny, it is early trust validation plus a short, standardised workflow that removes ambiguity before it creates hiring delay.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 29, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org