Join our Newsletter — 33% off our NHI Course
Home FAQ Identity Beyond IAM How should security teams reduce the risk of…
Identity Beyond IAM

How should security teams reduce the risk of fraudulent hires entering through an applicant tracking system?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 6, 2026 Domain: Identity Beyond IAM

Treat the applicant tracking system as part of the security perimeter, not just an HR workflow. Security teams should inventory it, review third-party risk, and monitor identity, email, and candidate signals together. The key control is to catch synthetic personas before account provisioning, so suspicious applicants can be reviewed before access is granted or a laptop is issued.

Why applicant tracking systems need security controls, not just HR process

An applicant tracking system can become a low-friction entry point for fraud because it concentrates identity claims, contact data, interview workflows, and downstream hiring decisions in one place. If a synthetic persona survives that stage, the organisation may later trust it for onboarding, payroll setup, device issuance, or internal access. NHI Management Group recommends treating the system as a governed intake control, not a standalone recruiting tool. In practice, many security teams discover weak candidate vetting only after a hire request has already moved into provisioning.

How fraudulent applicants move from résumé submission to access

Fraudulent hires usually succeed by making the application look operationally normal enough to pass early screening, then exploiting the handoff between recruiting and onboarding. The risk is not limited to a fake name on a form; it is the chain of trust that begins with a candidate record and can end with a corporate account. That is why identity, email, device, and workflow signals need to be assessed together rather than separately. The relevant security question is whether the organisation can distinguish a real applicant from a coordinated synthetic persona before any downstream trust is granted.

Security teams should focus on control points where false confidence tends to accumulate:

  • Candidate identity evidence that is internally consistent across submissions, but not independently verified.
  • Email, phone, and location signals that appear disposable, mismatched, or reused across multiple applications.
  • Recruiting workflows that allow a candidate record to advance without a separate security review when risk indicators appear.
  • Provisioning paths that assume HR validation is sufficient for account creation, laptop assignment, or contractor-style access.

This becomes especially important when staffing volume, remote hiring, or third-party recruiters increase the speed of intake. The faster the process, the easier it is for teams to confuse administrative completeness with trustworthiness. Where applicant tracking data feeds automation, the control objective is to make suspicious records visible before they become approved identities. NIST's cybersecurity guidance is relevant here because the issue is really governance of trust boundaries around a business system, not just a people process. NIST Cybersecurity Framework 2.0

The guidance starts to break down when teams assume one verification step is enough for every hiring path, because the same fraud patterns do not present uniformly across employee, contractor, and vendor onboarding.

Where the standard answer breaks down in real hiring operations

Tighter screening often increases hiring friction, requiring organisations to balance fraud prevention against candidate drop-off, recruiter workload, and legal or privacy constraints. That tradeoff is real, and it is why the answer is not to reject every unusual application, but to define which anomalies require escalation and which can be documented as benign.

There is also no single indicator that proves a candidate is fraudulent. Strong teams look for combinations, not isolated anomalies, and they distinguish between unusual but legitimate applicants and records that appear engineered to survive automated review. If a workflow only flags one weak signal at a time, it will miss the more common case where a synthetic persona is built to look ordinary across several channels.

For teams that want a control-oriented baseline, the question is less about whether the applicant tracking system is secure in isolation and more about whether it is governed as part of onboarding risk. That usually means aligning recruitment review, third-party screening, and provisioning approval so that a suspicious application cannot silently become an active user. The broader control posture is supported by NIST SP 800-53 Rev 5 Security and Privacy Controls, particularly where organisations need consistent control ownership across intake, approval, and account lifecycle steps.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

MITRE ATT&CK address the attack and risk surface, while NIST CSF 2.0, CIS Controls v8 and NIST SP 800-63 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0GV.SC-01 — Cyber Supply Chain Risk ManagementATS vendors and integrations create third-party intake risk.
ID.IM-01 — Identity ManagementFraudulent hires exploit weak identity proofing before onboarding.
Recommendation — Assess ATS vendors and integrations before letting candidate data drive access decisions. Separate candidate review from identity approval before provisioning accounts or devices.
CIS Controls v86.1 — Establish and Maintain an Inventory of AccountsHiring fraud can create illegitimate downstream accounts from bad candidate records.
Recommendation — Tie onboarding approvals to accountable account inventory and review exception paths.
NIST SP 800-63IAL2 — Identity Assurance Level 2Applicants need stronger identity evidence when hiring feeds access decisions.
Recommendation — Require stronger identity evidence when candidate records can trigger onboarding access.
MITRE ATT&CKT1585.001 — Establish Accounts: Social Media AccountsSynthetic personas often rely on fabricated or staged identities to gain trust.
Recommendation — Map persona-building patterns to threat hunting and watch for coordinated fake identity creation.

Practitioner Guidance

What to prioritise: Treat the decision to approve a candidate as separate from the decision to provision access. If those steps are merged, the organisation loses the ability to stop synthetic hires before they inherit trust.

Decision rule: If an application shows multiple weak anomalies across identity, contact, and workflow data, escalate it for human review rather than trying to automate a yes/no decision from any single signal. The useful threshold is pattern consistency, not perfect proof.

What to verify: Confirm that the applicant tracking system, background-check workflow, and onboarding process share a common exception path. Security teams should be able to show who can block a questionable hire, what evidence is required, and when the case is reopened after review.

Practitioner takeaway: Fraud prevention here is strongest when the hiring pipeline is designed so that trust is earned in stages, because once a synthetic persona reaches provisioning, the cost of correction rises sharply.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 6, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org