There's a sentence that shows up in almost every applicant tracking system's sales deck: "fully compliant candidate records." It sounds like a guarantee. It's actually a description of a filing cabinet.

An ATS stores documents. A DBS certificate gets uploaded. A right-to-work scan gets attached to a profile. A training certificate gets logged with an expiry date. All of that is useful — it's evidence a check happened, at some point, and the outcome was positive. None of it is the same as knowing whether that outcome still holds true today.

The quiet assumption baked into most staffing software

Ask a compliance manager what "verified" means to them, and they'll usually describe a moment in time: the day the check was run. Ask a director what they need "verified" to mean for an audit or a framework review, and they'll describe a standing state: true, right now, for every active placement. Most staffing software is built around the first definition and marketed using language that implies the second.

That's not necessarily dishonest — it's a genuinely hard problem to solve properly, and storing evidence well is still meaningfully better than not storing it at all. But the gap between "we have a document confirming this was checked" and "we know this is still true" is exactly where placements go wrong, usually discovered at the worst possible moment: during a client audit, after an incident, or when a framework body asks a question nobody prepared for.

What "verify," properly used, should mean

  • A document is not a verification. A DBS certificate on file proves a check happened once. It doesn't prove nothing has changed since.
  • An expiry date is not a verification. Flagging that a registration expires in six weeks is useful admin. It's not the same as confirming the registration is valid today.
  • A renewal reminder is not a verification. A reminder depends on a human acting on it before the gap becomes real. That's a process, not a guarantee.
  • A live, re-run check against the current authoritative source, at the moment it matters, is a verification. This is the only version of "compliant" that actually answers the question anyone auditing you is going to ask.

Why this distinction is worth arguing about

Because the cost of getting it wrong isn't hypothetical. A candidate placed on the strength of a six-week-old screening file, whose registration lapsed in week four, isn't a system failure anyone can point to — it's a document that looked fine, sitting in a record nobody re-checked. That's not a rare failure mode in compliance-heavy sectors. It's close to the default failure mode, because most of the category is built to store proof of a past check rather than confirm a present state.

This is the exact distinction behind why we built SOS Global Recruitment around two checkpoints instead of one — a screening check, and then a live re-verification against the current authoritative source on the actual day a placement starts. Not a document. A confirmed, timestamped, present-tense fact.

Want to see the difference in practice against your own compliance items?

Book a walkthrough