A name screen no longer answers whether your counterparty is exposed to Iran. On 24 August, the US Treasury announced Operation Economic Outcast, issuing sectoral determinations under Executive Order 13902 against five sectors of the Iranian economy: digital assets, technology, gold, aviation, and shipping, building on earlier determinations covering finance and petroleum. The operative line is jurisdictional: OFAC can now sanction any person, regardless of location, that operates in those sectors. Treasury also sanctioned nearly 60 entities, individuals, and vessels across three networks, including a procurement network supporting Iran's Ministry of Defense, a cyber group directed by Iran's Ministry of Intelligence and Security, and an oil revenue network moving funds to the IRGC-Qods Force through the UAE, Hong Kong, China, Singapore, Switzerland, and Europe. Read as analysis: the designation count is the least significant part of this action. A determination replaces a list of names with a description of activity, so a clean SDN screen no longer answers whether a counterparty is exposed. The four commercial sectors chosen, shipping, aviation, gold, and digital assets, are the ones where beneficial ownership is hardest to see. The harder population for compliance teams is the undesignated customer whose activity sits inside a determined sector, not the newly designated names. Treat the general licence suspensions as a dated deadline. OFAC suspended Iran General Licences F and G, covering academic exchanges and certain educational services, with the personal remittance licence also in scope, and a wind down under General Licence BB running to 8 September 2026. Rebuild your exposure question around activity rather than identity: pull customers whose business description, cargo, licence type, or wallet flow touches these five sectors with any Iran nexus. #AML #Sanctions #PF #Compliance More stories like this, every Monday: https://lnkd.in/eHFz9_bm
Background Screening Regulations
Explore top LinkedIn content from expert professionals.
-
-
You're allowed to verify a candidate's background. You're not allowed to do it however you want. Background checks sit at the intersection of three regulations that rarely agree with each other: data privacy, pay transparency, and local labor law. Get the intersection wrong, and the check itself becomes the liability. Here's what's actually possible, country by country — and what gets companies fined. Germany You can't run your own criminal record search. Only the candidate can request their own Führungszeugnis (police clearance certificate), and you can only require one when it's directly tied to the role — finance, childcare, critical infrastructure. Make it a blanket policy for every hire, and you're outside GDPR's proportionality principle. United Kingdom Criminal record data is "special category" under UK GDPR. Consent alone doesn't make it lawful — the power imbalance in an employment relationship means you need a separate legal basis under Schedule 1 of the Data Protection Act. References aren't even a legal requirement outside regulated sectors like education and care. Brazil LGPD requires specific, written, informed consent before any check — no blanket authorizations. Credit history is off-limits unless the role carries real financial responsibility. Criminal record checks are restricted to roles where security is legally mandated. India The DPDP Act requires consent that's free, specific, and revocable — not a clause buried in an offer letter. Data collection has to be proportional to the role, full stop. Enforcement tightens further in 2027, so the standard to build to now is already set. United States FCRA governs the mechanics of the check itself: separate written disclosure, written authorization, and adverse action notices with dispute rights before you reject anyone based on a report. Layer on 37+ states with ban-the-box laws delaying criminal history questions until after a conditional offer, and 18+ states now banning salary history questions outright. EU-wide The Pay Transparency Directive's transposition deadline passed in June 2026. The direction is set: asking candidates about pay history is headed toward a bloc-wide ban, and pay ranges will need to be disclosed upfront in the hiring process. The pattern across all five: consent isn't a formality, "relevant to the role" is doing all the legal work, and pay history is becoming untouchable almost everywhere you hire. Best practice isn't "check everything." It's checking the right thing, in the right country, with the right paper trail — before you extend the offer, not after a regulator asks. This is exactly the kind of call ONE, our compliance agentic companion, is built to help you make — country by country, hire by hire. Laws here move fast and vary by state, sector, and role. Treat this as a starting point for your own legal review, not a compliance sign-off.
-
The audit firm that used to send 6 people for 5 weeks now sends 2 for 2 weeks. Not (just) because they're more efficient. Because your GRC platform already did the testing. This is the Zillow effect in compliance. Platforms shifted from passive storage to active control testing. They now collect evidence, test controls, and form opinions on effectiveness. The auditor validates the platform's opinion instead of forming their own from scratch. This is what we discuss in this week's entry of the GRC Engineer newsletter! → Platforms now collect evidence automatically → Test controls based on their logic → Form opinions on effectiveness → Present auditors with pre-assessed landscape The auditor validates platform opinions instead of forming their own from scratch. This created: → Information parity (you see what auditors see in real-time) → Audit fees dropping 60-90% (discovery work already done) → New business model: checkbox audits at £15k (just trust platform, sign report) → Power inversion (platform choice matters more than auditor choice) But here's the problem most miss: Your platform is now your compliance brain. It decides control effectiveness using vendor methodology. If that logic is wrong, everyone trusts the wrong assessment. Quality auditors question platform logic. Checkbox auditors trust it. Full breakdown in this week's newsletter (link in comments). Huge shoutout to Tines for being the lead sponsor of this week's entry #GRCEngineering
-
Background checks. Sensitive data. Zero DPDP compliance. The most sensitive personal data comes from your hiring process. 📌 Criminal records. 📌 Financial history. 📌 Past employment. 📌 Address verification. 📌 Education certificates. And almost no Indian company has a DPDP-compliant process for any of it. Here is the legal reality your HR team doesn't know: Your company = Data Fiduciary. Your BGV vendor = Data Processor. Your candidate = Data Principal with enforceable rights under DPDP. Every obligation that applies to your customer data — applies here too. The 5 gaps I find in almost every BGV process I review: 1️⃣ Consent was never properly obtained. Most companies collect a generic clause inside the offer letter. Under DPDP — consent for a background check must be specific to that purpose, informed about what will be verified and with which sources, and separate from the employment acceptance. "I accept this offer" is not consent to a criminal record check. 2️⃣ No signed DPA with the BGV vendor. You have a commercial agreement with your BGV vendor. Under DPDP — that vendor relationship requires a Data Processing Agreement with breach notification timelines, deletion obligations, sub-processor controls, and Data Principal rights flowing down. A commercial agreement and a DPA are not the same document. 3️⃣ Candidate rights are completely unaddressed. Under DPDP, your candidate has the right to access what data was collected about them, from which sources, and what the report concluded. Most HR teams have no process for this. No one has asked before — but it is now a legal right, not a courtesy. 4️⃣ BGV reports are retained indefinitely. The candidate joined — or didn't. The report is still in your HRMS, your email, your recruiter's drive — years later. Under DPDP — personal data must be deleted once the purpose is fulfilled. The purpose of a background check is the hiring decision. Once made — the legal basis for retaining the report ends. 5️⃣ Cross-border transfers nobody mapped. Most BGV vendors verify employment and academic records through international databases. That is a cross-border data transfer. Under DPDP Section 16 — your company is responsible for it. Not your vendor. Does your BGV vendor's contract specify which countries your candidate's data flows to? _____________________________ The background verification industry processes thousands of sensitive personal data records every month in India. Almost none of it is DPDP-compliant. And the liability doesn't sit with the BGV vendor. It sits with the company that initiated the check and is the Data Fiduciary. Does your company have a signed DPA with your BGV vendor? ___________________ I help companies build DPDP-compliant hiring data processes — from candidate consent to vendor DPAs to rights response frameworks. Book 1:1 call to find out where you stand. (Link in comment.)
-
95 new vessels are now sanctioned. Does your sanctions compliance program still trust vessel names as a reliable risk indicator? I once thought vessel names were enough. Then I learned the hard way. They’re just the tip of the iceberg. Australia has just added 95 vessels to its sanctions list. See links in comments. Many have cycled through multiple names and identities in recent years. A deliberate tactic to evade detection. The Australian Sanctions Office from the Australian Department of Foreign Affairs and Trade (DFAT) warns: "Vessels involved in illicit activities have often painted over vessel names and IMO numbers to obscure identities and pass themselves off as different vessels." Traditional static screening is increasingly insufficient. To keep pace, compliance teams need to: ↳ Track IMO* numbers, not just names ↳ Leverage AIS data to detect “dark” periods ↳ Watch for suspicious sailing patterns and transfers ↳ Monitor ownership changes and complex structures *International Maritime Organization or IMO The shadow fleet is an increasing regulatory concern. Our defences must evolve with it. For those responsible for keeping sanctions programs effective: - How robust is your maritime risk assessment? - Are you relying on static watchlists or dynamic behavioural analysis? - How quickly can you adapt when 95 new vessels suddenly enter the risk pool? The rules of the game have changed. Have you? PS: What’s your biggest challenge in detecting exposure to sanctioned vessels through financial transactions? __ 📥 Save for later (top right-hand corner of post, 3 dots) 👤 Follow me (Crispin Yuen 🎙️) for more ♻️ Reshare if this was helpful __
-
Is a criminal record/DBS check conducted for all employees? A question I am regularly asked by clients evaluating us as a supplier. Do you conduct DBS checks? If you do, should you be? We do run a background check for employment on prospective employees, including references and right to work in the UK, but our checks do not extend to a criminal records check. Be aware, access to Standard, Enhanced, and Enhanced with Barred List(s) DBS checks is only available to employers who are entitled by law to ask an individual to reveal their full criminal history, including spent convictions (excluding protected cautions and convictions that will be filtered from a criminal record check). This is known as asking ‘an exempted question’. An exempted question applies when the individual will be working in specific occupations, for certain licenses or specified positions. These are covered by the Rehabilitation of Offenders Act 1974 (Exceptions) Order 1975. Knowingly requesting a higher-level check than the legislation allows is unlawful and likely to be a breach of the Data Protection Act 2018 and other relevant legislation. A job applicant has no legal obligation to reveal spent convictions. If an applicant has a conviction that has become spent, the employer must treat the applicant as if the conviction has not happened. Refusal to employ a rehabilitated person on the grounds of a spent conviction is unlawful under the the Rehabilitation of Offenders Act. Consider your services, the types of data being processed and the access controls you have in place, do you deem that this meets a requirement to conduct or request this level of information from your employees?
-
Mammography screening is inherently longitudinal where women return every few years, imaging protocols evolve, and subtle lesions may emerge gradually. Radiologists rely on comparisons across time and views, yet most AI models still analyze a single exam and ignore temporal context. Existing methods often compress each visit into one feature vector, losing lesion‑level detail, and they rarely encode the irregular time gaps between exams, which are clinically meaningful. Prior solutions for irregular clinical time series like GRU‑D, Time‑aware LSTM, Neural ODE/CDE, and continuous‑time Transformers, struggle with sparse, high‑dimensional imaging spaced months or years apart. Video transformers and 3D CNNs capture spatio‑temporal patterns but assume uniform timing and scale poorly. State‑space models like Mamba handle long sequences efficiently but also assume evenly spaced tokens. To address these gaps, the authors of [1] propose a computational efficient model called 'Time‑Aware Δt‑Mamba3D', which embeds true inter‑visit intervals into state‑space transitions and fuses spatial–temporal features with efficient multi‑scale 3D convolutions. This preserves lesion morphology, models irregular timing, and scales linearly. #MedicalInformatics In large‑scale breast cancer risk prediction, Δt‑Mamba3D outperforms recurrent, transformer, and SSM baselines, improving C‑index by 2–5 points and achieving higher 1–5 year AUCs, enabling more accurate use of longitudinal mammography. The links to the preprint [1] and #Python code are posted in the comments.
-
The effects of powerful new healthcare technologies may be smaller than we expect if we fail to consider system constraints. A new study in JAMA examined system-level spillover effects during the NHS-Galleri Trial, in which 142,000 British adults were randomized to receive an annual DNA-based cancer screening blood test. Compared with patients in regions not participating in the trial, those living in the eight participating regions experienced modest increases in diagnostic delays. The average delay was just two days, which is likely an acceptable tradeoff. But the study illustrates that when an intervention increases demand for a constrained resource, access for others may decline, and services may become strained. This comes to mind whenever I hear discussions about AI in healthcare. In his landmark 1984 book, The Goal, Eliyahu Goldratt argued that complex systems are ultimately limited by their bottlenecks. Improvements upstream do not necessarily improve overall performance if downstream capacity remains constrained. If an AI tool encourages more patients with headaches to seek neurology care, they may still face waits of weeks to months if neurology capacity is limited (as it almost always is). Increased demand may simply increase the wait. Similarly, an algorithm that identifies patients who would benefit from palliative care consultation will not generate more consults if the palliative care team is already operating at capacity. One encouraging finding from the NHS study is that the delays largely disappeared by year three, suggesting that healthcare systems can adapt. But adaptation takes time, and technology is often better at exposing bottlenecks than eliminating them.
-
Your vendor's security posture changed this morning. Their annual report did not. Static, point-in-time attestation was built for a slower world. Today your third parties run on: - Cloud infrastructure that changes daily - Software supply chains you cannot see - AI systems making autonomous decisions - Threats that adapt faster than audit cycles A report that describes one window in time cannot keep up with risk that moves every day. That is not a knock on the people doing the work. It is a structural limit of point-in-time attestation. Sponsored by the GRC Engineering Club and HITRUST. Threat-adaptive, validated assurance is where this has to go, and I am digging into why with HITRUST over the next few months. Annual snapshots cannot govern daily risk. #GRCEngineering
-
A $45 fee almost blocked women from getting life-saving breast cancer screening. That’s all it took. Just $45. UCLA recently studied what happened when they quietly removed a $45 out-of-pocket fee for 3D mammograms. The result? - Screening rates jumped from 84% to 92%. -Uptake soared among Black, Hispanic, Asian, Medicaid-insured, and non-English-speaking patients. -All because one small financial friction was lifted. Even after removing the fee, the highest screening rates still belonged to wealthier, White, English-speaking, Medicare-insured women. As a gastroenterologist, I’ve seen this story before. We talk about colon cancer prevention like it’s a simple yes/no decision—screen or don’t. But in real life, small barriers carry enormous weight: • The cost of the prep • Missing a shift at work • Not understanding the letter from the insurance company • Being on hold too long when trying to schedule • Not having a ride I see these hurdles prevent people from getting their colonscopies. We often label them a “ no-show “ without full understanding the circumstances that lead to the cancel. In the world of preventative screenings, an extra few months of delay could be the difference between life and death. I recently had a patient with a cancerous polyp. Incredibly, it was completely localized to the polyp, and I was able to remove it with confirmed clear margins. If one of those barriers delayed him following through with the screening, we’d be in a completely different situation. The patients who need us most are often the ones who fall off between intention and access. This pattern will repeat—and could worsen—as AI tools, advanced diagnostics, and personalized screening become the new standard. If we let cost-sharing or convenience gaps define who gets access, innovation will quietly deepen existing inequities. Equity isn’t charity, our healthcare system as a whole , benefits when barriers to routine screenings are eliminated What’s one “invisible barrier” that’s prevented you from getting care?? #HealthcareonLinkedin #Healthcare #HealthEquity #PublicHealth https://lnkd.in/ekdS6VFm