Screenata

Integrations / HR & people ops

Screenata + Checkr

How do you automate SOC 2 and ISO 27001 personnel evidence from Checkr?

Quick answer

Checkr is where the screening half of personnel controls is proved. It supplies the per-hire record auditors sample when they test whether the vetting step in your hiring policy actually ran before access was granted. A screening policy existing on paper is not the control. The control is the completed and adjudicated check plus the record that it operated for every hire across the audit period. Screenata runs 8 native checks against those screening records on a schedule and turns each result into signed evidence mapped to the control it satisfies.

Screenata connects to Checkr read-only and runs 8 native checks against your screening records: background check completion and adjudication status. The findings prove the screening step in your hiring policy actually ran for each hire, recorded as signed, timestamped evidence mapped to SOC 2 and ISO 27001 personnel controls.

8 native checks · read-only · signed evidence

What it proves

Checkr evidence, mapped to controls.

Each area below is scanned on a schedule. A finding is not a green checkmark: it is a signed artifact an auditor can verify, mapped to the exact requirement it satisfies.
Evidence area
What the checks verify
Maps to
Background check completion

Whether hires subject to your screening policy have a completed background check on record.

Per-hire proof that screening happened before or at start, the record auditors sample under personnel controls.

SOC 2CC1.4ISO 27001A.6.1
Adjudication status

The adjudication outcome on completed checks, so unresolved reports do not sit silently.

Proof that check results are reviewed and resolved, not just ordered.

SOC 2CC1.4ISO 27001A.6.1

Control references are the requirements each evidence area supports, via the shared control catalog. Your auditor decides sufficiency; the artifacts are theirs to verify.

Compliance checks

What Screenata checks on Checkr, and why each matters.

Each row is a real native check, the framework control it produces evidence for, and the risk it closes. This is what continuous Checkr compliance actually looks like. Checks run on a schedule; a failing check opens a ticket and re-verifies after a human applies the fix.
Check & why it matters
Maps to

Background Check Coverage

Verifies every candidate has at least one completed background check. A hire with no completed report means screening never finished, and an auditor samples hires to confirm the screening step in your policy ran for each.

SOC 2CC1.4

Background Check Adjudication Complete

Confirms reports flagged consider have been adjudicated. An unadjudicated result sits unresolved with no hiring decision recorded, and an auditor verifies check outcomes are reviewed, not just ordered.

SOC 2CC1.4

Background Checks Completed Timely

Checks that no report has stayed pending past the completion window. A stalled check means screening evidence is missing when it is needed, and an auditor verifies screening completes within your defined timeline.

SOC 2CC1.4

No Suspended Background Checks

Verifies no report is suspended or in dispute. A stuck report leaves a hire unscreened and needs immediate attention, and an auditor checks that problem reports are resolved rather than left open.

SOC 2CC1.4

Criminal Screening

Confirms completed reports include a criminal search. Criminal screening is the core of the competence control auditors sample, and a package without it leaves a gap in the vetting your policy commits to.

SOC 2CC1.4

Sex Offender Search

Verifies completed reports include a sex offender registry search. This screening is part of the vetting many hiring policies require, and an auditor checks that the package your policy names actually ran.

SOC 2CC1.4

Drawn from Screenata’s Checkr check library. Control refs are the requirements each check produces evidence for; your auditor decides sufficiency.

How it connects

Read-only, revocable, yours.

You create a read-scoped API key and Screenata uses it for scheduled checks. Vera never receives write access to your Checkr account, and credentials never touch the Screenata database.

Read-only by construction

OAuth scopes and IAM roles are scoped to read. Vera never gets write access to your systems.

Signed findings

SHA-256 per artifact, RSA/ECDSA signatures, RFC 3161 timestamps. Verifiable without a Screenata account.

Mapped to controls

Each finding lands on the shared control catalog, so one scan satisfies SOC 2, HIPAA, and ISO 27001 at once.

Checkr FAQ

What teams ask before connecting.

Full provider list on the integrations page.
What access does Screenata need to Checkr?

A read-scoped API key that you create and control. Screenata reads check status for scheduled verification and never receives write access. You can revoke the key at any time.

Does SOC 2 require background checks?

SOC 2 requires the controls your policies commit to. Most companies commit to pre-hire screening under the competence criteria, and once it is in your policy, auditors sample hires for completed checks. The Checkr integration produces that sample automatically.

Does Screenata see the contents of background reports?

The checks use completion and adjudication status, which is what the evidence requires. The report contents stay in Checkr.

What are the steps to implement SOC 2 with Checkr?

Connect Checkr read-only with a scoped API key. Let the first scan establish a baseline so you can see which candidates are covered and which are not. Fix what fails: make sure every candidate has at least one completed background check, adjudicate the reports flagged consider so no outcome sits unresolved, clear reports that have stayed pending past your completion window, resolve suspended or disputed reports, and confirm the package your policy names actually ran, including the criminal search and the sex offender registry search. Collect the passing results as signed evidence on a schedule, so you hold coverage across the whole audit period rather than one snapshot. Then hand the evidence package to an independent auditor. The audit is a separate engagement with a CPA firm; Screenata prepares the evidence and does not issue the report.

What evidence do auditors ask for about onboarding and offboarding?

They sample hires and leavers. For each hire they expect a start date with the training and policy acknowledgments that followed it, and screening completed before access was granted. For each leaver they expect a termination date with the access removal that followed it. Timing is what gets tested, not just existence. A background check completed a month after the hire already had system access is a finding even though the report exists.

Do auditors accept evidence Screenata collects from Checkr?

Yes. Every finding is exported as a signed, timestamped artifact, a SHA-256 hash with an RSA or ECDSA signature and an RFC 3161 timestamp, that an auditor verifies outside Screenata with a free CLI. A person reviews and approves the evidence before it reaches the auditor. Screenata collects and signs it; it does not decide the audit result.

Connect and see

Fifteen minutes after connecting Checkr, you know your real posture.

Pricing

Related: BambooHR · Gusto · Deel · Rippling