10 min readBrendan J.

Moving identity verification to the top of the hiring funnel

How to filter out synthetic applicants and proxy interviewers before they consume expensive technical assessment hours.

Moving identity verification to the top of the hiring funnel

Quantifying the operational cost of proxy interviewers in technical screens

Technical recruitment faces an operational crisis that traditional background checks cannot solve. Engineering teams are losing hundreds of hours a month interviewing synthetic applicants and proxy candidates. These individuals submit impressive resumes and pass automated coding tests using artificial intelligence. When the live technical interview begins, a different person speaks while the actual applicant lip syncs.

The financial drain of this fraud is highly predictable. A standard technical interview loop requires about four hours of senior engineering time. At an average loaded cost of $120 per hour in North America, a single fraudulent interview wastes $480 in payroll. In European tech hubs like Berlin or Amsterdam, the equivalent cost hovers around 400 euros per candidate.

This does not include the platform fees. Testing platforms like HackerRank and Codility charge per assessment. You pay every time a proxy farm runs a script against your coding challenges.

In May 2022, the US Department of Justice issued an advisory warning that North Korean IT workers were securing freelance contracts using stolen identities. This activity has accelerated rapidly. In 2023, the cybersecurity firm Mandiant reported a surge in proxy identities attempting to infiltrate corporate networks through remote hiring channels.

If a recruitment team processes 1,000 engineering applications a quarter, they might invite 100 candidates to a live technical screen. In fully remote pipelines, up to 15 percent of those candidates may use proxy assistance. That translates to $7,200 in wasted engineering time per quarter. The opportunity cost is worse. Every hour spent interviewing a fraudster delays the hiring of a legitimate engineer. This extends time to fill metrics by weeks. You must intercept these candidates before they reach the hiring manager.

Shifting verification workflows to the first forty eight hours of the application stage

The standard operating procedure places identity verification at the end of the hiring funnel. HR teams run checks only after extending a conditional job offer. You need to pull this process forward to the first forty eight hours of the application stage.

When a candidate applies through an applicant tracking system like Workday or Greenhouse, the system should trigger an immediate identity verification request. Vendors like Persona, Stripe Identity, or Onfido integrate directly into these platforms via API. The candidate receives an SMS or email link asking them to scan a government issued ID and take a live selfie.

Moving this step to the top of the funnel requires a clear communication strategy. If you demand a passport scan before a screening call, you will see a 15 to 25 percent drop in applicant volume. This reduction is intentional. It filters out automated application bots, proxy farms, and uncommitted candidates.

Implementing early verification demands strict data discipline. In North America, candidates are accustomed to providing identification early, but European applicants expect privacy by design. The General Data Protection Regulation dictates how you handle this information. Article 5 of the GDPR mandates data minimization. You cannot stockpile images of French or German passports in your ATS.

You must configure your identity vendor to act as a blind broker. The vendor confirms the document validity and face match. They immediately delete the underlying image and return a simple pass or fail token to your ATS. You should set a time to live of 24 hours on all temporary document scans.

The UK Information Commissioner's Office allows identity checks early in the recruitment lifecycle if you can demonstrate a legitimate interest in preventing fraud. Protecting expensive assessment infrastructure qualifies as a legitimate interest. By day two of the application process, you either have a cryptographically verified human being or you automatically close the file. This ensures your technical assessors only speak to verified individuals.

Auditing identity vendors against Illinois biometric privacy laws

Shifting verification to the application stage introduces significant compliance risks if you use facial recognition. The Illinois Biometric Information Privacy Act is the strictest biometric law in the United States. If an applicant residing in Illinois scans their face for your remote role, this law dictates your legal obligations.

The financial penalties for noncompliance are severe. The statute allows civil damages of $1,000 for negligent violations and $5,000 for reckless violations. In August 2024, Illinois amended the law with Senate Bill 2979. The amendment limits recovery to one violation per person. Despite this change, class action liability remains a massive risk for any organization running high volume recruitment pipelines.

You must audit your identity vendors specifically against these requirements. The law requires a clear written release from the candidate before capturing any biometric data. You cannot bury this in a general privacy policy link at the bottom of an application form. The ATS integration must present a standalone consent checkbox that explicitly mentions facial geometry collection.

You also need a publicly available written retention policy. The law mandates that organizations destroy biometric identifiers when the initial purpose is satisfied, or within three years of the last interaction. Ask your vendor to demonstrate their deletion protocols. Demand written proof showing exactly how they purge data from their Amazon Web Services or Microsoft Azure servers.

In the European Union, the regulatory environment is equally strict. GDPR Article 9 classifies biometric data as a special category of personal data. Processing this data requires explicit consent. You cannot make a facial scan an absolute requirement for employment without offering an alternative path.

Update your ATS workflows to branch candidates based on this consent. If a candidate refuses the automated biometric check, route them to a manual verification step. Train your recruiting coordinators to conduct these manual ID checks over a brief Zoom call before moving the candidate to the technical assessment phase.

Balancing early verification requirements with candidate conversion rates

Moving identity verification to the top of the funnel inevitably increases application abandonment. You should anticipate a 20 to 25 percent drop in completion rates when you introduce this step. This reduction serves as your primary defense mechanism against automated systems. Fraud rings rely entirely on high volume applications. They will not spend time spoofing documents manually for a single initial screening step.

This abandonment rate varies by engineering seniority. Junior developer roles may see a 30 percent abandonment rate due to the sheer volume of speculative applications. Senior architectural roles typically see less than a 10 percent drop. Legitimate candidates occasionally abandon the process if the verification request looks suspicious or poorly integrated.

You must design the communication flow to build trust immediately. Send the identity check request from your primary corporate email domain. Do not rely on unbranded templates sent directly from your verification vendor. A generic message asking for passport photos will trigger phishing alerts for engineers focused on security. Provide a direct link to your privacy policy immediately above the submission button.

You must explicitly state that the automated check takes under 90 seconds. Inform the candidate that your organization deletes the image data upon completion. In North America, candidates generally accept automated identity checks for remote positions without complaint. The California Privacy Rights Act requires you to disclose this biometric collection clearly at the exact point of application. You must detail the specific categories of personal data collected and the precise purpose of processing.

Next quarter, proxy networks will begin deploying automated localized deepfakes to bypass standard identity checks. To counter this emerging threat, your engineering recruitment team needs to tighten verification thresholds. Set a hard expiration of 72 hours on the identity link. If a candidate fails to complete the scan within this strict window, the applicant tracking system must archive their profile automatically.

Do not trigger these checks blindly for every single inbound application. Wait until your applicant tracking system parses the resume and flags the candidate as a potential technical match. Platforms charge between one dollar and three dollars per automated verification transaction. By triggering the check only for applicants moving to the technical assessment stage, you control vendor costs aggressively. Applying this filter immediately before issuing a Codility or HackerRank test yields the highest financial return.

Designing alternative verification paths for European Union applicants

European privacy frameworks strictly regulate biometric data collection during any recruitment phase. Article 9 of the General Data Protection Regulation classifies facial recognition scans and biometric passports as special category data. You cannot force an applicant in France or Germany to submit a biometric selfie as the only authorized way to secure an interview.

Regulators enforce these privacy rules aggressively across the continent. The French data protection authority CNIL mandates that organizations must offer a manual alternative when verifying identities. If you rely entirely on automated facial matching algorithms, you risk severe financial penalties. You must provide a manual verification path for any candidate who refuses the automated data collection step.

The regulatory environment across Europe is shifting rapidly right now. The European Union eIDAS regulation mandates the full rollout of European Digital Identity Wallets by 2026. This upcoming digital infrastructure allows citizens to prove their identity cryptographically without transmitting physical document scans. Recruitment teams operating in the European Union must upgrade their systems to accept these secure digital wallet credentials over the next twelve months.

Until the digital wallet infrastructure matures widely, you must design a compliant manual fallback process. When a European applicant declines the automated check, your applicant tracking system should trigger a secondary scheduling workflow. An internal recruitment coordinator schedules a five minute Microsoft Teams or Zoom session using a scheduling tool. The candidate shows their physical official identification to the camera during this live video call.

The coordinator visually confirms the name and photograph match the person on the screen. The coordinator then logs a verification timestamp directly in a custom field within the applicant tracking system. They must never take a screenshot or record the live video session. Recording the session explicitly violates the strict data minimization principles of the General Data Protection Regulation.

This manual path adds predictable friction and operational cost. Allocating five minutes of coordinator time costs approximately 12 euros per candidate in direct labor. This minor expense remains significantly lower than wasting 400 euros of senior engineering time on a fraudulent technical interview.

North American jurisdictions rarely mandate manual alternatives by law. Canadian employers governed by PIPEDA must obtain explicit consent for data collection but can often require the automated check as a mandatory condition of the job application. You should implement the manual fallback globally anyway to provide an inclusive experience for candidates lacking valid biometric passports.

Immediate steps to update applicant tracking systems this quarter

You must overhaul your recruitment infrastructure before the start of the fourth quarter of 2024. These operational changes require exact technical configuration within your applicant tracking system. Start by mapping out the internal application stages in enterprise platforms like Workday or Greenhouse. Create a dedicated internal stage named Identity Verification immediately preceding the automated technical assessment phase.

Configure your system webhooks to fire the identity check application programming interface only when a recruiter advances a candidate into this specific stage. This logical sequence prevents you from paying unnecessary verification fees for unqualified applicants. Define custom fields in your tracking system to capture the precise pass or fail token returned by the vendor integration.

Audit your current identity vendor data retention policies before November 15. You must configure your identity provider dashboard to purge all biometric images and document scans within a maximum limit of 30 days. Check your vendor service level agreements to verify regional data processing rules. European applicant data must remain physically on servers located within the European Economic Area.

You must rewrite your automated rejection communications completely. If a candidate fails the identity check, the automated email must never mention fraud detection systems or artificial intelligence matching flags. The message should state simply that the candidate did not complete the required application prerequisites to advance in the hiring process.

Train your recruitment coordinators on the new manual video fallback process by the end of next month. They need to understand exactly how to verify a national identity card over a live video feed. Create a simple internal wiki page detailing the acceptable forms of physical identification for your major target hiring markets.

Finally, establish a reporting dashboard within your tracking system to monitor verification failure rates weekly. If your automated failure rate spikes above 15 percent in a single geographical region, you are likely facing a targeted proxy farm attack. By securing the top of your hiring funnel right now, your engineering team will spend next quarter interviewing legitimate candidates instead of sophisticated frauds.

Sources

  1. 01Deepfakes and Stolen PII Utilized to Apply for Remote Work PositionsFederal Bureau of Investigation
  2. 02Guidelines 3/2019 on processing of personal data through video devicesEuropean Data Protection Board
  3. 03Biometric Information Privacy Act (BIPA)Illinois General Assembly
  4. 04Guidance on the North Korean IT Worker ThreatU.S. Department of State
ShareLinkedInXEmail

The newsletter

Every two weeks: interview design, time to hire benchmarks, and the process changes that hold up when volume spikes.

Back to all articles