Employee screening services
We provide employee screening services, including DBS checks, Access NI, Disclosure Scotland, BPSS screenings, ID verification, employment references and other background checking services.
Features
- Comprehensive background checks including identity, employment, education, and references.
- Real-time DBS status tracking with automated notifications.
- Right-to-work verification with secure document validation technology.
- Digital identity verification using biometric and fraud-prevention tools.
- Customisable screening packages aligned to organisational risk requirements.
- GDPR-compliant data handling with encrypted storage and secure audit trails.
- Integration with HR systems for seamless applicant onboarding workflows.
- Candidate self-service portal for quick document upload and progress tracking.
- Rapid turnaround checks supported by automated verification processes.
- Dedicated support team providing expert guidance throughout screenings.
Benefits
- Reduces recruitment risk through accurate, verified candidate background information.
- Speeds up hiring by automating and streamlining screening processes.
- Improves compliance with safeguarding, right-to-work, and regulatory requirements.
- Enhances workforce security by identifying potential red flags early.
- Reduces administration workload for HR teams and hiring managers.
- Increases confidence in candidate integrity and suitability for roles.
- Provides transparent progress tracking for applicants and hiring teams.
- Strengthens organisational governance with auditable screening records.
- Supports remote recruitment with digital identity and document verification.
- Ensures consistency and fairness across all recruitment checks.
Pricing
- Education pricing available
- Free trial available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
5 9 5 5 9 4 4 8 5 3 1 5 3 5 2
Contact
EUROCOM C.I. LIMITED
Jagriti Patwari
Telephone: 01372886920
Email: info@eurocomci.co.uk
About your service
- Service categories
-
Applications
Production and operations
- Other operations
- Multi cloud support
- No
Service scope
- Software add-on or extension
- No
- Cloud deployment model
- Public cloud
- Service constraints
- Our service is delivered online and may occasionally require planned maintenance to ensure performance and security. Scheduled maintenance is normally conducted outside standard UK working hours and customers will be notified in advance of any disruption. Service availability may also depend on buyers having stable internet connectivity and modern web browsers. Very high-volume or bespoke screening requirements may require prior agreement. No installation is required, and the service operates within our defined hosting environment, with no support for on-premise deployment.
- System requirements
-
- Modern web browser such as Chrome, Edge, Firefox or Safari.
- Stable internet connection for accessing the cloud-based service platform.
- Email access for receiving screening notifications and system alerts.
- Device capable of running standard web applications securely.
- Smartphone with camera for completing digital identity verification steps.
User support
- Email or online ticketing support
- Yes
- Support response times
- Support tickets are answered within one working day.
- User can manage status and priority of support tickets
- No
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- Yes
- Web chat support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support accessibility standard
- WCAG 2.2 AA
- Web chat accessibility testing
- We have carried out internal accessibility testing of our web chat function using a range of assistive technologies and accessibility tools. This included testing with keyboard-only navigation to ensure all interactive elements can be accessed without a mouse, confirming visible focus states, and verifying that messages can be sent and received using keyboard controls.
- Onsite support
- Yes, at extra cost
- Support levels
-
We provide comprehensive support for both candidates and employers as part of our standard per-check pricing. Support is available via web, live chat, phone and email, and covers all aspects of using the screening platform, completing checks, uploading documents, and understanding requirements.
Candidate support includes guidance on completing identity verification, documentation queries, and troubleshooting access issues. Employer support includes assistance with managing checks, interpreting results, and using the dashboard.
For organisations requiring additional support with contacting candidates for missing information or liaising with previous employers to obtain references, this is provided as part of our fully managed service. The cost for this level of support is included within the per-check managed service fee, with no additional charges.
A dedicated support team is available during business hours, and technical support staff escalate any platform issues where required. We do not charge separately for a technical account manager; support is included within the fixed per-check pricing model. - Support available to third parties
- Yes
- AI chatbot
- No
Onboarding and offboarding
- Getting started
-
We support customers through a structured onboarding process to ensure the service is configured correctly and users are confident using it from day one.
Onboarding and setup support
We begin with an onboarding meeting with key customer stakeholders to understand:
-the customer’s screening requirements and policies
-the job roles being screened and the required screening level for each role
-user access requirements, including who needs administrative and operational access
We then set up the service accordingly, including creating access for the relevant users and configuring screening packages for the requested job roles.
Training
Once setup is complete, we provide online training sessions for platform users. Training covers:
-how to initiate and manage candidate screenings
-how to monitor progress and view status updates
-how to access, interpret, and download screening reports and outcomes
Training can be delivered to different user groups (e.g., administrators vs day-to-day HR users) depending on customer needs.
Documentation and ongoing support
We provide user documentation via our customer service helpdesk platform. Documentation is produced specifically for each customer, ensuring it reflects:
-their configured screening levels
-their agreed process and workflows - Service documentation
- Yes
- Documentation formats
- End-of-contract data extraction
-
Users can extract their data at any time throughout the contract. For each screening completed, the system generates an exportable record including the screening outcome and associated reports. These export files are made available for download via the platform and can also be returned to the customer’s HR system where an integration is in place.
At end of contract, customers can undertake a full data extraction exercise if required. This can include downloading all historical screening records and reports in bulk, covering all candidates screened during the contract term.
Where data deletion is configured in line with the customer’s retention policy, the customer will be supported to complete any required exports before data is deleted. Our customer service team and account manager can assist with confirming the data scope, providing guidance on the export format, and ensuring the customer has successfully retrieved all required information prior to contract closure. - End-of-contract process
-
At the end of the contract, we agree an offboarding plan with the customer and confirm whether the service will be renewed or closed. We support the customer to extract any required data (including screening outcomes and reports) and confirm successful completion of exports before access is removed.
Once data extraction is completed, we disable user accounts, revoke API credentials/integrations where applicable, and close the customer environment. Data is then securely deleted in line with the customer’s retention requirements and our contractual and regulatory obligations. Confirmation of deletion can be provided on request.
Included within contract price: standard offboarding support, access deactivation, and availability of individual screening exports and reports generated during service delivery.
Additional costs (if required): bespoke bulk data extraction, specialist reporting formats, or additional technical support for complex HR system integrations or migration activity. - Documentation accessibility standard
- WCAG 2.2 AA
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- There is no functional difference between the desktop and mobile versions of the service. The same features, content and workflows are available across devices. The service uses a responsive design that automatically adapts to different screen sizes, with layouts, navigation and touch controls optimised for mobile use to ensure usability, accessibility and performance on smartphones and tablets.
- Service interface
- Yes
- User support accessibility
- WCAG 2.2 AA
- Description of service interface
- The service provides a secure, web-based user interface accessible via desktop and mobile devices. Employer users can log in to add candidates for screening, view real-time status updates on ongoing checks, and download completed reports. Candidates have their own secure login, allowing them to upload required information and documentation directly to the platform. The interface is designed to be intuitive and role-based, ensuring users only see information relevant to their permissions.
- Accessibility standards
- WCAG 2.2 A
- Accessibility testing
-
Accessibility testing to date has been carried out internally as part of our design and quality assurance processes. The interface has been reviewed against WCAG 2.2 Level A criteria, including keyboard navigation, form labelling, colour contrast, focus states and screen reader compatibility. Internal testing has included the use of common assistive technologies such as screen readers and browser accessibility tools to identify and address potential barriers.
While formal testing with external users of assistive technology has not yet been undertaken, accessibility is considered throughout development and enhancements are made iteratively. We are committed to continuous improvement and are open to conducting further accessibility testing, including user-led testing, in collaboration with clients where required. - API
- Yes
- What users can and can't do using the API
-
Users can:
Link the API integration to their organisation’s account so all screening activity is associated with the correct customer profile.
Configure and enable an integration using supported authentication and integration credentials.
Use existing, proven integrations that can be set up quickly with common HR/recruitment platforms.
Establish a bespoke integration with a customer’s HR software where required, allowing screening requests to be initiated from the customer’s system.
Once the integration is set up, screening requests can be triggered directly from the HR platform. Candidates are then directed to our platform to complete the relevant steps in the screening journey
How users can make changes through the API
Users can:
Create screening requests for new candidates from within the HR platform.
Track screening progress via status updates returned through the integration.
Receive completed screening outcomes, reports, and supporting evidence back into the HR platform once the screening is finalised.
Limitations to how users can set up or make changes through the API
Users can’t:
Make unrestricted changes to screening requests once a check is in progress, as certain changes may be locked depending on the screening type and stage (to maintain compliance and data accuracy). - API documentation
- Yes
- API documentation formats
- Open API (also known as Swagger)
- API sandbox or test environment
- Yes
- Customisation available
- Yes
- Description of customisation
-
Users can customise the service to ensure screening is aligned to their roles, risk level, and internal recruitment policies.
What can be customised
Users can customise:
Checks included within each screening level, including the ability to add or remove checks depending on the role requirements
Role-based screening rules, so that different job roles trigger different screening levels
Operational process preferences, such as:
- frequency and style of candidate communications
- how findings are presented on screening reports
How users can customise
Customisation can be requested and implemented through:
- Our Customer Service team, who support configuration changes and service adjustments
- The customer’s Account Manager, who helps define the screening approach and ensures it matches the customer’s policies and compliance requirements
Where required, we work with customers to confirm the required screening standard for each role and apply the updated configuration accordingly.
Who can customise
Customisation can be requested by authorised customer users, including:
- HR users and recruitment administrators responsible for onboarding and screening
- Designated customer contacts (such as HR Managers or Compliance Leads)
Scaling
- Independence of resources
- Our service is hosted on Google Cloud and is designed to scale automatically based on demand. We use autoscaling to increase compute capacity during peak usage and can run multiple instances to maintain consistent performance. Workloads are managed to prevent any single customer’s activity impacting others, including request throttling and queueing where appropriate. We actively monitor performance, availability, and capacity, with alerting and operational procedures in place to respond to spikes in demand. This ensures the platform remains responsive and users are not adversely affected by the activity levels of other organisations.
Analytics
- Service usage metrics
- Yes
- Metrics types
- We provide real-time service usage metrics through a dashboard showing all ongoing screenings. Metrics include screening status (in progress/complete), status of each check within a screening, overall screening progress, number of SLA days remaining, screening start date, and allocation by division/manager (where configured). This allows HR users to monitor workload, track progress against agreed timescales, and identify any screenings requiring action or escalation.
- Reporting types
- Real-time dashboards
- Resource tagging
- Yes
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- Baseline Personnel Security Standard (BPSS)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
-
- United Kingdom
- European Economic Area (EEA)
- Other locations
- User control over data storage and processing locations
- No
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- Another external penetration testing organisation
- Protecting data at rest
-
- Encryption of all physical media
- Other
- Other data at rest protection approach
- Our service is hosted on Google Cloud Platform. All customer data stored within the platform is protected using Google Cloud’s default encryption at rest, which encrypts data automatically using strong encryption (AES-256) without requiring customer configuration. Encryption keys are securely managed by Google’s hardened key management systems with strict access controls and auditing. Google Cloud data centres are protected by robust physical and environmental security controls and are subject to independent assurance and compliance reporting (for example ISO/IEC and SOC reports).
- Data sanitisation process
- Yes
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
- Data sanitisation type
-
- Deleted data can’t be directly accessed / Cryptographic Erasure
- Data Erasure
Data importing and exporting
- Data export approach
- Users can export data directly from the platform once a screening has been completed. Each completed screening generates an exportable record including the screening outcome and associated reports. These files are available to download from the Completed Screenings section of the application. Where an HR system integration is in place, screening results and reports can also be pushed back to the customer’s HR platform automatically, enabling users to store and access the data within their existing recruitment workflow.
- Data export formats
- Other
- Other data export formats
-
- PDF/A (screening results and reports)
- Original document formats provided by candidates/third parties
- Data import formats
- Other
- Other data import formats
-
- JPG
- PNG
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
-
We aim to provide continuous availability of the service and host the platform on resilient, autoscaling infrastructure in Google Cloud.
We operate the following support service levels during standard office hours (09:00–17:00, Monday to Friday, excluding UK public holidays):
Full service unavailability: We will respond within 2 working hours of notification and aim to resolve within 10 working hours.
Major functionality unavailability: We will respond within 5 working hours of notification and aim to resolve within 20 working hours.
Minor functionality issues: We will respond within 10 working hours of notification and aim to resolve within 10 working days.
Full service and major functionality issues should be reported by telephone to meet the response timelines. Minor issues can be reported by telephone or email.
We do not provide automatic service credit refunds for missed service levels. However, service performance is monitored and we will work with customers to investigate incidents, provide updates, implement corrective actions, and prevent recurrence. - Approach to resilience
-
Our service is hosted on Google Cloud Platform (GCP) and is designed to be resilient and highly available. The platform uses autoscaling infrastructure to automatically increase capacity during periods of high demand, helping to maintain consistent performance for all users.
We use a resilient cloud architecture with redundancy across key components to minimise single points of failure. Service health and performance are continuously monitored, with alerting in place to support rapid investigation and resolution of incidents.
Data resilience is supported through a structured backup approach. We perform automated incremental backups to enable recovery of recent data states, and we also maintain backups in a separate data centre to provide protection in the event of a site-level incident. Backup and recovery processes are tested and managed to support service restoration and continuity. - Outage reporting
-
We report service outages and disruptions through a combination of real-time visibility and direct customer communications. Customers can access a dashboard view to monitor the status of their screenings and identify any delays or issues affecting progress.
In the event of a confirmed outage or major service degradation, we notify customer stakeholders directly via email (and telephone where required for critical incidents). Updates include the nature of the issue, the expected impact, actions being taken, and regular progress updates until the service is restored.
Our internal monitoring and alerting systems detect service issues proactively, enabling rapid investigation and escalation to technical support. Following resolution, we can provide a summary of the incident, including root cause and corrective actions taken, on request.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Username or password
- Access restrictions in management interfaces and support channels
-
Access to management interfaces is restricted using role-based access controls, with permissions assigned according to user role (for example, administrator vs standard user) and least-privilege principles. Customer administrators control who has access to the system and can add, remove, or amend user access as required. All users authenticate using multi-factor authentication (2FA).
Access to support channels is also restricted to authorised customer contacts. Support requests must be submitted via nominated email addresses or approved users, and identity is verified before any account changes are made. Administrative access changes are logged and auditable to maintain security and accountability. - Access restriction testing frequency
- At least once a year
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Username or password
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- User-defined
- Access to supplier activity audit information
- Users have access to real-time audit information
- How long supplier audit data is stored for
- User-defined
- How long system logs are stored for
- At least 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- ISO/IEC 27001
- Information security policies and processes
-
We follow information security policies and processes aligned to ISO/IEC 27001 and secure software development good practice. This includes secure development practices such as controlled access to code repositories, peer code review, and testing prior to release. Access to systems and customer data is managed through role-based access control and multi-factor authentication (MFA), with access granted on a least-privilege basis and reviewed regularly.
We maintain vulnerability management and patching processes, including monitoring for security updates, applying patches in line with risk and severity, and tracking remediation actions to completion. Changes to the platform are managed through secure configuration and change control, including documented approvals and release management.
We operate an incident response process covering identification, containment, investigation, customer communications, and post-incident reviews to ensure corrective actions are implemented.
Security responsibilities are assigned within the organisation with escalation routes to senior management. Policies are communicated to staff, supported through onboarding and periodic awareness, and compliance is monitored through internal reviews and audits. - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
-
Customer user access is controlled through role-based permissions. The customer’s nominated administrator can add, amend, or remove users directly within the platform. All users authenticate using multi-factor authentication (2FA). If the customer administrator requires changes to their own access level, they must request this from their authorised email address and the change is verified and logged.
Platform configuration and software changes are managed through formal change control. Service components are version controlled and tracked through their lifecycle. Changes are assessed for operational and security impact, tested, deployed in a controlled manner with rollback procedures. All changes are logged and auditable. - Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
-
We maintain a Technical Vulnerability Management Policy to identify, assess, and remediate vulnerabilities across our infrastructure and cloud services. We monitor vendor security advisories and trusted sources to stay informed of emerging threats, based on an up-to-date inventory of technology components and versions.
Patches and updates are obtained electronically and deployed according to risk, criticality, dependencies, and planned release schedules through our change management process.
We complete vulnerability assessments at least annually and may commission specialist penetration testing where required.
Configuration hardening and security awareness training are also used to reduce the attack surface. - Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
- We operate protective monitoring to identify potential compromises through continuous monitoring of service availability, authentication activity, and system/application logs. Alerts are generated for abnormal events (for example repeated failed logins, unusual access patterns, or service errors) and are reviewed by authorised technical staff. Where a potential compromise is detected, we follow an incident response process to investigate, contain the issue (including disabling access where required), and remediate. Critical incidents are prioritised for immediate triage and escalation, with customer updates provided as appropriate. Monitoring outputs also inform vulnerability management and change control to reduce recurrence and strengthen preventative controls.
- Incident management type
- Supplier-defined controls
- Incident management approach
-
We follow a defined Information Security Incident Response Procedure covering detection, impact assessment, containment, eradication, recovery, and post-incident review.
Incidents can be reported by customers or third parties and are assessed promptly to determine severity and whether formal incident response is required.
Where necessary, an Incident Response Team is assembled, actions are coordinated through regular incident meetings, and communications are controlled to ensure timely and accurate updates.
Following resolution, we complete a debrief and formal post-incident review, and provide incident summaries/reports to customers on request. - Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Conforms to a recognised standard, but self-assessed
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- Yes
- Free trial available
- Yes
- Description of free trial
- Our free version provides the same functionality as the paid service, including access to customer’s required screening package. The free version is limited to 2 customer user accounts and up to 10 candidate screenings. There is no charge during the free period. The free period is available for one month.
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 5%
- Between £250,000 and £500,000
- 5%
- Between £500,001 and £1,000,000
- 5%
- Between £1,000,001 and £2,500,000
- 0%
- Between £2,500,001 and £5,000,000
- 0%
- Over £5,000,001
- 0%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- British-assessment.co.uk
- ISO/IEC 27001 accreditation date
- Friday 30 August 2024
- What the ISO/IEC 27001 doesn’t cover
- The whole business is covered by the certification
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- 50902c16-25a3-4a01-a004-7d61a9ba4a94
- Cyber essentials plus
- Yes
- Please provide your Cyber Essentials Plus Certificate Number
- Af943ed8-843f-465f-8c37-437109f871ea
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero
Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.
- Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Collaborative ways of working with the supply chain to deliver additional environmental benefits in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Delivery of additional environmental benefits through the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Understanding of how to influence staff, suppliers, customers, communities and/or any other appropriate stakeholders through the delivery of the contract to support climate and nature protection and improvement
- Activities to reconnect people with the environment and increase awareness of ways to protect and enhance it
-