The security questionnaire that now arrives before the PSL

Recruitment agencies are being asked to prove their security before they are allowed to pitch. The questions are not hard, but they are specific, and the honest answer is usually no.

Something has changed in how agencies win corporate work. The questionnaire used to arrive after the win, buried in onboarding. It now arrives before the pitch, it comes from procurement rather than HR, and it decides whether you get onto the preferred supplier list at all. Agencies that cannot answer it are being quietly filtered out before anyone reads their proposal.

The questions are not sophisticated. They are the same ten or so every time, and most of them are satisfied by controls an agency either has or could have within a fortnight. The problem is that nobody in the business owns the answer, so the form sits with whoever is least able to fill it in.

Why agencies attract the question

Think about what sits in a recruitment database. Not just names and job histories: dates of birth, home addresses, national insurance numbers, bank details for contractor payroll, and scanned right-to-work documents, which means passports, visas and biometric residence permits. For a mid-sized agency that is tens of thousands of records, each one containing enough to open an account in somebody's name.

Very little else in the SME world concentrates identity data like that. A manufacturer holds drawings. An accountancy practice holds accounts. An agency holds the raw material of identity fraud, at volume, usually in a cloud CRM that half the office can export from.

Your corporate clients have worked this out, which is why the questionnaire exists. They are not worried about your firewall. They are worried that a breach at their supplier puts their employees' and candidates' data on a leak site with their name attached to it.

What the questionnaire actually asks

Across the forms we see, the recurring questions are:

  • Do you hold Cyber Essentials or an equivalent certification, and can you provide the certificate?
  • Is multi-factor authentication enforced on email and on the CRM, for every user?
  • Who can export the candidate database, and is that export logged?
  • What is your retention policy for CVs and right-to-work documents, and is it actually applied?
  • Where is candidate data stored, and does any of it leave the UK or the EEA?
  • How quickly are leavers deprovisioned?
  • Do you carry out independent security testing, and when was the last one?
  • What is your incident response process, and what would you tell us, how quickly?
  • Do your subcontractors and umbrella partners meet the same standard?

Read that list again as a procurement officer. Every question has a yes or no answer and a document behind it. There is nowhere to be vague, which is the point.

The three that catch people out

Export rights on the CRM. In most agencies, every consultant can export the whole database to a spreadsheet, because that is how the job has always worked. It is also the single largest data loss risk in the business, and it does not require an attacker. It requires a consultant leaving for a competitor. If you can only fix one thing on this list, restrict bulk export to a named handful of people and turn on the audit log.

Retention. Almost every agency has a retention policy. Almost none of them delete anything. A CV from 2017 sitting in the CRM is data you have no lawful basis to hold and no commercial reason to keep, and it is in scope for every breach you ever have. Deleting it is free and reduces the blast radius permanently.

Right-to-work documents. These are frequently stored where they landed, which is an inbox or a shared drive folder, rather than in the system with the access controls. A passport scan in a mailbox is the worst of all worlds: highly sensitive, indefinitely retained, and reachable by anyone who compromises one account.

The fraud that is actually happening

Two things worth naming, because both are live and neither is theoretical.

The first is payroll diversion. Agencies move money to contractors on a weekly cycle under time pressure, which makes them an attractive target for the same business email compromise that hits conveyancers. The approach is identical: read a real email thread, wait, then send changed bank details from a real address at the right moment. Verified callbacks to a number you already hold, never a number in the email, are the control. The question is whether it survives a Friday payroll run.

The second is candidate impersonation, which has become materially easier in the last two years. Synthetic identities, borrowed credentials and assisted video interviews are now cheap enough to use at scale, particularly for remote technical roles. This is not primarily your security problem, but it will become your reputation problem the first time a placement turns out not to be the person who interviewed. It is worth having a documented verification step you can describe to a client, because they are starting to ask.

What to do first

  1. Enforce MFA everywhere, including directors and including the CRM, not just email.
  2. Restrict and log bulk export from the candidate database.
  3. Move right-to-work documents out of inboxes and shared drives into the system that has access control, and delete the copies.
  4. Apply the retention policy you already wrote. Delete what you cannot justify holding.
  5. Certify. Cyber Essentials answers most of the questionnaire in a single document, and a certificate ends the conversation faster than any amount of explaining.
  6. Then test what is public facing, particularly the candidate portal, under penetration testing.

None of the above is expensive and most of it is configuration rather than purchase. The agencies that struggle are not the ones with weak security, they are the ones who have never been asked to describe it, and so have to invent an answer under deadline with a client waiting.

More on how we work with agencies on the recruitment sector page.

Common questions

Do we need Cyber Essentials to get on a PSL?
Not always, but it is increasingly the fastest route. Most corporate questionnaires either ask for it directly or ask a set of questions that Cyber Essentials covers. Holding the certificate turns a long form into a one-line answer with an attachment.
Our CRM is cloud-hosted, so is security the vendor's problem?
Partly. The vendor secures the platform; you remain responsible for who has access, what they can export, how long you keep records and whether accounts are closed when people leave. Every question on a client questionnaire about your data is about your configuration, not the vendor's infrastructure.
How long can we keep a candidate CV?
There is no fixed statutory period, so you set a retention period you can justify and then apply it. The practical test is whether you could explain the period to the ICO and show that deletion actually happens. Most agencies fail the second half.
We are a small agency. Is any of this proportionate?
The data you hold does not shrink with headcount. A ten-person agency can hold thirty thousand candidate records including identity documents, which is why clients ask the same questions of small agencies as large ones. The controls scale down; the obligation does not.
What should we do about fake or AI-assisted candidates?
Treat it as a process question rather than a technology one. Have a documented identity verification step, apply it consistently for remote roles, and be able to describe it to a client. Clients are beginning to ask what your process is, and not having one is becoming a commercial problem.

Related

Ready to talk?

Scoping conversations are free and there is no sales team to get past. Tell us what you're dealing with and we'll tell you honestly what you need.