Employers often assume that complying with the Fair Credit Reporting Act (FCRA) is enough to satisfy background screening requirements. In reality, many states have enacted additional laws that go beyond federal requirements, creating a layered compliance landscape that can quickly become complicated.
Understanding how federal and state laws work together is critical for employers conducting background checks. A process that may appear compliant under federal law could still create risk under state or local regulations.
This article explains the difference between the FCRA and state background screening laws, where employers commonly encounter problems, and why compliance becomes increasingly complex for multi-state organizations.
What Is the FCRA?
The Fair Credit Reporting Act (FCRA) is a federal law that regulates how consumer reports, including employment background checks, are obtained and used.
When employers use a third-party Consumer Reporting Agency (CRA) to conduct background checks, the FCRA establishes requirements designed to protect applicants and employees.
- Providing a clear disclosure before obtaining a background check
- Obtaining written authorization from the applicant or employee
- Certifying permissible purpose
- Following the pre-adverse action and adverse action process
- Providing copies of reports and rights summaries when required
- Allowing individuals the opportunity to dispute inaccurate information
The FCRA applies nationwide and creates the baseline framework for employment screening compliance.
Why State Laws Matter
States may create laws that provide greater protections than federal law. In many cases, employers must comply with both the FCRA and additional state-specific requirements simultaneously.
A background check process that satisfies federal law may still violate state fair chance hiring laws, state consumer reporting laws, local Ban the Box ordinances, marijuana testing restrictions, salary threshold rules, or state-specific disclosure requirements.
For employers operating across multiple states, screening policies often require careful customization depending on where the applicant works.
The FCRA Creates the Floor, Not the Ceiling
One of the most important concepts employers should understand is that the FCRA establishes minimum federal requirements, but states may impose stricter rules.
Employers are generally expected to follow whichever law provides greater protection to the consumer.
For example, the FCRA may permit certain reporting practices, while a state law may restrict or prohibit those same practices. In those situations, the stricter state requirement often controls.
Common Areas Where State Laws Differ
Although laws vary widely by jurisdiction, several compliance areas create the most confusion for employers.
Reporting Time Limits
The FCRA limits the reporting of non-conviction information (arrests, dismissed charges, civil suits, paid tax liens) to seven years for positions paying under $75,000 annually. Criminal convictions may be reportable indefinitely under federal law, though many states impose their own limits.
Some states restrict conviction reporting to seven years regardless of salary, and others place additional limits on how far back employers may consider criminal history when making hiring decisions.
Ban the Box and Fair Chance Hiring Laws
Many states and local jurisdictions have enacted Ban the Box or Fair Chance Hiring laws.
These laws may regulate when criminal history questions can be asked, when background checks may occur, how employers evaluate criminal records, whether individualized assessments are required, and what notices must be provided before adverse action.
Some jurisdictions prohibit criminal history inquiries until after the first interview, a conditional offer, or another later stage of the hiring process.
Others require employers to consider the nature of the offense, the time passed, and the relationship between the record and the job duties.
Marijuana and Drug Testing Restrictions
Drug testing laws are rapidly evolving at the state level.
While federal law still classifies marijuana as a controlled substance, some states restrict employment decisions based solely on off-duty marijuana use, a positive marijuana test, or recreational cannabis use.
Certain states prohibit adverse action for marijuana findings unless impairment occurred during work, safety-sensitive roles are involved, or federal regulations apply.
DOT-regulated positions operate under separate federal requirements, which may override state recreational marijuana laws.
Credit Report Restrictions
The FCRA governs how credit reports are obtained and used, but several states restrict when employers may request employment credit reports at all.
Some states limit credit report use to financial positions, management roles, or positions involving access to sensitive financial information.
Improper use of employment credit reports can create both compliance and litigation risk.
California: A Major Compliance Example
California is one of the most heavily regulated employment screening environments in the country.
In addition to the FCRA, California employers may also encounter the Investigative Consumer Reporting Agencies Act (ICRAA), Consumer Credit Reporting Agencies Act (CCRAA), California Fair Chance Act, state privacy laws, salary threshold considerations, and marijuana employment protections.
California also places significant emphasis on individualized assessments, job-relatedness, business necessity, and procedural fairness.
For example, employers subject to California Fair Chance laws may be required to evaluate the relationship between criminal history and job duties, consider rehabilitation and time passed, and provide detailed notices before final adverse action.
Why Multi-State Employers Struggle With Compliance
Many employers use a single national hiring process for simplicity and operational consistency.
Unfortunately, compliance laws are rarely uniform. An employer hiring in multiple states may encounter different requirements for disclosures, authorization forms, timing rules, adverse action procedures, criminal history evaluations, and drug testing policies.
As laws continue changing rapidly, maintaining compliant procedures becomes increasingly difficult without ongoing monitoring.
Common Employer Mistakes
Using Generic Disclosure Forms
Disclosure and authorization forms may not satisfy state-specific language requirements.
Failing to Provide State-Specific Summary of Rights Documents
The FCRA requires employers to provide applicants with a summary of their rights, but several states (including California and New York) require their own versions beyond the federal CFPB summary. Using only the federal document may not satisfy state obligations.
Applying One Hiring Policy Nationwide
A single standardized policy may violate local restrictions in certain jurisdictions.
Taking Automatic Adverse Action
Automatically disqualifying candidates based on criminal records may create compliance risk under Fair Chance laws.
Ignoring Individualized Assessments
Some jurisdictions require employers to evaluate context rather than relying solely on the existence of a record.
Overlooking Local Laws
City and county regulations may create additional requirements beyond state law.
How Employers Reduce Compliance Risk
Employers can reduce risk by reviewing hiring workflows regularly, using state-compliant disclosure forms, training HR personnel on adverse action requirements, understanding jurisdiction-specific restrictions, maintaining consistent documentation, and partnering with knowledgeable screening providers.
Strong compliance processes are not only about avoiding legal exposure. They also help create fairer, more defensible hiring decisions.
Compliance Is Constantly Evolving
Background screening laws continue changing rapidly across the country.
New Ban the Box laws, Fair Chance Hiring ordinances, privacy regulations, marijuana employment protections, and AI hiring regulations continue reshaping employer obligations. Several jurisdictions, including Illinois and New York City, have enacted laws specifically governing the use of automated decision-making tools in hiring, with requirements around bias audits, candidate notifications, and data transparency. Employers using AI-assisted screening tools should confirm those tools meet applicable local requirements.
Policies that were compliant several years ago may no longer satisfy current legal expectations.
Final Thoughts
The FCRA remains the foundation of employment background screening compliance, but employers must also understand how state and local laws affect hiring decisions.
Compliance is no longer a one-size-fits-all process.
As hiring regulations continue evolving, employers benefit from clear procedures, consistent documentation, ongoing compliance review, and knowledgeable screening support.
Understanding the relationship between federal and state laws helps employers make more informed, defensible, and compliant hiring decisions.
