What do financial services firms need to check before hiring? (And why it can't stop at day one)

Financial Services

Every industry screens its new hires. Financial services is one where the regulator checks your homework.

Between ASIC, APRA, and AUSTRAC, hiring in this sector carries more obligations than nearly any other industry in Australia. And compliance itself isn’t usually the hard part. Keeping track of it is. Different checks for different roles. Different regulators. Different renewal dates. Different systems. Plenty of firms are still juggling all of it manually, and here’s what that can look like when it goes wrong:

Scenario one: a wealth management firm hires an experienced adviser on a polished CV and two warm references. Nobody checks the Financial Advisers Register, so nobody spots the banning order until the adviser is six weeks into client meetings.

Scenario two: a payments analyst clears a criminal history check at hire. Fourteen months later, an internal audit surfaces a sanctions match that appeared on a watch list well after their start date, but nobody was looking.

Neither scenario needs bad luck. It just needs a screening process built for a less regulated industry. Let’s explore what financial services employers actually need to check, role by role, and how to keep those checks running for the whole employment lifecycle.

In this guide:

  • What financial services employers need to check
  • Which roles need which checks
  • Why screening can't stop at the start date
  • How Checkmate handles financial services screening
  • FAQs

What do financial services employers need to check?

Ten checks come up again and again across banks, insurers, super funds, wealth managers, fintechs, and payments providers. Not every role needs all ten. A bankruptcy check on the office barista helps nobody, least of all the barista. We've mapped checks to roles further down, but first, here's what each one does and why the regulators care.

Identity verfication

Everything else on this list assumes you're screening a real person. Identity verification confirms it, the same way customer due diligence does under the AML/CTF Act, and it matters even more now that synthetic candidates built on stolen or fabricated credentials are actively targeting the sector. Biometric checks that match a live selfie to a government-issued ID catch what document checks alone can't. Get this one wrong and every other result on this list belongs to someone who doesn't exist.

Criminal history check

This one is the foundation of nearly every financial services screening package. A criminal history check surfaces convictions for fraud, dishonesty, and financial crime before someone gets access to client money or sensitive data. Most firms treat it as non-negotiable for any role touching funds, and it feeds straight into fit and proper assessments for senior appointments. It's far cheaper to find a fraud conviction at hire than after the funds have moved

Right to work and VEVO checks

For candidates on a visa, a VEVO check confirms work rights and conditions directly with the Department of Home Affairs. Employing someone without valid work rights carries penalties whether you knew or not, and the recognised legal defence is being able to show you ran the check. Visa conditions can also change mid-employment, which is why this check works best paired with ongoing monitoring rather than run once and filed away.

Bankruptcy check

An AFSA bankruptcy check searches the National Personal Insolvency Index for bankruptcies, debt agreements, and insolvency history. Undischarged bankrupts face legal restrictions on managing corporations, so this one matters for directors, executives, and anyone with fiduciary duties. Put simply, it tells you whether the person about to manage other people's money has a history of trouble managing their own.

Credit check

A credit history check goes wider than bankruptcy, covering defaults, judgements, and repayment history from credit bureau records. It exists to flag financial pressure that could leave someone vulnerable to fraud or bribery. Most firms save it for roles with access to money, payment systems, or client accounts rather than running it on everyone. Financial pressure is one of the most consistent red flags in insider fraud, and this is the check that surfaces it early.

ASIC register checks

Two separate registers matter here. The Financial Advisers Register lists everyone authorised to give personal financial advice to retail clients, and advisers must be registered before they give it. The Banned and Disqualified register covers people prohibited from managing corporations or working in financial services at all. Checking both takes minutes and saves you from appointing someone the regulator has already shown the door. A broader financial regulatory check sweeps ASIC and APRA registers in one pass.

AUSTRAC sanctions and PEP screening

You already screen customers against sanctions and politically exposed persons lists. Screening candidates the same way closes an obvious gap, and for some roles it's now required. Under the reformed AML/CTF regime, AUSTRAC requires initial and ongoing personnel due diligence for anyone performing AML/CTF functions. Those integrity checks can include police checks, sanctions and adverse media screening, and bankruptcy checks. The reformed rules have applied to existing reporting entities since 31 March 2026, and to newly regulated sectors since 1 July 2026. A sanctions match inside your own workforce carries the same exposure as one on your customer books, with far less excuse for missing it.

APRA fit and proper requirements

Banks and insurers assess responsible persons under Prudential Standard CPS 520, and super fund trustees under SPS 520. Both ask the same question: does this person have the skills, experience, and knowledge for the role, and the honesty and integrity to be trusted with it? The standards leave the actual checks up to you, which is exactly why a documented screening process matters. APRA is consolidating these standards into a single cross-industry framework expected around 2028, and has made it clear that tick-a-box fit and proper assessments are on the way out. When APRA asks how a responsible person was assessed, a documented screening process is the answer you'll be glad to have.

Reference checks with a compliance lens

Standard reference questions about teamwork and performance won't surface a dismissal for cause or a run-in with a regulator. In this sector, reference checks need direct questions about compliance conduct, disciplinary action, and why the candidate really left. Structured digital reference checks make that repeatable and defensible, with fraud detection built in to confirm referees are who they say they are. A referee who saw the conduct firsthand is often the only source that will ever mention it.

Ongoing PEP and sanctions monitoring

The last one is less a check than a habit. Sanctions and PEP lists update continuously, so a clean result at hire only proves the person was clean at hire. Continuous monitoring re-screens your workforce as the lists change and alerts you the moment something shifts. More on why that matters below.

Which roles need which checks?

Most firms bundle checks by role risk rather than running everything on everyone. A clear matrix also settles the standoff between your head of compliance, who wants every check on every hire, and your hiring managers, who just want the offer out the door. Here's a starting point, but your own risk assessment gets the final say.

Role group Why the risk is higher Typical checks
Executives and accountable persons Personally accountable to APRA and ASIC under the Financial Accountability Regime, which has applied to banks since 15 March 2024 and to insurers and super trustees since 15 March 2025. The full suite: identity, criminal history, bankruptcy, credit, ASIC register checks, directorship history, sanctions and PEP screening, and compliance-focused references.
Financial advisers Must be registered before giving personal advice, and bans and disciplinary action are public. Financial Advisers Register, Banned and Disqualified register, identity, criminal history, and references that probe advice conduct.
Front office and client-facing roles Direct KYC and AML exposure, plus access to client funds. Identity, criminal history, right to work, and sanctions and PEP screening, with credit checks where the role touches client money.
Compliance, risk, and audit officers They run the control environment, and personnel performing AML/CTF functions need documented initial and ongoing due diligence under the reformed Rules. Criminal history, bankruptcy, regulatory register checks, and references with direct integrity questions.
IT and data-access roles Privileged access to systems, client data, and payment infrastructure. Criminal history, identity, and right to work as a floor, with credit checks for anyone who can move money or alter payment data.
Support and back office Lower risk, scaled to what the role can access. Identity, right to work, and criminal history, stepped up where the role carries data access or payment exposure.

Why isn't pre-employment screening enough in financial services?

The lists don't stop moving after your new hire starts. Sanctions and PEP databases update daily. An adviser who was clear at hire can be banned three years in, and ASIC publishes banning orders all year round. FAR accountability sticks to a role for as long as the person holds it, and APRA's fit and proper standards expect reassessment rather than a one-off test at appointment.

Most compliance failures in this space surface years after onboarding, once the original check is a PDF in a personnel file and nobody owns the re-screening calendar. The hire was screened properly, but the employee never was again.

Continuous monitoring closes that gap. Checkmate Safeguard re-screens employees against sanctions and PEP lists on a schedule you set, tracks visa status and work rights in real time, runs scheduled criminal history renewals for higher-risk roles, and alerts the right person when a licence lapses or a register status changes. Screening in this sector works best treated as a lifecycle, from the first identity check to the day the person leaves.

How Checkmate handles financial services screening

Most HR teams don't wake up wanting another background screening platform. They want confidence that every hire has the right checks, every renewal happens automatically, and nobody has to remember which spreadsheet tracks what. That's exactly what Checkmate was built to do.

The checks in this guide come bundled into role-based packages, so an adviser hire triggers a different set than a back-office hire. Identity verification includes biometric liveness matching, which catches the synthetic candidates document checks miss, and everything from ASIC register checks to sanctions and PEP screening runs through one platform with any flags surfaced up front. After hire, Safeguard keeps watch: continuous sanctions and PEP re-screening, work rights tracking, and real-time alerts when a register status changes, all logged to an audit trail for the day APRA asks how you know your people are fit and proper. 

Jumbo Interactive runs its screening through Checkmate, and its Group Talent Acquisition Lead credits the platform with driving efficiency, adoption, and control.

If you're building your own screening matrix against the obligations above, we'd love to show you how other financial services firms have set theirs up.

FAQs

Are ASIC adviser register checks mandatory for all financial advisers?

Registration on the Financial Advisers Register is mandatory for anyone providing personal financial advice to retail clients, and the legal obligation to ensure an adviser is registered sits with the licensee. Checking the register before hire is how licensees discharge that obligation in practice. The register also shows qualifications, exam status, and disciplinary history, so most firms treat the check as standard for every adviser appointment.

What does "fit and proper" actually mean under APRA's standards?

Fit and proper means a person has the skills, experience, and knowledge to hold a responsible position, and the honesty and integrity to be trusted with it. Banks and insurers assess this under Prudential Standard CPS 520, and super fund trustees under SPS 520. The standards require assessment before appointment and, generally, annual re-assessment, though they leave the specific checks to each entity. In practice that usually means criminal history, bankruptcy, regulatory register, and reference checks.

How does the Financial Accountability Regime (FAR) affect background screening?
FAR replaced the Banking Executive Accountability Regime, applying to banks from 15 March 2024 and to insurers and superannuation trustees from 15 March 2025. It makes named accountable persons personally responsible for their areas, with obligations that continue for as long as they hold the role. That raises the stakes on screening senior appointments thoroughly, and it keeps re-screening relevant, because accountability under FAR doesn't expire after onboarding.

Do banks need to run credit checks on all hires?

No. Credit checks are a risk-based tool rather than a blanket requirement. Most banks reserve them for roles with access to money, payment systems, or client accounts, plus executives and accountable persons. Running them on every hire adds cost and privacy handling without much added protection. A sensible screening matrix applies credit checks where financial pressure would create genuine fraud or bribery risk.

How often should AML sanctions and PEP screening run?

At hire, then continuously or on a regular schedule. Sanctions and PEP lists update daily, so annual re-checks leave long windows of exposure. Many financial services firms now run continuous monitoring, where the workforce is automatically re-screened whenever lists update. For personnel performing AML/CTF functions, AUSTRAC expects ongoing due diligence under the reformed Rules, with frequency proportionate to the risk of the role.

What is a bankruptcy check and which financial services roles need one?

A bankruptcy check searches the Australian Financial Security Authority's National Personal Insolvency Index for bankruptcies, debt agreements, and insolvency history. Undischarged bankrupts face legal restrictions on managing corporations, so the check is standard for directors, executives, and accountable persons. It's also common for roles with fiduciary duties or access to client funds, where undisclosed financial distress is a genuine risk factor.

Do fintechs face the same screening obligations as banks?

Mostly, once they hold the same licences. A fintech with an AFSL, a credit licence, or AUSTRAC reporting obligations carries the corresponding screening expectations, and one that becomes an ADI or insurer picks up APRA's fit and proper standards too. What fintechs often lack is the compliance infrastructure banks have built over decades, which is why many automate screening from the start rather than retrofitting it later.

How do you screen overseas hires for financial services roles?

International screening runs the same core checks through overseas sources: identity, criminal history, employment and education verification, credit history where available, and global sanctions and PEP screening. Turnaround varies by country. A VEVO check confirms Australian work rights for visa holders. Platforms like Checkmate run verifications across more than 190 countries, so an overseas hire goes through the same bundled process as a local one.

What happens if an existing employee appears on the ASIC banned register?

It depends on their role, but you need to know quickly. A banning order can make it unlawful for the person to keep performing certain functions, so the immediate steps are confirming the match, restricting the relevant duties, and taking advice on your obligations to clients and the regulator. The practical problem is detection, since bans happen throughout the year. Continuous register monitoring means you find out when ASIC acts, rather than at the next annual audit.

Can Checkmate monitor PEP and sanctions lists continuously after hire?

Yes. Checkmate's Safeguard platform runs continuous AML sanctions and PEP monitoring across your workforce, alongside visa and work rights tracking, licence and certification monitoring, and scheduled criminal history renewals for higher-risk roles. Real-time alerts show what changed, who is affected, and the recommended next step, with everything logged for audit. Screening data from pre-employment flows straight into monitoring, so nothing needs re-entering.