Skip to content

How to run social media and adverse media checks the defensible way

Referoo
Author Referoo
Published:
Reading TIme: 8 mins
How to run social media and adverse media checks the defensible way

Social media and adverse media checks have quietly moved from an optional extra to standard practice. Around 70% of employers now review candidates' social profiles as part of the hiring process – and social media recruiting has become one of the most used talent strategies around. At the same time, AI tools that scan profiles and flag ‘risk’ at scale are under real scrutiny from regulators and the courts.

This creates a tricky spot for HR and talent teams. These checks can genuinely protect your organisation. Done carelessly, however, they can expose you to bias, privacy breaches and decisions that you can't defend later.

The good news is that a defensible process isn’t complicated. It comes down to four things: consent, relevance, documentation and human oversight.

 

Two checks doing two different jobs

It helps to be clear on what you're actually running, because the two types of checks often get lumped together.

A social media check reviews a candidate's public online activity for genuine red flags: things like hate speech, threats of violence or conduct that clearly clashes with the role. An adverse media check scans global news sources and publicly available information for negative coverage, such as fraud, regulatory action or criminal matters.

One looks at what a person has done online; the other looks at what's been reported about them. Both checks are about protecting your people, your brand and your compliance position, not about snooping.

 

Why ‘just google them’ is the riskiest option

The instinct to quietly look someone up is understandable, but it's also where most of the legal risk sits.

When a hiring manager manually scrolls a candidate's Facebook or Instagram profile, they're exposed to protected attributes that have nothing to do with the job: religion, health, political views, sexual orientation, family status. Under the Privacy Act 1988 and the Australian Privacy Principles (APPs), you can only collect personal information that's relevant to the role, by lawful and fair means, and with clear notice to the candidate. To collect sensitive information, you need explicit consent.

The Fair Work Act 2009 adds another layer. It protects candidates from adverse action based on lawful off-duty conduct. So, knocking someone back over a weekend social media post unrelated to their work is a definite risk. An informal, inconsistent process is far harder to defend than a structured one.

 

The AI scrutiny problem

AI screening tools promise speed, and many deliver it. The catch is accountability.

Regulators and courts are increasingly treating the employer, not the vendor, as responsible for what an automated tool decides. In the closely watched Mobley v. Workday, Inc. case in the US, a court found a screening vendor could potentially be liable as an ‘agent’ of the employers using it, over claims its tools disproportionately rejected certain applicants.

What you need with every decision is explainability. If you reject a candidate flagged by an AI tool, you need to be able to say exactly why, backed up with specific content and a clear, job-related reason. Simply using the explanation that an algorithm detected a risk won't hold up if a decision is ever challenged. Automation can support your process, but ultimately, you make the final call.

‘Technology should do the heavy lifting, not the deciding,’ says Neil Rose, Referoo CEO. ‘The moment a person can't explain why a candidate was flagged, you've got a problem, not a process.’

 

The four pillars of a defensible check

Whatever tools you use, a defensible social media or adverse media check rests on the same four foundations:

  • Consent. Inform candidates upfront that these checks are part of your process and make sure you have their agreement in writing. Never conduct secret searches, access private content or ask for passwords.
  • Relevance. Only collect and act on information that relates to the role. If you find something that isn't job-relevant, set it aside and document why.
  • Documentation. Record what was reviewed, when, by whom and the job-related reason behind any decision. Your documentation is your defence if a decision is questioned.
  • Human oversight. Use technology to gather information, then have a trained person assess it in context. A flagged word might be very different from a real behavioural red flag.

Applied consistently across every candidate for a given role, these four pillars help you avoid risky checks and instead create a fair, accountable and defensible process.

 

What's changing in Australia

Under changes to APPs starting 10 December 2026, organisations that use automated decision-making (ADM) in recruitment decisions will need to disclose what those systems are, what decisions they make and what personal information they use.

Automated social media and adverse media screening both fall squarely inside that category. Many organisations have deployed these tools without cataloguing them or the data they rely on, which is exactly what the new obligations will require.

By starting the process now, you can be in good shape by December and not scrambling with last-minute audits.

 

Your defensible check checklist

So, before your next round of hiring, this is what you should check:

  • Have you told candidates these checks are part of your process, and captured their consent?
  • Are you only collecting information relevant to the specific role?
  • Do you have a documented, consistent process applied to every candidate for that role?
  • Can you explain any flag or decision with specific, job-related reasoning?
  • Is a trained person, not just a tool, making the final call?
  • Have you mapped which automated tools you use, ready for the December 2026 disclosure rules?

If you can tick all six, you're running these checks the defensible way.

 

Getting the balance right

Social media and adverse media checks are now a standard part of hiring, and for good reason. They catch risks that a CV and interview might miss, and they help protect your team and your reputation. The organisations that get real value from these checks are the ones that use them as a structured, consented, documented step, rather than an ad-hoc search.

‘For years these checks sat in the too-hard basket, or they were done off the side of someone's desk,’ Rose adds. ‘That's the part that has to change. A check is only worth running if you can stand behind how you ran it.’

That's the same principle behind everything we do at Referoo: checks that are consistent, secure and easy to defend, with a clear audit trail from start to finish.

Want to see how Referoo Hub keeps all your employment checks in one place, with the documentation to back every decision? Book a demo.