Your auditor will ask how you verify. You answer with a record: what was checked on every application, against which register, when, and who decided.
High turnover, agency workers next to your own people, and an audit that asks for the procedure rather than the intention. ISO 27001 Annex A 6.1 and ISO 45001 both put the question in writing.
What you get: A record for the audit: what was checked on every application, against which register, and when.
The fact Candora states
Candora reports employers that did not exist during the period claimed, and documents that expire before the start date, each with the register it came from.


An answer for the auditor
The answer to how you verify is a log with a rule key and a query time.
Expiry dates ahead of time
The end of a work permit is flagged before it arrives, not during an inspection.
The same procedure everywhere
Every application goes through the same rules, so one plant does not differ from another.
The objection that comes first
The agency guarantees it to us contractually.
A contractual guarantee is compensation after the fact. It does not lower the chance of the fact.
The same limits apply in every industry
- No score, no risk, no probability. We give no overall verdict, by design: Article 22 GDPR gives candidates, with limited exceptions, the right not to be subject to a decision based solely on automated processing, so your team makes the call. Every finding is a fact with a source and the time it was read.
- No nationality, ethnicity or country of origin. It is discarded before anything is stored.
- No biometrics and no photo comparison.
- Candora contacts nobody. Not previous employers, not schools, not references.
- The CV file is never written to disk and the text is discarded after extraction.
See it produce a report
Sample candidates, the rules that run in the product, no account.