Skip to content
Investigator connecting security token on desk

Background Check RFP Template and Checklist for Procurement Teams

A complete background check RFP must specify four things: the scope of work items required for each check type, minimum vendor qualifications and compliance proof, technical and reporting requirements, and a separate cost proposal template that scores on price alone, not narrative. Skip any one of these and you get vendor responses that are impossible to compare side by side.

The must-have sections to paste into your draft, in order:

  • Scope of Work naming every search type your agency requires, from county criminal records to national sex offender registry checks
  • Deliverables and Formats specifying PDF final reports, interim updates, and itemized evidence
  • Turnaround SLAs for each check category, not a single blanket promise
  • Vendor Minimum Qualifications covering FCRA compliance, state licensing, and 50-state search capability
  • Technical and Integration Requirements including API/XML specs and data security standards
  • Submission Instructions and Attachments listing required exhibits
  • Evaluation and Scoring Criteria with weighted categories
  • Pricing Template submitted as a separate file from the technical proposal

Pro Tip: Build your evaluation matrix before you publish the RFP, not after proposals arrive. Scoring criteria written under deadline pressure tends to bend toward whichever vendor responded first.

A downloadable template bundle covering the SOW checklist, pricing worksheet, and scoring matrix referenced throughout this guide is available further down this page.

Key Takeaways

A defensible background check RFP separates cost from technical scoring, requires named SOW items instead of vague language, and demands proof documents before contract award, not after.

Point Details
Name every SOW item List specific checks like county criminal, MVR, and education verification rather than “comprehensive screening.”
Require separate cost files Public procurement offices treat mixed pricing and technical content as non-responsive.
Set SLAs per check type Same-day for national database checks, 3 to 10 business days for education and employment verification.
Demand proof up front Require sample reports, API documentation, and SOC 2 evidence during the responsiveness screen, not after award.
OMNI Intel maps to public safety SOWs OMNIScreen™ aligns education, license, and investigative modules directly to the checklist this guide outlines.

Table of Contents

What Is a Background Check RFP, and When Do You Actually Need One?

A background check RFP is a formal solicitation document that asks vendors to propose how they would meet a defined set of screening requirements, along with pricing and proof of qualifications, so an agency can compare responses on a consistent basis. It exists to solve a specific procurement problem: you know what you need screened, you know the compliance bar you must clear, but you do not know which vendor can deliver it best or most affordably.

That distinction matters when choosing your solicitation vehicle. An RFP fits when requirements are complex and vendor approach matters, which describes nearly every public safety or municipal screening program. An Invitation for Bid (IFB) fits better when the service is a commodity and price is the only real variable, as seen in the Illinois State Treasurer’s approach, which is structured around accuracy certification and turnaround rather than technical scoring. A Request for Information (RFI) belongs earlier in the process, when you are still mapping the vendor landscape before committing to formal requirements.

Procurement should lead the drafting process, but HR and hiring managers own the SOW content since they know which checks each role actually requires. Legal counsel should review adverse action language and data retention clauses, and IT needs a seat at the table for the technical interface section. Skipping any of these voices tends to produce an RFP that reads well but fails on execution.

What Should the Scope of Work Include for Background Screening?

The scope of work is where most background check RFPs succeed or fail. A vague SOW (“comprehensive background checks required”) invites vendors to propose whatever they already sell, which defeats the purpose of comparing apples to apples. A granular SOW forces every respondent to price and describe the same list of deliverables.

Comparison diagram of background check scope of work details

Standard Checks to Require by Name

Washington State’s Office of Financial Management built its RFP around twelve distinct SOW items, and that level of specificity is worth copying almost verbatim. At minimum, your SOW should require:

  • County and city-level criminal record searches in every jurisdiction where the candidate has lived or worked
  • Statewide criminal repository searches
  • Federal criminal court record searches
  • National criminal index searches used as a locator, not a standalone source
  • National sex offender registry checks
  • Social Security Death Master File (SSDMF) or SSN trace and address history validation
  • Motor vehicle records (MVR) for any role involving agency vehicles
  • Credit history checks, only where state law permits and the role justifies it
  • Employment verification covering dates, titles, and eligibility for rehire
  • Education verification, ideally routed through the National Student Clearinghouse for degree validation
  • Professional license verification tied to the state licensing board of record
  • Professional reference checks, with a defined minimum number of contacts attempted

Some public-sector RFPs, including Durham’s, also fold credit checks and DMV searches into the base scope rather than treating them as add-ons. Decide early which checks are standard and which are role-dependent, and say so explicitly. A vendor that has to guess whether MVR applies to every requisition or only sworn officer roles will price it wrong either way.

Deliverable Formats and Documentation Standards

Specify exactly what a completed case looks like. Require a final PDF report as the archival record, interim status updates for cases that exceed a set number of business days, itemized evidence for every source consulted, and a certification of accuracy signed by the vendor. The Illinois Treasurer’s IFB requires this certification explicitly, along with a commitment to deliver results in PDF or another agreed format rather than leaving format negotiable after award.

Chain-of-custody language matters more than most drafters realize. If a candidate disputes a criminal record finding, you need documentation showing exactly which court, docket number, and record source the vendor consulted, not a summary line that says “criminal record found.” Require this at the SOW level, not as an afterthought during a dispute.

Turnaround Times and What “Case Closed” Means

Turnaround expectations should vary by check type because the underlying data sources vary wildly in speed. National index and sex offender registry searches typically return same day. Education and employment verification, which depend on a human at a university registrar’s office or a former employer’s HR department, commonly run 3 to 10 business days. County criminal searches vary by jurisdiction, since some courts still require in-person retrieval or manual clerk lookups.

Investigator wiring secure monitoring equipment

Define “case closed” precisely in the RFP: does it mean all standard checks are complete, or does it include pending verifications still awaiting third-party response? Vendors will interpret an undefined term in whatever way makes their SLA look best.

Optional and Safety-Sensitive Add-Ons

Public safety roles need scope items that go beyond database checks. Build these as separate, clearly priced SOW packages rather than burying them in the base scope:

  • In-person or virtual candidate interviews conducted by trained investigators
  • Deep-dive background investigations for sworn law enforcement, corrections, or dispatch roles
  • Structured social media and internet research protocols, with documented methodology and legal boundaries
  • Continuous post-hire monitoring subscriptions for arrest and court record activity
  • International checks, scoped separately since turnaround and data availability differ by country

Pro Tip: Treat specialized investigative modules for safety-sensitive roles as their own SOW line item. Bundling manual investigative work into the same pricing bucket as automated database checks makes it nearly impossible to tell which vendor is actually staffed to do the deeper work.

What Minimum Qualifications Should Vendors Have to Bid?

Minimum qualifications exist to screen out vendors who cannot legally or operationally deliver what you need before you waste evaluation time on their proposal. Set the bar high enough to protect your agency, but specific enough that a qualified vendor knows exactly how to prove it meets the bar.

FCRA compliance and adverse action process. Require vendors to describe, in writing, how they support your agency’s pre-adverse and adverse action obligations under the Fair Credit Reporting Act, including sample notice templates and dispute-resolution timelines. Ask for a sample adverse action letter as a submitted attachment, not just a narrative claim of compliance.

Multi-jurisdictional licensing. Require proof that the vendor can legally perform searches in all 50 states and relevant U.S. territories. Some vendors operate primarily in a handful of states and subcontract elsewhere, which introduces a chain-of-custody risk you should ask about directly.

Certifications and attestations. Ask for evidence of Professional Background Screening Association (PBSA) accreditation or an equivalent industry credential, plus documentation of a formal quality assurance program. Vendors serving healthcare or gaming clients, as seen in the NYC Health + Hospitals RFP, are also commonly asked to show FACIS, OIG, and OFAC screening capability alongside standard criminal checks.

Security certifications. Require SOC 2 Type II or ISO 27001 evidence, not a self-attestation. This is one of the fastest ways to eliminate vendors who have not invested in real security infrastructure.

Insurance and data protection. Set minimum requirements for:

  • General liability and professional errors and omissions insurance, with a certificate of insurance as a required attachment
  • Bonding, if your agency’s procurement policy requires it for service contracts
  • Encryption standards for data at rest and in transit
  • A defined breach notification timeline, typically 24 to 72 hours from discovery

Large public systems, following NYC Health + Hospitals’ lead, also tie minimum qualifications to demonstrated volume experience. If your agency processes several thousand checks a year, require vendors to show they have handled comparable volume for another client, not just that they technically can.

What Technical and Reporting Requirements Should the RFP Specify?

Public-sector background check RFPs increasingly treat the technical interface as a scored requirement, not a nice-to-have. The Pennsylvania Gaming Control Board’s RFP requires ordering and results reporting through a defined XML interface, and that level of specificity prevents vendors from proposing a manual, email-based workflow disguised as “integration.”

Your technical requirements section should cover:

  • API or XML interface specifications, including order-submission file formats, confirmation and error-handling behavior, and archival deliverables such as a final PDF embedded within the XML response
  • Reporting formats, requiring itemized, machine-readable results alongside a human-readable final PDF suitable for records retention
  • SLA metrics tied to the technical workflow: time to order confirmation, time to first result, time to final report completion, system uptime commitments, and incident response times for outages
  • Data retention and access control policies, spelling out how long records are stored, who can access them, and how they are purged
  • Secure transmission standards for both order submission and any applicant-facing payment collection, if your program requires candidates to pay for portions of their own screening

Interim reporting behavior deserves its own line item. A vendor that only delivers a single final report, with no visibility into which checks are pending, makes it impossible for HR to manage candidate communication during a multi-week hiring process. Require real-time or near-real-time status updates as a scored technical capability, not an assumed feature.

How Should Proposal Submissions and Scoring Be Structured?

Structure submission requirements so every vendor response arrives in the same format, which is the only way a scoring committee can compare proposals fairly.

Required proposal sections:

  1. Cover letter confirming intent to bid and acknowledgment of any addenda
  2. Technical submittal describing SOW approach, technology, and QA processes
  3. Cost submittal, submitted as a completely separate file
  4. Attachments: sample reports, SOC audit summary, API documentation, insurance certificates

Public procurement offices, including Durham’s, treat mixing pricing into the technical narrative as a non-responsive proposal. Say this explicitly in your instructions rather than assuming vendors will keep the two separate on their own.

Administrative responsiveness checklist before full evaluation begins:

  • Minimum qualifications met and documented
  • Licensing confirmed for required jurisdictions
  • Proof of insurance included
  • Cost and technical files submitted separately, as required

A sample scoring matrix that works well across public-sector RFPs weights categories roughly as follows: technical approach and SOW coverage at 30 points, compliance and QA documentation at 20 points, past performance and reference checks at 20 points, technical integration capability at 15 points, and cost at 15 points. Adjust these weights based on how much your agency values price versus capability, but publish the weights in the RFP itself so vendors understand what you are scoring.

Submission logistics should specify whether responses go through a procurement portal or email, set a firm deadline with time zone noted, and define a Q&A window that closes several business days before submissions are due.

How Do You Build a Fair Pricing Template for Vendor Comparison?

A cost proposal template only works if every vendor fills in the same fields, which means you have to design the template, not leave pricing format up to the respondent. Require these line items at minimum:

  • Per-check unit price, broken out by check type (criminal, MVR, education, employment, and so on)
  • Anticipated third-party or court fees passed through to the agency, itemized by jurisdiction where possible
  • One-time setup or integration fees
  • Recurring monthly or portal access fees
  • Volume discount tiers, with the threshold volumes clearly stated
  • Rush fee schedules, if expedited turnaround is available
  • Pilot or introductory pricing, if offered

Require a sample invoice as a submitted attachment. This single request exposes more about a vendor’s actual billing practices than pages of narrative pricing description, since it shows you exactly how pass-through fees get itemized on a real bill.

Pass-through fees deserve particular scrutiny. Court and county fees vary by jurisdiction and change over time, so require vendors to explain the source of any third-party fee rather than folding it into a flat per-check price that obscures markup. Vendor guidance on RFP structure consistently flags transparent pricing as one of the most commonly mishandled sections, precisely because vague cost proposals hide fees that surface only after contract award.

Evaluate cost on total cost of ownership across a full year of anticipated volume, not just the headline per-check price. A vendor with a slightly higher unit price but no setup fee and better volume discounts often costs less at scale than a vendor advertising the lowest per-check rate.

What Attachments and Contract Exhibits Should You Require?

A complete RFP response depends on requiring the right attachments up front, since a vendor that skips a required exhibit gives you an early, low-cost signal about how carefully they follow instructions.

Require these attachments, in this order:

  1. Experience and qualifications summary, including client references comparable in size and sector
  2. Detailed SOW response, addressing every scope item point by point
  3. Quality assurance plan describing internal review and error-correction processes
  4. Price quotation using your standardized cost template
  5. Diverse business inclusion forms, if your jurisdiction requires minority or woman-owned business documentation
  6. Sample report, redacted for privacy, showing the actual deliverable format
  7. API documentation, if the vendor claims integration capability
  8. SOC 2 or ISO 27001 audit summary
  9. Certificate of insurance

For the resulting contract, spell out expected exhibit topics before award rather than negotiating them from scratch afterward: contract term and renewal options, termination for convenience and for default, indemnification language, data ownership provisions, SLA remedies for missed turnaround targets, and audit rights allowing your agency to verify vendor compliance periodically.

Requiring a sample report and sample API documentation as part of the responsiveness screen, not just the evaluation phase, filters out vendors who cannot actually produce what they are proposing to sell.

What Questions Should You Ask Vendors During the RFP Process?

A well-run RFP treats the Q&A period as a two-way exchange, and drafting both sides in advance saves weeks of back-and-forth once proposals start arriving.

Questions procurement should ask vendors:

  • Describe your primary-source verification methodology for criminal records versus reliance on aggregated databases
  • What is your documented dispute resolution process when a candidate contests a finding
  • Provide your API documentation and describe a typical order-to-result cycle
  • What quality assurance checks occur before a report is released to the client
  • How do you handle a jurisdiction where county records are not available electronically

Questions vendors typically ask procurement in return:

  • What data fields are available for export from our applicant tracking system
  • What is anticipated seasonal volume, and are there hiring surges the vendor should plan for
  • Is pilot access available before full contract award
  • Which specific roles require the deepest investigative tier versus standard screening

Run the Q&A process formally: set a firm deadline for written questions, post every question and answer as a numbered addendum visible to all bidders, and designate a single point of contact so vendors are not fielding informal calls that create inconsistent answers. Treating vendor questions as public information, rather than answering some bidders privately, is what keeps a public procurement process defensible if a losing bidder ever protests the award.

How OMNI Intel Maps to Public Safety Background Check RFP Requirements

OMNIScreen™ is built around the exact SOW structure public safety agencies write into their RFPs. Education verification runs through the National Student Clearinghouse, professional license checks route to the issuing state board, and safety-sensitive roles get access to investigator-driven modules rather than a database lookup dressed up as due diligence. For agencies hiring fire and EMS personnel, that distinction between automated checks and manual investigative work is exactly the separation this guide recommends building into your SOW packages.

Implementation support that RFP evaluators typically look for shows up as standard, not as a paid add-on:

  • A dedicated project manager for onboarding and go-live
  • Integration assistance for applicant tracking system connections
  • Training for HR and hiring staff before the first case is submitted
  • A pilot approach that lets your agency validate turnaround and accuracy on a limited case volume before full rollout
  • Ongoing customer success support once the contract is live

On compliance and security, OMNI Intel’s platform is built around FCRA-compliant workflows, encrypted data handling, and documentation practices designed for agencies used to public-sector audit requirements.

Pro Tip: When you shortlist OMNI Intel or any vendor, ask for a sample report, API specification document, and SOC audit summary on day one of your evaluation, not after the contract is drafted. A vendor that hesitates to produce these on request during evaluation will not move faster once you are locked into a contract.

Investigator hands organizing secure case files

Procurement perspective: practical red flags and tips for evaluating vendor responsiveness

The fastest way to spot a weak proposal is to check whether pricing and technical content are cleanly separated. Mixing them signals a vendor unfamiliar with public procurement norms, and it should disqualify the response outright under most agency rules.

Watch for these red flags during initial screening:

  • Missing SOC 2 or equivalent security evidence
  • Vague SLA language (“prompt turnaround”) with no defined business-day targets
  • Inability to confirm coverage in all 50 states without a subcontractor explanation
  • No sample report or API documentation provided despite claiming integration capability

A five-minute pre-screen checklist, before committing hours to full scoring, catches most of these issues: confirm separate cost and technical files, confirm insurance certificate is attached, confirm licensing claims match the jurisdictions you actually need, and confirm a sample report was included as instructed.

How OMNI Intel Can Help With Your Background Check RFP

If your agency is drafting an RFP for background screening services, OMNI Intel gives procurement teams a vendor built specifically around public safety hiring rather than general commercial screening retrofitted for government use. The SOW mapping covered in this guide, from National Student Clearinghouse education verification to investigator-led modules for sworn roles, is not an add-on OMNI Intel builds for you after award. It is how the platform is already structured.

OMNI Intel

You can request a full RFP packet or schedule a demo through OMNI Intel’s pre-employment screening page, and that packet includes the exact documentation this article recommends requiring: a sample report, API specification, SOC audit summary, and a completed pricing template ready to drop into your evaluation spreadsheet. OMNI Intel is one qualified option among the vendors your agency should be comparing, and the packet is built so your evaluation committee can score it against competing proposals using the same criteria outlined above. Reach out to start that comparison.

Sources

Real public-sector RFPs are the fastest way to see this structure in practice. Washington State’s Office of Financial Management RFP offers a strong template for scope of work language. The City of Durham’s RFP 25-0050 shows municipal-level submission structure, and the Pennsylvania Gaming Control Board’s RFP demonstrates a detailed XML technical interface specification worth adapting.

Treat every public RFP as a starting template, not a final draft. Local procurement codes, state licensing rules, and agency-specific compliance requirements will always require adjusting the language before you publish your own solicitation.

FAQ

How Will Background Verification Be Done in the USA?

U.S. background verification typically combines county, state, and federal criminal record searches with employment, education, and license verification, sourced directly from courts, registrars, and licensing boards rather than a single national database.

What Will Disqualify You on a Background Check?

Felony convictions relevant to the role, falsified employment or education history, and failed license verification are the most common disqualifiers, though specific criteria vary by employer policy and applicable state law.

What Are the Top Background Check Companies for Public Safety Agencies?

Vendor quality depends on FCRA compliance, 50-state licensing, and investigative depth for safety-sensitive roles rather than name recognition alone. OMNI Intel focuses specifically on public safety and government hiring, which sets it apart from general commercial screening vendors evaluated in a typical RFP.

Can I Run a Background Check on a 1099 Contractor?

Yes, but FCRA obligations still apply, including proper disclosure and authorization before ordering a report, regardless of whether the individual is classified as an employee or independent contractor.

What Is the Difference Between an RFP and an RFI for Background Screening?

An RFP asks vendors to propose a full solution with pricing for defined requirements, while an RFI gathers general market information before an agency finalizes its scope, typically used earlier in the procurement process.