Can a Company Be Liable for Negligent Hiring If It Skips AI Interview Proctoring?
TL;DR: Negligent hiring claims don't require a company to have used any specific vendor or tool — they require a court or regulator to find the company failed to take reasonable care in vetting someone who then caused foreseeable harm. Skipping identity verification entirely, in an environment where fake IT worker schemes and interview fraud are now widely publicized risks (DOJ has dismantled 29 laptop farms tied to North Korean operatives), makes "we had no way to know" a much harder argument to make than it was a few years ago. This isn't legal advice — talk to counsel — but the risk calculus around "reasonable care" has shifted now that identity fraud in hiring is documented, common, and detectable.
The claim
Negligent hiring and negligent retention are established tort theories in most U.S. states: an employer can be liable when it knew or should have known a hire posed a risk, and that risk materializes into harm — a data breach, theft, harassment, or fraud. The standard turns on what was foreseeable and what precautions were "reasonable" for the role. As fraudulent-hire schemes become well-documented and detection tools become standard, courts and regulators have more basis to treat "we didn't check" as unreasonable for high-risk roles.
The evidence
The specific fact pattern — a fraudulent remote IT worker gaining system access through a proxy interview or stolen identity, then causing a breach or funding sanctioned activity — is no longer hypothetical. Multiple DOJ prosecutions have detailed exactly this mechanic, including a facilitator sentenced to 8.5 years over a $17 million North Korean IT worker scheme, and joint DOJ/Microsoft action dismantling 29 laptop farms holding roughly 200 computers. Gartner has projected that by 2028, 1 in 4 candidate profiles worldwide will be fake or synthetic. Fabric's dataset of 19,368 interviews found 38.5% of candidates flagged for AI-cheating behavior, rising to 48% in software engineering roles specifically — the exact population most often targeted by remote-access fraud schemes.
None of this creates automatic liability for skipping proctoring. But negligence law asks what a reasonably prudent employer would do given known, documented risks in its industry. As these risks move from "unusual" to "documented and common," the argument that no reasonable precaution was available gets weaker — particularly for roles with privileged system access, financial controls, or client-facing trust.
Where exposure concentrates
| Risk factor | Why it raises exposure | Practical mitigation |
|---|---|---|
| Remote role with system/data access | Fraudulent hire can cause a breach with real financial and regulatory consequences | Identity verification at interview + periodic re-verification |
| Staffing/contractor placement | Agency may face client indemnification claims if a placed worker turns out fraudulent | Contractual proctoring requirements + documented verification trail |
| Client-facing or financial role | Impersonation risk extends past your own company to your customers | Continuous face verification, not just document check |
| No verification process at all | Weakest position if harm occurs — no evidence "reasonable care" was exercised | Even a basic identity-check policy creates a defensible record |
| Documented verification process, still defrauded by novel technique | Stronger position — shows reasonable care was taken | Keep trust reports/evidence as part of the hiring file |
Step-by-step: building a defensible position
- Adopt a written interview-integrity policy covering identity verification for roles above a defined risk threshold (system access, financial controls, client-facing).
- Apply it consistently. An inconsistently enforced policy is nearly as exposed as no policy — document why any exceptions were made.
- Keep evidence. A session trust report — showing identity checks were run and what they found — is exactly the kind of record that demonstrates "reasonable care" if a hire is later found fraudulent.
- Extend the same standard to staffing/vendor placements, since courts have found agencies liable for negligent referral in some circumstances.
- Review the policy annually as fraud techniques evolve — a policy that was reasonable in 2023 may not be considered reasonable given 2026's documented cheating and fraud rates.
- Loop in legal and risk/insurance teams before finalizing thresholds — this is a business risk decision informed by legal exposure, not a pure HR call.
FAQ
Has any company actually been sued for negligent hiring specifically tied to skipping interview verification? Negligent hiring suits are typically tied to harm caused by an employee (theft, violence, data breach) rather than the absence of a specific vendor tool, but the underlying legal theory — failure to exercise reasonable care during hiring — applies squarely to identity-fraud scenarios as they become better documented.
Is this different from ordinary background-check negligence claims? Background checks and interview identity verification address different gaps: background checks review a person's history; identity verification confirms the person you background-checked is the same person you hired.
Does using AI interview proctoring guarantee legal protection? No tool guarantees immunity from claims, but a documented, consistently applied verification process is strong evidence of reasonable care, which is the standard negligence law actually asks about.
Should every role get the same level of verification? No — risk-based tiering makes more sense than a blanket policy; roles with system access, financial authority, or client trust warrant the highest scrutiny.
Who should decide the verification policy — HR, legal, or security? All three, ideally. HR owns the hiring process, legal assesses liability exposure, and security/IT understands which roles carry the highest access risk.
By Pinal Dave Last updated: August 4, 2026