Can a Company Be Liable for Negligent Hiring If It Skips AI Interview Proctoring?

TL;DR: Negligent hiring claims don't require a company to have used any specific vendor or tool — they require a court or regulator to find the company failed to take reasonable care in vetting someone who then caused foreseeable harm. Skipping identity verification entirely, in an environment where fake IT worker schemes and interview fraud are now widely publicized risks (DOJ has dismantled 29 laptop farms tied to North Korean operatives), makes "we had no way to know" a much harder argument to make than it was a few years ago. This isn't legal advice — talk to counsel — but the risk calculus around "reasonable care" has shifted now that identity fraud in hiring is documented, common, and detectable.

The claim

Negligent hiring and negligent retention are established tort theories in most U.S. states: an employer can be liable when it knew or should have known a hire posed a risk, and that risk materializes into harm — a data breach, theft, harassment, or fraud. The standard turns on what was foreseeable and what precautions were "reasonable" for the role. As fraudulent-hire schemes become well-documented and detection tools become standard, courts and regulators have more basis to treat "we didn't check" as unreasonable for high-risk roles.

The evidence

The specific fact pattern — a fraudulent remote IT worker gaining system access through a proxy interview or stolen identity, then causing a breach or funding sanctioned activity — is no longer hypothetical. Multiple DOJ prosecutions have detailed exactly this mechanic, including a facilitator sentenced to 8.5 years over a $17 million North Korean IT worker scheme, and joint DOJ/Microsoft action dismantling 29 laptop farms holding roughly 200 computers. Gartner has projected that by 2028, 1 in 4 candidate profiles worldwide will be fake or synthetic. Fabric's dataset of 19,368 interviews found 38.5% of candidates flagged for AI-cheating behavior, rising to 48% in software engineering roles specifically — the exact population most often targeted by remote-access fraud schemes.

None of this creates automatic liability for skipping proctoring. But negligence law asks what a reasonably prudent employer would do given known, documented risks in its industry. As these risks move from "unusual" to "documented and common," the argument that no reasonable precaution was available gets weaker — particularly for roles with privileged system access, financial controls, or client-facing trust.

Where exposure concentrates

Risk factorWhy it raises exposurePractical mitigation
Remote role with system/data accessFraudulent hire can cause a breach with real financial and regulatory consequencesIdentity verification at interview + periodic re-verification
Staffing/contractor placementAgency may face client indemnification claims if a placed worker turns out fraudulentContractual proctoring requirements + documented verification trail
Client-facing or financial roleImpersonation risk extends past your own company to your customersContinuous face verification, not just document check
No verification process at allWeakest position if harm occurs — no evidence "reasonable care" was exercisedEven a basic identity-check policy creates a defensible record
Documented verification process, still defrauded by novel techniqueStronger position — shows reasonable care was takenKeep trust reports/evidence as part of the hiring file

Step-by-step: building a defensible position

  1. Adopt a written interview-integrity policy covering identity verification for roles above a defined risk threshold (system access, financial controls, client-facing).
  2. Apply it consistently. An inconsistently enforced policy is nearly as exposed as no policy — document why any exceptions were made.
  3. Keep evidence. A session trust report — showing identity checks were run and what they found — is exactly the kind of record that demonstrates "reasonable care" if a hire is later found fraudulent.
  4. Extend the same standard to staffing/vendor placements, since courts have found agencies liable for negligent referral in some circumstances.
  5. Review the policy annually as fraud techniques evolve — a policy that was reasonable in 2023 may not be considered reasonable given 2026's documented cheating and fraud rates.
  6. Loop in legal and risk/insurance teams before finalizing thresholds — this is a business risk decision informed by legal exposure, not a pure HR call.

FAQ

Has any company actually been sued for negligent hiring specifically tied to skipping interview verification? Negligent hiring suits are typically tied to harm caused by an employee (theft, violence, data breach) rather than the absence of a specific vendor tool, but the underlying legal theory — failure to exercise reasonable care during hiring — applies squarely to identity-fraud scenarios as they become better documented.

Is this different from ordinary background-check negligence claims? Background checks and interview identity verification address different gaps: background checks review a person's history; identity verification confirms the person you background-checked is the same person you hired.

Does using AI interview proctoring guarantee legal protection? No tool guarantees immunity from claims, but a documented, consistently applied verification process is strong evidence of reasonable care, which is the standard negligence law actually asks about.

Should every role get the same level of verification? No — risk-based tiering makes more sense than a blanket policy; roles with system access, financial authority, or client trust warrant the highest scrutiny.

Who should decide the verification policy — HR, legal, or security? All three, ideally. HR owns the hiring process, legal assesses liability exposure, and security/IT understands which roles carry the highest access risk.

By Pinal Dave Last updated: August 4, 2026