While many companies, especially financial institutions, insurance companies and similarly regulated entities, already recognize the importance of performing background checks prior to hiring employees and independent contractors, some may overlook the need to require certain of their suppliers to do likewise. Failing to screen personnel could result in a violation of law and economic loss. Specifically, the Violent Crime Control and Law Enforcement Act of 1994, 18 U.S.C. Sections 1033-1034 ("the Act"), forbids an individual who has been convicted of a crime involving dishonesty, breach of trust or a violation of the Act to work or continue to work in the business of insurance affecting interstate commerce without receiving written consent from an insurance regulatory official authorized to regulate the insurer. A person who has committed a crime subject to the Act is considered a "prohibited person" in the insurance industry until such consent is received. This prohibition similarly applies to third party contractors, such as outsourcing vendors, providing services to the insurance company.
If a prohibited person under the Act works or continues to work without such a written consent from the designated regulatory official, both the prohibited person and the insurer risk federal criminal and civil sanctions. Furthermore, the Act does not contain a time limitation limiting how far back the felony conviction triggering such prohibition may have occurred.
Insurance companies and others who employ anyone to conduct the business of insurance may be in violation of the Act if they willfully permit participation by a prohibited person, including persons who are already employed or being considered for employment. An employer is responsible for ensuring that any prohibited person who is currently employed or being considered for employment is not permitted to conduct the business of insurance in accordance with 18 U.S.C. A,?1033(e)(1)(B). Insurers should also verify the status of a prohibited person who has already received consent to work in the business of insurance with the insurerAca,!a,,cs domestic state insurance regulator. Because waivers are granted conditionally by insurance regulatory officials, the prohibited personAca,!a,,cs authority to work may be revoked if the employer or applicant does not meet the enumerated conditions of such waiver.
In addition to federal civil and criminal liability under the Act, certain states impose civil liability on employers for the negligent hiring of employees or contractors if such negligent hiring is the proximate cause of a plaintiffAca,!a,,cs injury and the Aca,!A"employer knew or should have known that the person had a Aca,!EoeparticularAca,!a,,c unfitness for the job that would create a foreseeable danger to others.Aca,!?1
Legal liability provides a significant incentive for inquiring into the background of personnel, but companies can also suffer significant economic and reputational loss for acts of Aca,!A"rogueAca,!? employees. Although news of hackers and external security breaches dominate the headlines, the greatest risk to a company comes from its own employees and contractors. Furthermore, there is a significant risk for a company in the situation where a rogue employee of a key supplier with access to such companyAca,!a,,cs sensitive information may cause harm to his or her employer which in turn harms the company. According to the 2005 CSI/FBI Computer Crime Survey, insider abuse cost U.S. companies $6,856,450 in that year.2 Providing perhaps the most compelling argument for screening personnel is the 2002 deployment of a Aca,!A"logic bombAca,!? by a disgruntled UBS Paine Webber IT system administrator. UBS Paine WebberAca,!a,,cs failure to conduct a background check in this instance resulted in a financial loss of over $3 million to assess and repair the damage and even more significant costs in business downtime and lost trading opportunities. If UBS Paine Webber had conducted a background check on Roger Duronio, it would have likely discovered that Duronio possessed a criminal record that included charges of burglary and aggravated assault.3 According to the government in their prosecution of Duronio for securities fraud and computer sabotage, Duronio was angry after receiving a smaller bonus than Aca,!A"expected, sought revenge against his employer by building, planting, and disseminating the logic bomb[, which was] designed to delete all the files in the host server in the company's central data center and in every server in every U.S. branch office.Aca,!?4
In the Duronio case, the governmentAca,!a,,cs key witness and director of computer forensics and incident response at Mandiant testified that UBS had a Aca,!A"solid security set-up.Aca,!?5 However, despite having sound security and even if its few weaknesses were corrected, Aca,!A"security analysts say a corporate IT professional with a good-size chip on his shoulder could still wreak a frightening amount of havoc and high-cost damage.Aca,!?6 The IT insider is behind a companyAca,!a,,cs firewalls and intrusion detection systems. Even more dangerous is the IT professionalAca,!a,,cs knowledge of Aca,!A"what information is most vital to the companyAca,!a,,cs ability to make money and sustain itself.Aca,!?7
One of the ways a company can protect itself from insiders who possess access to its most sensitive information is to perform background checks on those employees and contractors who pose the greatest risk to the company. Such inquiries can prove predictive as evidenced by Aca,!A"a 2006 study [that] showed that 30% of insiders who are caught launching an attack against their employers have arrest records, and that those charges don't generally include computer crimes.Aca,!?8 For example, approximately Aca,!A"18% were for violent offenses such as rape and manslaughter, 11% were for alcohol- and drug-related offenses, and another 11% were for theft.Aca,!?9 Those companies that have not conducted background checks before are advised to not only focus on new hires, but to perform checks on current employees. Companies can also protect themselves by dividing responsibilities of its personnel so as to limit one rogue insiderAca,!a,,cs ability to cause significant damage.
Along with stricter security guidelines for employees and contractors, companies should also impose similar requirements on its suppliers having access to sensitive information or access to the companyAca,!a,,cs facilities where such access may be had. Consider the following illustrative provisions for use in such supplier agreements to protect sensitive information:
Because background checks have become routine in most companies today, requiring your suppliers to screen its employees and contractors is not likely to be considered as onerous as it may have been a few years ago. Given frequent headlines about employee misconduct, the merits of simple preventative measures, such as background checks of employees, contractors and suppliers, are becoming increasingly apparent.
Review articles and blog posts by our list of insurance experts!
Click Here For Participating Firms