Responsible Verification
The controls behind a fair verification process.
These principles explain how Datapoint scopes, performs, reviews and reports verification work so that findings are relevant, traceable and suitable for responsible decision-making.
Every assignment should begin with a clear decision, authorised requester and defined purpose. Datapoint does not treat verification as unrestricted investigation. The scope must be connected to the stated role, transaction, access, responsibility or risk decision.
Checks are selected according to the decision and level of assurance required. Datapoint seeks to avoid unnecessary collection, excessive screening and checks that are unrelated to the stated purpose.
Sources are selected according to the information being verified. Reports distinguish between source-confirmed information, information supplied by a subject or client, information that could not be resolved, and information requiring attention.
Datapoint applies review and quality-control steps before releasing a report. The process may include completeness checks, source comparison, internal escalation, verification of material discrepancies and review of the wording used to present findings.
Analytics and automation may support workflow, matching, prioritisation and reporting, but significant findings should be reviewed in context. Datapoint does not present automated output as a substitute for appropriate human assessment.
Verification should not be used to support unlawful discrimination, harassment, retaliation or decisions based on irrelevant protected or sensitive characteristics. Clients should assess findings consistently and in relation to the legitimate requirements of the decision.
Where information is disputed, incomplete or cannot be confirmed, the report should state that position rather than treat uncertainty as an adverse finding. A subject or authorised client may provide additional information for review in accordance with the applicable correction or dispute process.
Reports and supporting records are restricted to authorised personnel and authorised client users. Access, sharing, retention and disposal are controlled according to the assignment, sensitivity of the information and applicable legal and contractual requirements.
Field work should be performed lawfully, safely and with appropriate identification, instructions and limits. Field personnel must not misrepresent their authority, obtain information by intimidation or exceed the approved assignment scope.
- Provide a lawful purpose, accurate instructions and an authorised contact.
- Use the report only for the agreed purpose and protect it from unauthorised access.
- Consider the full context, relevance and applicable law before making a decision.
- Provide any notice, consent or opportunity to respond that the decision process requires.
- Notify Datapoint where instructions, purpose or authorised users change.
Datapoint may decline or stop an assignment that appears unlawful, deceptive, discriminatory, disproportionate, outside the stated purpose, unsupported by adequate authority, unsafe for field personnel, or intended for harassment, surveillance or misuse of personal information.
Datapoint maintains assignment records, review controls, access restrictions, incident and complaint processes, and updates its methods as risks, services, sources and legal requirements change.
