A VA agency that places someone into a sensitive role without a background check, and the client who never asked for one
A lease renewal coordinator with access to tenant payment records and lease files is not a low-stakes hire. The agency markets trained staff, the client assumes trained means vetted, and neither conversation includes the word background check until something goes wrong. That gap is where the exposure sits.
The mechanism that creates it is straightforward. An agency's margin depends on placement speed. A thorough background check adds cost and slows the process. If the client never requires one in the contract, the agency has no incentive to run one on its own. The client, relieved to have someone placed, does not push. The role goes live. The person has system access to names, unit numbers, bank routing information, and move-in dates within the first week.
What makes this worth examining is that the dollar loss from a bad placement in this role does not show up as a single event. A tenant whose personal information is misused creates a liability that runs parallel to the landlord relationship for months. A falsified lease renewal confirmation delays an eviction filing. Neither of these appears on any onboarding checklist.
The standard contract language between a client and a VA agency typically disclaims responsibility for the conduct of placed staff once the engagement begins. That clause is often buried under the section about payment terms. It is worth reading before anyone receives system credentials.
The thing the client controls entirely is what the contract requires before placement. A background check requirement, a scope-of-access limit, and a clause naming who holds liability for data handled during the engagement cost nothing to add at signing and are nearly impossible to add after.
What does your current VA contract say about who owns the liability if a placed worker misuses client data?