For employers and HR teams

How Do Employers Verify Certificates?

Five routes an employer can take to check a candidate's certificate, what each one actually proves, why only one of them resolves in seconds, and how to turn any of it into a process that survives a hiring deadline.

Last updated · 11 min read

The short version

There are five ways an employer can check a certificate, and they are not variations on one method. They differ in what they prove, how long they take, and whether anyone else has to cooperate. Choosing between them is the decision, and most organisations never make it consciously.

One route is fast and conclusive: opening a verification link that the issuer published with the credential. It takes seconds, needs nobody's cooperation, and either the details match or they do not. The catch is the part employers cannot do anything about. Whether that link exists was decided by the issuing organisation at the moment the certificate was created, typically years before the candidate applied to you. The underlying idea, and the three questions it is routinely confused with, is credential verification.

Everything else on the list is slower, weaker, or both. That is not a complaint about anyone's competence. It is the structure of the problem, and once you can see the structure, the practical question stops being how do I verify certificates and becomes which certificates is it worth verifying, and by which route.

The five routes, and what each one proves

Read this table as a menu rather than a sequence. You will not run all five, and running them in order would be the slowest possible way to reach an answer.

RouteWhat a success actually provesTypical timeDepends on
Verification link on the credentialThe details you are looking at are the details the issuer recorded and signed, unalteredSecondsThe issuer having published one
Asking the issuer directlyThat a named person holds a named award, to the extent whoever replies checked properlyDays to weeks, sometimes neverThe issuer replying, and the candidate consenting
A national or professional registerThat the qualification or licence is recorded by the body that governs itMinutes to weeks, depending on the bodyThe credential being of a type the register actually covers
A background screening vendorWhatever the vendor established, which is the routes above run by someone elseDays to weeksBudget, and the same underlying cooperation
Documents the candidate suppliesThat the candidate possesses a document. Nothing about the award behind itInstantNothing, which is the problem
Five certificate verification routes, plotted by speed against strength of answerVerification link on the credential: the issuer's own page, opened by you. A national or professional register: conclusive only for what it covers. Asking the issuer directly: strong, when it arrives at all. A screening vendor: they run the routes above, for a fee. Documents the candidate supplies: instant, and proves the least. The verification link is the only route that is both fast and conclusive, and it is available only if the issuer chose to provide one.ConclusiveMinutesWeeks, or neverHow long an answer takesWhat the answer is worthWeakVerification link on the credentialthe issuer's own page, opened by youA national or professional registerconclusive only for what it coversAsking the issuer directlystrong, when it arrives at allA screening vendorthey run the routes above, for a feeDocuments the candidate suppliesinstant, and proves the leastNo route on this chart tells you the person in front of you is the person named on the certificate. That is a separate check.
The five routes an employer can take, placed by how long an answer takes and how much it is worth. Only one sits in the fast, conclusive corner — and it is the only one the employer cannot choose, because the issuer chose it at issuance.

The bottom row is the one worth sitting with. Asking a candidate to email their certificate is not a verification step, though it is what a great many organisations record as one. It establishes that they have a file. Every input needed to produce that file, the layout, the crest, the signature block and the wording, is published by genuine recipients online, which is why inspecting a certificate narrows the question without ever closing it. The fix is upstream of you: a candidate who has put the credential ID and verification link on their CV has moved themselves out of that bottom row without being asked.

If the certificate carries a URL, a QR code, or a credential ID with a lookup page, this is the route to take and it beats everything else on the list. A signed credential is checked mathematically against the issuer's public key, so a confirmation does not depend on anyone being available, being helpful, or being at their desk.

Three rules make the difference between doing this properly and going through the motions.

  1. Open the link yourself. Type it or scan the code from the document. Never accept a screenshot of a verification page, and never click through from an email the candidate sent. A screenshot of a green tick is an image, and an image is the easiest thing on this page to fabricate.
  2. Check the domain. The page should sit on the issuer's own domain or on a credentialing platform the issuer plainly uses. A lookalike domain is the standard attack here, and it is cheap.
  3. Compare every field. Name, award, issuing organisation, and date, against the document in front of you. A verification page that loads but disagrees with the certificate is a failure, not a pass, and it is a more informative failure than a page that does not load.

Verifying a certificate online walks through both branches of this in full, including what to do when there is no link at all.

One honest note, because it cuts against our own argument. We measured what happens when verification is available and free. Across one issuer's 48 credentials, only 10 of 302 recorded views opened the verification panel. Publishing a verification route does not make people use it. It makes the check possible for the people who decide to do it, which is a smaller and more honest claim than the one this industry usually makes.

2. Asking the issuer directly

For paper certificates and bare PDFs, this is the fallback, and it is a real one. It is also where most verification programmes quietly die, for a reason that has nothing to do with anyone's diligence.

The sequence that works is narrow. Find the issuing organisation independently of the certificate. Search for the institution, not for the contact details printed on the document, since those are supplied by whoever produced it. Identify the office that holds records, usually a registrar, examinations office, or membership secretary. Send a request that identifies the person, the award, and the year, and that says the candidate has consented.

Then wait, and build your process around the waiting. Institutional confirmation arrives in days at best and weeks routinely, and a meaningful share of requests are never answered at all. That is the single fact that determines whether verification survives contact with hiring: a check that resolves after the decision it was meant to inform is an archive entry, not a control.

Two replies look similar and mean very different things. “We have no record of this person” is substantive and worth acting on. “We cannot confirm that” often means the records are archived, the year predates their current system, or whoever answered is not authorised to say. Press for which one it is before drawing a conclusion, because the second is not evidence of anything.

3. A national or professional register

Where a credential is governed by a body that keeps a public register, the register is faster and more authoritative than the issuing institution. Licensed professions are the clearest case: a practising licence is meaningful precisely because a body maintains a list of who currently holds one, and that list is usually searchable.

The limit is coverage, and it is a hard one. A register answers only for the credential types it was built for. In Nigeria, the National Credential Verification Service covers tertiary academic qualifications and has been mandatory for appointments since October 2025, but it does not extend to professional bodies, training providers, bootcamps, corporate training, or events. What the gazetted policy actually says sets out the scope in detail, and the National Credential Number covers what a clearance is and who can obtain one.

So a candidate presenting a degree and three professional certificates is not one verification problem. It is one register lookup and three separate approaches to three unrelated organisations, and the register solves the easiest quarter of it.

4. A background screening vendor

Screening vendors are worth the money at volume, and it is worth being clear about what you are buying. You are not buying a faster method. You are buying the routes above, executed by someone whose full-time job is executing them, with relationships already established and a documented result at the end.

That is genuinely valuable when you hire continuously, when a regulator expects a paper trail, or when the roles carry real risk. It is poor value for a handful of hires a year, and it does not change the underlying physics: a vendor chasing an unresponsive registrar waits exactly as long as you would.

Ask any vendor one question before signing. For each credential type you actually care about, which of the routes above will they use, and what will they report if that route returns nothing? A vendor that reports “unable to verify” without saying which door they knocked on has sold you a document, not a check.

5. What the candidate hands you

Worth naming explicitly because it is the most common practice and it is rarely written down as a choice. Collecting scans of certificates at offer stage, filing them, and treating the file as evidence is not verification. It is documentation of a claim.

There is one version of this that carries real weight, and it is a different thing: the candidate providing a credential ID or verification link that you then check independently. That is route one, initiated by the candidate. The distinction is whether the confirming step happens on the issuer's system or in your inbox.

Before contacting any institution about a person, tell the person and get their agreement. This is not only a courtesy, and it is not only a compliance matter. It is the practical precondition for the route working at all: most registrars and membership bodies will not discuss an individual's record with a stranger who has not established that the individual agreed.

In practice this costs one line in the offer or shortlist correspondence, naming which qualifications you intend to verify and with whom. Keep the reply. It is also the cheapest early-warning system there is. A candidate who objects to a specific check, having supplied the certificate, has told you something worth knowing.

You are handling someone's personal data when you do this, and the obligations that come with that are a matter for your own counsel rather than for us. This page is not legal advice. What it can say is that the operational answer and the responsible answer point the same way: ask, record that you asked, verify only what the role genuinely requires.

“We could not verify it” is not “it is fake”

This is the distinction that most often goes wrong once a verification programme is running, and it goes wrong in both directions.

A failed verification has at least four common causes that are not fraud: the institution never replied, the records are older than the system that holds them, the name on the certificate differs from the name on the application because of marriage or transliteration, or the award was issued by a body that has since closed or merged. Treating any of those as a finding of dishonesty is both unfair and, if you act on it, a decision you may have to defend.

The reverse error is just as expensive. Recording “Verified” in a spreadsheet cell with nothing behind it converts an unanswered email into a fact. In a year, when somebody asks how you established it, the cell will not help you.

So record three separate states, not two: verified, with the URL or the name and date of whoever confirmed it; could not be verified, with what you tried and when; and contradicted, where the issuer positively says the record does not exist. Only the third is an allegation, and it is the only one that should be treated as one.

Making it a process rather than an intention

Verification rarely fails in organisations because anyone disagrees with it. It fails because it is nobody's job in particular, and because it was designed to happen at a point in the timeline where there is no time left. Four decisions make it stick, and all four are cheap.

  1. Decide what you verify, per role, once. Verifying every line of every CV is unaffordable and everyone knows it, which is how organisations end up verifying nothing at all. Verifying the one qualification a role legally or practically requires is affordable indefinitely. Write the list down and stop relitigating it per candidate.
  2. Start at shortlist, not at offer. If a route takes three weeks and you begin it at offer stage, you are choosing between delaying the hire and skipping the check, and you will skip the check. Beginning at shortlist costs the same effort and removes the conflict entirely.
  3. Record the evidence, not the conclusion. A verification URL, or the name and date of the person who confirmed it. This is what turns a check into something that still exists after the person who ran it has left.
  4. Define the response to a failure before you have one. Ask the candidate first; most failures are administrative and clear up in a single email. Deciding what to do in the moment, about a specific person you have already met, is how inconsistent decisions get made.

One addition that costs nothing and pays immediately: ask for verifiable credentials at application. A line saying that credentials with a verification link or credential ID are preferred moves a share of your intake into the one route that resolves in seconds. It also, slowly, tells the institutions your candidates come from what employers now expect, which is the only mechanism by which any of this improves.

What none of this catches

Three limits, stated plainly, because a page arguing for verification that omitted them would be selling rather than explaining.

None of it proves identity. Every route on this page confirms that a record exists and matches. Not one of them establishes that the person in front of you is the person named in it. That is a separate check, against identity documents, and no credentialing system replaces it.

None of it catches fraud at the point of award. If a credential was issued to someone who did not earn it, whether through a compromised assessment or someone inside the institution, verification confirms the fraud rather than exposing it, because the record is genuine. The Benin and Togo degrees invalidated in Nigeria are the case study for this, and it is covered in certificate fraud in Nigeria.

Verifiable is not the same as accredited. Confirming that an organisation really issued a credential says nothing about whether that organisation's awards mean anything. An unknown body issuing perfectly verifiable certificates is still an unknown body, and that is a judgement you have to make separately.

If you are on the other side of this

Most organisations that read this page are both: they hire, and they also issue certificates to people who will be hired elsewhere. If you issue, the entire article above describes work your own graduates are putting employers through, and work your team absorbs one email at a time.

The fix is not a better reply process. It is issuing credentials that answer the question without you: signed at issuance, hosted at a permanent URL, checkable by anyone holding the link with no account and no request to you. Credential verification covers what that looks like in practice, and the security page sets out the signing scheme and its limits in full, including what a signature does not prove.

Frequently asked questions

What is the fastest way to verify a candidate's certificate?
Open the verification link or QR code printed on the credential itself, on the issuer's own domain, and compare every field against the document. That resolves in seconds and needs nobody's cooperation. It is only available if the issuing organisation published one at issuance, which is a decision made years before the candidate applied to you.
How do I verify a certificate that has no link or QR code?
Contact the issuing organisation directly, found independently rather than through the contact details printed on the certificate. Ask the office that holds records, identify the person, the award and the year, and confirm the candidate has consented. Expect days or weeks, and expect a meaningful share of requests to go unanswered.
Do I need the candidate's permission to verify their certificate?
Ask for it as a matter of course. Most registrars and membership bodies will not discuss an individual's record with a stranger who has not established that the individual agreed, so consent is the practical precondition for the check working at all. Tell the candidate which qualifications you intend to verify and with whom, and keep the reply.
What does it mean when a certificate cannot be verified?
Usually not fraud. The common causes are an institution that never replied, records older than the system holding them, a name that changed through marriage or transliteration, and an issuer that has closed or merged. Record it as could not be verified, with what you tried, which is different from the issuer positively saying no such record exists.
Is a background screening vendor worth it?
At volume, or where a regulator expects a paper trail, usually yes. You are buying the same routes executed by someone who does it full time, with relationships already in place and a documented result. You are not buying a faster method: a vendor chasing an unresponsive registrar waits exactly as long as you would.

Stop being the office that gets asked

If verification requests land on your team one email at a time, tell us how many and how you answer them today. If the honest answer is that nobody asks, this is not urgent, and we will say so.