top of page

ATS Platforms Can't Verify Credentials -That Gap Is Now a Hiring Liability (2026)

  • Jun 15
  • 9 min read

Updated: Jun 23

By Samik Das | Blockchain Solutions, VARA Technology


                Samik writes on blockchain infrastructure, enterprise credential verification, and workforce trust systems. He is part of the team behind CertCheck, VARA Technology's blockchain-backed credential verification platform.


When Meta announced its latest round of layoffs in May 2026, the reaction inside enterprise hiring teams across India was quiet, uncomfortable anticipation. Thousands of credentialed tech professionals would re-enter the job market within weeks. ATS inboxes would flood. Recruiters would need to move fast.

And that urgency is precisely when credential fraud accelerates.

Large-scale hiring surges do not just attract qualified candidates. They attract coordinated fraud. AI-generated profiles, fabricated degree certificates, and deepfake video identities are now timed deliberately to coincide with high-volume hiring events because volume creates noise, and noise creates cover. According to Sardine.ai's research on job application fraud, synthetic identity attacks targeting enterprise hiring pipelines have grown into structured, repeatable operations - not opportunistic individual fraud.

The deeper problem is not that fraud exists. It is that the infrastructure most Indian enterprises use to manage hiring - the applicant tracking system. But it was never built to catch it.


What ATS Systems Were Actually Designed to Do

ATS platforms cannot verify a single academic certificate or professional credential. They are built to move candidates through a recruitment pipeline efficiently but not to authenticate the documents inside it.

This is not a criticism of the category. It is a structural fact. When a candidate uploads a degree certificate, a professional licence, or a relieving letter, the ATS stores the file. It does not check whether the issuing institution recognises the document. It does not confirm whether the dates are accurate. It cannot detect whether the certificate has been digitally altered. That authentication step was always assumed to happen elsewhere, typically through a background verification agency, typically weeks after an offer was extended.

Over the past decade, ATS platforms have become remarkably sophisticated at the problems they were designed to solve: AI-driven screening, automated ranking, pipeline management, interview scheduling. These are real operational gains. But the question they have never been designed to answer is the more fundamental one: is this person who they say they are?

That gap was tolerable when fraud was opportunistic and manual. It is no longer tolerable in 2026.


The Verification Gap at the Center of the ATS Ecosystem

Sardine.ai's research on job application fraud found that synthetic identity fraud in hiring has grown into a structured, repeatable operation not opportunistic individual fraud, but coordinated attacks using AI-generated profiles, fabricated credential documents, and in some cases, deepfake video capabilities deployed during remote screening. Their analysis identified device spoofing, location masking, and AI-generated resume content as the primary fraud vectors now targeting enterprise hiring pipelines.

These attacks are not aimed at small companies with informal hiring processes. They target organizations with structured Application Tracking System workflows, precisely because those workflows create a false sense of procedural security. A candidate who clears automated screening, passes an AI-ranking threshold, and schedules an interview through an ATS has implicitly been vetted in the recruiter's mind, even though the system did nothing to verify a single underlying claim.

Enterprise adoption of applicant tracking software across India has accelerated sharply this year, and the recruiter workflows that come with it. What has not kept pace is the question sitting underneath every one of those workflows: once a candidate clears the pipeline, does anyone actually know their credentials are real? The demand for verification is clearly there. The hiring infrastructure that delivers it at the point where it matters, inside the ATS, before a recruiter's time is spent largely is not. 


Diagram showing the verification gap between ATS resume screening and blockchain-anchored credential authentication in Indian enterprise hiring pipelines
Diagram showing the verification gap between ATS resume screening and blockchain-anchored credential authentication in Indian enterprise hiring pipelines

The scale of credential fraud hitting Indian hiring pipelines


Credential fraud in Indian hiring has moved well beyond fake degree certificates printed at local shops. According to Sardine.ai's fraud research, the primary attack vectors now targeting enterprise hiring pipelines include AI-generated resume content, fabricated credential documents with accurate-looking metadata, device spoofing to bypass identity checks, and in advanced cases, deepfake video capabilities deployed during remote screening interviews.

These attacks do not target small companies with informal processes. They target organisations with structured ATS workflows — precisely because those workflows create a false sense of procedural security. A candidate who clears automated screening, passes an AI ranking threshold, and schedules an interview through an ATS has implicitly been "vetted" in the recruiter's mind, even though the system authenticated nothing.

Consider the verification gap in practical terms:

What ATS handles

What ATS cannot do

Resume ingestion and parsing

Verify the degree listed is real

AI-based candidate ranking

Confirm the certificate is unaltered

Pipeline and interview scheduling

Check credentials against issuing institution

Offer management and onboarding

Detect deepfake identity in video interviews

HRMS integration

Validate professional licences in real time

Compliance tracking

Authenticate relieving letters from past employers

The 30–45 day delay typical of manual background verification - cited across VARA's own CertCheck research means that in fast-moving hiring cycles, candidates are often onboarded before a single credential has been confirmed. For enterprises in regulated sectors — BFSI, healthcare, government contracting — that delay is not just operationally inefficient. It is a compliance liability under India's Digital Personal Data Protection Act, 2023.


The Question ATS Providers Should Be Asking


If you are building or operating an applicant tracking system in 2026, the strategic question is no longer just "how do we screen faster?" It is increasingly "how do we ensure that what we are screening is real?"

The distinction matters because the liability asymmetry has changed. An enterprise client who hires a fraudulent candidate through your platform's workflow is going to ask, at some point, where the verification failure occurred. If the answer is "our ATS doesn't verify credentials that is a separate step," that answer will hold for now. But as AI-generated application fraud becomes more visible and more documented, the expectation that hiring infrastructure should incorporate some form of credential authentication is going to harden into a procurement requirement.

Platforms like CertCheck are building exactly the layer that would close this gap - blockchain-anchored certificate verification that integrates directly into hiring workflows, delivering instant credential authentication at the point where a candidate enters the pipeline, not weeks after an offer is signed. For an ATS provider, the commercial case is straightforward: the platform that can offer verifiable hiring confidence, not just workflow efficiency, is a different product in a sales conversation with an enterprise compliance team.



CertCheck by VARA Technology - Hyperledger Fabric blockchain credential verification integrated into ATS hiring workflow
CertCheck by VARA Technology - Hyperledger Fabric blockchain credential verification integrated into ATS hiring workflow

What Verification-First Hiring Infrastructure Actually Looks Like


The shift is not about adding a background check step to the ATS workflow. It is about embedding trust architecture at the infrastructure level so that when a candidate submits credentials, those credentials either validate against an immutable record or they do not, before the application advances. No additional TAT. No separate vendor relationship for the end client. No gap between screening and verification that fraud can occupy.

The ATS platforms that figure this out first will find themselves in a different competitive tier  not because they added a feature, but because they changed what "candidate verified" actually means.


ATS vs blockchain verification: a capability comparison


The distinction between what ATS platforms do and what blockchain verification adds is worth making explicit, because the two are often conflated in vendor marketing.

Capability

Traditional ATS

CertCheck blockchain verification

Resume storage and parsing

Yes

Yes (ATS handles this)

AI candidate screening and ranking

Yes

Yes (ATS handles this)

Certificate authenticity check

No

Yes — cryptographic hash match

Tamper detection on documents

No

Yes — any alteration produces mismatch

Institution confirmation

Manual / 7–45 days

Automated / real-time

Deepfake document detection

No

Yes — hash-level verification

DPDP Act compliance

Partial

Built-in by design

Personal data stored for verification

Yes (document stored)

No — only hash stored

Cost per verification

High (manual BGV agency)

Low (automated, scalable)

Time to verified result

7–45 business days

Seconds

The shift being described here is not about adding a background check button inside an ATS. It is about embedding trust architecture at the infrastructure level — so that credential verification happens at the same moment as candidate ingestion, with the same speed and the same scalability.


What this means for HR teams and ATS buyers in India

For HR leaders evaluating ATS platforms in 2026, credential verification capability is moving from a differentiator to a procurement requirement. The pressure is coming from three directions simultaneously.

Regulatory: The Digital Personal Data Protection Act, 2023 creates accountability for how personal data including credential documents is stored and processed during recruitment. Verification workflows that store unverified documents introduce compliance exposure.


Operational: As India's white-collar hiring market grows, with an estimated 8% growth in professional roles projected in 2026, the volume of applications makes manual credential verification increasingly impractical. Automation is not optional at scale.


Reputational: High-profile cases of credential fraud in Indian enterprises, particularly in BFSI and healthcare are creating board-level awareness of hiring risk. The question "how do we know our credentials are verified?" is being asked at the CHRO level, not just the recruiter level.

The next wave of ATS adoption in India will not be won on speed alone. The platforms that inherit the largest enterprise accounts will be the ones that answered a question their competitors assumed someone else was responsible for: not just "did this candidate apply?" but "is this candidate real?"

Explore how CertCheck integrates blockchain-backed certificate verification into enterprise hiring workflows at certcheck.in.


Frequently Asked Questions


Q: Can ATS platforms verify academic certificates on their own?

A: No. ATS platforms are designed to manage and route candidate information, not to authenticate it. When a candidate uploads a degree certificate, the ATS stores the file but has no mechanism to check whether the issuing institution recognises the document, whether the dates are accurate, or whether the file has been altered. Verification requires connecting to issuing institutions or an immutable ledger like a blockchain, which is a separate infrastructure layer that most ATS platforms have not yet integrated.


Q: How does blockchain solve credential verification in hiring?

A: Blockchain-anchored verification stores a cryptographic hash of each credential on an immutable ledger at the time of issuance. When a candidate submits a certificate during an ATS application, the system computes a new hash of the submitted file and compares it against the on-chain record. If the hashes match, the credential is authentic and unaltered. If they do not, the document has been tampered with. This process takes seconds and requires no manual confirmation call to the issuing institution.


Q: What is CertCheck, and how does it integrate with ATS systems?

A: CertCheck is VARA Technology's blockchain-based credential verification platform built on Hyperledger Fabric. It issues tamper-proof digital credentials to educational institutions and employers and enables real-time verification when candidates apply through ATS workflows. Integration is via API: when a candidate submits credentials, the ATS queries CertCheck's verification layer, receives a verified or flagged result, and routes the application accordingly, before any recruiter time is invested. CertCheck does not store personal data on-chain; only cryptographic proofs are recorded, keeping the platform compliant with India's DPDP Act.


Q: Why is credential fraud more prevalent during high-volume hiring events?

A: Large-scale hiring surges, triggered by competitor layoffs, campus placement cycles, or rapid expansion create high application volumes that increase noise in recruiter workflows. Fraudulent applications are harder to detect when processed at volume under time pressure, and structured fraud operations time their activity to coincide with these events precisely because the signal-to-noise ratio works in their favour. Sardine.ai's research on job application fraud identified that synthetic identity attacks targeting enterprise hiring are coordinated, not opportunistic and that ATS-structured workflows are a specific target because automated screening creates a false sense of verification.


Q: What does DPDP Act compliance mean for ATS credential verification?

A: India's Digital Personal Data Protection Act, 2023 creates accountability for how personal data including credential documents is stored and processed. Traditional BGV workflows that store unverified certificate files introduce compliance exposure, since those documents contain sensitive personal data that must be protected under DPDP rules. CertCheck addresses this by recording only cryptographic hashes on-chain, not the underlying documents. Verification is possible without storing personal data, which is DPDP-compliant by design.


Q: Is blockchain verification scalable for high-volume Indian hiring?

A: Yes. Because verification is automated and API-driven, CertCheck processes credential checks in seconds regardless of application volume. A traditional BGV agency operating manually creates a bottleneck that grows proportionally with hiring volume. Blockchain verification scales horizontally, the same infrastructure that handles 10 verifications per day handles 10,000, with no additional TAT or manual intervention required.


The hiring landscape is changing fast. We're documenting the trends, risks, and technologies shaping the future of trusted credentials.


If you are still in doubt if your data is safe with CertCheck, let us reassure you that


  • Blockchain-Powered Trust: CertCheck uses Hyperledger Fabric, a permissioned blockchain, to issue and verify tamper-proof digital credentials.

  • DPDP-Compliant by Design: CertCheck does not store student or individual personal data, helping institutions maintain privacy and regulatory compliance.

  • Privacy-First Verification: Only cryptographic proofs are recorded on the blockchain, enabling secure verification without exposing sensitive information.

  • Secure & Verifiable Credentials: Every credential is independently verifiable, fraud-resistant, and backed by a transparent audit trail for employers and institutions.



Follow CertCheck for practical insights and industry updates:


If credential trust matters to your organization, we'd love to have you along for the journey.



bottom of page