Skip to content
Compliance

FCRA Disclosure and Authorization Form Guide

VolunteerBadge Team·September 4, 2026·14 min read

Learn what an FCRA disclosure and authorization form requires, what to include, common nonprofit pitfalls, and how to integrate it into volunteer screening.

Screen for $5

FCRA-compliant volunteer background checks. No monthly fees.

A volunteer coordinator is halfway through onboarding when the screening vendor pauses the order. The packet contains a background-check paragraph inside the application, a liability waiver on the same page, and a vague authorization covering “other companies.” The volunteer has signed, but the organization can't confidently prove that it provided a compliant disclosure before requesting the consumer report.

That situation is common because nonprofits treat the FCRA disclosure and authorization form as paperwork instead of workflow infrastructure. The form controls whether the organization can order the report, how broadly it can use the authorization for later screening, and whether the records will support a lawful response when a report raises concerns. The FTC's FCRA guidance makes the basic sequence clear: provide the required written disclosure, obtain written authorization, and follow the applicable process if the report may affect placement.

A clean form won't solve every compliance problem. It will, however, prevent a preventable one at the front door.

Table of Contents

Why the Form Matters More Than Most Nonprofits Realize

The coordinator calls the vendor, expecting a quick fix. Instead, the vendor asks for the exact disclosure shown to the volunteer, the signed authorization, the timestamp, and the version used for that application. The coordinator sends the packet and learns that the disclosure wasn't standalone, the authorization didn't clearly identify the screening purpose, and the release language had been copied from a general volunteer waiver.

The check itself may be accurate. The organization may have a legitimate safety reason for screening. Neither point repairs defective consent.

The form starts the legal chain

The FCRA treats the disclosure and authorization as the gateway to a third-party consumer report used for employment purposes. Volunteer programs can't treat the signature as a general permission slip. They need to show that the person received a clear disclosure before the report was obtained and then gave written authorization.

The FTC's employer guidance on consumer reports also explains why authorization wording matters beyond the initial application. A properly drafted authorization can cover reports obtained during the application process and later reports during the person's tenure, if the form clearly says so. A vague or narrow authorization may force the organization to obtain fresh consent before a later check.

Operational rule: If your team can't connect the signed form to the screening order, the report review, and the final decision record, you don't have a workflow. You have a loose collection of documents.

Small drafting choices create large process problems

The most dangerous shortcuts look harmless. A coordinator adds a liability waiver to “save space.” A program uses one authorization for criminal history, credit, motor vehicle records, and “anything else the organization considers appropriate.” Another team adds a state rights summary directly into the federal disclosure without checking whether the added language belongs there.

These choices can create disputes over whether consent was valid. They can also leave the nonprofit unable to prove what the volunteer understood, what report the organization intended to obtain, or whether later screening fell within the original authorization.

The right response isn't to build a fifty-page packet. It's to make the front-end form narrow, readable, versioned, and connected to the steps that follow. An hour spent removing unrelated language is cheaper and more defensible than weeks spent reconstructing consent after a dispute.

What the FCRA Actually Requires on the Form

The FCRA disclosure and authorization are related, but they do different jobs. The disclosure tells the individual that a consumer report may be obtained. The authorization records the individual's written permission for the stated screening purpose.

The federal statute requires the disclosure to appear in a document that consists solely of that disclosure when an organization seeks a consumer report for employment purposes. The FTC describes the same principle in practical terms. The disclosure must be clear and conspicuous, and it can't be buried in an application, waiver, handbook, or release. The FCRA compliance guidance for nonprofits is useful for translating that distinction into a volunteer application workflow.

Separate the notice from the permission

The disclosure should plainly state that the organization may obtain a consumer report for volunteer screening or placement. Keep it focused on that notice. Don't use the disclosure as a container for general onboarding terms, confidentiality obligations, liability releases, or unrelated state-law acknowledgments.

The authorization is the written consent that follows. It should identify the purpose, describe the report or report categories the organization may obtain, identify the consumer reporting agency where appropriate, and give the volunteer a clear way to sign. The FTC permits the authorization to appear in the same document as the disclosure, but that doesn't turn the entire page into a general-purpose application.

Federal appellate decisions have sharpened this distinction. In 2020, the Ninth Circuit held that the disclosure must be in a document consisting solely of the disclosure, while the authorization doesn't have to be a separate standalone document because the authorization subsection doesn't use the same “solely” language. The practical lesson is narrow. Combining disclosure and authorization can be defensible, but adding unrelated material to the disclosure is still a poor design choice.

Audit the three requirements

Before publishing a template, check three boxes:

  • Standalone: The disclosure isn't embedded in the volunteer application or a release.
  • Conspicuous: The language is easy to find and understand, with no distracting legal clutter.
  • Specific: The form identifies the volunteer-screening purpose and the types of reports the organization intends to obtain.

If a reviewer has to search through application text to find the notice, the form has already failed its most important usability test.

Must-Include Clauses and Must-Avoid Additions

Use the form as an audit object, not a document everyone edits freely. The table below separates the language that supports a defensible process from the additions that commonly undermine it.

Must-Include Clause Must-Avoid Addition
Screening purpose: State that the consumer report may be obtained for a specific volunteer role or placement decision. Liability release: Don't make the volunteer waive claims or release the organization inside the FCRA disclosure.
CRA identity: Name the consumer reporting agency, or clearly describe the agencies used when the process involves multiple vendors. Vague vendor language: Don't rely on “this organization and other companies” when the authorization should identify the screening source or category.
Report description: Explain the type of consumer report sought, such as criminal-history information when that is the actual scope. Unrelated report categories: Don't authorize credit or other reports that aren't tied to the role and applicable law.
User statement: Clarify that the screening provider supplies the report and isn't the organization making the volunteer decision. Bundled authorization: Don't bury the permission inside a general application, waiver, or policy acknowledgment.
Written consent: Capture the volunteer's signed acknowledgment and authorization. Automatic denial clause: Don't condition service on a report outcome without preserving the required adverse-action process.
Copy request notice: Tell the volunteer that a copy of the report may be requested under the FCRA. Excess legal text: Don't turn the disclosure into a multipurpose contract.

The three lines I won't compromise on

First, the form must clearly state that a consumer report may be obtained for the volunteer purpose. Second, it must identify what report the organization seeks and who supplies it. Third, it must capture written authorization after the disclosure is provided.

The FTC's explanation of clear and conspicuous disclosures supports a plain-language approach. The Ninth Circuit clarification doesn't authorize clutter. It distinguishes the disclosure rule from the authorization rule, and that distinction should guide form design rather than invite extra language.

Delete the five risky lines

Remove liability releases, waivers of the right to sue, vague “other companies” permissions, unrelated credit-report language, and any statement promising automatic rejection based on a report. These clauses either belong elsewhere, need a more precise purpose, or interfere with the downstream review process.

A clean form says what will happen. It doesn't try to make the volunteer surrender every possible right before the organization has even ordered the report.

Anatomy of a Compliant Sample Template

A defensible volunteer form should read like a controlled workflow. Each block should answer one operational question, and the completed record should let a reviewer reconstruct what happened without relying on someone's memory.

Start with identification

The opening block should identify the nonprofit, the volunteer role or program, the volunteer's identifying information, and the consumer reporting agency. Include the CRA's contact details where the form or workflow requires them. A blank contact field or a generic reference to “a screening company” creates unnecessary ambiguity.

The disclosure paragraph should come before the signature and should stand on its own. In plain language, it can state that the organization may obtain a consumer report for volunteer-screening purposes. Keep this paragraph limited to the notice. Don't insert a release, application certification, confidentiality clause, or general consent into it.

Label the authorization clearly

The authorization should be visually distinct, even if it appears on the same document. It should state that the volunteer authorizes the nonprofit to obtain the identified report for the stated volunteer purpose and acknowledges receipt of the disclosure.

Describe the report categories accurately. If the program seeks criminal-history information, say so. If it may conduct later reports during the volunteer's tenure, state that plainly and define the relationship between the continuing authorization and the volunteer role. The FTC's guidance permits a one-time blanket authorization when the language clearly covers both the application process and later reports during the person's tenure.

Finish with evidence

The form needs the volunteer's signature, date, and a reliable contact method. For electronic workflows, retain the signed document with the signature timestamp and the form version. That record helps establish that the disclosure preceded the screening request.

The form should also point into the next steps. The screening record should show which report was ordered under that authorization. If a report raises concerns, the organization's adverse-action record should reference the relevant report and form version. If the volunteer remains active and the program later conducts another check, the system should show why the original authorization covers it or why a new authorization was collected.

Design test: Every field should either identify the parties, explain the report, capture consent, or preserve proof. If it does none of those things, remove it from the FCRA form.

Common Pitfalls That Get Volunteer Forms Rejected

Volunteer programs usually don't fail because a coordinator intended to ignore the law. They fail because someone reused an old employment template, added a convenient clause, or treated a completed signature as the end of the process.

An infographic titled Common Pitfalls That Get Volunteer Forms Rejected, listing five key FCRA compliance errors.

Five errors to remove from your process

  1. Bundled consent: A liability release or general application certification rides beside the disclosure. The fix is simple: move unrelated terms to the appropriate document and keep the disclosure focused.

  2. Overbroad authorization: The volunteer authorizes every possible report, regardless of the role. Replace the blanket language with a role-specific description of the reports the nonprofit intends to obtain.

  3. Missing state-specific material: The federal form is used without checking whether the volunteer's location adds a required notice or restriction. Treat state and local requirements as a separate review layer, not as text to paste blindly into the federal disclosure.

  4. One-time signature with no repeat-screening plan: The organization later orders another report but can't show that the original authorization covers later reports. Either draft continuing authorization language correctly or collect fresh consent before the later check.

  5. Silent adverse action: A report contains information that may affect placement, and the coordinator calls the volunteer with a final decision. The school volunteer background-check workflow highlights why consent paperwork must connect to the notices that follow.

A rejected dispute, an unsupported placement decision, or a claim that the volunteer never received a meaningful notice can all trace back to one drafting choice. Fix the form, then fix the trigger that prevents staff from bypassing the next required step.

The video below provides another visual explanation of the workflow.

Collecting, Storing, and Wiring the Form Into Screening

A compliant template is only useful if the system prevents staff from ordering a report before the form is complete. Paper packets and email attachments make that difficult because the screening request, signed consent, and volunteer record can live in different places.

Build a controlled intake sequence

Use a fixed sequence:

  1. Present the disclosure first: Deliver the form through the volunteer application or screening portal, with the disclosure clearly visible before consent is collected.
  2. Capture the signature: Record a timestamped electronic signature or retain the signed paper form.
  3. Block the order until completion: Don't allow the screening request to proceed until the signed record exists.
  4. Attach the record: Store the completed form with the volunteer profile and screening order, including the form version.
  5. Record changes: If a volunteer withdraws consent or leaves the program, route that request into the same record system and stop future screening activity unless a lawful new process applies.

This sequence creates evidence that the disclosure came before the report request. It also prevents a coordinator from finding a “completed” box checked in a spreadsheet while the actual authorization is missing.

Control access and preserve the audit trail

Background-screening records contain sensitive personal information. Give access only to staff who need it for screening, compliance, or placement administration. Keep an audit log showing who viewed or changed the record, when the form was signed, which version was used, and which report was ordered.

Retention should follow the organization's documented legal and operational requirements. Don't delete the authorization while retaining the report, and don't keep scattered copies in personal inboxes. A clear retention schedule should address the disclosure, authorization, report, dispute communications, and any adverse-action notices together.

Tools such as VolunteerBadge can place the disclosure and authorization at the point where the screening request begins, store the signed record in the volunteer profile, and support repeat screening and adverse-action workflows. The volunteer background-check process guide provides a practical reference for connecting intake to screening operations.

Test the workflow before launch

Run a complete test with a sample volunteer record. Try to order a report without a signature. Try to change the form after signing. Try to access the record as a staff member without the required role. Then verify that the system preserves the original version and timestamp.

If the test reveals a bypass, assume a real coordinator will eventually find it. Fix the control before launch.

Connecting the Form to the Full FCRA Workflow

The form is the front door, not the whole house. It establishes the permission and scope for the screening request, but the organization still needs a controlled path for report review, repeat checks, disputes, and decisions based on report information.

A five-step infographic illustrating the FCRA disclosure and authorization workflow for background checks on volunteers.

Use this desk-side model:

  1. Form: Provide the standalone disclosure and obtain written authorization before ordering the report.
  2. Scope: Match the report to the volunteer role and the authorization language. Don't order categories the form doesn't cover.
  3. Review: Apply the organization's documented, role-relevant review criteria consistently. Preserve the report and the reviewer's decision record.
  4. Pre-adverse action: If the report may lead to denial, provide the report and the required summary of rights before making the final decision. Give the volunteer a meaningful opportunity to review and dispute inaccurate information.
  5. Final decision: If the organization proceeds with denial, send the final adverse-action notice with the CRA's contact information and the required explanation that the CRA didn't make the decision.

The record should tie each artifact to the original form by date and version. For repeat screening, confirm that the continuing authorization covers the later report. If it doesn't, stop and collect fresh consent.

Desk-side check: Disclosure delivered, authorization signed, scope matched, report reviewed, adverse-action steps completed when triggered, records retained.

A nonprofit that follows this sequence can explain not only why it screened a volunteer, but also how it handled the result fairly and documented each decision.


VolunteerBadge can embed the disclosure and authorization into the volunteer application flow, capture the signed record, and connect screening results with pre-adverse and final adverse-action notices. Visit VolunteerBadge to review a workflow that keeps the form, screening request, and compliance record together.

VolunteerBadge

Ready to stop overpaying for background checks?

Full national criminal checks at $5. Free address history. FCRA compliant from day one. No monthly fees, no contracts.

Create Free Account

Legal Disclaimer: The content on this page is for informational purposes only and does not constitute legal advice. VolunteerBadge and ScreenForge Labs, LLC are not law firms and do not provide legal counsel. FCRA requirements and applicable laws vary by jurisdiction and circumstances. For guidance specific to your organization, please consult a qualified attorney.

AI Content Transparency: We use AI tools to assist in the research and drafting of our blog content. That said, the opinions, perspectives, and editorial judgment in every article reflect the author's genuine views and real-world experience. We believe in full transparency about how content is created — because trust matters as much in publishing as it does in background screening.