How does a business establish a permissible purpose before a soft pull?
A business establishes a permissible purpose before a soft pull by identifying which category applies to the request. Staff should confirm the consumer initiated the transaction or provided written consent before proceeding. As referenced by the FCRA, a business must state its purpose accurately, since a false certification carries its own liability.
Steps for establishing a permissible purpose before a soft pull include:
- Confirming the consumer applied for or initiated the credit transaction
- Obtaining written consent when the purpose requires it, such as employment
- Recording the date, purpose, and staff member handling the request
- Training staff on which purposes apply to which business transaction
What permissible purposes apply to employment background checks?
Employment purposes apply when a business is screening a candidate for hiring, promotion, or reassignment. An employer must provide written disclosure and obtain signed authorization before requesting the report. As indicated by FTC guidance on background screening, the employer must also send a pre-adverse action notice. This notice must arrive before the employer moves toward taking action based on a report. This permissible purpose only covers legitimate employment decisions, not general research on a candidate.
How does a permissible purpose apply to tenant screening?
A permissible purpose applies to tenant screening when a landlord is evaluating a rental application. The landlord must have a genuine, pending application before requesting a report, not a general interest in a prospective tenant. As outlined by CFPB reporting, accuracy and dispute problems remain common in tenant background screening. A property manager relying on this purpose should document the application date alongside the screening request.
What happens if a business pulls a credit report without a permissible purpose?
A business that pulls a credit report without a permissible purpose faces statutory damages and potential regulatory action. As noted by a Department of Justice action, one violation resulted in a 1.2 million dollar civil penalty. The FCRA also lets a consumer recover 100 to 1,000 dollars per violation, even without proof of actual harm.
| Consequence |
What It Means for the Business |
| Statutory damages |
The business owes damages per violation regardless of harm |
| Punitive damages |
Willful violations can add penalties up to 5,000 dollars each |
| Regulatory enforcement |
The FTC or CFPB may open a formal investigation |
| Bureau account suspension |
Reporting agencies may revoke access for a business that failed to comply |
How does a permissible purpose differ for a soft pull versus a hard pull?
A permissible purpose differs for a soft pull versus a hard pull mainly in consumer impact. The underlying legal requirement stays the same either way. In accordance with the FCRA, both pull types remain subject to statutory damages if the certified purpose proves inaccurate.
| Aspect |
Soft Pull |
Hard Pull |
| Consumer impact |
Does not affect the credit score |
Can lower the credit score slightly |
| Common purpose |
Prequalification or account review |
New credit application the consumer initiated |
| Visibility |
Not visible to other lenders |
Visible to other lenders reviewing the file |
What role does consumer consent play in establishing a permissible purpose?
Consumer consent plays a central role whenever a business relies on a purpose that requires written authorization. Employment and some tenant screening purposes cannot proceed without this signed consent on file. As cited by the CFPB's December 2024 proposed rule, expanding data broker obligations are tightening consent expectations further. A business obtaining consent should keep the signed authorization alongside its other compliance records. Following this practice protects a business if a consumer later disputes the reporting agency's decision to release a report.
How do credit bureaus verify a business has a permissible purpose?
Credit bureaus verify a business has a permissible purpose by reviewing its certification and account setup documentation. According to CFPB reporting, the three largest bureaus issue more than 3 billion consumer reports a year. Their files cover 200 million Americans. Each reporting agency requires a signed agreement before providing ongoing report access.
A bureau typically verifies permissible purpose by:
- Reviewing the business's stated use case during account onboarding
- Requiring a signed contract identifying approved permissible purposes
- Auditing sample requests to confirm the stated purpose remains accurate
- Suspending access when a business is found requiring an unauthorized purpose
What compliance risks does a missing permissible purpose create for lenders?
A missing permissible purpose creates compliance risk the moment a lender requests a report without one. As per CFPB enforcement priorities, permissible purpose compliance around data furnishing remains a top supervisory focus. Failing to document a legitimate reason exposes a lender to both consumer lawsuits and regulatory scrutiny.
Compliance risks a lender should actively manage include:
- Requesting reports for marketing purposes without a qualifying firm offer
- Failing to obtain written consent for an employment related purpose
- Allowing staff to pull reports based on personal curiosity, not business need
- Leaving certification records incomplete during a bureau or regulator audit
What is the difference between a permissible purpose and a firm offer of credit?
The difference between a permissible purpose and a firm offer of credit is scope. As stated by the FCRA, a firm offer of credit is the only permissible purpose for a prescreened list. A permissible purpose is the broad legal category, while a firm offer is one narrow type within it.
| Aspect |
Permissible Purpose |
Firm Offer of Credit |
| Scope |
Broad category covering many use cases |
One specific, defined use case |
| Consumer action required |
Varies by purpose type |
None, consumer receives an unsolicited offer |
| Common use |
Credit, employment, tenant screening |
Prescreened credit or insurance marketing |
How can a business document a permissible purpose for compliance audits?
A business documents a permissible purpose for compliance audits by keeping a written record tied to each report request. As outlined by the CFPB, it sent 1.3 million complaints to over 3,400 companies in 2023 alone. This record should include the date, the stated reason, and any related consumer consent obtained.
Documentation a business should maintain for compliance audits includes:
- A written log identifying the permissible purpose behind each request
- Signed consumer authorization forms for purposes requiring consent
- Staff training records showing employees understand approved purposes
- Copies of bureau agreements establishing which purposes are authorized
Choosing a disciplined approach to permissible purpose protects a business from costly compliance failures. iSoftpull helps American businesses run soft pulls with a documented, accurate permissible purpose behind every request. This gives lenders and screening companies a legitimate, compliant way to evaluate applicants without unnecessary legal exposure. Whether a business needs credit, employment, or tenant screening purposes covered, iSoftpull keeps the process accurate and defensible. Businesses ready to build a compliant credit check process should talk to iSoftpull today.