ATS compliance is about evidence: your system should preserve who did what, when, and to which candidate, job, offer, export or permission.
- ATS compliance is about evidence: your system should preserve who did what, when, and to which candidate, job, offer, export or permission.
- Do not treat candidate history, activity feeds and audit logs as the same thing. Audit logs are stronger evidence, but may sit behind higher-tier plans.
- EEOC guidance says many hiring records must be kept for one year; OFCCP-covered contractors generally need two years, with a smaller-contractor exception.
- Greenhouse is the strongest featured fit if you need enterprise-grade auditability, but its audit log is tied to Pro and shows the previous 30 days in-app.
- BambooHR is a practical SMB fit if you want HRIS, ATS and compliance training together, but its ATS job openings are capped at 5, 25 or 50 by plan.
Choosing an ATS for compliance is not the same as choosing one with a compliance badge on its website. The real test is whether the system can prove what happened in a hiring process after the fact.
For regulated recruiting teams, ATS compliance and audit trail features should answer plain questions. Who saw a candidate record? Who changed a stage? Who exported data? Who changed a permission? What evidence can you produce if legal, security or a regulator asks?
This guide explains what to verify before signing an ATS contract. It focuses on record retention, audit logs, access controls, exports, background-check evidence and AI-hiring governance, rather than broad feature lists.
What do ATS compliance and audit trail features actually mean?
A useful compliance setup preserves hiring evidence in a form your team can retrieve. At minimum, it should show who did what, when they did it, and which candidate, requisition, job, offer, permission, export or integration was affected.
That sounds simple, but vendors often blur different controls together. Legal recordkeeping, security monitoring, privacy controls, background-check workflows and AI governance are related, but they are not the same job.
A candidate status history may show that someone moved from phone screen to rejected. That helps recruiting operations, but it may not show who exported the candidate list, who changed an interviewer’s access, or which API key touched the record.
The audit trail only matters if you can get it out. If the log exists in a screen that cannot be searched, filtered or exported, it may not satisfy your legal, security or reporting needs.
Which hiring records should your ATS preserve?
Your ATS should preserve the evidence behind each hiring decision, not just the final candidate status. That usually means applications, CVs, interview notes, scorecards, status changes, disposition reasons, offers and approvals.
For roles that involve checks, the system should also retain consent records, background-check steps and review outcomes. BambooHR, for example, lets users initiate background checks and track statuses such as Consent Requested, Processing, Approved and Consider, but buyers still need to confirm retention and reporting details.
Retention rules vary by employer type and jurisdiction. EEOC guidance says employers must keep personnel or employment records for one year, and its background-check guidance says application forms and hiring-related records must be preserved for one year after the record was made or the personnel action was taken, whichever is later.
Covered federal contractors face different expectations. OFCCP guidance says Internet Applicant and Traditional Applicant records generally must be preserved for two years, with a one-year exception for contractors with fewer than 150 employees or less than $150,000 in a federal contract or subcontract.
Do not rely on an ATS vendor to interpret every rule for your company. The software can support evidence collection and retention workflows, but counsel should confirm your actual obligations.
Audit log, activity feed or candidate history: what is the difference?
Candidate history is record-level context. It helps a recruiter see what happened to one applicant, such as stage moves, notes, scorecards or application status changes.
An activity feed is broader, but still often built for day-to-day recruiting. It may show user actions across jobs or candidates, yet it may miss security-grade details such as API usage, permission changes or export events.
An audit log is stronger compliance evidence. Greenhouse is a useful example because its Audit Log FAQ says the audit log is more comprehensive than the change log or activity feed, and includes metadata, API key usage and other data not included in the change log.
The catch is plan access and retention. Greenhouse lists Audit log under its Pro plan, and its FAQ says the audit log shows the previous 30 days in-app. Longer paper trails require exports through Business Intelligence Connector to Redshift or S3, or saving payloads from the Audit log API.
Ask vendors exactly which events are logged. Permission changes, exports, deletions, API activity, integration actions and data-access events matter more than a vague promise that the system tracks activity.
What should be on your compliance buying checklist?
Start with the plan being quoted. A feature that exists somewhere in the product is not useful if your contract does not include it.
Ask for the exact event list captured by the audit log. The better answers include actor, timestamp, target object, source, IP address where available, before and after values where available, and metadata.
Then ask how long logs are retained in-app, and how they leave the system. For compliance-heavy teams, exports to an API, SIEM, S3, Redshift or a data warehouse can matter more than a tidy admin screen.
Access controls need the same scrutiny. EEO, veteran, disability and demographic responses should be stored separately where required, with restricted access and clear reporting boundaries.
Retention and deletion workflows should be tested, not assumed. Ask about retention rules, legal holds, candidate deletion, consent tracking and what happens when a candidate asks for their data to be removed.
AI features need their own evidence pack. If a vendor uses screening, ranking, matching or recommendations, ask for bias-audit support, model-governance documentation, notices and human-review controls. In New York City, employers and employment agencies face specific automated employment decision tool rules, including annual bias-audit requirements and public audit information.
Greenhouse: the fit if enterprise auditability matters more than price
Greenhouse is the strongest featured option here if your recruiting team needs enterprise-grade auditability and structured hiring controls. It is still ranked 19th in ATSLab’s overall index, so this is a use-case recommendation rather than a claim that it is the best fit for everyone.
Greenhouse’s public pricing is custom. Its pricing page lists Core, Plus and Pro, with pricing based on plan, hiring volume, organisational complexity and required workflows. ATSLab records Greenhouse as From ~$6k.
The compliance case is strongest on Pro. Greenhouse lists Audit log under Pro, and its Audit Log FAQ says the audit log is available to the Pro subscription tier, with the previous 30 days visible in-app.
For longer evidence trails, Greenhouse says customers can export through Business Intelligence Connector to Redshift or S3, or save payloads from the Audit log API. That is useful for security and data teams, but it also means procurement should confirm export setup, retention design and any implementation needs before signing.
Greenhouse’s security page lists single sign-on, SCIM provisioning, audit log API, permissions approvals, annual third-party penetration testing, encryption in transit and at rest, annual SOC 1 Type 2 and SOC 2 Type 2 audits, plus ISO 27001:2022, ISO 27701:2019 and ISO 42001:2023 certifications.
The limitation is that audit logging is not intrusion detection. Greenhouse says the audit log does not include intrusion detection, although customers can connect it to third-party monitoring tools. Confirm the Pro cost, sandbox needs, security requirements and export method in writing.
Lever: the fit if your ATS and CRM teams need API audit events
Lever is a better fit if your team wants ATS and CRM workflows in one platform, and your security team cares about API-accessible audit events. ATSLab ranks Lever 9th overall and records it as From ~$4k.
Lever’s public pricing is quote-based. Its pricing page says pricing scales by team size and hiring needs, and that every plan includes its core ATS, CRM, advanced reporting and analytics, and key integrations.
The audit detail is the main reason to include Lever in a compliance shortlist. Lever’s developer documentation includes an Audit Events API endpoint, GET /audit_events, with categories such as user provisioning, user authentication and data export.
The API also supports filters including event type, user ID, target type, target ID, and created-at start and end timestamps. That helps if your security or data team wants to investigate activity without relying only on screenshots from an admin panel.
Lever’s security page states that its programmes and practices are independently verified against SOC 2 and ISO 27001 frameworks. It also states SOC 2 Type 2, ISO/IEC 27001, GDPR and CCPA support, TLS-encrypted transport, AES-256 encryption at rest, role-based access control, and rolling 6-month application and system log retention.
The commercial caveat is the same as with most enterprise tools. Confirm audit-event availability, retention, export limits, AI governance evidence and any add-on costs in the contract, especially if Lever AI is part of the evaluation.
BambooHR: the fit if SMB compliance sits inside HR operations
BambooHR is the practical fit if a smaller company wants recruiting, onboarding, employee records and compliance training in one HRIS-first system. ATSLab ranks BambooHR 8th overall and records it as From ~$250.
BambooHR’s pricing page says companies with 25 employees or fewer have a flat monthly rate starting at $250/month. It also offers a free trial with no credit card required, and the trial ends automatically.
The limitation is ATS scale. BambooHR lists applicant tracking limits by plan: Core has 5 job openings, Pro has 25, and Elite has 50. That may suit an SMB, but it can frustrate a team running many requisitions at once.
The compliance training angle is useful for smaller HR teams. BambooHR’s pricing page includes Compliance Intelligence by Virgil HR, with training limits of 1 course on Core, 15 on Pro and 300+ on Elite.
BambooHR’s Trust Center lists certifications including SOC 1, SOC 2 Type 2, PCI DSS, EU-US DPF, UK Extension to EU-US DPF, and Swiss-US DPF. Its data processing agreement says access to data is logged, monitored and tracked.
For hiring evidence, BambooHR’s Applicant Tracking API can return full application details, including applicant information, job details, questions and answers, and status history. That is useful, but do not treat BambooHR as an enterprise audit-log platform unless the vendor confirms your exact audit exports and retention controls.
How much does a compliance-focused ATS cost?
Compliance-focused ATS pricing depends less on the headline subscription and more on the plan gates. Audit logs, advanced permissions, exports, sandbox environments, BI connectors and implementation work can sit outside the cheapest package.
Greenhouse and Lever use quote-based public pricing, while ATSLab records Greenhouse as From ~$6k and Lever as From ~$4k. Those figures help with early budgeting, but they are not a substitute for a written quote.
BambooHR is more transparent for small companies, with ATSLab recording From ~$250 and BambooHR stating a flat monthly rate starting at $250/month for companies with 25 employees or fewer. The trade-off is the job-opening cap by plan.
Watch the surrounding costs. Paid job ads, background checks, SMS, sourcing data, data exports, implementation, sandbox environments and BI connectors may be separate commercial items depending on the vendor and contract.
The cleanest buying process is to turn compliance needs into a requirements matrix. Ask each vendor to mark included, paid add-on, unavailable or requires services against every requirement.
What should you confirm before signing the contract?
Before procurement closes, confirm the exact plan name, audit-log inclusion, retention window, export options and support for legal holds or deletion workflows. Do not accept a demo answer if the contract says something narrower.
Request the security evidence your company needs. That may include SOC reports, ISO certificates, the data processing agreement, subprocessors, data residency options and incident-response commitments.
Ask for a sample audit-log export and a sample candidate-record export. The sample should show the fields, filters, timestamps and identifiers your legal, security and recruiting operations teams would rely on during an investigation.
If AI features are enabled, ask how the vendor supports transparency, bias-audit requests, candidate notices and human review. AI can speed screening, but the documentation burden can grow if the feature affects employment decisions.
Finally, make legal, security, HR and recruiting operations review the same requirements matrix. Compliance failures often happen because each team assumed another team had checked the evidence trail.
Frequently asked questions
What is an ATS audit trail?
An ATS audit trail is a record of important system activity, such as user actions, permission changes, exports, API activity and changes to hiring records. It is stronger than a candidate history or activity feed if it captures actor, timestamp, target object and metadata, and if it can be exported when needed.
Is Greenhouse a good ATS for compliance and audit trails?
Greenhouse is a strong fit for enterprise teams that need auditability, structured hiring and security evidence. The catch is that Greenhouse lists Audit log under Pro, its FAQ says the previous 30 days are shown in-app, and longer paper trails require exports through BI Connector or the Audit log API.
Is Lever better than Greenhouse for audit logs?
Lever may be the better fit if you want ATS plus CRM workflows and API-accessible audit events. Greenhouse is the stronger featured option for enterprise-grade auditability in this guide, while Lever’s Audit Events API is useful for teams that need filters by event type, user, target and timestamp.
Can BambooHR handle ATS compliance for a small business?
BambooHR can suit SMBs that want HRIS, ATS, employee records and compliance training together. It is not the right fit if you need a highly specialised enterprise audit-log setup, and its ATS job openings are capped at 5 on Core, 25 on Pro and 50 on Elite.
How long should recruiting records be kept in an ATS?
EEOC guidance says many employment and hiring records must be kept for one year. OFCCP guidance says covered federal contractors generally need to preserve Internet Applicant and Traditional Applicant records for two years, with a one-year exception for smaller contractors under stated thresholds. Confirm your exact obligations with counsel.