EPPA Compliance Best Practices for Employers

EPPA compliance is a risk-control issue before it is a testing issue. The U.S. Department of Labor states that the Employee Polygraph Protection Act generally prohibits most private sector employers from requiring, requesting, suggesting, or causing an employee or applicant to take a lie detector test, subject to limited exemptions described in DOL EPPA guidance. Employers that treat those exemptions as routine screening tools are likely starting from the wrong premise.

The safer starting point is restraint. A workplace integrity program may include audits, access controls, complaint channels, interviews, document review, and, in narrow situations, polygraph testing. The Act does not make polygraph use impossible for every employer, but it does set strict boundaries around who may be tested, why testing may occur, what notices must be given, how records must be kept, and how results may be used.

EPPA Compliance Starts With The Prohibition

Why EPPA Compliance Applies Before Testing

The first employer question should not be whether a test would be useful. It should be whether the law allows the employer even to request, suggest, or cause the test. That distinction matters because the statute reaches conduct before an examination occurs. A manager who informally pressures an applicant or employee can create exposure even if no test is completed.

A useful EPPA compliance habit is to separate general workplace concern from a legally recognized basis for testing. General distrust, a poor interview impression, a missing inventory item without a focused inquiry, or a desire to screen applicants for honesty will not, based on the research supplied here, satisfy the Act’s ordinary private-employer limits. Employers should document why they believe an exception may apply before contacting an examiner.

Where Exceptions May Apply

The research identifies several categories where exemptions may be relevant. They include prospective employees of certain security service firms, such as armored car, alarm, and guard services; certain pharmaceutical manufacturers or distributors; and current or prospective employees tied to a specific workplace investigation involving theft, embezzlement, or economic loss. Those categories should not be read loosely. They are conditions to analyze, not labels to apply after a decision has already been made.

For an investigation-based exam, the employer must have a specific ongoing investigation involving economic loss or injury, the employee must have had access to the property at issue, and the employer must have reasonable suspicion that the employee was involved. A broad desire to reduce losses across a facility is not the same as a specific inquiry into a defined incident.

Written Notices, Records, And Examiner Controls

Investigation Statements And Retention

Documentation is one of the clearest safeguards. The research states that an employer invoking an exemption must provide a written statement, signed by someone other than the examiner, identifying the economic loss, the basis for suspicion, and the employees to be tested. That statement must be retained for at least three years.

For EPPA compliance, records should show the decision path rather than merely the result. Employers should preserve the written statement, notices provided to the examinee, relevant test details, and records of any adverse action based on polygraph results. A file that contains only a final employment action, without the pre-test basis and required notices, may leave the employer unable to show that the process met statutory conditions.

Employee Rights During A Permitted Exam

Even when an exemption may allow testing, the process remains rights-based. The research states that examinees must receive written notice about their rights and the limits imposed by the Act before the test. It also states that examinees have the right to refuse or discontinue a test without fear of discipline. Employers should train supervisors not to contradict that notice orally, since a casual statement from management can undermine written safeguards.

Confidentiality also requires attention. Test results must be kept confidential, and disclosure to unauthorized persons is prohibited. From a practical standpoint, that means limiting access to those with a legitimate role in the permitted investigation or decision process, avoiding broad distribution by email, and keeping polygraph files separate from general personnel material when appropriate under the employer’s records practice.

The examiner’s role is not a formality. The research states that polygraph examiners must satisfy EPPA licensing, bonding, or liability insurance requirements. It also identifies regulated phases of a permitted test: pre-test, testing, and post-test. Employers should confirm those basics in writing before scheduling, because a qualified examiner cannot cure an employer’s defective basis for testing, and a valid employer reason cannot cure a deficient examination procedure.

Policy Risks From State Rules And New Tools

Compliance team discussing software screening risks in a conference room

More Protective Laws And Agreements

Federal compliance is not always the final standard. Under 29 CFR 801.5, EPPA does not preempt state or local laws that are more restrictive with respect to lie detector tests, and it does not override collective bargaining provisions that provide greater protections. That means an employer may satisfy the federal rule and still face a stricter state, local, or contractual limit.

EPPA compliance also belongs in policy review, not only in investigation response. Multi-state employers, unionized workplaces, security contractors, pharmaceutical employers, and companies with remote hiring processes should confirm which rule provides the higher employee protection before drafting a testing notice or requesting an exam.

AI And Other Deception Screening Tools

The research notes that Department of Labor guidance has addressed technologies labeled as alternatives to traditional lie detection, including tools that analyze voice patterns, facial micro-expressions, or similar indicators and suggest whether someone is lying. Employers should be cautious about assuming that a tool is outside the Act simply because it is marketed as software rather than as a polygraph service.

A practical review asks what the product claims to do. If the tool is used to detect deception or suggest truthfulness in employment screening or workplace investigation, the employer should treat the issue as potentially governed by lie detector restrictions unless a reliable compliance review says otherwise. Product labels should not replace statutory analysis.

Penalty exposure gives this review more weight. The research states that for violations assessed on or after January 16, 2025, the maximum civil monetary penalty for most EPPA violations increased to $26,262 per violation, compared with $25,597 for violations assessed on or before January 15, 2025. As of September 16, 2026, that penalty figure makes preventive review more practical than correction after an unsupported test request.

Employer Practice For Employee Polygraph Protection Act

A Practical Pre-Test Review

Before any permitted test is scheduled, employers should pause long enough to answer a small set of control questions. The point is not to slow a legitimate investigation. It is to keep the employer from converting a workplace concern into an unlawful testing request.

  • Is the employer covered by the Act’s private-sector restrictions?
  • Is there a specific exemption, rather than a general desire to screen for honesty?
  • For an investigation-based exam, is there a specific economic loss or injury?
  • Did the employee have access to the property or issue under investigation?
  • Is reasonable suspicion documented before the test is requested?
  • Has the required written statement been prepared and signed by someone other than the examiner?
  • Has the examinee received the required written notice of rights?
  • Has the examiner’s licensing, bonding, or insurance status been checked?
  • Are state, local, and collective bargaining standards more protective?
  • Will records be retained for at least three years?

Employers reviewing broader workplace testing policies may also find it useful to compare these safeguards with related employer polygraph test limits, especially where managers need plain-language rules for investigations. For those comparing resources across the same publishing network, they can explore similar topics on Stuyvesant YC, a related site offering further insights on managerial decisions and compliance within different contexts.

How To Communicate Without Overstating The Result

A measured EPPA compliance process should also control internal messaging. Employees should not hear that a polygraph result is treated as automatic proof of misconduct. The research provided here supports strict procedural rules, confidentiality, refusal rights, and limits on permitted testing; it does not support presenting any result as a stand-alone guarantee of truth or deception.

Good communication is direct: explain the specific investigation, provide the required notice, identify the voluntary rights described by law, protect confidentiality, and avoid threats that conflict with the examinee’s right to refuse or discontinue where that right applies. Managers should be told not to improvise. Scripts and written notices should be reviewed before use, especially in remote or hybrid settings where required posting and notice practices may differ from a single physical workplace.

The most defensible employer practice is to treat polygraph testing as a narrow, regulated tool within a larger integrity system. That system should favor evidence quality, documented reasons, limited access to sensitive information, qualified examiners, and respect for employee rights. Used that way, the process can support a workplace investigation without promising certainty or substituting pressure for proof.