Interviews
Andrew Johnson, CEO of Yardstik – Interview Series

Andrew Johnson, CEO of Yardstik, is an experienced technology executive with a background in scaling high-growth software companies, building go-to-market organizations, and driving enterprise revenue. He joined Yardstik as Chief Operating Officer in 2022 before being promoted to CEO in October 2024. Previously, Johnson served as Chief Revenue Officer at Branch, where he helped guide the workforce payments company through a period of rapid growth, and spent more than five years at Dialpad, including as Head of Enterprise Sales, where he helped build its U.S. and Canadian sales operations. Earlier in his career, he held business and partner development roles at Compellent Technologies, which was acquired by Dell for approximately $960 million in 2011.
Yardstik is a Minneapolis-based workforce trust technology company founded in 2020 that provides fraud prevention, identity verification, background screening, credential verification, and continuous workforce monitoring through its Human Trust Platform. The company is built around an API-first architecture that allows its technology to be integrated directly into applicant tracking systems, human capital management platforms, gig marketplaces, and other workforce applications. Yardstik also supports the Model Context Protocol (MCP), enabling AI agents to connect with its trust infrastructure and automate workflows such as background checks, identity verification, credential screening, re-screening, and adjudication within AI-driven hiring and onboarding systems.
Before joining Yardstik, you spent more than five years at Branch, where you saw firsthand a fraud ring using stolen Social Security numbers to obtain jobs under other people’s identities. How did that experience change the way you thought about background screening, and when did you realize identity verification needed to extend beyond a one-time check at hiring?
When I was at Branch, one of our biggest customers got hit by a fraud ring out of Venezuela, something gig platforms broadly get hit with. They were stealing Americans’ Social Security numbers and selling them to people who didn’t have status to work in the U.S. Someone would apply under a stolen identity, start delivering, and everything looked fine until tax season, when the actual SSN holder got a 1099 bill for work they never did. That was the first time I watched fraud show up on the other side of a hiring decision instead of during it.
The moment that really reframed things for me. I realized how often people who pass a background check aren’t the person who shows up for the job. For example, someone with a clean record completes the screen, then a family member who couldn’t have passed it takes the actual shift. A background check has no way to catch that, because it only ever looks at the applicant on paper, once, at the very start. By the time I joined Yardstik, I brought what I learned during my experience at Branch and worked with the team to build the continuous monitoring approach for our customers.
Generative AI has dramatically lowered the barrier to creating fake identities, forged credentials, synthetic profiles, and even convincing deepfakes. Which AI-enabled fraud techniques are advancing fastest today, and which do you believe employers are least prepared for?
The fastest-moving fraud right now isn’t the flashy deepfake video. It’s synthetic identity: a real Social Security number mixed with a fake name and a fabricated work history, stitched together into something that looks clean the first time anyone checks it. Add AI tools that generate a polished resume and a matching set of credentials, and you’ve got an applicant.
What employers are least prepared for is the remote, never-met-in-person hire. Gig platforms, remote IT roles, virtual call centers. If nobody at the company ever sees this person, every signal that used to catch a fraudster (a nervous interview, an ID that looks a little off in person) disappears. That’s exactly where remote-hiring fraud rings have been operating and most companies still treat it as someone else’s problem until it happens to them.
Yardstik has moved from traditional background screening toward a broader platform combining AI fraud prevention, identity verification, credential verification, and continuous monitoring. What role does AI play in connecting those signals, and what can the system detect that a conventional background check cannot?
Yardstik started as a background screening company, and for most customers that’s still a foundational piece of what we do. But a background check is a single transaction: run it, get an answer, throw the data away. What connects fraud prevention, identity verification, credential checks and monitoring into one thing is that we don’t throw the data away. We keep a profile on a candidate over time, and every new check adds to it instead of starting from zero.
That’s what lets us catch things a one-time check never will. For example, a customer of ours had fraudsters repeatedly trying to get into agent accounts with access to customer tax data. Because we could see the same device, or the same slightly altered identity, show up across multiple attempts, we could stop it before it ever became a screening decision. A one-time check would have looked at each of those applications in isolation and passed every one of them.
Yardstik uses signals such as personal identity data, payment activity, and device or location indicators to uncover potential identity deception. How do you separate genuinely suspicious behavior from unusual but legitimate behavior, particularly as AI models become responsible for evaluating increasingly complex patterns?
We don’t try to draw a hard line between suspicious and unusual, because most of the time there isn’t one at the moment we see it. What we do is surface the delta. If someone’s application says one school, and a year later a new application under the same identity says a different school, that’s worth a second look. If someone’s always applied from an iPhone and shows up on an Android with a new IP address, same thing. Neither one means fraud on its own but multiple signals combined start to elevate the risk profile. We’re the layer that flags what’s changed since the last time we saw someone and provide employers with more data to help them make informed decisions.
Yardstik says roughly one in 30 applicants fails government ID verification, while flagged or duplicate Social Security numbers are blocked on a daily basis. What are you learning from that data about how workforce fraud is evolving, and how much of what you encounter appears organized rather than opportunistic?
That data tells us identity fraud in hiring isn’t a fringe problem anymore. It’s become a baseline cost of doing business at any real scale, the same way chargebacks are baseline in payments. A meaningful share of it looks organized rather than opportunistic. Opportunistic fraud tends to be a one-off: someone pads a resume, or fudges a graduation date. Organized fraud shows a pattern, the same device or the same near-identical identity attempting the same kind of job across different employers, sometimes changing one detail at a time to see what gets through. That’s the version I saw years ago with stolen SSNs being resold, and it’s the version I still see today. It’s just automated now, and running at a much higher volume because generative tools made the fake identities cheaper to produce.
Identity verification increasingly incorporates government IDs, biometrics, liveness checks, device signals, and other risk indicators. As generative models become more capable of producing realistic documents, faces, and voices, which signals do you believe will remain hardest for attackers to fake?
Anything you can generate as a single artifact, a photo, a document, even a short video, keeps getting easier to fake convincingly. What stays hard to fake is consistency over time, across places nobody controls together. A synthetic identity can pass one liveness check with a good enough deepfake. It’s much harder for that same identity to also have a matching device history, a matching location pattern, and a work history that lines up the way an actual person does across employers and years. That’s really the bet behind continuous monitoring instead of a single verification moment. A legacy check gives you a photograph, one frame, taken once. Ours behaves more like a live feed, because it’s built to notice when the frames stop matching each other.
Continuous monitoring represents a major shift from verifying someone once to evaluating trust throughout the worker lifecycle. How do you design that type of system without creating unnecessary surveillance, false positives, or decisions that workers have little ability to understand or challenge?
Surveillance is watching someone who doesn’t know they’re being watched. That’s not how this works. Every worker we monitor has given written consent, they know exactly what’s being checked, and by law we have to give them a copy of anything we find and a way to dispute it if it’s wrong. None of that is optional. It’s FCRA.
The other piece is that we don’t make the call ourselves. If an arrest shows up on someone we’re monitoring, that’s a flag for the employer to look into, not a verdict. Due process still applies. Employers must notify the candidate, give them a chance to respond, and then make a final determination. cOur job stops at surfacing that something changed; the employer decides what it means and what to do about it, the same way they would with a check at hire. We built it that way on purpose.
As recruiting and workforce management become increasingly agentic, where should the boundary sit between an AI agent gathering and evaluating trust signals and actually making a consequential hiring decision?
I’d put the line where the law already puts it for us today. We’re careful not to call ourselves an AI company because our industry has a hard requirement that a human be in the loop on anything touching a dispute or an adverse decision. An agent can gather signals, score them, flag what’s changed. What it shouldn’t do on its own is decide if someone doesn’t get the job or doesn’t keep it, because that decision needs to be attached to a person who’s accountable for it and can explain it if it’s challenged.
As hiring gets more automated end to end, I think that boundary gets more important, not less. The easier it becomes to let an agent run the whole funnel, the more tempting it is to also let it make the call at the end. Gathering and evaluating trust signals is exactly what software should be doing faster. Deciding a person’s livelihood isn’t something I’d hand off at all.
With the new $30 million Series B bringing Yardstik’s total funding to $65 million, which areas of AI and fraud prevention do you believe now warrant the biggest investment, and what technical problems still need to be solved for continuous identity verification to work at much larger scale?
We’re putting the new capital into the parts of fraud prevention that are the least glamorous and the most expensive to build well. Motor vehicle report and OIG exclusion monitoring. Automated alerts the moment a license, an insurance policy, or a certification lapses, instead of waiting for the next renewal cycle to notice.
The technical problem nobody in this industry has solved is cost. Many countries and states charge their own fee to pull a record, sometimes over $100 for a single pull in a place like New York, and that cost doesn’t drop just because you want to check someone more often. Making continuous verification affordable enough that a company with thousands of gig workers can actually run it monthly instead of once a year is as much a data-sourcing and pricing problem as it is a machine learning problem. It’s the one I think about most right now.
There is an interesting arms race emerging: AI is simultaneously making identity fraud easier and giving platforms better tools to detect it. As both sides improve, do you expect proving that someone is genuinely who they claim to be to become substantially harder, or will AI ultimately make digital identity more trustworthy than it has ever been?
Both are true, and I don’t think one cancels the other out. Our customers often tell us they expect us to be able to “fight fire with fire.” They know that we need modern solutions to modern problems. My honest read is that digital identity gets more trustworthy for the systems built to track someone over years and across platforms, and it gets less trustworthy for anything still betting on a single point-in-time check. This means businesses that only ever verified someone once are going to be the ones left exposed, and the ones who built for the long view are going to look a lot smarter in hindsight than they probably feel today.
Thank you for the great interview, readers who wish to learn more should visit Yardstik.












