# The Candidate-Screening Tool Clearance Standard

*You can grade any automated candidate-screening or ranking tool against four overlapping rulebooks and return one verdict: deploy, restrict, or pull.*

- Canonical URL: https://www.refolk.ai/guides/candidate-screening-tool-clearance-standard
- Pillar: Process, data, and compliance
- Format: Standard
- Published: 2026-08-24
- Last reviewed: 2026-08-24
- Reading time: 15 min

Deciding whether an automated tool that scores, ranks, or filters job candidates is cleared to switch on is not one question. It is four overlapping questions - NYC's AEDT rule, the EU AI Act, Colorado, and Illinois - that share no definition, no deadline, and no format. This is the pass/fail rubric for recruiting operations, revenue operations, and anyone answerable for how a hiring decision got made, so two reviewers grade the same tool the same way and return one verdict: deploy, restrict, or pull.

Every ranking guide explains one regime in isolation and leaves you to reconcile the rest. This one grades against the union. It tells you what each criterion proves, and what it looks like when the criterion lies.

## What counts as an in-scope screening tool

A tool is in scope when it applies machine learning, statistical modeling, data analytics, or AI to issue a simplified output - a score, a classification, or a recommendation - that substantially assists or replaces a discretionary hiring or promotion decision. If it only retrieves, sorts alphabetically, schedules, or filters spam, it is out.

Under NYC Admin Code § 20-870 and the DCWP Final Rule (6 RCNY 5-300 to 5-304), an Automated Employment Decision Tool, or AEDT, is any computational process that issues that simplified output. The Final Rules narrow it to processes where a computer identifies the inputs and their relative importance to improve prediction accuracy. "Substantially assist or replace" has a precise meaning: the tool does one of three things.

- Scores, classifies, or ranks applicants based on only one factor.
- Gives more weight to a simplified output than to other criteria.
- Uses a simplified output to overrule conclusions from human decision-making.

What is out of scope matters as much. A search engine that retrieves resumes without ranking them, a scheduling tool that books interviews, and a spam filter applied to incoming applications are all excluded. The bright line is retrieval versus ranking.

> **Rule:** The scope test is about output, not intent
>
> A spreadsheet that sorts applicants alphabetically is not an AEDT. Software that assigns a fit score and auto-rejects below a threshold is. What the tool produces decides scope, not what you call it.

The other three regimes draw their own lines and do not borrow NYC's. The EU AI Act classifies recruitment and candidate-screening AI as high-risk under Annex III point 4, a classification untouched by any deadline change. Colorado's replacement law turns on whether an automated decision-making tool influences a consequential decision. Illinois HB 3773 amends the Human Rights Act and reaches "AI" used in covered employment decisions with no audit concept at all. One tool can be in scope for all four under four different definitions, which is why a single clearance is the wrong mental model.

## The four rulebooks side by side

Here is the union you are grading against. No two rows share a trigger, a notice mechanism, or a binding date, so read across the row for each regime that applies to your roles and locations.

| Regime | Mandatory bias audit? | Candidate/worker notice | Key compliance date |
|---|---|---|---|
| NYC LL144 | Yes, independent, annual | 10 business days advance | Enforced Jul 5, 2023 |
| EU AI Act Annex III | No formal bias audit; risk mgmt + FRIA | Inform workers before use | Dec 2, 2027 |
| Colorado SB 26-189 | No (impact-assessment mandate dropped) | Notice + 30-day adverse-outcome disclosure | Jan 1, 2027 |
| Illinois HB 3773 | No | Required, timing set by IDHR rulemaking | Jan 1, 2026 |

Two facts on this table move and will keep moving. Colorado's original SB 24-205 was repealed before it ever took effect; the replacement, SB 26-189, takes effect January 1, 2027, after a federal court paused enforcement and the governor signed the new bill. The EU date deferred by 16 months: Regulation (EU) 2026/1744, the Digital Omnibus on AI, was published in the Official Journal on July 24, 2026 and entered into force on July 27, 2026, pushing Annex III standalone high-risk systems to December 2, 2027. Do not hardcode either into policy. Record the mechanism - a rulemaking, a repeal, an omnibus - and re-check the source before each annual review.

> **Watch out:** The deadline moved, the classification did not
>
> The EU deferral covers only the Annex III substantive-obligations date. The classification duty under Article 6 was unaffected, and Article 50 transparency plus Article 4 AI-literacy duties stayed on the August 2, 2026 timeline. "The deadline moved so we're fine" is a failure mode, not a clearance.

## What the bias audit must actually calculate

A compliant Local Law 144 bias audit calculates, at minimum, the selection or scoring rate and its impact ratio across three dimensions: sex categories, race/ethnicity categories, and intersectional categories combining sex with race or ethnicity. Anything less is not an audit that clears.

The categories come from the EEOC EEO-1 Component 1 report. The impact ratio is each category's selection or scoring rate divided by the highest-scoring category's rate. Scoring rate has a specific definition: the share of a category scoring above the sample median. Categories representing less than 2% of the data may be excluded from the impact-ratio calculation, which keeps thin cells from producing noise.

The 0.80 line is where practitioners misread the standard. Four-fifths is a federal EEOC benchmark that triggers regulatory attention, not a statutory Local Law 144 pass/fail line. Falling below 0.80 does not automatically mean a violation. It means you examine, document, and justify - or you restrict.

#### What a compliant bias audit produces

1. **Gather data** - Historical selection data, or disclosed test data if history is thin
2. **Compute rates** - Selection or scoring rate per EEO-1 sex and race/ethnicity category
3. **Compute ratios** - Each category rate divided by the highest-scoring category rate
4. **Add intersections** - Repeat for sex combined with race or ethnicity
5. **Grade** - Compare ratios to 0.80, document review for anything below

*An audit that stops before impact ratios and intersectional breakdowns is not a clearance.*

### Who counts as an independent auditor

NYC defines independence narrowly. An independent auditor is a person or group capable of exercising objective and impartial judgment, and is not independent if it was involved in using, developing, or distributing the tool, has an employment relationship with the employer or vendor, or holds a financial interest. DCWP maintains no approved list, so the selection is your responsibility and part of what you must be able to defend.

A vendor audit can be reused, but it does not transfer the legal duty. The Final Rule treats the employer, not the vendor, as the responsible party, and Illinois and Colorado likewise keep the deployer accountable for third-party tools. If you rely on a vendor's public audit, verify it is current, covers your exact configuration, and includes your use case where required.

## The clearance procedure

Run these steps in order. The output is a defensible file for each tool: a classification, an audit, a verdict, and the notice and oversight controls that back it up. Assign an owner and a done-condition to each step so the work does not stall between legal and RecOps.

#### From inventory to verdict

1. **Inventory and classify every scoring tool** - Map every tool that scores, ranks, or screens candidates, including features embedded in HR platforms, and label each as provider or deployer. Done means a written in-scope or out-of-scope determination with reasoning. Shadow AI procured by business units is the most common gap.
2. **Determine scope per jurisdiction** - Apply NYC's substantially-assist-or-replace test, EU Annex III point 4, Colorado's consequential-decision test, and Illinois's covered-decision list. Done means a scope memo naming which regimes bind for which roles and locations. Record reasoning for close cases like multi-class classifiers.
3. **Commission the independent bias audit** - Engage an auditor with no development, distribution, or financial tie to the tool or vendor, and provide historical selection data. Done means a report with selection or scoring rates and impact ratios across every EEO-1 category plus intersectional combinations. State and justify any test-data use.
4. **Grade results against the 0.80 threshold** - Examine impact ratios against four-fifths, treating anything below as a trigger for review, not an automatic fail. Done means a documented deploy, restrict, or pull decision tied to specific ratios. A restrict verdict names the allowed roles or configurations.
5. **Publish the audit summary** - Post the selection and scoring rates, impact ratios, and audit distribution date on a public careers URL. Done means a live link with actual numbers and demographic breakdowns, kept posted at least six months after the tool's latest use.
6. **Stand up per-candidate notice** - Configure the ATS to send in-scope candidates a 10-business-day advance notice listing the characteristics assessed and a real alternative route. Done means every in-scope candidate receives notice before evaluation, verified in the workflow.
7. **Implement EU deployer controls** - Put human oversight, six-month log retention, worker information, and a FRIA where required in place ahead of December 2, 2027. Done means oversight logs and, where triggered, a FRIA on file for the exact deployed system.
8. **Re-audit and monitor annually** - Renew the audit at least every 12 months, and trigger a fresh audit on any retraining or reconfiguration inside that window. Done means a current audit matching the exact deployed configuration.

Inventory takes RecOps and legal one to two weeks; the scope memo, days; the audit itself, two to six weeks depending on data readiness. Publishing the summary is a one-day task once the audit lands. Notice configuration takes one to two weeks of ATS work because it usually needs workflow changes, not a copy edit.

## Reading the verdict: deploy, restrict, or pull

The verdict is a two-variable judgement: how clean the impact ratios are, and how complete the surrounding controls (notice, publication, oversight) are. A tool with clean ratios but no candidate notice is not a deploy. A tool with a marginal ratio but full controls and a real alternative process is a restrict, not a pull.

#### The clearance verdict

Horizontal axis runs from Controls incomplete to Controls complete. Vertical axis runs from Ratios marginal or below 0.80 to Ratios clean.

| Quadrant | What it means |
| --- | --- |
| Ratios clean, controls incomplete | Restrict: hold until notice, publication, and oversight are live |
| Ratios clean, controls complete | Deploy: monitor and re-audit within 12 months |
| Ratios marginal, controls incomplete | Pull: no audit backing and no candidate protection |
| Ratios marginal, controls complete | Restrict: narrow to defensible roles, document review, offer a real alternative |

*Impact-ratio health on one axis, control completeness on the other, decides deploy, restrict, or pull.*

Grade each binding regime separately and take the strictest result across them. A tool that earns deploy in NYC can still owe an EU Fundamental Rights Impact Assessment and an Illinois notice, and until those are on file the honest verdict is restrict.

> A tool cleared in NYC still carries open EU and Illinois duties. Grade each regime and take the strictest verdict.

The people who own these obligations are scarce and unevenly placed, which shapes how fast you can staff the work. In Refolk's index of professional profiles, dedicated AI-governance titles outnumber their nearest comparator by roughly 11.5x in the US versus Germany, and Recruiting or TA Operations titles by roughly 7.7x US versus UK. The staff who own EU deployer obligations are thinnest exactly where the December 2027 deadline bites.

**11.5x - US vs Germany supply of exact-title AI-governance professionals in Refolk's index**

23 in the US against 2 in Germany, so the people who own EU deployer duties are hardest to hire where the Annex III deadline lands.

When you need to find those owners rather than post and wait, describing the exact accountability in plain English beats keyword filtering.

I ran this search: `AI governance leads at US banks and insurers who own algorithmic hiring compliance` - [see the full result list](https://www.refolk.ai/s/vn9yc7sd0m).

*Returns named people accountable for algorithmic hiring compliance across US financial employers, not a generic title search.*

| Role cluster | US | Comparator | Ratio (derived) |
|---|---|---|---|
| AI Governance / Responsible AI / AI Compliance (exact title) | 23 | Germany 2 | 11.5x |
| Recruiting / TA Operations (exact title) | 146 | UK 19 | 7.7x |

Counts are exact current-title matches in [Refolk](/)'s index, narrow by design, with ratios derived. They read the supply of the two functions that jointly own this standard.

## How this goes wrong

Most failed clearances fail on process, not on math. These are the false positives and the ways a criterion lies, drawn from live enforcement and litigation patterns.

- **Scope false-negative.** Calling a ranking tool a "search" tool to dodge the audit. The lie hides in the label. Check the output: does it score and rank, or only retrieve? A fit score with an auto-reject threshold is an AEDT no matter what the vendor's marketing calls it.
- **Vendor audit mistaken for compliance.** The employer keeps the legal duty. A vendor audit that does not cover your version, configuration, or use case fails silently because it looks like a clearance. Check the audit date, the tool version, and the use case.
- **Stale audit.** A tool cannot run on an audit older than 12 months. The number can be perfect and still expired. Check the distribution date, and re-audit on any retraining.
- **Vague published summary.** A generic statement that the tool "was audited and showed no significant bias" does not meet the publication standard. DCWP expects actual selection rates, scoring rates, and impact ratios with demographic breakdowns.
- **Notice as a website disclaimer.** The 10-business-day notice is a per-candidate obligation, not a one-time page footer. ATS workflows often need reconfiguring so every in-scope candidate gets notice with enough lead time.
- **Paper opt-out.** An alternative selection process that exists only on paper is a documented violation. It must be a real, available process a candidate can actually elect.
- **Undisclosed test data.** Test data is allowed when historical data is thin, but silence is the violation. The published summary must state and justify the use.

> **Note:** Weak public enforcement is not lower risk
>
> On December 2, 2025 the NY State Comptroller found DCWP's enforcement ineffective, with 75% of test calls to 311 about AEDT issues misrouted. That does not lower your exposure. Mobley v. Workday shows the real jeopardy has shifted to civil suits against tools and their deployers.

The stakes read small per line and stack fast. NYC penalties are $500 for the first violation and $500 to $1,500 for each subsequent one, but each day a tool runs in violation and each missing notice is a separate violation. A non-compliant deployment running 30 days exposes an employer to up to $44,000, and 365 days up to $546,500 before counting notice violations. Exposure scales with application volume.

| Regime | Penalty basis | Ceiling |
|---|---|---|
| NYC LL144 | Per violation, per day/use | $500 first; $1,500 each subsequent |
| EU AI Act | Per infringement | €15M or 3% global turnover |
| Colorado | Unfair/deceptive trade practice | No fixed statutory figure |
| Illinois | Human Rights Act remedies | Actual damages + fees + penalties |

The EU ceiling of €15 million or 3% of global annual turnover, whichever is higher, is an order of magnitude above the NYC per-line figures, which is why EU deployer controls belong in the file even while the December 2027 date still feels distant.

## The clearance checklist

Run this before you record a verdict. Every unchecked item is a restrict, not a deploy.

#### Before you sign off

- [ ] Every scoring, ranking, or screening tool is inventoried, including features embedded in HR platforms
- [ ] Each tool is labeled provider or deployer, with in-scope or out-of-scope reasoning written down
- [ ] A scope memo names which of the four regimes bind for the roles and locations in question
- [ ] An independent auditor with no development, distribution, or financial tie ran the audit
- [ ] The audit reports selection or scoring rates and impact ratios across all EEO-1 and intersectional categories
- [ ] Impact ratios were examined against 0.80 and anything below is documented, not ignored
- [ ] The public summary shows actual rates and ratios with demographic breakdowns and a distribution date
- [ ] The public summary will stay posted at least six months after the tool's latest use
- [ ] Every in-scope candidate receives a 10-business-day advance notice before evaluation
- [ ] A real, available alternative selection process exists, not a paper opt-out
- [ ] EU human oversight, six-month logging, and worker information are in place, with a FRIA where required
- [ ] Any use of test data instead of historical data is stated and justified in the summary
- [ ] The audit distribution date is under 12 months old and matches the exact deployed configuration

## Keeping the clearance current

A clearance is a snapshot, and both the tool and the rules move underneath it. Renew the bias audit at least annually, and treat any retraining or reconfiguration as an event that triggers a fresh audit inside the 12-month window, because the audit must describe the exact configuration in production.

Re-check the two moving dates every quarter. The EU deferral to December 2, 2027 came through an omnibus regulation, and Colorado's law was already repealed once before its replacement landed on January 1, 2027, so treat any date in this document as a value to verify against the primary source, not a constant. Watch the litigation line too: vendor liability is live in Mobley v. Workday, and a marginal impact ratio you cleared under a restrict verdict is exactly the kind of fact a plaintiff will surface. When the tool changes, the roles change, or a deadline shifts, the verdict is stale, and a stale deploy is indistinguishable from no clearance at all.

## Frequently asked questions

### Is my AI hiring tool compliant if the vendor already ran a bias audit?

Not automatically. A vendor's public bias audit is helpful but does not transfer the legal obligation, which stays with you as the employer or deployer. Before you rely on it, verify the audit is under 12 months old, covers the exact tool version and configuration you deployed, and includes your own use case where the rule requires it. Mobley v. Workday shows liability can reach both the vendor and the deployer, so treat a vendor audit as an input, never as your clearance.

### Does a resume search tool need an AEDT bias audit?

Only if it ranks or scores. Under NYC's Final Rule, a search engine that retrieves resumes without ranking them is out of scope, and so are scheduling tools and spam filters. The line is whether the tool issues a simplified output that substantially assists or replaces a hiring decision. A spreadsheet sorting applicants alphabetically is not an AEDT; software that assigns a fit score and auto-rejects below a threshold is.

### What exactly must a Local Law 144 bias audit calculate?

An independent auditor must calculate the selection or scoring rate and the impact ratio for each sex category, each race/ethnicity category from the EEO-1 Component 1 report, and each intersectional combination of sex with race or ethnicity. Scoring rate is the share of a category scoring above the sample median. The impact ratio divides each category's rate by the highest-scoring category's rate. Categories under 2% of the data may be excluded from the impact-ratio math.

### Did the EU AI Act deadline moving mean recruitment tools are off the hook?

No. Regulation (EU) 2026/1744 deferred the Annex III substantive-obligations deadline to December 2, 2027, but the classification duty under Article 6 was unaffected, and Article 50 transparency plus Article 4 AI-literacy duties stayed on the August 2, 2026 timeline. Recruitment and candidate-screening AI remains high-risk under Annex III point 4. The delay buys time to build oversight and logging, not permission to skip them.

### How large can NYC penalties actually get?

They stack. The fine is $500 for the first violation and $500 to $1,500 for each subsequent one, but each day an AEDT runs in violation is a separate violation and each missing candidate notice is another. A non-compliant deployment running 30 days exposes an employer to up to $44,000, and 365 days up to $546,500 before counting separate notice violations. The exposure is a function of application volume, not a flat fine.

### Can one bias audit clear all four regimes at once?

Rarely. The regimes share no common trigger. NYC turns on impact ratios and public posting, the EU on Annex III classification and human oversight, Colorado on consumer notice and 30-day adverse-outcome disclosure, and Illinois on notice and effect-based discrimination with no audit mandate at all. A tool cleared in NYC still has open EU and Illinois obligations. Grade each regime separately and take the strictest verdict.

---

*From the Refolk guide library. I revise these guides rather than replacing them, so the current version is always at https://www.refolk.ai/guides/candidate-screening-tool-clearance-standard*
