Skip to content

AI Governance & Ethics

Map Hiring AI Before Disclosure and Audit Rules Apply

A useful employment AI inventory follows one candidate through each decision, records how software changes the outcome, and separates enforced rules from enacted or proposed duties.

Irene VaskoGovernance & Ethics Writer

August 9, 2026 · 8 min read

A laptop displaying an employment systems inventory beside printed hiring workflow notes on a desk.
A laptop displaying an employment systems inventory beside printed hiring workflow notes on a desk.

Start with one warehouse-associate requisition.

An applicant uploads a résumé to an applicant tracking system. A screening tool extracts work history and rejects applications missing required certifications. Another model ranks the remaining candidates, a scheduler allocates interview slots, and a video platform records interviews for later review. After hiring, workforce software predicts attendance risk and recommends shifts.

Calling that stack “the hiring AI” hides the facts that matter. Each component acts at a different point, uses different data, affects a different employment decision, and may fall under a different law. The inventory should preserve those boundaries.

This is a practical setup for compliance review, not legal advice. Counsel still has to interpret coverage, exemptions, enforcement history, and any amendments in the jurisdictions where an employer operates.

Build rows around decisions, not products

Create one inventory row whenever software produces an output that changes, recommends, or materially structures an employment decision. A vendor contract may cover several products, while one product may screen applicants, rank employees for promotion, and flag workers for discipline. Those uses should not share a row.

For the warehouse requisition, résumé extraction is not necessarily the decision point. The consequential action occurs when a rule rejects someone for a missing credential, when a score changes interview order, or when the scheduler withholds a desirable shift. Record each event separately, even if the same platform performs all of them.

Use a stable schema:

`workflow ID | decision point | system and version | input data | output | human action | affected people | locations | legal status | evidence owner`

The system field should name the vendor, product, configured module, and internal version or deployment identifier. “Machine learning” is too broad. Record whether the tool applies a fixed rule, predicts an outcome from historical data, generates text, recognizes a face, or calculates a score. A deterministic knockout rule can trigger employment obligations even though its vendor does not market it as AI.

Under input data, identify the fields the system receives rather than the fields procurement believes it receives. Résumé text, ZIP code, interview audio, facial images, badge events, keyboard activity, sales records, and manager ratings create different exposure. Include inferred data, such as an attendance-risk score calculated from past absences, because an inference can drive the decision even when the underlying records remain elsewhere.

Replay the warehouse application

The fastest way to find missing systems is to replay a real or test application from submission to disposition. Use a requisition identifier and follow the records through the applicant tracking system, vendor APIs, spreadsheets, recruiter dashboards, email, and calendar tools. Interview the recruiter and hiring manager while the workflow is open on screen.

At each transition, capture the incoming record, the transformation, the output, and the person or system that consumes it. If the ranking service returns a score from zero to one, document whether the recruiter sees the number, a label, or only a reordered list. If candidates below a configured threshold disappear from view, the ranking tool has more practical control than a contract describing it as advisory would suggest.

Human review needs the same precision. “Human in the loop” can mean that a recruiter independently reads every résumé, or that a recruiter may override a recommendation after the system has filtered most applicants out. Record who can override, what evidence appears on the screen, whether the interface defaults to acceptance, and whether an override enters a log.

Return to the warehouse requisition after interviewing the users. If policy says recruiters review every rejection but system logs show automatic disposition codes, retain both records and resolve the discrepancy. The law-facing inventory should describe deployed behavior, not the intended workflow.

Add geography at three levels

Employment rules can turn on the location of the candidate, employee, job, employer, or decision. One “United States” field will not support that analysis.

For each row, record where the affected person resides, where the job is performed, where the employing entity operates, and whether remote work is available. Keep the decision maker’s location too. A single warehouse requisition may attract applicants from several jurisdictions, while a scheduling model may affect employees assigned to one physical site.

Do not infer legal coverage from an IP address alone. Remote access, travel, and network routing make it a weak location signal. Use the address and work-location records already collected for employment administration, then document any uncertainty.

Map requirements only after the workflow is visible

New York City’s Local Law 144 is an enforced local rule for certain automated employment decision tools used in hiring or promotion. It bars covered use unless the tool received a bias audit “no more than one year prior” and information about that audit is publicly available. The law also requires advance notice to covered candidates or employees, including notice of the job qualifications and characteristics the tool will assess.

Coverage does not follow the vendor’s AI label. City rules focus on tools that use specified computational techniques and “substantially assist or replace discretionary decision making.” For the warehouse requisition, counsel would need the ranking tool’s mechanics, the rejection threshold, the recruiter’s authority, and the relevant locations before deciding whether the rule applies. If it does, an old audit for a different model or configuration may not answer the operational question.

Illinois’s Artificial Intelligence Video Interview Act applies to employers that ask applicants to record video interviews and use AI analysis when considering fitness for a position. Before the interview, an employer must notify the applicant that AI may analyze the video, explain how the system works and the “general types of characteristics” it uses, and obtain consent. The law also restricts sharing and requires deletion after a qualifying applicant request within the statutory period.

That means the warehouse inventory cannot stop at a box labeled video interview. It must distinguish recording for human playback from software that analyzes speech, expression, language, or other characteristics. Maryland separately restricts an employer’s use of a facial recognition service during an applicant interview without a signed consent waiver, making facial analysis its own inventory field rather than a generic video feature.

Illinois has also enacted broader Human Rights Act provisions addressing employer use of AI in recruitment and other employment decisions when that use has a discriminatory effect, along with an employee-notice requirement. Those provisions were enacted for 2026 implementation, while rulemaking can determine operational details. Mark them as enacted, not currently enforced merely because implementation work is underway.

Colorado has enacted duties for deployers of certain high-risk AI systems used as a substantial factor in consequential decisions, including employment decisions. The framework calls for reasonable care against known or reasonably foreseeable algorithmic discrimination, impact assessments, consumer notices, adverse-decision information, correction and appeal opportunities, and human review where technically feasible. Its 2026 timing and amendment history require a current legal check; the inventory work remains useful because those duties depend on knowing the system, purpose, data, safeguards, and decision path.

Keep a status column with controlled values such as enforced, enacted with a future operative date, proposed, stayed, or repealed. Add the source and review month. A proposed regulation may justify preserving logs or negotiating vendor access, but it should not be presented to managers as an existing audit mandate.

Preserve the receipts an audit will need

An inventory without evidence becomes a questionnaire that vendors and business owners can answer optimistically. Link each row to contracts, model documentation, configuration exports, screenshots, notices, consent records, data-retention settings, validation reports, completed assessments, and representative decision logs.

For the warehouse ranking tool, retain the score delivered by the vendor, the list shown to the recruiter, the configured cutoff, any override, and the final disposition. This creates a chain from input to employment action. It also reveals a common gap: the employer may possess final outcomes but lack the intermediate scores needed to reproduce selection rates or investigate a complaint.

Ask vendors whether they can export results for the employer’s deployed configuration and relevant population. A general fairness report may describe a base model without covering the customer’s threshold, added knockout questions, local applicant pool, or human review. Obtaining better evidence can cost contract time, engineering work, and storage; replacing a tool may cost more, but an employer should know about an evidence gap before an audit deadline or adverse decision.

Make change control part of the inventory

Assign an owner to every row and require review when the vendor changes a model, the employer changes a threshold, a new data source appears, or the tool moves to another job or jurisdiction. Version identifiers matter because a notice, assessment, or audit tied to yesterday’s configuration may not describe today’s system.

The scheduling component deserves this treatment too. A model first used to forecast staffing may later recommend individual shifts or penalize availability patterns. That is a new employment use even if procurement buys nothing new. Change control should open a fresh row, route it for legal-status review, and preserve the prior configuration rather than overwriting it.

Do not wait for a perfect enterprise catalog. Finish the warehouse-associate path, test the evidence links, then repeat the method for a salaried role and an existing-employee workflow. Gaps will appear quickly: unlogged overrides, missing vendor versions, generic notices, and monitoring tools owned outside human resources.

Questions people ask

Does every résumé filter count as an automated employment decision tool?

No. Coverage depends on the wording of the applicable law and how the configured filter affects a decision. Record fixed rules, statistical models, thresholds, and human review separately so counsel can assess the deployed mechanism rather than relying on a vendor category.

Can one vendor audit cover every employer using the product?

Not necessarily. A vendor audit may omit an employer’s configuration, knockout questions, decision thresholds, applicant population, or workflow. Employers should record what system and data the audit covered, when it was completed, and whether the audited use matches the row in their inventory.

Should proposed AI rules appear in the inventory?

Yes, with their status clearly marked as proposed rather than enforced. Tracking a proposal can support contract terms, logging, and future assessments, but managers should not be told that a proposal already creates a notice or audit duty.

Who should own the employment AI inventory?

Human resources can coordinate it, but procurement, information security, privacy, legal, and operating teams hold different evidence. Give each workflow row one accountable owner and named evidence owners, then require updates when the model, configuration, data, decision, or covered location changes.

ShareFacebook
ai governanceai at workemployment aialgorithmic auditsstate ai lawshiring technologyai compliance

One story a day

The story of the day, in your inbox

One real story about AI each morning — no hype, no alarm, just company for the road.

Read next

Laptop displaying a cropped airport image beside metadata fields and a Content Credentials verification panel.

AI Governance & Ethics

What an AI-Generated Image Label Can Actually Prove

A visible badge, file metadata, generation log, and signed Content Credential answer different questions. Cropping and reposting expose the gaps between them.

Irene Vasko · 8 min read

A support chat labeled Automated assistant beside a phone displaying an incoming customer-service callback.

AI Governance & Ethics

When a Customer-Service Bot Has to Say It Is a Bot

There is no blanket U.S. disclosure rule. A practical answer depends on where the customer is, what the bot is doing, and whether chat becomes an AI-generated call.

Irene Vasko · 8 min read

A laptop displaying a hiring bias-audit table beside a printed job notice and handwritten calculation notes.

AI Governance & Ethics

How to Read NYC’s Hiring-AI Bias Audit Before You Apply

A public audit can reveal which hiring system was tested, whose outcomes were counted, and where selection rates diverged. It can also conceal job-level differences and omit demographic groups.

Irene Vasko · 8 min read