NYC Hiring AI Audits Can Show Disparity, Not Certify Fairness
New York City requires a published bias audit for covered automated hiring and promotion tools. The resulting table is a compliance artifact, not proof that every deployment is fair or lawful.
August 9, 2026 · 7 min read

The concrete artifact to inspect is the employer’s public audit table for a résumé-ranking tool. It may show how often candidates in different sex and race or ethnicity categories advanced, along with impact ratios comparing those rates, while offering little evidence about résumé parsing errors, disability accommodations, job relevance, or how recruiters used the ranking.
That distinction matters under New York City’s Local Law 144. Before an employer or employment agency uses a covered automated employment decision tool, or AEDT, the law requires a bias audit conducted no more than one year before use, public disclosure of a summary, and notices to covered candidates or employees. The Department of Consumer and Worker Protection began enforcement in July 2023.
Compliance starts with determining whether the system is an AEDT, a statutory category for certain computational processes that issue a score, classification, or recommendation used to substantially assist or replace discretionary decisions in hiring or promotion. A chatbot that schedules interviews may fall outside that function. A model whose ranking effectively decides which applications recruiters review is much closer to the core case, even when a human clicks the final button.
What the audit table measures
For a résumé-ranking workflow, the auditor first needs records linking the tool’s output or downstream selection decision to demographic categories covered by the city rules. A selection rate is the proportion of people in a category who were selected to advance. An impact ratio compares a category’s selection rate with the rate for the most-selected category; the rules also address scoring rates when a tool assigns scores rather than a binary pass or fail.
The calculations cover sex categories, race or ethnicity categories, and intersectional combinations of those categories. A public table can therefore reveal that one group advanced at a lower rate than another in the supplied dataset, including a disparity that disappears when race and sex are examined separately. That is useful evidence. It gives compliance staff a repeatable measurement, gives applicants some visibility, and gives investigators or counsel a place to begin.
The table does not explain why a disparity occurred. A lower selection rate could reflect the tool, the applicant pool, a job requirement, missing demographic records, a recruiter’s later intervention, or several linked decisions. The audit calculation describes an outcome in the audited data; it does not, by itself, establish causation or determine whether a practice violates employment discrimination law.
There is no general fairness passing score in Local Law 144. The federal Uniform Guidelines on Employee Selection Procedures use the four-fifths rule as one way to identify potential adverse impact, but that benchmark is not a guarantee of legality, and a ratio above it is not a safe harbor. New York City’s law requires the audit and publication. It does not declare every tool with a particular ratio fair, nor does it prohibit use solely because the table reports a disparity.
The dataset sets the boundary of the finding
Return to the résumé-ranking audit table and look below the ratios. The required public summary should identify the audit date, explain the source and type of data, report category counts, and disclose how many people were excluded from calculations because demographic information was unknown. Those details determine how broadly anyone can read the result.
An audit may use the employer’s historical data, meaning records from real prior decisions made with the tool. Historical data can reflect the deployed workflow, but it also carries earlier recruiting patterns, incomplete demographic fields, recruiter overrides, and changes in job mix. If the employer has too little historical data, the rules permit test data, which must be identified and explained. Test data can fill sparse categories, yet it cannot recreate every résumé format, language pattern, accommodation need, or recruiter behavior found in production.
Pooled data from multiple employers creates another boundary. It may produce enough observations for calculations that would otherwise be unstable, especially for intersectional groups with small counts, but a vendor-wide result can hide a customer’s configuration and applicant population. The rules place conditions on using aggregated historical data, including auditor judgment about why aggregation is appropriate; an employer should not treat a vendor’s broad table as automatic evidence about its own requisitions.
Small categories matter even when the arithmetic runs. A ratio based on few people can swing sharply after one decision, while a blank or omitted category can conceal a gap in collection rather than an absence of risk. Counsel, statisticians, and hiring teams should review counts beside ratios instead of circulating the most favorable number alone.
Independence is a relationship, not a label
The rules require an independent auditor, defined around objective and impartial judgment and separation from using, developing, or distributing the AEDT. They also restrict employment and financial relationships that could compromise the review, including compensation contingent on a favorable result.
A vendor cannot settle the issue by naming its own assessment an independent audit. Employers should document who selected and paid the auditor, whether the auditor helped build or deploy the model, which entity supplied the data, and whether anyone outside the auditor controlled categories, exclusions, or the published summary. Vendor payment does not make every engagement invalid on its face, but the actual relationships must satisfy the rule.
Independence also does not expand the engagement. An auditor hired to calculate selection rates may do that work impartially without testing model accuracy, cybersecurity, accessibility, job relatedness, or compliance with other discrimination laws. The résumé-ranking table should be read with the auditor’s scope statement, not as if the word “independent” converts a limited statistical exercise into a complete assurance opinion.
Notice is a separate engineering requirement
The city’s notice obligation is not fulfilled by placing the audit summary somewhere on a corporate website. For covered candidates or employees, notice must identify that an AEDT will be used and state the job qualifications and characteristics it will assess. The law specifies notice “at least ten business days before such use,” which means the recruiting workflow needs a timed disclosure before the system evaluates the person, not after a rejection email.
The notice must also provide instructions for requesting an alternative selection process or a reasonable accommodation. Local Law 144 creates the request channel but does not itself require an employer to grant every alternative-process request; disability, civil rights, and other employment rules may impose separate duties. Data-source and retention information must also be made available through the required disclosure route, subject to the law’s provisions.
This is where implementation often separates from policy. The applicant-tracking system needs to record when notice was delivered, which version was shown, when the AEDT first processed the application, and whether an accommodation request paused automated review. A generic privacy notice without those event records may be difficult to reconcile with the ten-business-day requirement.
What employers should review beyond the audit
Treat the public table as one item in a deployment file. The same file should map the decision workflow from application intake through parsing, scoring, recruiter review, override, and advancement, because a statistically acceptable vendor output can still be used in a way the audit never examined. Version changes and customer-specific thresholds deserve attention too: an audit of one model configuration may say little about a later release or a rule that automatically discards everyone below a locally chosen cutoff.
Reviewers should compare the audited population with the jobs and locations where the tool is used, trace excluded and missing demographic records, and test whether the qualifications described in the notice match the signals the model consumes. They should also examine false negatives, cases in which qualified applicants are screened out, across representative résumé formats and accommodation scenarios. Selection parity does not establish predictive accuracy, and equal error rates would not establish job relatedness.
The fallback must be operational. If the audit expires, a material configuration falls outside its scope, or notice timing fails, the employer needs a documented way to stop automated scoring and route applications to a trained human review queue. That costs recruiter time and may slow hiring, but continuing with an unsupported configuration can turn a narrow audit gap into a repeated compliance problem.
Legal review should address whether the tool is covered, which people and decisions trigger the city requirements, whether the auditor meets the independence standard, and how Local Law 144 interacts with federal, state, and local discrimination or accommodation duties. Those are fact-specific judgments. This explainer describes the public requirements and practical review points; it is not legal advice.
Questions people ask
Does a passed
NYC bias audit mean a hiring tool is fair?
No. The law does not create a universal passing ratio or fairness certificate. An audit reports specified selection or scoring disparities in a defined dataset, while fairness and legality may also depend on job relevance, accuracy, accommodations, recruiter behavior, data quality, and discrimination rules outside Local Law 144.
Can an employer rely on the software vendor’s audit?
Possibly, but the employer should verify that the audited system and configuration match its deployment, that the underlying data are appropriate, and that the auditor satisfies the city’s independence rules. A pooled vendor audit may not represent the employer’s applicant population, thresholds, job mix, or human-review workflow.
Must an employer offer a human alternative when someone objects?
Local Law 144 requires instructions for requesting an alternative selection process or reasonable accommodation, but it does not itself require every requested alternative to be granted. Other disability, civil rights, or employment obligations may change the answer, so employers should establish a request and escalation workflow with counsel.
How often does the audit need to be updated?
A covered AEDT cannot be used unless it received a bias audit no more than one year before use. Employers should also assess model releases, threshold changes, and workflow changes rather than assuming an annual calendar reminder covers every configuration that reaches candidates.
One story a day
The story of the day, in your inbox
One real story about AI each morning — no hype, no alarm, just company for the road.



