AI Screening Software Compliance: Best Practices, a Law-by-Law Checklist and 9 Vendor Questions for 2026
By Sparsh Goyal, Founder at The Cognitive. Published · Last updated
- AI screening software compliance means telling candidates before the tool runs, explaining what it judges, keeping a person in the decision, testing outcomes for adverse impact and keeping records, with extra duties under NYC Local Law 144, Illinois, Maryland, California, Colorado, the EU AI Act and UK GDPR.
- The four-fifths rule is the first check under US federal law, and the employer, not the vendor, carries the duty in every one of those laws.
- I run The Cognitive, which has not published a bias audit; nothing is rejected automatically, integrity flags are logged not scored, and the invitation tells candidates the interview is run by AI.
AI screening software compliance comes down to 5 duties that repeat across almost every law: tell candidates before the tool runs, explain what it judges, keep a person in the decision, test the outcomes for adverse impact, and keep records you can hand over. New York City adds a yearly independent bias audit. California has applied its anti-discrimination rules to automated decision systems since 1 October 2025, Colorado's new law starts on 1 January 2027, and the EU AI Act treats recruitment AI as high-risk from 2 December 2027.
Enforcement is uneven, which is no reason to relax. When the New York State Comptroller audited the city's enforcement of Local Law 144 in December 2025, the city had found 1 compliance issue across 32 companies; the Comptroller's auditors found at least 17 potential ones in the same set. Under US federal law, the four-fifths rule of thumb applies to an AI screen exactly as it applies to a human one.
Full disclosure: I run The Cognitive, AI recruiting software that sources candidates across ~900M public profiles and interviews them in a live, two-way AI video interview. We have not published a bias audit. I say exactly where we stand on every item in this checklist further down, including the ones where the answer is no.
The compliance paradox nobody warns you about
Here's the strange part about using AI to evaluate candidates: it can produce better-documented hiring than a room full of humans, and yet it draws far more legal scrutiny. The rules are new and still being written, and an algorithm making decisions is simply more visible than a hiring manager's gut feel that never gets written down.
That visibility cuts both ways. If you set it up carelessly, every decision is logged and discoverable. If you set it up well, that same logging becomes the best legal defense you've ever had. This guide is about landing on the right side of that line.
This is a practical guide, not legal advice (talk to your own counsel before you rely on any of it). But by the end you'll know which rules actually apply to you, how to run the one math test regulators care about most, what a compliant setup looks like line by line, what to ask any vendor, and the notification wording you can adapt today. If you're earlier in the journey and still asking whether AI hiring is fair at all, start with our guide to bias in AI hiring; this piece picks up where that one leaves off and goes deep on the legal mechanics.
The rules that actually apply to you
You don't need to know all of these. You need to know which ones touch your company, based on where you hire and what you hire for. Here's the map, and the dated table after it gives the official source for each.
EEOC (United States)
Federal law holds you to the same anti-discrimination standard whether a human or an AI makes the call. Title VII bans employment practices that cause a disparate impact on race, color, religion, sex or national origin unless the practice is job related and consistent with business necessity. The everyday screening test is the four-fifths rule from the Uniform Guidelines: the pass rate for any protected group should be at least 80% of the pass rate of the best-performing group. (There's a worked example of the math in a later section.)
A correction to older guides, including the first version of this one: the EEOC's 2023 technical assistance on AI and adverse impact was taken off eeoc.gov in January 2025. Title VII and the Uniform Guidelines did not change, so the core point holds: you own the outcome of any AI tool you deploy, and you can't push the blame onto your vendor. The EEOC's 2023 settlement with iTutorGroup shows the stakes: $365,000 over software that automatically rejected women aged 55 or older and men aged 60 or older.
State and local laws (United States)
These are spreading fast, and they're specific:
- Illinois (AI Video Interview Act): if you use AI to analyze video interviews you must notify candidates, explain how it works, and get consent before the interview. The Biometric Information Privacy Act adds a written release for any face geometry or voiceprint.
- New York City (Local Law 144): automated hiring tools need an independent bias audit within the past year, a public summary of the results, and notice to candidates 10 business days before use.
- Maryland: since 1 October 2020, no facial recognition in an applicant's interview without a signed consent waiver.
- California: since 1 October 2025, Civil Rights Council regulations apply the Fair Employment and Housing Act to automated decision systems. Privacy rules on automated decisionmaking add pre-use notices from 1 January 2027.
- Colorado: SB26-189 replaced the 2024 Colorado AI Act in May 2026, with duties from 1 January 2027.
The direction is the same everywhere: notify, be transparent, keep a human able to review, and keep monitoring for bias.
GDPR and UK GDPR (EU / UK)
The moment you process a candidate's data, this applies. The piece that matters most for screening is the rule on automated decisions. In the EU, Article 22 limits decisions based solely on automated processing, and where they're allowed, candidates keep the right to human intervention. The EU AI Act also lists AI that filters applications and evaluates candidates as high-risk.
The UK replaced its Article 22 with Articles 22A to 22D in the Data (Use and Access) Act 2025, allowing more automated decisions if safeguards are in place. The ICO's March 2026 hiring guidance names them: tell candidates automated decision-making is used and how it works, let them request a human review, and test regularly for biased outputs. In both places, the AI's score can't be the sole reason for a rejection without a person able to review it.
FCA (UK financial services)
For regulated SMCR roles, the FCA wants proof that hiring is consistent, fair and documented, which is exactly where subjective human interviews tend to fall apart. This is the clearest example of the paradox: structured AI evaluation can make that documentation easier, because a fixed rubric applied to every candidate, with a written score per criterion, is auditable in a way that scattered interviewer notes never are. The questions can adapt to each answer; the standard they're scored against stays the same. One UK fintech hiring for compliance roles on The Cognitive cut time to hire from 52 to 18 days while meeting its FCA standards, according to the customer (read the case study).
Industry-specific layers
On top of general employment law: healthcare brings patient-privacy rules when real patient information is involved, banking adds insider-risk and background rules, and government contracting adds its own recordkeeping and clearance requirements. For screening, these almost always come down to 2 things: how you handle the data, and how good your audit trail is.
AI screening software compliance checklist by law, dated
I read every source below on 4 October 2026. It's a summary, not legal advice, so open the official source before you act.
| Law | Who it covers | What it asks of an AI screen | In force | Official source |
|---|---|---|---|---|
| NYC Local Law 144 | Employers and agencies using an automated tool to screen people who applied for NYC-linked jobs | Independent bias audit within the past year, public summary, notice 10 business days before use, instructions for requesting an alternative process or accommodation | 1 Jan 2023, enforced from 5 Jul 2023 | NYC DCWP |
| Illinois AI Video Interview Act | Employers using AI to analyze video interviews for Illinois-based positions | Notice, explanation of how the AI works, consent before the interview, limited sharing, deletion within 30 days of a request | 1 Jan 2020 | 820 ILCS 42 |
| Illinois BIPA | Any private entity collecting face geometry or voiceprints in Illinois | Written notice of purpose and term, written release, public retention schedule, destruction within 3 years of last interaction at most | 2008 | 740 ILCS 14 |
| Maryland HB 1202 | Employers interviewing applicants in Maryland | No facial recognition during the interview without a signed consent waiver | 1 Oct 2020 | Maryland General Assembly |
| California FEHA ADS regulations | California employers using automated decision systems in hiring | No disparate impact on protected traits, 4 years of records including automated-decision data, care with disability-revealing tests | 1 Oct 2025 | Civil Rights Council |
| California CPPA ADMT rules | Businesses covered by the CCPA using automated decisionmaking for significant decisions | Pre-use notice, opt-out or a human appeal, access rights, risk assessment | Employment duties from 1 Jan 2027 | CPPA |
| Colorado SB26-189 | Developers and deployers of automated decision systems used in consequential decisions, including hiring | Notice, explanation within 30 days of an adverse outcome, 3 years of records, right to request human review | 1 Jan 2027 | Colorado General Assembly |
| Title VII and the Uniform Guidelines (EEOC) | US employers with 15 or more employees | No unjustified disparate impact; keep impact records by race, sex and ethnic group; four-fifths rule as the first check | 1964 / 1978 | 42 USC 2000e-2, 29 CFR 1607.4 |
| EU AI Act | Providers and deployers of AI used for recruitment or selection in the EU | High-risk duties: risk management, documentation, logging, transparency, human oversight | Stand-alone high-risk duties from 2 Dec 2027 | Annex III |
| UK GDPR and ICO guidance | Anyone processing UK candidates' data | Tell candidates about automated decisions, explain how they work, offer human review, test for bias, collect only what you need | Articles 22A to 22D under the 2025 Act; ICO guidance March 2026 | ICO |
The 2 NYC details most guides get wrong: the notice must tell candidates how to request an alternative process or accommodation, but the law doesn't require you to provide one. And the duty sits with the employer, not the vendor. Sourcing and outreach are out of scope, because the law covers people who applied. Our Local Law 144 page walks through what that means for a tool like ours.
The ICO's 2024 audits of AI recruitment tools show why the table exists. It made almost 300 recommendations after finding tools that inferred gender and ethnicity from names, let recruiters filter out protected characteristics, or kept far more data than needed, indefinitely.
The one test regulators care about most: the four-fifths rule
If you remember one piece of math from this whole guide, make it this. Most adverse-impact questions start here.
Say you screened candidates for a role and tracked who passed:
| Group | Applied | Passed | Pass rate |
|---|---|---|---|
| Group A (highest) | 200 | 100 | 50% |
| Group B | 200 | 90 | 45% |
| Group C | 200 | 56 | 28% |
- Step 1: find the highest pass rate. That's Group A at 50%.
- Step 2: divide each other group's rate by it. Group B: 45 ÷ 50 = 0.90 (90%), which is above 0.80, so it's fine. Group C: 28 ÷ 50 = 0.56 (56%), which is below 0.80, so that's a flag.
A flag doesn't automatically mean the AI is biased. It means you have to investigate and document why. That's the whole job, and the next section is how you do it.
2 limits keep the rule honest. With small numbers it breaks: the EEOC's own Q&A warns about results where "the selection of one different person for one job would shift the result." And passing it is no safe harbor: the same Q&A says it "does not resolve the ultimate question of unlawful discrimination," and with large numbers a gap under 20% can still count. For the full arithmetic, including NYC's scoring-rate version, read our adverse impact explainer.
Running a bias audit (the 5 steps)
Done well, a bias audit gives you real confidence and a paper trail. Done as a checkbox, it gives you false confidence that hides the problem. The difference is in steps 3 and 5.
- Pick the categories to track. At minimum race, gender and age. Add disability, veteran status or national origin where your industry expects it. Collect this with proper consent and store it separately from the evaluation data. NYC audits need sex, race and ethnicity, and their intersections, and inferred demographics aren't allowed.
- Measure pass rates per group and run the four-fifths math above.
- Investigate any flag, don't panic at it. Ask: are the criteria actually job-relevant? Is the AI scoring something it shouldn't? This is where written, per-criterion scoring earns its keep, because you can read the stated reason each candidate scored low and check it against the transcript instead of guessing. (How that scoring works is covered in how AI interview questions are scored.)
- Fix the criteria if needed. Trim them to the minimum that actually predicts success on the job. Every criterion beyond that adds legal risk without adding signal.
- Document everything: the rates over time, the investigations, the changes you made, the ongoing checks. This record is your defense if anyone ever asks.
Your compliant-setup checklist
Configure for compliance on day one. Retrofitting it later is painful. Here's the short version you can hand to whoever sets up the tool:
- ☐ Content-only scoring. The tool should judge what candidates say and how they reason, full stop. Avoid anything that scores faces or tone of voice (more on why below).
- ☐ Every criterion maps to the job. If you can't say why a criterion predicts success, cut it.
- ☐ Scores come with reasons. Each criterion score carries written feedback a reviewer can check against the transcript and recording, so it can be verified, not just accepted.
- ☐ A human makes the final call. The AI informs the decision; it doesn't make it. This is what the EU and UK automated-decision rules, Colorado's review right and the EEOC's accountability expectation all point at.
- ☐ Notification is built into the application, not buried or sent after the fact. For NYC roles, at least 10 business days before use.
- ☐ Data is encrypted in transit and at rest, with role-based access and access logging.
- ☐ Retention and deletion policies are set and written down, with a working right-to-delete process. The law sets the edges: California wants automated-decision data kept 4 years, Colorado 3 years of records, and Illinois deletes videos within 30 days of a request. Your counsel reconciles them.
Why "content-only" is non-negotiable
Some tools market facial analysis or tone analysis. Avoid them. These methods have repeatedly been challenged for scoring differently across demographic groups, Illinois and Maryland already put consent rules on face technology in interviews, and they add real legal exposure for no reliable gain. HireVue, the best-known example, stopped visual analysis in March 2020 and said it "no longer significantly added value". Judge the substance of the answer, never the face giving it.
A candidate-notification template you can adapt
Notification trips up more companies than the math does, usually because it's an afterthought. Put something like this in the application flow itself, before the interview, in plain sight:
This role uses an AI-assisted interview as part of our screening.
What that means for you:
- An AI interviewer will ask you role-specific questions in a live
video conversation. It scores your answers, not your appearance
or tone of voice. [If the tool checks the camera for integrity,
such as whether more than one person is visible, say so here.]
- A member of our team reviews the results. The AI does not make the
final hiring decision on its own.
- You can request a human review of your interview, and you can ask
what criteria were used to evaluate you.
- Your recording and transcript are stored securely and deleted after
[RETENTION PERIOD]. You may request deletion at any time at [CONTACT].
By continuing, you consent to an AI-assisted interview. If you'd prefer
an alternative selection process or need an accommodation, contact us
at [CONTACT] and tell us what you need.
Run the final wording past your counsel and adjust the bracketed parts. The point is that it's clear, it's before the interview, and it's the same on every posting, which makes your documentation trivial. For NYC roles, also publish your retention policy and the type and source of data the tool uses, or send it within 30 days of a written request.
What the audit trail should contain
When an audit comes, you're being asked one question: how was this decision made? A compliant AI setup answers it better than human interviews ever could, if it captures 4 things:
- The criteria, version-controlled. What was evaluated, the weights, the pass threshold, and what those were on any given date.
- Per-candidate evidence. A written reason for each score, plus the transcript and recording it came from, not a vague "seemed strong."
- The human decision. Who made the final call and what they reviewed (the report plus their own notes).
- Change history. When and why you changed criteria or rubrics. Showing intentional, documented improvement is itself evidence of good-faith effort.
If your system of record is an applicant tracking system (ATS), check what actually lands there. Many AI tools keep the full evidence in their own app and write only a summary back, so your audit file may need both.
What to ask any AI screening vendor: the due-diligence checklist
The vendor decides how hard your compliance is. Send these questions in writing before a pilot and keep the answers in your vendor file. They line up with the ICO's own list for buyers of AI recruitment tools.
- Bias audit. When was the last independent bias audit, by which auditor, on whose data? Can I see the summary? For NYC it must be under a year old, by an auditor with no tie to the vendor.
- What is scored. Which inputs feed the score: transcript, resume, video, voice? Is anything inferred about demographics? Is there any face or voice processing, even just for integrity checks?
- Human review. Can the tool reject anyone automatically, and can a reviewer override the score?
- Candidate notice. What does the candidate see before the interview, and can I add my own notice and consent text?
- Opt-out. How does a request for an alternative process or accommodation reach me?
- Data retention. How long are recordings, transcripts and scores kept by default, and can one candidate's data be deleted within 30 days?
- Explanation. Is each score explained in writing, tied to what the candidate said, clearly enough to give a rejected candidate a plain-language explanation within 30 days, as Colorado will require?
- Records and export. Can I export criteria versions, scores and decisions for my own impact analysis?
- Adverse impact data. Does the tool calculate impact ratios, or do I calculate them myself?
A vendor that answers all 9 in writing within a week belongs on the shortlist. One that answers with a certification logo and no specifics belongs at the bottom of it.
Where does The Cognitive stand on each item?
Here is my own product held to the checklist above, checked against our code on 4 October 2026. The Cognitive sources candidates across ~900M public profiles from a plain-English brief, then runs a live, two-way AI video interview of 10 or 20 minutes, in 9 languages, at a slot the candidate books.
- Bias audit: no. We have not published a bias audit, and the app does not calculate impact ratios for you. If you use our interview score to decide who advances for a New York City role, that use may count as an automated employment decision tool, and you'd need your own independent audit first. Sourcing and outreach sit outside Local Law 144.
- What is scored: the interview answers. Each criterion gets a 1 to 5 score with written feedback, produced from the transcript. The evaluator also reads the job description and resume, so it isn't blind to background. The rubric is fixed per role and the questions adapt live.
- Resume claims: checked. The AI probes up to 5 resume claims, and each comes back marked verified, refuted or unclear with evidence from the interview.
- Human review: always. Nothing is rejected automatically. The report gives a weighted score out of 100 and a suggested verdict from a fixed rule on that score, and a person decides.
- Integrity checks: logged, not scored. Camera frames are checked for signals such as no face visible, more than one face or looking away, alongside tab switches. They show up as flags and don't change the score. The check counts faces and reads head angle; it doesn't create a face ID. Whether that counts under BIPA or Maryland's law is a question for your counsel.
- Candidate notice: in the invitation. The invitation tells candidates the interview is run by AI. Put your own notice and alternative-process instructions in the job posting too, because the timing rules (10 business days in NYC, before the interview in Illinois) are yours to meet.
- Opt-out: handled by you. There's no built-in alternative-process flow. Candidates who ask come to you, and you route them to a human interview.
- Data retention: no published policy yet. Ask us in writing for current handling before you pilot.
- Audit trail: per interview. Each interview keeps the per-criterion scores and feedback, weighted score, verdict, transcript and recording. A read-only share link carries the scores, feedback and recording, not the transcript.
- ATS record: partial. For candidates imported from your ATS, we write back a note with the score, summary and report link. People sourced inside The Cognitive are not written into the ATS automatically.
That report is what a reviewer reads before deciding: a score and written reason per criterion, the weighted total and suggested verdict, and the transcript and recording to check them against.
This 5-minute recording shows a live AI interview for a go-to-market role. The AI asks the candidate about an outbound email campaign, then follows up on reply rates and how leads were qualified, so you can see the questions adapting to each answer while the rubric stays fixed.
The controls behind those answers are written up on our bias and fairness page, and our EU AI Act page covers the high-risk timeline.
Put one written rubric behind every screen Live, two-way AI interviews scored per criterion, with nothing rejected automatically and a person making every call. Start free
What it looks like in your industry
Fintech and banking
Align the evaluation criteria to FCA competencies for SMCR roles, document them in your firm-level governance, and keep the per-criterion reports with your compliance records. The consistency is the selling point to your regulator, not just your recruiter.
Healthcare
Patient-privacy law such as HIPAA protects patient health information, not a candidate's interview, so the practical rule is simple: keep real patient details out of interview scenarios and use invented cases. Limit recording access to people with a genuine clinical-hiring need, and set retention to your state's employment-record rules. (For the operational side of healthcare hiring, see AI video interviews for healthcare and our picks of healthcare recruiting software.)
BPO and high-volume
When you hire 100+ a month, even a small disparate-impact rate touches a lot of real people, so audit quarterly, not annually, and document every adjustment. (The volume mechanics are in AI interviews for BPO and staffing, and our BPO agent hiring case study shows one team's setup.)
Government contracting
Executive Order 11246, the source of the old race and sex affirmative-action plans, was revoked on 21 January 2025. Disability and veteran duties under Section 503 and VEVRAA still stand, and so does Title VII. For OFCCP-covered work, keep applicant-flow data that includes AI screening outcomes, make sure accommodation requests reach a person, and be ready for an audit that may inspect the tool itself.
Does compliance change for technical screening software or outsourced technical interviews?
No. The Uniform Guidelines define a selection procedure as any measure used as a basis for an employment decision, down to informal interviews and unscored application forms. A coding test, an AI technical screen and an interview run by an outsourced technical interview service are all selection procedures, so the four-fifths records apply to each.
Where they differ is Local Law 144. It covers tools that produce a simplified output, such as a score, ranking or tag, and lean on it heavily in the decision. An AI technical screen that scores candidates is likely in scope. A human engineer from an interview service writing notes usually isn't, though the service's own scoring software might be. Ask any technical screening vendor the same 9 questions above. For the tools themselves, our guide to technical interview software compares them.
The five mistakes that cause most problems
- Thinking the vendor's compliance is your compliance. This holds for any AI screening tool, ours included. Their SOC 2 doesn't cover your EEOC duties; their GDPR posture doesn't write your notification. You own the deployment.
- Skipping demographic tracking. Companies avoid it thinking it's safer. The opposite is true: with no data you can't spot a problem or prove good faith if challenged. The Uniform Guidelines expect you to keep impact records by race, sex and ethnic group.
- Treating the audit as a once-a-year event. Pass rates drift as volume, criteria and candidate pools change. Quarterly is a sensible floor; monthly for high volume.
- Using facial or tone analysis. Demonstrated risk, consent laws in Illinois and Maryland, no reliable upside. Content only. The same caution applies to tests that infer traits; see our guide to pre-employment assessments for how validity is judged.
- Weak notification. Buried in fine print or sent after the interview doesn't count in most places. Clear, prominent, before.
Putting a real program together
A complete program is mostly a set of documents you keep current. You want: policy docs (AI use, criteria, notification, data, retention, audits), process docs (where the human review sits, how decisions are recorded), training for everyone who uses the tool, scheduled monitoring with documented findings, vendor records (the 9 answers above, certifications, agreements), and a simple incident-response path for complaints or inquiries.
Pick a platform that makes this possible by default: content-only scoring, a written reason for each score, a real audit trail per interview, and rubrics you control. From there, the smartest move is to run a small batch, do a sample four-fifths analysis on the results, and confirm the audit trail actually meets what your documentation needs, all before you commit to a multi-year contract. If you're still choosing tools, our list of the best AI candidate screening software covers selection, and AI hiring vs traditional recruiting covers the bigger "why" for skeptical stakeholders.
The takeaway worth keeping: compliance for AI screening is mostly the byproduct of running the technology well. Judge content, document everything, keep a human in the loop, and the audit trail does most of the defending.
To start this week: fill in the law table for every place you hire, send the 9 vendor questions to whoever runs your screen today, and pull last quarter's screen-to-interview pass rates for a first four-fifths check. If you want a fixed rubric and a live AI interview on a real role, open a The Cognitive account. The free trial comes with 100 sourcing credits.
Run your next screen against one written standard Describe the role, set the rubric, and read a per-criterion report for every candidate you interview. Start free
Related reading
- Best Talent Acquisition Software Platforms
- 10 Recruitment Automation Tools to Cut Admin Time
- Online Recruiting Software: Cloud vs On-Prem, Explained for Teams That Own the Mess
- Applicant Tracking System for Small Business: 4 Tool Types That Actually Fit
- One-Way Video Interview Software vs Live Video: Which Should You Use?
- AI Recruiting Software
Sources
- NYC Department of Consumer and Worker Protection, Automated Employment Decision Tools, and the DCWP AEDT FAQ: nyc.gov, FAQ PDF, read 4 October 2026
- Office of the New York State Comptroller, Enforcement of Local Law 144, 2 December 2025: osc.ny.gov, read 4 October 2026
- Illinois Artificial Intelligence Video Interview Act, 820 ILCS 42: ilga.gov, read 4 October 2026
- Illinois Biometric Information Privacy Act, 740 ILCS 14: ilga.gov, read 4 October 2026
- Maryland HB 1202 (2020), Chapter 446, facial recognition in interviews: mgaleg.maryland.gov, read 4 October 2026
- California Civil Rights Council, release of 30 June 2025 on automated-decision system regulations: calcivilrights.ca.gov, read 4 October 2026
- California Privacy Protection Agency, CCPA updates including automated decisionmaking technology: cppa.ca.gov, and Littler, 26 September 2025, on the 1 January 2027 employment date: littler.com, read 4 October 2026
- Colorado SB26-189, Automated Decision-Making Technology: leg.colorado.gov, read 4 October 2026
- Title VII, 42 USC 2000e-2(k): law.cornell.edu; Uniform Guidelines, 29 CFR 1607.4: law.cornell.edu; definitions, 29 CFR 1607.16: law.cornell.edu, read 4 October 2026
- EEOC, Questions and Answers on the Uniform Guidelines: eeoc.gov, read 4 October 2026
- EEOC, iTutorGroup settlement, 11 September 2023: eeoc.gov, read 4 October 2026
- Executive Order 14173, 21 January 2025, section 3(b)(i) revoking Executive Order 11246: whitehouse.gov, read 4 October 2026
- EU AI Act, Annex III: artificialintelligenceact.eu; Council of the EU, AI Act timeline: consilium.europa.eu, read 4 October 2026
- ICO, AI tools in recruitment audit outcomes, 6 November 2024: ico.org.uk; key questions for buyers: ico.org.uk, read 4 October 2026
- ICO, automated decisions in hiring, 31 March 2026: ico.org.uk, read 4 October 2026
- SHRM, HireVue discontinues facial analysis screening, 3 February 2021: shrm.org, read 4 October 2026
Frequently Asked Questions
What compliance frameworks apply to AI screening software?
Title VII and the EEOC's Uniform Guidelines apply in the US, GDPR or UK GDPR apply in Europe, and a growing set of state, city and EU laws add specific duties. The four-fifths rule is the first adverse impact check under US federal law. NYC Local Law 144 requires a bias audit within the past year and notice 10 business days before use. Illinois requires notice and consent before AI analyzes a video interview, Maryland requires consent for facial recognition in interviews, California's FEHA rules on automated decision systems have applied since 1 October 2025, Colorado SB26-189 starts on 1 January 2027, and the EU AI Act's high-risk duties for recruitment AI apply from 2 December 2027. UK financial services firms also need consistent, documented hiring for FCA-regulated roles.
How do you audit AI screening software for compliance?
Track pass rates by demographic group, run the four-fifths check, investigate every flag and document what you changed. Collect demographic data with consent and store it apart from evaluation data. Check that the tool scores what candidates say, with no facial analysis or proxies for protected traits, and that every criterion maps to the job. For NYC roles you also need an independent bias audit no more than 1 year old, published on your careers site. The Cognitive keeps per-criterion scores, the transcript and the recording for each interview, but it does not calculate impact ratios, so you export and run that math yourself.
Is AI screening software GDPR compliant?
It depends on how you configure and use it, because GDPR duties sit with you as the controller. You need to tell candidates AI is being used, explain the criteria, offer human review of automated decisions, secure the data and set retention and deletion rules. In The Cognitive, nothing is rejected automatically and a person makes every decision, the invitation tells candidates the interview is run by AI, and each score comes with written feedback. We have not published a data-retention policy yet, so ask us in writing before a pilot and document your own program.
Can AI screening software be used in regulated industries like fintech?
Yes, as long as the tool gives you consistent criteria, a human decision and a record you can show a regulator. Fintech, banking, insurance and healthcare teams use AI screening; for FCA-regulated SMCR roles, a fixed rubric with a written score per criterion is easier to evidence than scattered interviewer notes. Avoid facial analysis and opaque scores, and check the tool's notice, retention and audit trail against the law table before you buy.
Our team is in a highly regulated industry and every AI tool gets rejected by compliance. What should we do?
Bring compliance the vendor's written answers to 9 questions before the demo, not after it. Ask about the last bias audit and auditor, what is scored, whether anything is rejected automatically, what candidates are told and when, how opt-out requests reach you, retention, explanations, exports and impact ratios. A pilot on 1 role with a sample four-fifths check and a sample audit file usually answers more objections than a slide deck. The Cognitive answers most of these in writing; it has no published bias audit or retention policy, which your compliance team should know up front.
What audit trail should AI interviewer software keep?
It should keep the version of the criteria used, a written reason for each candidate's score, the human decision and who made it, and a history of every criteria change. The transcript and recording let a reviewer check a score against what was said. The Cognitive keeps per-criterion scores with written feedback, the weighted score, the suggested verdict, the transcript and the recording for every interview. For candidates imported from your ATS it writes back a note with the score, summary and report link.
Is there EEOC-compliant AI screening software?
No software is EEOC compliant on its own, because Title VII duties sit with the employer that uses it. What a tool can do is make compliance easier: score job-related criteria, keep a person in the decision, and let you export results for a four-fifths check. The EEOC's 2023 technical assistance on AI was removed from its website in January 2025, but Title VII and the Uniform Guidelines still apply in full.
Does NYC Local Law 144 apply to AI interviews?
It can, if you use the interview's score, ranking or tag as the sole or heaviest factor in deciding who advances for a New York City role. Then you need an independent bias audit within the past year, a public summary of results and candidate notice at least 10 business days before use. Sourcing and outreach are out of scope, because the law covers people who applied. The Cognitive has not published a bias audit, so an employer using its interview score that way would need to commission one.
How do you protect candidate privacy when using AI-assisted screening?
Collect only what the screen needs, tell candidates what is collected and why, set a retention period and honor deletion requests. Illinois requires deleting AI-analyzed interview videos within 30 days of a request, and BIPA requires a written release before collecting face geometry or voiceprints. California's FEHA rules require keeping automated-decision data for 4 years, so retention has to balance both. In The Cognitive, integrity checks count faces and read head angle without creating a face ID, and are logged, not scored.
Does OFCCP compliance still apply to AI screening for federal contractors?
Partly: Executive Order 11246 was revoked on 21 January 2025, but disability and veteran duties under Section 503 and VEVRAA remain, and Title VII still applies. Keep applicant-flow records that include AI screening outcomes, make sure accommodation requests reach a person, and be ready for an audit that inspects the tool. Job posting software and AI screens should both export their records in a form your compliance team can file.
Which AI interview screening software has a published bias audit?
Ask each vendor directly for the audit date, the auditor's name and the summary, because audits expire and the vendor holds the summary. Under NYC Local Law 144 the audit must be under a year old and done by an auditor with no tie to the vendor. The Cognitive has not published a bias audit. It runs live, two-way AI video interviews scored per criterion from the transcript, with nothing rejected automatically.
Related reading
- 12 Interviewer Biases, Where AI Adds Bias, and How to Audit
- AI Candidate Screening Software: 10 Tools That Cut Time to Hire in 2026
- Artificial Intelligence Scoring: How AI Interviews Grade Real Evidence
- What Is a Normal Cost Per Hire? Benchmarks by Seniority, Sector, Role and Region
- Candidate Sourcing Channels Compared: Where to Find Candidates for Each Role in 2026
- How Many Candidates Are Interviewed per Hire? 2025 and 2026 Benchmarks by Role and Stage