New York City began enforcing a law that most people outside human resources have never heard of. Local Law 144 says that if an employer uses an automated tool to screen or rank candidates, that tool must be audited for bias within the previous year, the results of the audit must be published, and candidates must be told the tool is being used.
It is a small law with a large implication. It treats a piece of hiring software the same way an auditor treats a financial control, as something that must be tested by an independent party and disclosed.
For anyone working on corporate responsibility, that framing should feel familiar. We already accept that a supply chain needs auditing. The question now on the table is whether the systems that decide who gets hired deserve the same treatment. Here is a look at what such an audit actually involves.
What a bias audit measures
A bias audit is not a review of the source code, and it is not an ethics essay. It is a statistical exercise.
The auditor takes the tool’s outcomes and calculates selection rates for different groups of candidates, broken down by sex and by race or ethnicity. It then compares those rates. If one group is selected at a much lower rate than the most selected group, the tool has an adverse impact, and the size of that gap is the finding.
That is the whole core of it. Simple to describe, and much harder to do well, because it depends on having outcome data that is complete and honestly recorded.
Where the bias actually comes from
People tend to assume a biased hiring model is a badly written one. Usually it is a well written model trained on a biased record.
Three sources come up again and again. The first is historical data. If a company hired mostly from four colleges for fifteen years, a model trained on those hires will learn that those four colleges signal quality, and the pattern hardens.
The second is proxy variables. You can remove name, gender and age from a dataset and still leak all three. A postal code carries community information. A gap in employment history carries caregiving information. The membership of a sports club carries plenty.
The third, and the least discussed, is how success is defined. If the model is trained to predict who stays two years, and the workplace has been harder on some groups than others, the model learns to avoid the people the workplace treated badly. The target variable itself was never neutral.
Why this belongs on the responsibility agenda
There is a habit of filing this under information technology and moving on. That is a mistake, and it is worth saying why plainly.
Hiring is the single point where an organisation converts its stated values about opportunity into an actual outcome. Every diversity commitment in an annual report passes through that gate. If the gate is being operated by a system nobody has tested, the commitment is a sentence rather than a practice.
There is also a straightforward disclosure question. Companies already report on workforce composition. If a large share of the workforce was filtered by software that has never been audited, then the numbers in that report have an untested process sitting behind them.
The situation in India
India has no equivalent of Local Law 144 at present. What it does have is a growing body of employers using automated screening, and the Digital Personal Data Protection Act passed in 2023, which governs how personal data is collected and processed and gives individuals rights over it.
Candidate data is personal data. A recorded video interview is personal data of a fairly sensitive kind. So even without a hiring specific rule, the consent, purpose limitation and grievance requirements that sit in data protection law already reach into the screening process.
Any serious AI recruitment agency working with Indian employers will already be handling consent notices and retention periods as part of the engagement. The gap tends to be on the fairness side, where nobody has yet been asked to produce a number.
What a board can reasonably ask for
Start with an inventory. Which tools are in use, at which stage, and who owns each one? Most organisations cannot answer this quickly, and the exercise of answering it is valuable on its own.
Ask whether the vendor has run an adverse impact analysis, and ask to see it rather than a summary of it. Ask what happens to a candidate who is rejected by the system, and whether any human reviews that rejection.
Have a clear policy on what the tool is permitted to decide. Ranking a longlist is one thing. Automatically rejecting an application without any human sight of it is another, and the second deserves an explicit decision at senior level rather than a default setting nobody chose.
Then ask the question that gets skipped. If the audit finds a gap, what happens next? An audit with no remediation path is a document, not a control.
A fair word for the technology
None of this is an argument that human screening was fair before the software arrived. It was not. Decades of research on identical resumes sent under different names established that long before any of these tools existed.
The difference is that a machine’s bias is measurable. You can run the numbers on ten thousand decisions in an afternoon. You cannot do that to a hiring manager’s intuition on a Thursday.
That is the genuine opportunity here, and it is being missed by companies that treat the audit as paperwork. The audit is the first time most employers get an honest measurement of their own hiring pattern. Some of them will not enjoy reading it, which is rather the point.
About The Author
Nikhil Vaidya
Nikhil Vaidya is the CEO of Prism HRC, a leading recruitment services company in India. Nikhil’s expertise in talent acquisition and has been instrumental in connecting hundreds of top-notch clients with exceptional IT talent over the last 15 years.
