Playbook ¡ 6 minute read
How to Build a Resume Screening System
A compliant resume screening system scores candidates against explicit job-related criteria rather than similarity to past hires, is bias-tested across protected groups before and during use, provides candidate notice where required, keeps the decision with a human recruiter, and retains audit evidence. Several jurisdictions regulate automated employment decisions directly, with penalties.
Resume screening is the AI application most companies reach for early and the one most heavily regulated, in ways teams frequently discover after deployment. Several jurisdictions now impose specific requirements on automated employment decision tools, anti-discrimination law applies to outcomes everywhere, and the failure mode, a system that learns who was hired before and reproduces the bias in those decisions, is both the easiest system to build and the one that creates liability. This guide covers building screening that helps recruiters and survives scrutiny, drawing on FISTA Solutions' AI agents delivery in HR operations. It complements ai resume screening and ai in hr recruiting. This article is general guidance, not legal advice.
What regulation applies?
More than most teams expect, and it varies by where the employer and the candidate are. Several jurisdictions require bias audits of automated employment decision tools, notice to candidates that such a tool is in use, and in some cases disclosure of the characteristics assessed. Anti-discrimination law applies to hiring outcomes regardless of what tool produced them, which means a system with disparate impact is a legal exposure whether or not a specific AI rule applies.
Data protection rules add requirements around automated decision-making affecting individuals, including in some regimes a right to human review and an explanation. Requirements should be established with counsel before the system is designed, because they shape the design rather than sitting on top of it.
Why not train on past hires?
Because the target variable is contaminated. A model trained to identify candidates resembling people the company hired and promoted learns the hiring patterns of the past, including every bias in them, and applies them at scale with the appearance of objectivity. If the historical team skewed in a particular direction, the model learns that skew as a success signal.
The alternative is scoring against explicit criteria derived from the role: the skills, experience, and qualifications the job actually requires, documented with a justification for why each is job-related. That is more work, produces a system that can be explained, and is defensible in a way a similarity model is not.
What are proxies and why do they matter?
Features that correlate with protected characteristics without naming them: school or university attended, postcode, employment gaps, sports and activities, language patterns, years since graduation as a proxy for age, and names. A model given these will use them, and removing the protected characteristic itself does nothing.
| Feature | Proxy risk | Handling |
|---|---|---|
| Institution attended | Socioeconomic, racial | Exclude or justify explicitly |
| Postcode or address | Racial, socioeconomic | Exclude |
| Employment gaps | Disability, caring, gender | Exclude or handle neutrally |
| Graduation year | Age | Exclude |
| Name | Racial, gender, national origin | Redact before scoring |
| Photos | Multiple | Redact before scoring |
| Extracurricular activities | Socioeconomic, gender | Scrutinise carefully |
Testing for proxy effects, rather than assuming exclusion of protected fields is sufficient, is the substance of bias testing.
What does bias testing involve?
Measuring outcomes across protected groups on a representative sample: selection rates, score distributions, and the rate at which each group is advanced. Comparing against the applicable standard for disparate impact in the relevant jurisdiction. Testing whether removing candidate features changes outcomes in ways that reveal proxy reliance. And repeating on a schedule and after every material change to the model, criteria, or candidate pool.
The audit and its methodology should be documented, because several jurisdictions require publication or provision on request. See the ai fairness audit checklist.
How much human involvement is required?
Enough to constitute a decision. A recruiter who reviews the ranked list and advances the top candidates has not made a decision; they have ratified one. Requirements in several jurisdictions expect meaningful human involvement, and audits examine whether it exists in practice.
Designs that support genuine decisions present candidates with their scores against each criterion and the evidence from the resume, rather than a single ranking; require the recruiter to record a reason for advancing or rejecting; and make it easy to advance a candidate the system ranked low, which is the behaviour that proves the human is deciding.
What should the system actually do?
Structured extraction and scoring, transparently. Extract qualifications, skills, and experience from the resume into a structured profile. Score each against the documented job criteria with the supporting evidence cited. Present the profile, the scores, and the evidence to the recruiter. Flag missing information rather than inferring it.
What it should not do: infer protected characteristics, score on personality or culture fit, rank on similarity to existing employees, or reject candidates automatically.
What evidence must be retained?
The criteria and their job-relatedness justification. Each candidate's structured profile, scores, and the evidence cited. The human decision, who made it, and the reason recorded. Bias audit results and methodology. Notices provided to candidates. The model and version in use at the time of each decision. Retained for the record-keeping period applicable to hiring records in the jurisdiction.
This is the evidence an audit, a regulator, or a claim will ask for, and it must exist at the time of the decision rather than be reconstructed.
How is it evaluated?
Extraction accuracy against recruiter-verified profiles. Scoring agreement with experienced recruiters on a blind sample. Bias metrics across protected groups. The rate at which recruiters override the system's ranking, which indicates whether they are deciding. And hiring outcomes over time, including whether candidates advanced by the system succeed, which is the only real validity check.
What does the build sequence look like?
Two to three weeks establishing legal requirements with counsel and documenting job-related criteria with the hiring function. Two weeks on extraction and structured profiling with redaction of proxy fields. Two weeks on criteria scoring with evidence citation. Two weeks on bias testing before any live use, with results reviewed by legal. One week on the recruiter interface designed for genuine decisions. Then notice implementation and audit scheduling.
What goes wrong?
Training on past hires. Excluding protected fields and assuming that suffices. Bias testing deferred until a complaint. Rankings that recruiters rubber-stamp. Notice omitted. Culture fit scoring. Evidence not retained at decision time. And deployment across jurisdictions without checking what each requires.
How FISTA Solutions helps
FISTA Solutions builds resume screening against documented job-related criteria with proxy redaction, bias testing before launch and on schedule, recruiter interfaces designed for genuine decisions, and audit evidence captured at decision time, with legal requirements established before design, through AI enablement, AI agents, and forward deployed engineers. The record behind the approach is 150+ projects for 50+ companies with 99.9% uptime.
To screen at volume without creating liability, message FISTA on WhatsApp, or read ai in hr recruiting.
Share-ready article cover
Download the generated social format.
Clear answers
Questions raised by this field note.
Straightforward guidance for evaluating scope, fit, and the next step.
01What regulation applies to AI resume screening?
Several jurisdictions regulate automated employment decision tools with requirements for bias audits, candidate notice, and human involvement, and anti-discrimination law applies to outcomes everywhere regardless of tool. Requirements differ by location of the employer and the candidate. Confirm with counsel; this is general guidance, not legal advice.
02Why not train on past successful hires?
Because it learns who was hired before, including whatever bias existed in those decisions, and reproduces it at scale with apparent objectivity. Screening should score against explicit job-related criteria derived from the role's requirements, not against resemblance to the current team.
03What does bias testing involve?
Measuring selection rates and score distributions across protected groups on a representative sample, checking for disparate impact against the applicable standard, testing for proxies such as school, postcode, or employment gaps that correlate with protected characteristics, and repeating on a schedule and after any change.
04How much human involvement is required?
Enough to be a genuine decision. Common requirements include a human making or meaningfully reviewing the decision rather than rubber-stamping a ranking, with reasons recorded. A recruiter who advances whoever the system ranked first has not made a decision, and that is visible in an audit.
05What evidence should be retained?
The criteria used and their job-relatedness justification, each candidate's scores and the reasons, the human decision and who made it, the bias audit results and methodology, notices given, and the model and version in use, retained per the applicable record-keeping period.
Continue exploring
Related capabilities
Start with the hard problem
Need the outcome owned, not merely analyzed?
Tell us where delivery is constrained. Weâll map the fastest credible path from intent to verified production.