Governance · 5 minute read
New York City AI Hiring Law: Audits and Notices
New York City requires employers using automated employment decision tools to obtain an independent bias audit within the previous year, publish a summary of the results, and notify candidates and employees before use. The duty sits with the employer, not the vendor.
New York City requires an independent bias audit for automated employment decision tools, published results, and candidate notices. The obligation sits with the employer rather than the vendor, which is the part most often misunderstood. This guide covers it, drawing on FISTA Solutions' AI enablement work. This article is general guidance, not legal advice.
What does the rule require?
Three things, all before the tool is used on a candidate.
| Requirement | What it means |
|---|---|
| Independent bias audit | Conducted within the previous year |
| Published summary | Results publicly available on the site |
| Candidate notice | Given before the tool is used |
| Qualifications disclosed | What the tool assesses |
| Data and retention information | Available on request or published |
| Records | Evidence the above happened |
What counts as a tool in scope?
Broadly, a computational process issuing a simplified output — a score, classification, or ranking — used to substantially assist or replace discretionary decision-making about hiring or promotion.
Scope turns on how the output is used rather than on the technology. A resume screener that ranks candidates is in scope; a tool that only schedules interviews is generally not. The question to ask about any tool is what decision its output influences and how much weight it carries.
What does the bias audit involve?
An independent assessment calculating selection or scoring rates across sex and race or ethnicity categories, and the impact ratios between groups.
The practical difficulty is data: the audit needs demographic information about candidates, which many employers do not collect, and test data may be used in defined circumstances. Establish what data you have before commissioning the audit, because that determines what is possible.
Who carries the obligation?
The employer or employment agency using the tool, not the vendor supplying it.
A vendor-supplied audit can be a useful input and does not discharge the duty. Employers relying on a vendor's assurance without their own current audit are exposed, and the fact that the vendor is large does not change that.
What evidence do you need?
The audit report and its date, the published summary and where it appears, notice records showing candidates were informed before use, the data used for the audit, and records of which tool version was in use during which period.
If that evidence exists as a by-product of how systems are built and operated, you are in good shape. If it exists only as documents written for a review, you are not, and the difference is visible to anyone who looks carefully.
How does this change engineering practice?
It pushes demographic data collection and version tracking earlier than most hiring stacks plan for. An audit needs data, and a tool that changed materially since the last audit raises the question of whether the audit still describes it.
Record which version of which tool was used for which requisition. Without that, an audit cannot be tied to the decisions it supposedly covers.
How does it interact with other regimes?
Usually more than expected. The same system can attract questions from a data protection authority, a sector supervisor, and a general AI regulator, each starting from a different premise and arriving at overlapping requirements.
One evidence base mapped to several requirements answers all of them. Separate programmes produce separate documents describing the same systems, and inconsistencies between them are themselves a finding.
What does compliance cost?
Mostly the cost of good engineering practice: evaluation, documentation, logging, and oversight design. Built into a project, the incremental cost is modest and much of it is work the system needed anyway.
Retrofitted onto a live system it becomes a project, performed under a deadline you did not choose, on something people already depend on. See AI compliance audit cost.
What are the common mistakes?
Relying on a vendor's audit without your own. Letting the audit lapse past a year. Giving notice after the tool has already scored a candidate. And changing the tool materially without re-auditing.
Who owns this internally?
The function that owns the systems, with legal and compliance support. Ownership by compliance alone produces documents describing systems nobody changed; ownership by engineering alone produces good practice with no one accountable for the interpretation.
Name a person per system rather than a committee. Committees review; people decide.
What should you ask a supplier?
What documentation they provide about capabilities and limitations, what evaluation evidence they share, how they handle personal data, where processing happens, and what happens to your prompts and outputs.
Suppliers who have prepared answer those quickly. Suppliers who have not take weeks, and that delay is itself information about how the relationship will run.
How do you keep this current?
Assign someone to watch the sources that actually bind you rather than general commentary. Record what was checked and when, so the next review starts from a known point.
Rules in this area change, and a position taken eighteen months ago and never revisited is a risk in itself.
How does this interact with other jurisdictions?
It stacks. Federal employment law applies regardless, other states have their own rules on AI in hiring, and equality obligations elsewhere reach the same decisions.
An employer operating in several places generally finds it cheaper to run one audit and notice process built to the strictest requirement than to maintain per-location variants that produce inconsistent candidate experiences.
What should you do first?
List every tool that produces a score, ranking, or classification used in hiring or promotion decisions, and check when each was last audited. Most organisations find at least one tool nobody had classified as in scope.
How FISTA Solutions helps
FISTA Solutions builds AI systems so the evidence exists when it is needed: tool versions recorded per decision so audits can be tied to the decisions they cover, notices delivered before scoring rather than after, evaluation results dated and versioned, oversight designed structurally rather than asserted in policy, and documentation produced during the build rather than reconstructed afterwards. Delivery runs through AI enablement, AI agents, and forward deployed engineers. The record is 150+ projects for 50+ companies across 12+ countries.
To align a system with these requirements, message FISTA on WhatsApp, or read AI and employment law.
Share-ready article cover
Download the generated social format.
Clear answers
Questions raised by this field note.
Straightforward guidance for evaluating scope, fit, and the next step.
01What counts as an automated employment decision tool?
Broadly, a computational process that issues a simplified output such as a score or classification used to substantially assist or replace discretionary decision-making about hiring or promotion. Scope turns on how the output is used. This is general guidance, not legal advice.
02What does the bias audit involve?
An independent assessment calculating selection or scoring rates across sex and race or ethnicity categories, and the impact ratios between groups, using data appropriate to the tool and the employer's use of it.
03Who carries the obligation?
The employer or employment agency using the tool, not the vendor supplying it. A vendor audit can be a useful input, but the duty to have a current audit and publish results sits with whoever uses the tool.
04What notices are required?
Candidates and employees resident in the city must be notified before use, including that the tool will be used, the job qualifications and characteristics it assesses, and information about the data collected and retention policy.
05What evidence should you keep?
The audit report and its publication date, the published summary, notice records showing candidates were informed before use, the data used for the audit, and records of which tool version was in use when.
Continue exploring
Related capabilities
Start with the hard problem
Need the outcome owned, not merely analyzed?
Tell us where delivery is constrained. We’ll map the fastest credible path from intent to verified production.