TwinEthosRequest access

Control

Automated employment tool without a current bias audit

An automated employment decision tool must have a bias audit within the last year, published.

Informational data, not legal advice. Summaries are TwinEthos's own words and rules have not been reviewed by a lawyer: check the official text before relying on any of it. A guard addresses an item; adding it is not a statement that your code meets any law.

Family: AI is used without bias, fairness, or proxy-discrimination controls · control id cond.aedt-without-bias-audit

Reach

1items this one guard addresses
1jurisdictions where binding law on it is in force
0more where it is enacted, not yet applying
0standards and frameworks on the same control

Law in force in New York City (US-NY-NYC).

The guard to add

Keep a dated bias-audit record for the AEDT with a link to its published summary, and disable AEDT scoring once the audit is more than one year old.

An audit record kept next to the tool (e.g. docs/bias-audit/aedt.yaml pointing to the independent auditor's report) with the audit date, the selection or scoring rates and impact ratios per category, and the URL of the published summary; the careers-site or job-posting source links that summary. A CI check or a guard in the scoring entry point compares the audit date with today and fails the build or refuses to score when the audit is older than a year or the summary link is missing. Schedule the next audit before the current one lapses.

Where it goes: 1 application source code, 11 CI/CD pipeline, 12 repository artifacts, 14 user-facing text.

What reviewers look for: a dated audit artifact (report or record with impact_ratio calculations) within the last 12 months, a link to the published audit summary in careers-site or job-posting source, and code or CI that ties the scoring path to that date rather than an audit mentioned only in prose.

Example (Python scoring service), before:

def score_candidate(c):
    return model.predict_proba([c.features])[0, 1]

After:

AUDIT = yaml.safe_load(open('docs/bias-audit/aedt.yaml'))

def score_candidate(c):
    audited = date.fromisoformat(str(AUDIT['audit_date']))
    if date.today() - audited > timedelta(days=365) or not AUDIT.get('published_summary_url'):
        raise AuditExpired('AEDT bias audit missing or older than one year; scoring disabled')
    return model.predict_proba([c.features])[0, 1]

Engineering guidance, not legal advice. Each provision below may add its own details (a cadence, a deadline, a required notice element): open it for those.

Every rule this guard addresses

Binding law — in force (1)

Related incidents

No guardrail sits on this exact control; these incidents are cited by guardrails on related controls.