TwinEthosRequest access

Control

No documented analysis of proxy variables

Systems using features that could proxy for protected traits should document a proxy-variable analysis.

Informational data, not legal advice. Summaries are TwinEthos's own words and rules have not been reviewed by a lawyer: check the official text before relying on any of it. A guard addresses an item; adding it is not a statement that your code meets any law.

Family: AI is used without bias, fairness, or proxy-discrimination controls · control id cond.no-documented-proxy-variable-analysis

Reach

1items this one guard addresses
0jurisdictions where binding law on it is in force
0more where it is enacted, not yet applying
1standards and frameworks on the same control

The guard to add

Keep a proxy-variable analysis for the decision system listing each input feature, the protected traits it could stand in for, the test run, and the decision taken.

An organizational record owned by the model's accountable owner, with review by whoever handles fairness or legal risk: a feature-risk register (docs/fairness/proxy-analysis.md or a section of the model card). It lists every input feature with its proxy risk, the evidence (correlation with protected attributes or inferred groups), the decision (keep with justification, coarsen, drop), the datasets used for bias validation and why they were chosen, and the system's application boundaries, meaning where it should not be used. It is updated whenever features or training data change and reviewed at each release; a CI check can confirm the record exists and names the current model version.

Where it goes: 2 data models, 12 repository artifacts, 13 tests and evals.

What reviewers look for: a dated record that covers every feature in the current feature list, states a decision and rationale for each proxy-capable feature, names the bias-validation dataset, and matches the deployed model version; not a generic fairness statement with no feature-level analysis.

Organizational control: the evidence is a kept record, its owner and its upkeep, not code.

Example (Feature-risk register (docs/fairness/proxy-analysis.yaml)), before:

model: tenant_screen_v2
features: [income, zip_code, years_at_address, school]

After:

model: tenant_screen_v2
reviewed: 2026-09-01
owner: risk-modeling-lead
application_boundary: residential rental screening only; not for employment or credit
bias_validation_data: holdout_2026q2 with BISG-inferred race/ethnicity (rationale: docs/fairness/data.md)
features:
  - name: zip_code
    proxy_for: [race, national_origin]
    evidence: strong association with inferred race in holdout
    decision: dropped
  - name: school
    proxy_for: [race, age]
    decision: coarsened to degree_level
  - name: income
    proxy_for: [sex]
    decision: kept; disparity tested, see reports/2026q2-fairness.html

Engineering guidance, not legal advice. Each provision below may add its own details (a cadence, a deadline, a required notice element): open it for those.

Every rule this guard addresses

Standard / soft law (1)

Related incidents

No guardrail sits on this exact control; these incidents are cited by guardrails on related controls.