Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

AI impact assessment for recruitment across sourcing, screening, interviews and selection with candidate harms

AI Impact Assessment for Recruitment Guide 2026

An AI impact assessment for recruitment examines how automated tools used to source, screen, rank, interview and select candidates could affect the people applying for jobs. Hiring decisions shape lives, the tools often operate at scale, and the data involved is personal and sometimes sensitive. Regulators and courts have taken a close interest, and candidates increasingly expect to know when a machine has judged them. This guide explains the legal and standards context, how to map where AI acts in the hiring funnel, which harms to assess, how to test tools for bias and accuracy, how to design human oversight and notices, and how to keep monitoring after launch.

Why recruitment is a high-attention use of AI

Recruitment tools affect access to work, which is a fundamental interest. The EU AI Act treats AI systems used for recruitment or selection, in particular to place targeted job advertisements, to analyze and filter applications and to evaluate candidates, as high-risk in its Annex III. It also prohibits AI systems that infer emotions of people in the workplace, with limited exceptions, which can affect tools that claim to read emotions in video interviews. You can find the text on EUR-Lex. Check the current application dates, since timelines have been subject to change.

Other rules apply as well. Article 22 of the GDPR restricts decisions based solely on automated processing with legal or similarly significant effects. Discrimination law applies to hiring in most jurisdictions, whether the decision is made by a person or a tool. New York City’s Local Law 144 requires a bias audit and notice to candidates for automated employment decision tools, and other jurisdictions have adopted or proposed similar rules. Our guide to the ISO 42001 impact assessment explains the management system requirement that sits behind such an assessment.

Map an AI impact assessment for recruitment onto the hiring funnel

StageTypical AI useMain concerns
Sourcing and advertisingTargeting job adverts, candidate searchWho never sees the role, indirect discrimination
Application screeningCV parsing, ranking, knock-out rulesUnfair ranking, proxies for protected traits, errors in parsing
AssessmentGames, tests, coding challenges, scoringValidity, accessibility, disability, cultural bias
InterviewVideo analysis, transcription, scoring, chatbotsAccent and speech bias, emotion inference, privacy
Selection and offerRecommendation, pay suggestionsReliance on scores, pay equity
Onboarding and checksIdentity verification, background screeningBiometric processing, accuracy, criminal data

Start with an inventory of all tools in use, including features inside applicant tracking systems that were switched on by default and tools used by recruitment agencies on your behalf. Then screen each one using the questions in our guide to AI impact assessment screening. Most recruitment tools will need a full assessment because they influence decisions about people.

Free AI impact assessment (ISO 42005)

Who could this AI system affect, and how?

Screen the system against sensitive and prohibited uses, describe it, check the safeguards for fairness, transparency and oversight, and rate its impacts on people and society from 26 scenarios with ISO 42001 Annex A measures. Free, with findings.

Start the free AI impact assessment →  or  View premium report sample

Affected parties and harms in an AI impact assessment for recruitment

Affected parties include applicants, especially those from groups likely to be disadvantaged, candidates with disabilities or non-standard careers, recruiters who rely on the tool, hiring managers, and the wider labor market. Harms to consider include the following.

  • Unfair exclusion. Qualified people ranked low or rejected because of patterns in the training data or proxies for protected characteristics.
  • Inaccuracy. Parsing errors, misread CVs and invalid scoring methods that do not predict job performance.
  • Lack of accessibility. Tools that disadvantage people with disabilities, speech differences or limited access to technology.
  • Privacy intrusion. Excessive data collection, social media scraping, biometric analysis and unexplained inference.
  • Opacity. Candidates not told AI is used, or given no way to understand or challenge outcomes.
  • Loss of human judgment. Recruiters over-relying on scores and not reading applications.

Use our AI harm taxonomy to make sure no category is missed, and involve those affected. Our guide to AI impact assessment stakeholders explains how to gather their views.

Testing recruitment tools for bias and validity

Ask two questions: does the tool measure what it claims to, and does it treat groups fairly? Validity means the score predicts relevant job performance, not just similarity to past hires. Ask the supplier for validation studies, and check whether they cover roles like yours. For fairness, compare selection rates and error rates across relevant groups, using the methods in our guide to AI bias testing. In United States practice, the four-fifths rule is a common screening measure of adverse impact, but it is not a safe harbor. Test tools on your own applicant data where lawful, and repeat the tests when the tool or the applicant pool changes.

Third-party tools and agencies

Most recruitment AI is bought from suppliers. You remain accountable for the way it is used in your hiring. Follow the approach in our guide to third-party AI impact assessment: ask suppliers for documentation and test results, record what you could not obtain, test in your context and write commitments into the contract. Where an agency uses AI on your behalf, require it to disclose its tools and to meet the same standards.

Human oversight and candidate rights

Design oversight so that people have real influence. Recruiters should see why a candidate was ranked as they were, have the authority to override, and review rejected applications from a sample to check for errors. Avoid fully automated rejection without human review for decisions with significant effects. Give candidates clear notice that AI is used, what it does and how to request human review or reasonable adjustments, for example an alternative assessment for a person with a disability. Offer a route to ask questions and to contest a result, and respond in a defined time.

Data protection alongside the impact assessment

Recruitment AI almost always involves personal data, and often warrants a DPIA. Share the system description between the two assessments and cross-refer them, as described in our guide to AI impact assessment versus DPIA. Limit the data to what is relevant to the role, set short retention for unsuccessful candidates, and avoid scraping personal data from social media without a clear basis.

Keep the scope of the assessment aligned with how the tool is really used, which is often broader than the vendor’s brochure suggests. Interview recruiters about what they actually do with the scores, since practice, not design, determines the effect on candidates. A tool intended only to help with sorting can become the de facto decision maker when workloads are high.

A short worked example

A retailer adopts a screening tool that ranks applications for store roles. The assessment maps the funnel and finds the tool influences shortlisting. It identifies risks that career breaks and part-time experience lower scores, and that the tool cannot process some document formats. Bias testing on last year’s applicants shows a gap in selection rates for older candidates. The supplier adjusts the model and the retailer adds a recruiter review of all candidates ranked below the cut-off who meet the minimum requirements, offers an alternative application route, tells candidates that AI is used, and monitors selection rates each quarter. The approver signs off subject to a repeat test after the next model update.

Monitoring after an AI impact assessment for recruitment

Track selection rates by group, complaints, override rates, time to hire and candidate feedback. Set thresholds that trigger review, and repeat the assessment after model updates, new roles, new markets, new data sources or regulatory change. Keep records of tests, decisions and changes, and store them with the AI impact assessment for recruitment so an auditor can follow the story. Assign a named owner in HR and a reviewer from compliance or legal.

Common mistakes in an AI impact assessment for recruitment

Organizations assume the supplier has checked fairness, forget agencies and embedded features, test only overall accuracy, neglect accessibility, give candidates no notice or route to challenge, treat scores as decisions and never repeat the assessment. Another mistake is assessing only the ranking step and leaving out advertising and background checks, where significant effects also arise.

Using a ready structure

If you want a starting structure, the AI Impact Assessment Report and Workbook provides a structured report with screening, impacts on people, safeguards and a working register that you can adapt for hiring tools. You can also see a completed record in our AI impact assessment example. Whatever you use, complete the AI impact assessment for recruitment before the tool is used on real candidates.

AI impact assessment for recruitment FAQ

Are AI recruitment tools high-risk under the EU AI Act?

Systems used for recruitment or selection, including targeting adverts, filtering applications and evaluating candidates, are listed as high-risk in Annex III, and emotion inference in the workplace is prohibited with limited exceptions.

Who is responsible when a vendor’s tool discriminates?

The employer generally remains responsible for hiring decisions and how tools are used, so it should assess, test and monitor them, and set contract terms with the supplier.

Do candidates have to be told?

Transparency is expected, and some laws require notice. Tell candidates when AI is used, what it does and how to ask for human review or adjustments.

How do I test for bias?

Compare selection and error rates across groups using your own data where lawful, investigate gaps, fix and retest, and repeat after changes to the tool or applicant pool.

How often should the assessment be repeated?

After model updates, changes in roles or markets, new data sources, incidents or regulatory changes, and at least annually.

When a standard changes, know first

One email a month: edition changes, new deadlines, and what they mean for documentation you already have. No sales sequence.

We don’t spam! Read our privacy policy for more info.