AI Recruitment Assessment Compliance Checklist: Bias, Explainability, Consent, Human Review
Using AI to screen candidates in the UK triggers four duties at once: the Equality Act, UK GDPR, ICO expectations and the EU AI Act. This checklist runs them before you deploy, not after a complaint.

By Ivan Pylypchuk, CEO of SoftBlues. Has led Claude and AI implementations for finance, legal and healthcare teams across the UK and Ireland.
If you use AI to screen or score candidates in the UK, four duties apply at once: the Equality Act 2010 (no discrimination), UK GDPR (fair, transparent processing and rights over automated decisions), the ICO's recruitment expectations, and, if you hire in the EU, the EU AI Act's high-risk rules. This checklist turns those duties into steps you can run before you deploy an AI recruitment tool, not after a complaint.
At SoftBlues, an AI implementation firm working with regulated mid-market companies across the UK and Ireland, we build and review these workflows for a living. The checklist below is the one we run ourselves.
Key facts
Who this is for, and who it isn't
This is for the person who signs off an AI recruitment tool in a 50–500-person UK or Ireland firm: a Head of HR, a COO, a DPO or the hiring lead in a regulated sector. If you are about to buy, renew or expand an AI screening tool, this is your pre-deployment list.
It is not legal advice, and it is not a substitute for your own DPO or employment lawyer. It is the practical checklist that gets you to a sensible conversation with them.
Why AI hiring is a compliance problem, not just an HR one
The ICO made automated decision-making in recruitment a regulatory priority, published a dedicated report on 31 March 2026, and in 2024 issued close to 300 recommendations after auditing providers (ICO). That is not a regulator warming up. It is a regulator that has already looked under the bonnet and found problems.
The ICO's headline finding is that many employers using automated recruitment are relying on decisions that are effectively solely automated, with no meaningful human involvement, and those decisions have a significant effect on people's lives. That is the exact situation UK GDPR restricts and the Equality Act can turn into a discrimination claim.
The four rulebooks you are under
| Rulebook | What it covers | Who enforces it |
|---|---|---|
| Equality Act 2010 | No direct or indirect discrimination against protected groups | Employment tribunals, EHRC |
| UK GDPR | Fair, transparent processing; rights over solely automated decisions | ICO |
| ICO recruitment expectations | Bias testing, transparency, meaningful human review | ICO |
| EU AI Act (if hiring in the EU) | High-risk obligations: risk assessment, oversight, explanation | National market-surveillance authorities |
The point of the table is simple. You do not get to pick one. A single AI screening step can engage all four at once, which is why a checklist that only covers data protection, or only covers bias, leaves you exposed.
The compliance checklist
Run these before you deploy, and re-run the testing and monitoring items on a schedule after.
1. Bias testing before and after launch. Test the tool's outputs across protected characteristics, using real or representative data, before it touches a live candidate. Then keep testing, because a model's behaviour drifts as your applicant pool changes.
2. An equality impact assessment. Document who could be disadvantaged by the tool and why, what you tested, and what you changed. This is your evidence if a decision is ever challenged.
3. A data protection impact assessment (DPIA). Automated candidate assessment is high-risk processing, so a DPIA is expected. It records the lawful basis, the data used, the risks and the mitigations.
4. Transparency to candidates. Tell candidates, in plain language and before they apply, that AI is used, what it does and what role it plays in the decision. Hidden automation is the fastest way to lose a case.
5. A route to challenge and request human review. Candidates must be able to contest a decision and ask for a human to look again. Under UK GDPR this is a right, not a courtesy.
6. Meaningful human review, not a rubber stamp. A person must be able to genuinely change the outcome, with the authority, time and information to do so. Clicking "confirm" on the model's ranking is not review.
7. Data minimisation and retention. Collect only what the assessment needs, store it no longer than necessary, and document where it lives and who processes it.
8. Vendor due diligence. Get the vendor's bias-testing evidence, their model documentation and their data-processing terms in writing. Under the EU AI Act, liability is shared, but under UK law the deploying employer still carries the duty.
Bias: how to actually test it
Bias testing is not a one-line assurance from a vendor. It means running the tool's decisions against protected characteristics and looking for a group that is disadvantaged at a higher rate without a job-related reason.
Two failure modes matter. Direct discrimination is the tool scoring someone lower because of a protected characteristic. Indirect discrimination is a neutral-looking criterion, such as an employment-gap penalty, that hits one group harder. AI is particularly good at the second kind, because it finds correlations you never intended.
The workable standard is: test before launch, monitor after, and keep the records. A tool that was fair at launch can drift, and "we tested it once in 2025" will not hold up.
Explainability: what a candidate can ask for
Under UK GDPR, and under EU AI Act Article 86 for high-risk systems, individuals can ask for an explanation of a significant automated decision. "The algorithm decided" is not an explanation.
What you need is a per-candidate rationale in plain English: the main factors that drove the score, expressed in terms a person can understand and, if needed, contest. If your tool can only output a number, you cannot meet this, and you should fix it before launch, not after the first subject access request.
Consent, transparency and candidate rights
Transparency is the cheapest safeguard and the one most often skipped. Tell candidates up front that AI is part of the process, what it assesses and how a human is involved. Publish it in the job advert and the privacy notice.
Note that consent is usually the wrong lawful basis for employment processing, because the power imbalance makes it hard to call freely given. Most employers rely on legitimate interests with proper safeguards. Your DPO should confirm the basis, but do not default to a consent checkbox and assume you are covered.
Meaningful human review, in practice
The ICO is explicit that human involvement must be active and capable of changing the outcome, not a token gesture. In a real workflow that looks like a named reviewer who sees the model's reasoning, has the authority to overturn it, and records the decision.
Our approach on assessment builds, including our work with the HR platform SofiaHR, keeps the model in an advisory role and a person on the decision. It is slower than full automation, and that is the point. A slightly slower process you can defend beats a fast one you cannot.
Worked example
A mid-market firm hiring across finance and operations wanted to add AI screening to cope with rising application volumes. Before deployment we ran the checklist: a DPIA, a bias test across protected characteristics on historic applications, a plain-English candidate notice added to every advert, and a review step where a hiring manager saw the model's reasoning and signed off every rejection. Two criteria that disadvantaged career-returners were removed after testing. The firm went live with a screening process that was faster than manual sifting and had a record behind every decision.
Red flags in a vendor's answers
Frequently asked questions
Is using AI in recruitment legal in the UK?
Yes, with safeguards. You must meet the Equality Act 2010, UK GDPR and the ICO's expectations, which means bias testing, transparency and meaningful human review. It is the way you use the tool, not the tool itself, that determines compliance.What does the ICO expect from employers using AI hiring tools?
Monitor and test for bias, be transparent with candidates that automation is used, give candidates a route to challenge a decision and request human review, and make sure human involvement is genuine rather than a rubber stamp (ICO).Does the EU AI Act apply if we only hire in the UK?
Not directly. The EU AI Act applies where you hire in the EU or your tool is used there. If you only hire in the UK, the Equality Act, UK GDPR and ICO guidance govern you, but the EU rules are a useful benchmark for good practice.Can a candidate demand a human review of an AI decision?
Yes. Under UK GDPR, candidates have rights around decisions made solely by automated means, including the right to contest them and obtain human intervention. Your process must make that route real and easy to use.Who is liable if an AI tool discriminates, us or the vendor?
The employer carries the legal duty not to discriminate and to process data lawfully. The EU AI Act shares some obligations with developers, but you cannot outsource your liability to a vendor by buying their tool.How often should we re-test for bias?
Test before launch and then on a regular schedule, at least when your applicant pool, the role mix or the model changes. Treat it as ongoing monitoring, not a one-off certificate.What is the fastest way to fail a compliance review?
Auto-rejecting candidates with no meaningful human review and no transparency. It engages UK GDPR, the Equality Act and ICO guidance at the same time.SoftBlues is a registered Anthropic Partner Network member and a Google Cloud Partner. We build AI hiring workflows that a compliance team can sign off, with bias testing, explainable scoring and a real human-review step designed in from the start. If you are choosing between tools, our companion guide on off-the-shelf versus custom recruitment assessment covers the build decision, and AI interviews: the good, the bad and the illegal covers where AI hiring goes wrong. To see how we approach the wider workflow, look at our work on business process automation.
See it in production
Systems we have built and run for clients, with the numbers that came out of them.


