Skip to main content
Download free report
Softblues
Softblues
Back to Blog
AI for HR & Recruiting
July 14, 20269 min read

AI Recruitment Assessment Compliance Checklist: Bias, Explainability, Consent, Human Review

Using AI to screen candidates in the UK triggers four duties at once: the Equality Act, UK GDPR, ICO expectations and the EU AI Act. This checklist runs them before you deploy, not after a complaint.

AI Recruitment Assessment Compliance Checklist: Bias, Explainability, Consent, Human Review

By Ivan Pylypchuk, CEO of SoftBlues. Has led Claude and AI implementations for finance, legal and healthcare teams across the UK and Ireland.

If you use AI to screen or score candidates in the UK, four duties apply at once: the Equality Act 2010 (no discrimination), UK GDPR (fair, transparent processing and rights over automated decisions), the ICO's recruitment expectations, and, if you hire in the EU, the EU AI Act's high-risk rules. This checklist turns those duties into steps you can run before you deploy an AI recruitment tool, not after a complaint.

At SoftBlues, an AI implementation firm working with regulated mid-market companies across the UK and Ireland, we build and review these workflows for a living. The checklist below is the one we run ourselves.

Key facts

  • The ICO published a report and draft guidance on automated decision-making in recruitment on 31 March 2026, with consultation open until 29 May 2026 (ICO).
  • In 2024 the ICO audited AI recruitment providers and made nearly 300 recommendations to improve legal compliance (ICO).
  • AI used to screen, filter, rank or evaluate candidates is high-risk under the EU AI Act, with obligations applying from 2 August 2026 (EU AI Act, Annex III).
  • The legal duty stays with the employer. Buying a compliant-looking tool does not transfer liability to the vendor.
  • The four safeguards regulators keep returning to are bias testing, explainability, transparency and consent, and meaningful human review.
  • Who this is for, and who it isn't

    This is for the person who signs off an AI recruitment tool in a 50–500-person UK or Ireland firm: a Head of HR, a COO, a DPO or the hiring lead in a regulated sector. If you are about to buy, renew or expand an AI screening tool, this is your pre-deployment list.

    It is not legal advice, and it is not a substitute for your own DPO or employment lawyer. It is the practical checklist that gets you to a sensible conversation with them.

    Why AI hiring is a compliance problem, not just an HR one

    The ICO made automated decision-making in recruitment a regulatory priority, published a dedicated report on 31 March 2026, and in 2024 issued close to 300 recommendations after auditing providers (ICO). That is not a regulator warming up. It is a regulator that has already looked under the bonnet and found problems.

    The ICO's headline finding is that many employers using automated recruitment are relying on decisions that are effectively solely automated, with no meaningful human involvement, and those decisions have a significant effect on people's lives. That is the exact situation UK GDPR restricts and the Equality Act can turn into a discrimination claim.

    The four rulebooks you are under

    RulebookWhat it coversWho enforces it
    Equality Act 2010No direct or indirect discrimination against protected groupsEmployment tribunals, EHRC
    UK GDPRFair, transparent processing; rights over solely automated decisionsICO
    ICO recruitment expectationsBias testing, transparency, meaningful human reviewICO
    EU AI Act (if hiring in the EU)High-risk obligations: risk assessment, oversight, explanationNational market-surveillance authorities

    The point of the table is simple. You do not get to pick one. A single AI screening step can engage all four at once, which is why a checklist that only covers data protection, or only covers bias, leaves you exposed.

    The compliance checklist

    Run these before you deploy, and re-run the testing and monitoring items on a schedule after.

    1. Bias testing before and after launch. Test the tool's outputs across protected characteristics, using real or representative data, before it touches a live candidate. Then keep testing, because a model's behaviour drifts as your applicant pool changes.

    2. An equality impact assessment. Document who could be disadvantaged by the tool and why, what you tested, and what you changed. This is your evidence if a decision is ever challenged.

    3. A data protection impact assessment (DPIA). Automated candidate assessment is high-risk processing, so a DPIA is expected. It records the lawful basis, the data used, the risks and the mitigations.

    4. Transparency to candidates. Tell candidates, in plain language and before they apply, that AI is used, what it does and what role it plays in the decision. Hidden automation is the fastest way to lose a case.

    5. A route to challenge and request human review. Candidates must be able to contest a decision and ask for a human to look again. Under UK GDPR this is a right, not a courtesy.

    6. Meaningful human review, not a rubber stamp. A person must be able to genuinely change the outcome, with the authority, time and information to do so. Clicking "confirm" on the model's ranking is not review.

    7. Data minimisation and retention. Collect only what the assessment needs, store it no longer than necessary, and document where it lives and who processes it.

    8. Vendor due diligence. Get the vendor's bias-testing evidence, their model documentation and their data-processing terms in writing. Under the EU AI Act, liability is shared, but under UK law the deploying employer still carries the duty.

    Important
    If you cannot produce evidence for items 1, 2, 3 and 6 today, you are not ready to deploy. Those four are the ones the ICO and a tribunal will ask for first.

    Bias: how to actually test it

    Bias testing is not a one-line assurance from a vendor. It means running the tool's decisions against protected characteristics and looking for a group that is disadvantaged at a higher rate without a job-related reason.

    Two failure modes matter. Direct discrimination is the tool scoring someone lower because of a protected characteristic. Indirect discrimination is a neutral-looking criterion, such as an employment-gap penalty, that hits one group harder. AI is particularly good at the second kind, because it finds correlations you never intended.

    The workable standard is: test before launch, monitor after, and keep the records. A tool that was fair at launch can drift, and "we tested it once in 2025" will not hold up.

    Explainability: what a candidate can ask for

    Under UK GDPR, and under EU AI Act Article 86 for high-risk systems, individuals can ask for an explanation of a significant automated decision. "The algorithm decided" is not an explanation.

    What you need is a per-candidate rationale in plain English: the main factors that drove the score, expressed in terms a person can understand and, if needed, contest. If your tool can only output a number, you cannot meet this, and you should fix it before launch, not after the first subject access request.

    Transparency is the cheapest safeguard and the one most often skipped. Tell candidates up front that AI is part of the process, what it assesses and how a human is involved. Publish it in the job advert and the privacy notice.

    Note that consent is usually the wrong lawful basis for employment processing, because the power imbalance makes it hard to call freely given. Most employers rely on legitimate interests with proper safeguards. Your DPO should confirm the basis, but do not default to a consent checkbox and assume you are covered.

    Meaningful human review, in practice

    The ICO is explicit that human involvement must be active and capable of changing the outcome, not a token gesture. In a real workflow that looks like a named reviewer who sees the model's reasoning, has the authority to overturn it, and records the decision.

    Our approach on assessment builds, including our work with the HR platform SofiaHR, keeps the model in an advisory role and a person on the decision. It is slower than full automation, and that is the point. A slightly slower process you can defend beats a fast one you cannot.

    Worked example

    A mid-market firm hiring across finance and operations wanted to add AI screening to cope with rising application volumes. Before deployment we ran the checklist: a DPIA, a bias test across protected characteristics on historic applications, a plain-English candidate notice added to every advert, and a review step where a hiring manager saw the model's reasoning and signed off every rejection. Two criteria that disadvantaged career-returners were removed after testing. The firm went live with a screening process that was faster than manual sifting and had a record behind every decision.

    Red flags in a vendor's answers

  • "Our model is proprietary, so we cannot share how it scores."
  • "We have never had a discrimination complaint," offered instead of test evidence.
  • No documented human-review step, or one that only allows confirming the model.
  • No DPIA support and vague answers on data location and retention.
  • A claim that using their tool makes you compliant. Compliance is your duty, not a feature you can buy.
  • Frequently asked questions

    Yes, with safeguards. You must meet the Equality Act 2010, UK GDPR and the ICO's expectations, which means bias testing, transparency and meaningful human review. It is the way you use the tool, not the tool itself, that determines compliance.

    What does the ICO expect from employers using AI hiring tools?

    Monitor and test for bias, be transparent with candidates that automation is used, give candidates a route to challenge a decision and request human review, and make sure human involvement is genuine rather than a rubber stamp (ICO).

    Does the EU AI Act apply if we only hire in the UK?

    Not directly. The EU AI Act applies where you hire in the EU or your tool is used there. If you only hire in the UK, the Equality Act, UK GDPR and ICO guidance govern you, but the EU rules are a useful benchmark for good practice.

    Can a candidate demand a human review of an AI decision?

    Yes. Under UK GDPR, candidates have rights around decisions made solely by automated means, including the right to contest them and obtain human intervention. Your process must make that route real and easy to use.

    Who is liable if an AI tool discriminates, us or the vendor?

    The employer carries the legal duty not to discriminate and to process data lawfully. The EU AI Act shares some obligations with developers, but you cannot outsource your liability to a vendor by buying their tool.

    How often should we re-test for bias?

    Test before launch and then on a regular schedule, at least when your applicant pool, the role mix or the model changes. Treat it as ongoing monitoring, not a one-off certificate.

    What is the fastest way to fail a compliance review?

    Auto-rejecting candidates with no meaningful human review and no transparency. It engages UK GDPR, the Equality Act and ICO guidance at the same time.
    SoftBlues is a registered Anthropic Partner Network member and a Google Cloud Partner. We build AI hiring workflows that a compliance team can sign off, with bias testing, explainable scoring and a real human-review step designed in from the start. If you are choosing between tools, our companion guide on off-the-shelf versus custom recruitment assessment covers the build decision, and AI interviews: the good, the bad and the illegal covers where AI hiring goes wrong. To see how we approach the wider workflow, look at our work on business process automation.

    Book a discovery call.

    See it in production

    Systems we have built and run for clients, with the numbers that came out of them.

    Browse all case studies

    Related Articles