AI Governance, Risk & Red Teaming
Aware · M14 · lesson 14 of 18 · queued
Preview — browse every lesson free. Enroll to mark lessons complete, open partner links and save your progress. Login & enroll →
NYC Local Law 144 AEDT - Post-Comptroller-Audit Enforcement
📖
now learning

NYC Local Law 144 AEDT - Post-Comptroller-Audit Enforcement

15 min

On December 18, 2025, the New York State Comptroller's Office published an audit of the New York City Department of Consumer and Worker Protection's (DCWP) enforcement of Local Law 144 of 2021, the city's Automated Employment Decision Tool (AEDT) statute. The audit's conclusion, in operational paraphrase: enforcement in 2024 and 2025 had been thin. Complaint volume was low. Proactive investigations were rare. Submitted bias audits were reviewed only at the most cursory level. The Comptroller recommended better complaint routing, proactive investigation initiation, deeper bias-audit review, and coordination with the EEOC. DCWP accepted the recommendations and committed in writing to a more rigorous 2026 enforcement posture. By the time you read this lesson, May 2026, that posture is live. The HR-tech vendor that shipped an unaudited AEDT in 2024 and got away with it has a different problem in 2026. This lesson teaches you how to run the four-fifths-rule check on a hiring tool, walk the three core LL 144 obligations, integrate the EEOC's Title VII guidance and the FTC Section 5 framework, and produce the multi-jurisdiction compliance brief that the Responsible AI Officer, the General Counsel, and the Head of Talent Acquisition read on the same day.

What NYC Local Law 144 Actually Regulates

NYC Local Law 144 of 2021, operational under the DCWP rule that took effect July 5, 2023, regulates Automated Employment Decision Tools used to make or "substantially assist" employment decisions for candidates or employees residing in or applying to jobs in New York City. The statute is short; the definitions are long. Penalties are per-violation, per-day, and per-instance, a non-compliant hiring funnel running for a quarter can generate six-figure exposure without anyone in HR realizing.

Three operative definitions do the work.

The AEDT Definition

Under §20-870 of the NYC Administrative Code, an AEDT is "any computational process, derived from machine learning, statistical modeling, data analytics, or artificial intelligence, that issues a simplified output, including a score, classification, or recommendation, that is used to substantially assist or replace discretionary decision making for making employment decisions that impact natural persons." Three pieces matter. First, the technical perimeter is broad: ML, statistical modeling, data analytics, or AI. A regression model in Excel counts; an XGBoost ranker counts; a vendor LLM-based candidate scorer counts. A rules engine does not count, but the day it is tuned against historical hiring data, it becomes a statistical model. Second, the output must be a "simplified output": score, classification, recommendation. Free-text feedback that does not collapse to a score is debated; conservative practice treats it as a recommendation. Third, the output must "substantially assist or replace" discretionary decision-making. That phrase is the gate.

"Substantially Assist or Replace" - Three Operative Patterns

The DCWP rule defines "substantially assist or replace discretionary decision-making" through three patterns. A tool substantially assists if the employer:

  • Relies solely on the simplified output, with no other factors considered (the rare auto-reject case);
  • Uses the simplified output as one of a set of criteria where the simplified output is weighted more than any other criterion (the common case for AI-driven candidate ranking); or
  • Uses the simplified output to overrule conclusions derived from other factors, including human decision-making (the override case, recruiter prefers candidate A but the AI score routes candidate B to the next round).

The vendor pitch "our tool is just decision support, the recruiter makes the final call" mirrors the Article 6(3) carve-out argument and fails for the same reason. If the AI score is the deciding weight, the tool substantially assists. If it overrides recruiter preference even occasionally, the tool substantially assists. Substantial assistance is "more than a tiebreaker," not "always determinative." Most modern HR-tech stacks meet the threshold.

The Employment Decision Definition

An "employment decision" under §20-870 covers screening for hire, employment, promotion, retention, or termination, every gating moment between "application received" and "offer extended" plus post-hire performance and termination loops. Resume screening, candidate ranking, video-interview analysis, skills-test scoring, promotion-prediction, retention-risk scoring, and performance-management AI all fit. Two carve-outs in practice: back-office HR administration (payroll, benefits enrollment) and aggregate workforce analytics without per-individual outputs.

The Three Core Obligations

An employer using an AEDT for an NYC-resident candidate or NYC job posting must satisfy three obligations. Missing any one is a separate violation; missing all three is the pattern the Comptroller flagged repeatedly.

Obligation 1 - Annual Independent Bias Audit

An AEDT may not be used unless an independent auditor has conducted a bias audit within one year. The audit must compute selection-rate metrics by sex (male, female), race/ethnicity (Black or African American, Hispanic or Latino, White, Asian, Native Hawaiian or Pacific Islander, American Indian or Alaska Native, Two or More Races), and intersectional sex × race/ethnicity combinations where the sample permits. The headline metric is the impact ratio, selection rate for each group divided by the rate for the highest-scoring group. The four-fifths rule (EEOC Uniform Guidelines on Employee Selection Procedures, 1978): impact ratio below 0.80 raises an inference of adverse impact.

The audit must use historical data on candidates evaluated by the tool. If insufficient, the auditor may use test data, with disclosure and rationale. "Independent" per the DCWP rule: did not use the tool to make decisions for the employer, did not develop it, no financial interest in employer or vendor. Auditor independence is the most common failure point.

Obligation 2 - 10-Business-Day Candidate Notice

An employer must notify each candidate at least ten business days before the AEDT is used. The notice must include: job qualifications and characteristics the AEDT will use; the type of data collected; the source of that data; and how the candidate may request an alternative selection process or reasonable accommodation. Notice can be provided in the job posting, on the careers webpage, or by direct individual notification (email, letter, in-application). The 10-business-day clock starts on receipt and runs against the AEDT's use, not the application deadline.

The accommodation language is what vendor templates routinely under-specify. A candidate with a disability has a right to request an alternative selection process under the ADA and NYC Human Rights Law. The notice must invite the request and identify a contact. DCWP in 2026 has flagged generic "we use AI in hiring" disclosures omitting the accommodation contact as substantively non-compliant.

Obligation 3 - Public Bias-Audit Summary

The employer must publish a summary of the most recent bias audit on the public-facing employment section of its website, prominently. The summary must include: the audit date; data source and explanation; number of individuals assessed per demographic category; selection rates per category; impact ratios; distribution date. The DCWP template at nyc.gov/dca provides minimum-compliant format. The summary must remain posted at least six months after the most recent date of AEDT use.

The "prominent location" requirement is the second routinely-missed element. A summary buried three clicks deep in a careers-site footer does not satisfy "prominent." DCWP's 2026 posture treats deep burial as substantive non-compliance.

The Four-Fifths Rule - A Worked Example

The four-fifths rule is the operational center of every LL 144 bias audit, the EEOC adverse-impact analysis under Title VII, and (in spirit) the Annex III §4 FRIA's disparate-impact section. Suppose an AEDT screens applicants for a software-engineer role at a NYC employer. Past-twelve-month data through the AEDT:

Male applicants: 1,000 applicants, 100 selected to interview = 10.0% selection rate
Female applicants: 800 applicants, 60 selected to interview = 7.5% selection rate
Non-binary applicants: 50 applicants, 4 selected = 8.0% selection rate
White applicants: 900 applicants, 95 selected = 10.6% selection rate
Asian applicants: 500 applicants, 50 selected = 10.0% selection rate
Black or African American applicants: 250 applicants, 14 selected = 5.6% selection rate
Hispanic or Latino applicants: 180 applicants, 11 selected = 6.1% selection rate
American Indian / Alaska Native applicants: 20 applicants, 1 selected = 5.0% selection rate

The impact-ratio math. The highest-selecting sex group is male at 10.0%. The female impact ratio is 7.5 / 10.0 = 0.75. That fails the four-fifths threshold of 0.80, an adverse-impact inference is triggered for female applicants. The non-binary impact ratio is 8.0 / 10.0 = 0.80; on the line, but compliant. The highest-selecting race/ethnicity group is White at 10.6%. The Black impact ratio is 5.6 / 10.6 = 0.53, substantially failing. Hispanic 6.1 / 10.6 = 0.58, substantially failing. American Indian / Alaska Native 5.0 / 10.6 = 0.47, substantially failing. Asian 10.0 / 10.6 = 0.94, passing.

The audit summary must publish those numbers verbatim: headcount, selection rate, and impact ratio per category. A single-line "audit passed" summary without underlying numbers does not satisfy LL 144. The Comptroller report singled out single-line summaries as a 2024-2025 enforcement gap that 2026 will close.

Intersectional analysis follows the same math on the cross-tab. Black female applicants might have a 4.2% selection rate, yielding an impact ratio against the highest cross-tab group of 0.42. The audit must compute these where the sample is large enough to be statistically meaningful (the DCWP rule sets no minimum; auditor judgment governs). Missing intersectional analysis is the most common audit-quality failure flagged by the Comptroller.

The December 2025 Comptroller Audit and the 2026 Enforcement Posture

The NY State Comptroller's audit, released December 18, 2025, examined DCWP's enforcement of LL 144 across 2023 and 2024. The findings, in operational paraphrase:

  • Complaint intake was minimal. DCWP received fewer than two dozen LL 144-specific complaints across the audit period. Comparable laws in adjacent jurisdictions (Illinois AI Video Interview Act, Maryland Facial Recognition) generated several multiples of that complaint volume. The audit attributed the gap to weak public-facing complaint routing and the lack of a dedicated LL 144 intake form on the DCWP website.
  • Proactive investigation was rare. DCWP did not initiate AEDT compliance investigations absent a complaint. The audit identified hundreds of employer career pages with no bias-audit summary published, a public-facing indicator of likely non-compliance that DCWP did not follow up on.
  • Bias-audit review was perfunctory. Where employers did publish summaries, DCWP did not assess whether the auditor met the independence standard, whether the methodology was adequate, whether the data sample was sufficient, or whether intersectional analysis was included. The audit cited specific employer-published summaries that on their face did not satisfy the regulation.
  • Coordination with federal partners was absent. DCWP did not coordinate with the EEOC on AEDT investigations or refer matters where Title VII issues overlapped LL 144 issues.
  • Outreach to candidates was minimal. The audit found low candidate awareness of LL 144 rights, including the right to request an alternative selection process.

The Comptroller recommended that DCWP: deploy a dedicated AEDT complaint-intake mechanism; initiate proactive investigations against employers without published audits; establish a bias-audit review protocol covering independence, methodology, sample adequacy, and completeness; coordinate with EEOC, NY State Division of Human Rights, and NYC Commission on Human Rights; and run a candidate-awareness outreach program. DCWP accepted the recommendations in writing and committed to 2026 implementation.

What that means operationally in May 2026:

  • Proactive investigations have begun. DCWP is sweeping NYC employer careers pages for missing bias-audit summaries and opening investigations on the public-facing record. The employer that has not published is presumptively non-compliant. The employer that has published a summary without underlying numbers is in the second wave.
  • Bias-audit review is now substantive. DCWP is reviewing submitted (and published) bias audits against the auditor-independence test, the methodology adequacy test, the data-sample adequacy test, and the intersectional-analysis completeness test. The "one-line compliance attestation" pattern from 2024 will not survive 2026 review.
  • Complaint routing is live. The DCWP website now hosts a dedicated AEDT complaint form. Complaint volume has risen materially in Q1 2026.
  • EEOC coordination is operational. DCWP and EEOC's New York District Office have a referral protocol for AEDT matters that implicate Title VII disparate-impact claims.
  • Candidate outreach is in progress. DCWP is partnering with workforce development organizations to publicize candidate rights, including the alternative-selection-process right.

The enforcement-intensity shift does not change the regulation; it changes the probability that non-compliance becomes a finding. A 2024 minimum-viable program needs to revisit in 2026 against a higher bar.

The Penalty Schedule - Per-Day, Per-Instance Escalation

The DCWP penalty schedule under §20-872 of the Administrative Code: $500 first violation; $500-$1,500 for subsequent violations; each day of non-compliance is a separate violation; each AEDT use without complete audit, notice, or summary is a separate violation. The per-day and per-instance compounding turns quiet non-compliance into a public number. Using an AEDT for ninety days without a published summary accrues ninety separate violations. A parallel national-job-board posting without AEDT disclosure adds a separate notice-failure violation per day.

DCWP also has authority to seek injunctive relief, preventing further AEDT use until compliance. Mid-hiring-cycle, an injunction is more disruptive than the fines. The 2026 posture has signaled willingness to pursue injunctive relief in egregious cases (vendor-bundled AEDT with no independent audit; fabricated summary).

Comparison: LL 144 penalties are modest versus Article 99 (up to €15M or 3%) or GDPR (up to €20M or 4%). But LL 144 is fast, DCWP can issue civil-penalty notices without litigation, and per-day compounding means small numbers add up. The operational disruption of an investigation is the larger cost.

Independent Auditor Requirements - The Quality Bar That Is Now Enforced

"Independent" under the DCWP rule means the auditor: (a) did not use the AEDT to make decisions for the employer; (b) did not develop it; (c) has no financial interest in employer or vendor. The 2026 posture has made the test substantive rather than nominal. Three failure modes account for the bulk of 2026 findings:

Vendor-Bundled "Independent" Audits

The most common failure: an AEDT vendor offers a "free bias audit" by an audit firm with a long-standing referral relationship. The independence test fails on the financial-interest prong. Vendor-bundled audits are not independent; they are vendor-paid. Procurement must source auditors separately from the vendor.

Captive Consulting Arms

An employer's own consulting arm or a long-engaged consulting partner doing operational work for the employer does not satisfy independence. The test is functional, not just structural, a firm that audits the AEDT in Q1 and rebuilds the ATS integration in Q2 has a financial interest creating independence concern.

Methodology Disclosure Failure

The audit must disclose the methodology used to compute selection rates, impact ratios, and intersectional analyses. An audit summary that publishes the numbers without explaining how the data was sourced, how missing data was handled, how intersectional categories were defined, and what statistical-significance tests were applied (if any) is methodologically incomplete. The 2026 enforcement posture treats methodology-disclosure failures as substantive non-compliance, not formatting.

Selecting an independent auditor: the Responsible AI Officer's playbook is to (a) maintain a panel of vetted independent auditors with no financial relationship to the AEDT vendor stack; (b) procure on a rotating basis to prevent multi-year independence drift; (c) require a written independence attestation as part of the auditor engagement; and (d) review the auditor's methodology disclosure against the DCWP rule before publication.

The EEOC Title VII Overlay

The EEOC issued AI hiring guidance in May 2023 (Select Issues: Assessing Adverse Impact in Software, Algorithms, and Artificial Intelligence Used in Employment Selection Procedures Under Title VII of the Civil Rights Act of 1964) and updated it in 2024. The guidance establishes three operational principles that overlay LL 144 for any NYC employer also subject to Title VII (which is essentially all NYC employers with fifteen or more employees):

  • Title VII disparate-impact analysis applies to AI-driven employment decisions. The fact that an algorithm made the decision does not insulate the employer from Title VII liability. The employer is responsible for the disparate impact of the AEDT just as it would be for any other selection procedure.
  • The four-fifths rule is one indicator of adverse impact, not the definitive test. The EEOC may find adverse impact at impact ratios above 0.80 where statistical-significance testing supports the conclusion. Conversely, an impact ratio below 0.80 on a small sample may not support a Title VII claim. The four-fifths rule is the screen, not the verdict.
  • The business-necessity defense applies. Where adverse impact is established, the employer may defend by showing that the AEDT measures a characteristic that is job-related and consistent with business necessity. The defense fails if the plaintiff can show that an equally valid, less-discriminatory alternative exists. For AI-driven tools, "less-discriminatory alternative" includes re-training the model on de-biased data, adding fairness constraints, switching to a different model architecture, or substituting a non-AI selection procedure.

The practical consequence: the LL 144 bias audit is the first half of the Title VII compliance story. The second half is the business-necessity analysis and the less-discriminatory-alternative analysis. Both belong in the compliance brief. An LL 144 bias audit that flags an impact ratio of 0.65 for Black applicants creates an immediate Title VII exposure that the employer must address: by remediating the AEDT, switching tools, or documenting the business-necessity defense. Documenting "we ran the audit" without addressing the audit's findings is the worst defensive posture; it creates a paper record of awareness without a paper record of action.

The EEOC's enforcement posture on AI hiring matters has tracked the LL 144 trajectory. The EEOC settled Mobley v. Workday-adjacent claims and pursued ITutorGroup's age-discrimination algorithmic-screening case (which settled in 2023). The 2026 EEOC has expanded AI-hiring intake guidance and signaled willingness to coordinate with state and city enforcement (including DCWP under the Comptroller-recommended protocol).

The FTC Section 5 Overlay - Unfair or Deceptive AI Practices

The Federal Trade Commission's Section 5 authority over unfair or deceptive acts or practices in commerce reaches AI vendors selling AEDTs that misrepresent capabilities, accuracy, bias-mitigation, or compliance status. The FTC's AI enforcement posture, articulated in the 2021 blog "Aiming for truth, fairness, and equity in your company's use of AI" and reinforced through 2024-2026 enforcement actions, treats three vendor patterns as Section 5 violations:

  • Misrepresenting algorithmic accuracy or bias-mitigation. A vendor that markets an AEDT as "bias-free" or "fair by design" without substantiating evidence may be liable under Section 5. The FTC has signaled scrutiny of vague accuracy claims and "responsible AI" marketing language unsupported by audit evidence.
  • Misrepresenting LL 144 (or comparable) compliance status. A vendor that markets an AEDT as "LL 144 compliant" without providing the customer with the independent-audit artifact, the candidate-notice template, and the public-summary template may be liable under Section 5. The customer-employer's downstream non-compliance becomes the vendor's evidence of misrepresentation.
  • Failing to disclose material limitations. A vendor that omits known accuracy disparities across demographic groups or known failure modes (e.g., transcription quality variance across accents in voice-based AEDTs) may be liable under Section 5 for failure to disclose material information.

The FTC's enforcement actions in this space, including settlements with Rite Aid (facial-recognition misuse, 2023), and various data-broker settlements, have established the operational pattern. The 2026 FTC has continued the AI-enforcement program and coordinates with the EEOC and state regulators on AI-related matters. For a Chief AI Risk Officer, the FTC overlay is the answer to the question "what is our exposure if the vendor's claims about the AEDT turn out to be overstated?" The answer is: significant, especially under Section 5's deception prong.

The Multi-Jurisdiction Overlay - One AEDT, Eight Regulators

A multinational enterprise with hiring operations across multiple jurisdictions faces overlapping AEDT regulation. The LL 144 bias audit is one input to a broader compliance picture. Here is the overlay for a representative HR-tech deployment by a Fortune-500 with NYC operations, EU operations, Texas operations, and Colorado operations:

  • NYC LL 144, Annual independent bias audit; 10-business-day candidate notice; public summary on careers page. Applies to all NYC-resident candidates and all jobs posted in NYC. DCWP enforcement (now intensified in 2026 post-Comptroller).
  • EU AI Act Annex III §4 (Employment), Article 6(2) high-risk, Article 9 RMS, Article 10 data governance, Article 11 + Annex IV technical file, Article 14 human oversight, Article 15 accuracy/robustness/cybersecurity, Article 26 deployer obligations including the Article 27 FRIA for any deployer relying on the AEDT in EU operations, Article 47 declaration of conformity, Article 71 EU database registration. Stand-alone applicability date Dec 2, 2027 under Omnibus VII; FRIA capability expected earlier.
  • Texas TRAIGA HB 149 (effective Jan 1, 2026), Intent-based discrimination prohibition for AI systems used to make consequential decisions. Narrower than disparate-impact analysis but still triggers documentation and incident-reporting requirements. Covers Texas-resident candidates and Texas-domiciled hiring decisions.
  • Colorado context: SB 24-205 is currently stayed by the federal court (Apr 27, 2026 preliminary injunction); SB 189 replacement legislation passed May 7-9, 2026 (effective Jan 1, 2027 if signed). Monitor for re-applicability.
  • Federal EEOC under Title VII, Disparate-impact analysis applies; business-necessity defense; less-discriminatory-alternative test. Coordinates with DCWP under post-Comptroller protocol.
  • Federal FTC under Section 5, Unfair or deceptive AI practices; applies to vendors and (in some configurations) to employers that misrepresent AI use to candidates.
  • Illinois AI Video Interview Act, Applies to candidates interviewed via AI-analyzed video in Illinois; pre-interview notice required; explicit consent required; data-retention limits.
  • Maryland HB 1202, Facial-recognition disclosure for pre-employment AI; pre-interview consent.
  • California AB 331 (failed) → California Workplace Technology Accountability Act activity, Monitor for re-emergence in 2026 session.
  • EEOC + NY State Division of Human Rights + NYC Commission on Human Rights, Layered employment-discrimination enforcement that overlaps LL 144 substantively.

The compliance brief that addresses one regulator at a time will not survive. The defensible brief addresses the regulators as a stack: one AEDT, one audit methodology (four-fifths plus intersectional plus business-necessity), one candidate-notice template (LL 144 + Illinois + Maryland + GDPR transparency), one public-summary template (LL 144 prominence + Annex IV transparency), and one vendor-management protocol (FTC Section 5 substantiation + EU provider-obligation flow-down).

Cross-Jurisdiction Evidence Reconciliation

The single most valuable cost-saving practice in multi-jurisdiction AEDT compliance is evidence reconciliation. The four-fifths-rule analysis serves NYC LL 144, the EEOC Title VII disparate-impact screen, and (in spirit) the EU AI Act Annex III §4 FRIA's disparate-impact section. The independent-auditor engagement serves LL 144's audit requirement and (with the right scope) doubles as part of the Article 27 FRIA evidence base. The methodology disclosure that satisfies DCWP's 2026 review bar also satisfies the FTC's substantiation test on accuracy claims. The candidate notice that satisfies LL 144's 10-business-day requirement can be expanded to satisfy Illinois consent and EU GDPR Article 14 transparency.

Write the evidence once. Cite it many times. Keep the underlying artifacts (selection-rate computation, impact-ratio table, intersectional analysis, auditor independence attestation) in a single repository. One engagement that serves a dozen regulators is the only economically rational model.

The LL 144 Compliance Brief - What the Responsible AI Officer Produces

The L1 deliverable is a compliance brief that covers, in order: the AEDT inventory (which tools are in scope for LL 144); the four-fifths-rule methodology (data sourcing, category definitions, missing-data handling, statistical-significance approach, intersectional combinations); the independent-auditor selection criteria (panel, rotation, independence attestation); the candidate-notice content checklist (10-business-day clock, the job qualifications and characteristics the tool uses, the data collected, the source of that data, the accommodation contact); the public bias-audit summary template (with the DCWP-mandated headcount, selection rate, and impact ratio per category); and the multi-jurisdiction overlay map (NYC + EU AI Act + Texas + EEOC + FTC + state-specific).

Here is the template, with one row filled in for a representative case:

AEDT: Acme.HR Resume Ranker (vendor: Workday Talent Acquisition AI, Q1 2026 release)
LL 144 in-scope determination: Yes. Tool uses ML-trained ranker; output is a candidate score; score is the deciding factor in routing candidates to first-round interviews; substantially assists per pattern (ii) of the DCWP rule.
Annual bias audit: Conducted Mar 12, 2026 by [Independent Auditor]; engagement scope per Exhibit A; independence attestation per Exhibit B; methodology disclosure per Exhibit C.
Four-fifths-rule analysis: Selection rates and impact ratios computed by sex (male, female, non-binary), race/ethnicity (seven EEO-1 categories), and sex × race intersectional cross-tabs where N ≥ 30. Headcount table per Exhibit D.
Adverse-impact findings: Female impact ratio 0.78 (below threshold); Black female intersectional 0.62 (substantially below). Remediation plan: model retraining on de-biased data + recruiter calibration training + quarterly re-audit until ratios above 0.85.
Title VII overlay: Business-necessity defense documented per Exhibit E; less-discriminatory-alternative analysis per Exhibit F (considered: alternate vendor, fairness-constrained model variant, structured human-review workflow).
10-business-day candidate notice: Notice posted on careers page Apr 1, 2026 + in-application notice triggered at submission; notice content covers job qualifications, data collected, data source, accommodation contact (HR Accommodations Coordinator, [email protected]).
Public bias-audit summary: Published Apr 1, 2026 at acme.com/careers/aedt-bias-audit-2026; includes per-category headcounts, selection rates, impact ratios, methodology summary, auditor independence attestation; "prominent" placement verified.
EU AI Act overlay: Annex III §4 high-risk; Article 27 FRIA in progress (Dec 2, 2027 stand-alone applicability under Omnibus VII); Article 26 deployer obligations under development.
Texas TRAIGA: Intent-based discrimination prohibition, applicable for Texas-domiciled hires (eff. Jan 1, 2026); intent-screening documented per Exhibit G.
Colorado: SB 24-205 stayed (Apr 27, 2026 federal court); SB 189 replacement monitored.
FTC Section 5 vendor diligence: Workday's accuracy and bias-mitigation claims substantiated against the bias-audit results; no material discrepancy. Vendor's "LL 144 ready" marketing language verified.
Operational owner: Head of Talent Acquisition; risk partner, Responsible AI Officer; counsel, Employment Law team lead.
Next review: Annual re-audit by Mar 12, 2027; quarterly impact-ratio recomputation; triggered review on vendor model update or expansion to new role categories.

The template makes every gate explicit: every LL 144 obligation, every adjacent regulator, every overlapping defense. The operational owner is named. The next-review cadence is set. The compliance brief is a living document; the four-fifths-rule numbers refresh quarterly even if the formal audit refreshes annually.

Common Mistakes - And How DCWP Will Find Them in 2026

Mistake 1 - Denying Substantial Assistance

The vendor argument "our tool is just decision support; the recruiter makes the final call; therefore no AEDT" is the same argument that failed under the EU AI Act Article 6(3) carve-out and fails under the DCWP rule's three patterns. If the AI score is weighted more than other criteria, or if it overrides recruiter preference, the tool substantially assists. The 2026 enforcement posture treats substantial-assistance denial as a substantive non-compliance finding.

Mistake 2 - Using a Non-Independent Auditor

Vendor-bundled audits, captive consulting arms, and long-engagement consulting firms with operational ties to the employer fail the independence test. DCWP's 2026 bias-audit review applies the independence test substantively. Selecting an independent auditor outside the vendor and consulting stack is the defensive baseline.

Mistake 3 - Missing Intersectional Analysis

The DCWP rule requires intersectional analysis where the data sample permits. A bias audit that publishes only the single-axis numbers (sex separately, race separately) misses the intersectional cross-tabs where the most acute adverse impact often appears (Black women, Hispanic women, Asian women, etc.). The 2026 enforcement bar treats missing intersectional analysis as a substantive completeness failure.

Mistake 4 - Publishing a Summary Without the Underlying Numbers

A "we ran an audit and passed" summary without the per-category headcount, selection rate, and impact ratio does not satisfy the DCWP rule. The 2026 review bar requires the actual numbers in the published summary. Sanitized summaries are non-compliant.

Mistake 5 - Missing or Under-Specified Candidate Notice

Generic "we use AI in hiring" disclosures that omit the accommodation contact, the data source, or the specific qualifications the tool assesses do not satisfy the LL 144 notice requirement. The 2026 enforcement bar treats under-specified notices as substantive non-compliance.

Mistake 6 - Deep Burial of the Public Summary

A bias-audit summary three clicks deep in a careers-site footer does not satisfy the "prominent location" requirement. The 2026 enforcement bar treats deep burial as a substantive non-compliance finding. The DCWP-mandated location is the public-facing employment section of the website, with a top-level link.

Mistake 7 - Assuming Federal Preemption

No federal preemption applies to LL 144. Title VII and the FTC Section 5 framework supplement rather than preempt LL 144. State-level activity (Texas TRAIGA, Colorado SB 24-205 / SB 189, Illinois) likewise does not preempt LL 144. An employer subject to LL 144 cannot rely on a more favorable federal or state regime to avoid the city law.

Mistake 8 - Underestimating 2026 Enforcement Intensity

The pre-Comptroller enforcement posture was thin enough that some employers and vendors treated LL 144 as a paper requirement. The post-Comptroller posture is materially different. Proactive investigations are live. Bias-audit review is substantive. Complaint routing is operational. The 2024 risk-acceptance pattern does not survive 2026 enforcement.

Aligning the LL 144 Brief With ISO 42001 and NIST AI RMF

The same dual-citation pattern from the EU AI Act risk-tier work applies here. The LL 144 bias audit and methodology disclosure satisfies ISO/IEC 42001:2023 Annex A control A.6.2 (AI system impact criteria) when scoped against the employment use case, and overlaps with A.6.1 (impact assessment) and A.7.2 (data quality for AI systems). The independent-auditor engagement plus the methodology disclosure together satisfy NIST AI RMF 1.0 function Measure 2.11 ("Fairness and bias, as identified in the MAP function, are evaluated and results are documented") and Govern 5.2 ("Mechanisms are established to enable AI actors to raise concerns and report incidents"). The quarterly re-audit cadence satisfies NIST AI RMF Manage 4.1 ("Post-deployment AI system monitoring plans are implemented").

Write the analysis once. Cite it across NYC LL 144, EU AI Act Annex III §4, EEOC Title VII, FTC Section 5, ISO 42001 A.6.2 / A.7.2, and NIST AI RMF Measure 2.11 / Govern 5.2 / Manage 4.1. The audit-cost reduction is real. The auditor surprise reduction is real. The compliance brief becomes an enterprise-wide evidence artifact rather than a city-specific binder.

Key Takeaways

  • NYC Local Law 144 regulates AEDTs. Three definitions matter: AEDT (computational process from ML, statistical modeling, data analytics, or AI that issues a simplified output); substantially assists (relies solely on the output, weights it more than other criteria, or uses it to override conclusions); employment decision (screening, hire, promotion, retention, termination). Most modern HR-tech meets the threshold.
  • Three core obligations. Annual independent bias audit (four-fifths-rule analysis by sex, race/ethnicity, intersectional); 10-business-day candidate notice (job qualifications, data collected, source, accommodation contact); public bias-audit summary on the careers page (with per-category headcounts, selection rates, impact ratios).
  • The four-fifths rule is the operational center. Selection rate for each demographic group divided by selection rate for the highest group; impact ratio below 0.80 triggers adverse-impact inference. Worked example: female 7.5%/male 10.0% = 0.75 fails; Black 5.6%/White 10.6% = 0.53 fails substantially. Intersectional cross-tabs reveal the most acute disparities.
  • The December 2025 NY State Comptroller audit reshaped enforcement. 2024-2025 DCWP enforcement was thin (low complaint volume, no proactive investigation, perfunctory bias-audit review). DCWP committed to more rigorous 2026 enforcement: proactive investigations against employers without published summaries; deeper bias-audit review against auditor independence, methodology, and intersectional completeness; complaint routing; EEOC coordination.
  • Penalty schedule is per-day and per-instance. $500 first violation; $500-$1,500 subsequent; each day and each AEDT use without compliance is a separate violation. Injunctive relief is available. The dollar cap is modest; the operational disruption is the larger cost.
  • Independent-auditor requirements are now substantive. Vendor-bundled audits fail the financial-interest prong; captive consulting arms fail the functional independence test; methodology disclosure must be substantive, not nominal.
  • EEOC Title VII overlay extends the analysis. Disparate-impact applies to AI-driven decisions; four-fifths rule is one indicator, not the verdict; business-necessity defense + less-discriminatory-alternative analysis required where adverse impact found. The LL 144 audit is the first half; the Title VII business-necessity story is the second half.
  • FTC Section 5 reaches AI vendors. Unfair or deceptive practices include misrepresenting accuracy, misrepresenting LL 144 compliance status, and failing to disclose material limitations. Vendor-claim substantiation is the customer's downstream defense.
  • Multi-jurisdiction overlay is a stack. NYC LL 144 + EU AI Act Annex III §4 (Dec 2, 2027 high-risk applicability) + Texas TRAIGA (Jan 1, 2026 intent-based) + Colorado SB 24-205 (stayed) / SB 189 (pending) + Illinois AI Video Interview Act + Maryland HB 1202 + EEOC Title VII + FTC Section 5. One AEDT; eight regulators; one evidence base if you design for reconciliation.
  • The LL 144 compliance brief is the L1 artifact. AEDT inventory, methodology, auditor selection, notice content, public-summary template, multi-jurisdiction overlay. Quarterly impact-ratio recomputation. Annual re-audit. Same evidence base serves ISO 42001 A.6.2 / A.7.2 and NIST AI RMF Measure 2.11 / Govern 5.2 / Manage 4.1.