An automated employment decision tool audit is a systematic, independent review of the AI software an employer uses to screen, rank, score, or otherwise evaluate job candidates and employees. As of September 2026, these audits have moved from a voluntary best practice to a legal requirement in several jurisdictions, and employers who treat them as a checkbox exercise are discovering that regulators, plaintiffs' attorneys, and even state attorneys general are looking at the substance of the audit, not just its existence.

The Direct Answer: What an Audit Is and Who Must Do One

Also worth reading: What does AI employment law compliance mean for employers in 2026, and how can HR teams manage automated hiring, promotion, and workforce decisions across U.S. cities and states? · How does automated labor law compliance software actually function to mitigate risk in modern HR operations? · What are the specific Colorado AI Act employer requirements for companies using automated decision-making tools in 2026?

An automated employment decision tool audit examines whether the algorithmic systems used in hiring, promotion, and termination decisions produce discriminatory outcomes, function as advertised, and comply with applicable disclosure and bias-testing laws. The most prominent mandate remains New York City's Local Law 144, which took enforcement effect in July 2023 and requires an annual independent bias audit of any automated employment decision tool used to evaluate candidates for employment in the city, along with published results and candidate notification. Colorado's SB 24-205, with its compliance obligations now fully operative, requires developers and deployers of high-risk AI systems used in consequential employment decisions to exercise reasonable care and complete impact assessments. Connecticut's SB 435 added its own requirements around AI use in employment decisions, and Illinois, California, New Jersey, and several other states have introduced or passed related measures, creating what commentators at the National Law Review and Bloomberg Law have described as a genuine patchwork of compliance risk.

The audit itself typically covers four domains: demographic impact analysis (disparate impact ratios across protected classes at each stage of the funnel), data quality and training-set review, explainability and documentation review, and governance controls such as human oversight and appeal mechanisms. A vendor or third-party auditor performs the work, produces a summary report, and the employer must post the results on its careers website where Local Law 144 applies.

Why a Fairness Score Alone Is Not Enough

A growing critique, articulated well in a 2026 Tech Policy Press piece arguing that AI audits need a power test rather than just a fairness score, is that most audits measure statistical parity while ignoring who holds decision-making power over the tool itself. A vendor can tune a model to pass a four-fifths rule test while still designing the system so that human reviewers rubber-stamp its outputs, effectively automating the decision without accountability. Regulators are starting to notice this gap. The EEOC's guidance on algorithmic fairness, state attorney general inquiries, and the Federal Trade Commission's enforcement posture all suggest that a fairness metric without governance documentation is a weak defense.

A defensible audit in 2026 therefore asks harder questions: Can candidates contest an adverse outcome? Does a human meaningfully review rejections, or does the tool auto-reject at thresholds no one has validated? Who owns the model's retraining schedule, and is there a log of when scoring criteria changed? These power and governance questions are increasingly what separates an audit that satisfies a regulator from one that merely satisfies a procurement checklist.

The Regulatory Patchwork Employers Face

There is no single federal statute governing automated employment decision tools. Title VII, the ADA, and the ADEA apply to algorithmic decisions exactly as they apply to human ones, and the EEOC has made clear that employers cannot outsource liability to a vendor. On top of that baseline, states and cities have layered distinct obligations. New York City requires annual independent bias audits with published results. Colorado requires impact assessments and notices for high-risk AI in employment. Connecticut's SB 435 imposes its own analysis and disclosure duties. Illinois has expanded its Artificial Intelligence Video Interview Act coverage, and multiple states now require disclosure that AI is being used in hiring at all, a trend documented by Clearance Jobs and Reed Smith.

The practical consequence is that a multi-state employer cannot run one audit and call it done. The scope of what counts as an automated employment decision tool differs by jurisdiction, the publication requirements differ, and the timing differs. Epstein Becker Green and K&L Gates both published 2026 guidance warning that the patchwork creates gaps in both directions: some employers over-comply in states with no rules while missing mandatory obligations elsewhere.

FeatureNYC Local Law 144Colorado SB 24-205Connecticut SB 435
Core obligationAnnual independent bias audit of the toolReasonable care + impact assessments for high-risk AIAI impact analysis and disclosure for employment decisions
PublicationAudit summary results posted publiclyNo public posting; documentation on demandNotice to candidates; state reporting elements
Candidate notice10 business days advance notice of AI useNotice that AI is used in consequential decisionsDisclosure of AI use in screening
ScopeTools that score, rank, or substantially assist hiring decisionsHigh-risk systems in consequential decisions including promotion, terminationEmployment decision tools as defined by statute
CadenceAnnually per toolOngoing, with review after material changesPer deployment cycle / annual review
Penalty exposureCivil penalties up to $500 per violation per dayAG enforcement; unfair practice exposureState enforcement mechanisms
## Practical Steps: How to Run a Compliant Audit

Start with an inventory. Most employers underestimate how many tools qualify. Applicant tracking systems with resume-scoring add-ons, video interview platforms that score facial or vocal signals, chatbot screeners, and gamified assessments can all fall within statutory definitions. Map each tool to the jurisdictions where you hire and flag which obligations attach.

Second, commission the audit from an independent party. Local Law 144 requires independence, meaning the auditor cannot have a conflict of interest with the vendor or the employer. Ask prospective auditors about their methodology: do they test at every stage of the funnel (application, screening, interview, offer), do they compute impact ratios by sex and race/ethnicity categories as the NYC rule requires, and do they document the data lineage of the training set?

Third, fix what the audit finds before publishing. A published audit showing a disparate impact ratio below 0.8 for a protected category at the screening stage is discoverable evidence in a Title VII suit. Employers should treat the audit as a remediation trigger: adjust thresholds, remove problematic features, add human review points, and re-test. Fourth, build the governance layer: written policies on when the tool may auto-reject, human review requirements, candidate notice templates, and a change-management log. This is where compliance platforms, including AI-powered regulatory management systems, earn their keep by tracking which tools need re-auditing when and under which state rules.

Common Mistakes That Turn Audits Into Liabilities

The most expensive mistake is treating the audit as a vendor problem. Under every current framework, the deployer employer bears the legal exposure; a vendor contract promising indemnification does not shield you from an EEOC charge or a city penalty. The second mistake is auditing once and never again. Local Law 144 requires annual audits per tool, and Colorado-style impact assessments must be refreshed after material modifications. A 2023 audit cited in 2026 is worse than none, because it proves you knew about the tool and ignored it.

Third, employers frequently audit the wrong population. If your tool only processes applicants in certain geographies or role families, the impact ratios must be computed on the actual candidate flow, not a company-wide average that dilutes the signal. Fourth, many employers publish audit results without any remediation narrative, which reads to a plaintiff's lawyer as an admission. A short, factual description of what was found and what was changed is both permitted and prudent. Finally, do not forget disclosure duties: several states now require telling candidates that AI is in use, and skipping the notice is an independent violation even if the audit is flawless.

When to Act and What It Costs

If you use any algorithmic screening in New York City, the audit obligation is already live and penalties accrue per violation per day, with civil penalties up to $500 for each violation. Colorado's requirements are operative, and Connecticut's SB 435 provisions are phasing in, so employers hiring in those states should complete a baseline impact assessment now rather than waiting for enforcement actions. Even in states with no statute, the EEOC's position that algorithmic decisions are covered by civil rights law means an audit is cheap insurance relative to litigation.

On cost, independent bias audits for a single tool typically run from roughly $10,000 to $50,000 depending on candidate volume, number of decision stages, and the depth of the data review; multi-tool or enterprise-wide programs can exceed $100,000 annually. Vendors increasingly bundle audit support, but independence requirements in NYC mean many employers still need a third party. Compliance software that tracks obligations, deadlines, and audit schedules across states generally ranges from a few thousand dollars per year for mid-market tools to six figures for enterprise deployments. Compare that to the cost of defending a single systemic discrimination class action, which routinely runs into the millions, and the economics favor acting early.

The Bottom Line

An automated employment decision tool audit in 2026 is not a one-time fairness score; it is an annual, jurisdiction-specific, independently verified examination of both statistical outcomes and the governance structures around the tool. Employers who inventory their tools, audit on the required cadence, remediate findings before publishing, and maintain human oversight documentation are positioned to satisfy regulators in New York, Colorado, Connecticut, and beyond. Employers who rely on vendor assurances or a single stale report are carrying unpriced legal risk in a regulatory environment that, as 2026 coverage from Bloomberg Law, Epstein Becker Green, and HR Executive consistently shows, is only tightening.