Regulatory compliance

Built for compliance across the EU, the US, and the UK.

Recruitment AI is now regulated as high-risk in the EU and audited annually in NYC. Here is how Ready handles consent, recording, retention, residency, and rights.

New York

Annual independent bias audit. Publicly posted. Candidate notice.

Under New York City Local Law 144, an automated employment decision tool used on an NYC-resident candidate must be bias-audited by an independent third party, the audit summary posted publicly, candidates notified before the assessment runs, and an opt-out made available.

Ready is designed to support this cooperatively. The customer remains the legal deployer. Before the first NYC-resident candidate is screened, an independent third-party bias audit will be commissioned for the deployment, with Ready supplying the impact-ratio data and the public posting template, and the audit refreshed annually thereafter. Demographic data is never imputed.

  • Audit commitment. An independent third-party bias audit will be commissioned for the deployment before the first NYC candidate is screened, and refreshed annually.
  • Public posting. Audit summary made available at the deployer's careers site for the legally required period from the date of completion.
  • Candidate notice and opt-out. Candidates are notified before the assessment runs. An opt-out or alternative assessment is arranged with the employer on request, with no negative inference applied. A built-in in-product opt-out is on the roadmap.
European Union

High-risk recruitment AI. Built to the EU's requirements, completed per deployment.

The EU AI Act classifies AI used to analyse, filter, or evaluate job applications as high-risk. Ready operates as the provider and supports the deployer's obligations. Human oversight, transparency to the candidate, and record-keeping are live in the product today. The remaining provider obligations, the formal risk management file, technical documentation, data governance, accuracy and cybersecurity testing, post-market monitoring, conformity assessment, EU database registration, and CE marking, are being completed per deployment ahead of the August 2026 enforcement date for high-risk systems.

  • Human oversight (live). Every score is advisory to a human reviewer, not a final decision. Ready never auto-rejects and never auto-hires.
  • Transparency and record-keeping (live). The candidate is told before the session that an AI scores it and a human decides. Consent, attempts, and deletions are written to an audit log.
  • Technical documentation (in progress). Data sources, methodology, and validation results compiled for the deployer ahead of conformity assessment.
  • Risk management and monitoring (in progress). The formal risk file and post-market drift and impact-ratio monitoring are being established with each deployment, not yet running automatically in-product.
Security and data transfers

Encrypted in transit. Processed in the US. Lawful UK transfers.

All traffic between the candidate's browser and the service is encrypted in transit. Audio, transcripts, and scoring evidence are held on infrastructure PrompX operates, with role-based access inside the employer console. Candidate audio is not used to train external models.

The AI subprocessors, OpenAI for scoring and Deepgram for speech-to-text, process candidate data in the United States. For UK candidates, that transfer is made lawful through the international data transfer terms in our data processing agreements with those providers (the UK Addendum or the providers' Data Privacy Framework certification). US candidate data stays within the US and is not subject to a transfer restriction.

  • Encryption in transit. Modern transport-layer encryption (HTTPS) on all candidate and console traffic.
  • Processed in the United States. OpenAI and Deepgram process candidate audio and transcripts in the US. This is disclosed to the candidate before the session.
  • Lawful UK transfers. UK-to-US transfers rely on the UK international data transfer terms in our subprocessor agreements, available to the deployer on request.
  • Role-based access, no external training. Scoped console views per role, and candidate data is not used to train external or third-party models.
Local employment law

Works councils, employee representation, and human oversight.

Where local employment law requires works council co-determination or employee-representative consultation before a candidate assessment is deployed, Ready provides the documentation, consultation templates, and timing guidance the deployer needs.

Where local law requires meaningful human oversight on any candidate-facing AI, Ready already operates as an advisory layer to a human reviewer. The legal framework varies by country; the product posture is the same everywhere.

  • Germany. Works council consultation templates and timing guidance for the deployer's HR and legal teams.
  • France. Human reviewer required for every adverse decision. CNIL guidance reflected in the consent flow.
  • United Kingdom. UK GDPR treated to EU GDPR standards. ICO guidance on AI in employment reflected in the deployment review.

Need the DPA or the latest audit?

Reach out for compliance documentation, infosec questionnaires, and the data handling controls applied to enterprise rollouts.