UAI Compliance Framework
Derived from the 297 recommendations and 51 advisory notes of the TRIZIST UAI recruitment audit outcomes report. Every tool and workflow on Platform Cab maps to this framework.
Nine audited focus areas
The audit reviewed the same focus areas for each organisation to identify key themes.
Provider & recruiter duties
Expand each recommendation to see provider and recruiter obligations.
Process personal information fairly. Monitor for potential or actual fairness, accuracy, or bias issues in the UAI and its outputs, and act to address them. "Better than random" is not enough where UAI materially influences decisions.
- Test regularly for fairness, accuracy and bias; address issues; report KPIs to senior managers.
- Assess and mitigate human bias, sampling bias, mislabelling, and demographic proxies.
- Consider a wide range of characteristics (gender, ethnicity, disability, other protected characteristics).
- Document how staff log and respond to candidates challenging outputs.
- Check how the provider monitors and mitigates fairness, accuracy and bias, and what data it uses.
- Record fairness/accuracy/bias risks and mitigations in a DPIA.
- Request test results and evidence that UAI operates fairly before and after use.
Inform candidates how their personal information is processed by UAI — clear, non-technical explanations of what is processed, the logic involved in outputs, and how data is used to train or test the UAI.
- Provide detailed privacy information if you are controller or contractually responsible.
- Explain the logic involved in predictions/outputs and how data trains or tests the UAI.
- Inform people clearly when creating inferred data or special category data, with a lawful basis.
- Provide privacy information within one month when data is not collected directly.
- Ensure contracts define who provides privacy information to candidates.
- Provide detailed privacy information; where the provider does this, check it is clear and accurate.
Collect only the minimum personal information required for each UAI element, and never repurpose it for a new incompatible purpose. Retain it only as long as necessary.
- Assess the minimum data required per UAI element; consider lower-data alternatives.
- Ensure all data is adequate and accurate for the intended purpose.
- Do not process data for a new incompatible purpose (including scraped or third-party data).
- Retain data only as long as necessary; record retention periods in contracts and privacy information.
- Review data collected by the UAI — confirm it is the minimum necessary.
- Confirm the provider does not reprocess data for an incompatible purpose.
- Record retention periods consistently in contracts, privacy information and a retention schedule.
Complete a DPIA early in UAI development and before processing that is likely to result in high risk. Update it as the UAI develops and processing changes, and have it formally approved.
- Complete a DPIA before commencing high-risk processing, early in development.
- Consider a DPIA even when acting as a processor.
- Include scope/purpose, data flows between parties, principle compliance and alternative approaches.
- Review regularly and get formal senior approval; consult the regulator on residual high risk.
- Complete a DPIA before procuring or deploying an AI recruitment tool.
- Ensure DPIAs are comprehensive and detailed, with clear data flows.
- Assess risks to people (not the organisation); identify and implement mitigations.
Define whether the UAI provider is controller, joint controller, or processor for each specific processing activity, and record it in contracts and privacy information.
- Identify controller/processor per specific processing instance; record in privacy information, contracts and DPIAs.
- You are the controller if you exercise overall control of means/purpose, or reprocess data for your own purposes.
- You are a processor only if the recruiter exercises meaningful control and you do not reprocess for your own purposes.
- Ensure the provider's role is correctly identified per instance and recorded consistently.
- Check you can fully control means and purpose as controller; if not, the provider may be controller/joint controller.
Recruiters must set explicit and comprehensive written processing instructions for the provider acting as processor, covering data fields, means/purpose, outputs and safeguards.
- Follow only the recruiter's explicit instructions when acting as a processor.
- Do not retain, share or reprocess personal information beyond those instructions.
- Review contracts periodically and get written authorisation before engaging sub-processors.
- Set explicit written instructions: data fields, means/purpose, output, storage, retention, sharing and safeguards.
- Periodically check the provider complies and does not process data for additional purposes.
Identify a lawful basis before processing, and an additional condition where processing special category data. Document it in privacy information, contracts and records of processing.
- Identify a lawful basis (and additional condition for special category data) before processing.
- Do not process if you cannot identify an appropriate lawful basis / condition.
- Complete a legitimate interests assessment; where relying on consent, make it specific and easy to withdraw.
- Identify a lawful basis and — for special category data — an additional condition before processing.
- Produce a RoPA based on regular data-flow mapping, recording purpose and lawful basis.
- Do not process if no appropriate lawful basis can be identified.
Competing interests assessed
Trade-offs must be identified, assessed and documented — typically in a DPIA.
Accuracy vs explainability
More data points improve output accuracy but make it harder to explain how the UAI works.
Data minimisation vs statistical accuracy
More data can improve accuracy and validity, but exceeds the minimisation principle.
Transparency vs understandability
Granular technical detail may be more transparent but less understandable.
Human reviews in UAI
UAI outputs are subject to robust, meaningful human review — never automated recruitment decisions.
Random & risk-based reviews
- Random sampling of AI outputs for fairness, validity and accuracy
- Risk-based reviews triggered by uncertain inputs, unexpected outputs or bias metrics
- Trained reviewers following a documented, formalised review methodology
- Records kept of reviews, actions taken and feedback given
No automated decisions (Article 22)
Tools on Platform Cab produce indicative grades or fit scores only. Human recruiters must consider them alongside other information and cannot progress or reject candidates based solely on UAI output.
Minimum data profile
Platform Cab collects only the minimum required to operate each UAI element.
| Data field | Purpose | Essential? | Retention (default) |
|---|---|---|---|
| Individual name | Identification of candidate | Essential | Requisition + 12 months |
| Contact information | Communication about vacancy | Essential | Requisition + 12 months |
| Career experience | Assessing suitability | Essential | Requisition + 12 months |
| Relevant skills | Matching to role | Essential | Requisition + 12 months |
| Qualifications / certifications | Verifying eligibility | Essential | Requisition + 12 months |
| Demographic characteristics | Bias monitoring (optional survey) | Optional | Separated & aggregated |
| Photos | Not required for assessment | Not collected | — |
Inferred or estimated characteristics (e.g. gender/ethnicity predicted from a name) are treated as special category data and are not generated on Platform Cab without a lawful basis and explicit additional condition.