Course › Module 11 · Compliance, bias and candidate experience

Lab 10: complete an AI hiring risk register

Module 11, Lesson 6  ·  4 min read ·  Updated 21 September 2026

Module 11 · Lesson 6

Build a risk register for your own process. It is the document that turns this module from reading into something you can hand to a legal team.

What to do

  1. List every point where AI touches hiring, across everything you built in Modules 4 to 9.
  2. For each, write what could go wrong for a candidate — not for you.
  3. Rate how likely it is and how bad it would be: low, medium or high. Avoid scoring out of ten; it suggests a precision you do not have.
  4. Name what already stops it happening, if anything.
  5. Name the gap, and one action with a person's name against it.
  6. Use the four questions from Lesson 1 to work out which rules apply to you.

Risks to include as a minimum

RiskComes from
A CV format is read badly, so a whole group is quietly excludedModule 4, Lesson 2
Rules are too strict and remove good people invisiblyModule 4, Lesson 3
A tool learning from past hires repeats old patternsModule 5, Lesson 1
The explanation given is decoration, not the real reasonModule 5, Lesson 4
Found profiles kept with no reason and no deletion dateModule 3, Lesson 7
A chatbot screens people without them knowingModule 6, Lesson 4
Automation follows instructions hidden inside a CVModule 9, Lesson 2
You cannot find all of one person's data to delete itModule 11, Lesson 4

What to hand in

The register, plus three things you will actually fix this quarter — each with a person's name and a date.

How to know you have done it right

CheckGood looks like
It is about candidatesRisks describe harm to people, not just exposure to you
Nothing is missedEvery point where AI touches hiring appears
Honest about controlsNothing listed that you do not actually do
Named ownersEvery action has a person, not a team
Accepted risks are markedWhere you are choosing to live with something, it says so

That last row is what makes a register real. Every organisation accepts some risk. The ones in trouble are the ones that never wrote down which.

Check yourself before Module 12

  • Which risk did you most want to leave off the list? That is usually the one to look at hardest.
  • Could you hand this to a lawyer tomorrow without rewriting it?
  • Is there a control listed that you believe happens but have never actually checked?
  • Which set of rules applies to you that you had not thought about?

Review it on a date, not after an incident

Every three months, in the calendar, alongside your list of tools. Registers that only get reviewed after something goes wrong are incident reports written in advance and never read.

Common questions

Does the EU AI Act apply to recruitment?

Yes. Systems used for recruitment or selection fall in the Annex III high-risk category. Those obligations were deferred from 2 August 2026 to 2 December 2027 by the Digital Omnibus on AI, Regulation (EU) 2026/1744. Separately, the prohibition on inferring emotions in the workplace has applied since February 2025, and Article 50 transparency since August 2026.

What is a bias audit in hiring, and how do you run one?

It measures outcomes rather than intent: the selection rate for each group at a given stage, and the impact ratio between them. A widely used screening heuristic treats a ratio below four-fifths as worth investigating — a starting point, not a verdict. Run it per stage and end to end, because small differences compound while no single stage looks alarming.

What do you have to tell candidates about AI screening?

That AI is used and at which stage, what it evaluates in terms they can check themselves against, what a human does, and how to ask a question or request an alternative. New York City requires notice at least ten business days before use. Disclosure buried in a privacy policy satisfies almost nobody, including regulators.

How long can you keep candidate data?

As long as you have a documented reason and a period you actually enforce — indefinite is not a period. The obligations attach at storage rather than at contact, which is why a private spreadsheet of sourced profiles is a problem waiting to happen. The practical test: could you find and delete every copy of one candidate's data today, across every system and person?

Check yourself

Four questions. Nothing is recorded anywhere but your own browser — this is for you, not for a score.

  1. 1Under the EU AI Act, when do high-risk obligations apply to recruitment systems?

  2. 2Your bias audit shows no disparity at the interview stage. What can you conclude?

  3. 3Why audit parse quality as part of a bias audit?

  4. 4What makes consent to a recorded interview meaningful?