Case: The Screening Model Nobody Owned

A candidate complaint unearths a vendor résumé screener that had been auto-rejecting applicants for 18 months — no owner, no audit, no register entry — at a 4,000-person logistics company.

A composite teaching case: realistic fiction assembled from well-documented public patterns — not a real engagement.

The setup. Meridian Freight is a composite: a 4,000-person logistics company — trucking, warehousing, a corporate office in Manhattan — hiring roughly 3,000 people a year, most of them drivers and warehouse staff, a few hundred of them corporate roles posted out of the NYC office. In early 2024, a talent-acquisition manager drowning in applications bought a SaaS résumé-screening tool from a mid-market HR vendor — call it Parsonix — for about $30k a year. Procurement waved it through under the ‘HR software’ category, the same lane as the survey tool and the org-chart plugin. Nobody involved thought of it as an AI purchase, because nobody was asking.

Parsonix scored every application against the job posting and, in the configuration Meridian ran, did something more consequential: auto-advance mode. Candidates above the score threshold moved to a recruiter’s queue; candidates below it received a polite automated rejection. No human ever saw them. The threshold — 62 out of 100 — was set during a one-hour onboarding call by a Parsonix sales engineer and never revisited.

The TA manager who bought it left in mid-2025. The tool kept running. By the time anyone looked, it had processed roughly 47,000 applications and auto-rejected about 61% of them.

The trigger. In February 2026 an email arrived in the careers inbox. A candidate for a Manhattan-based pricing-analyst role had applied at 10:40 p.m. and been rejected at 11:21 p.m. — 41 minutes later, on a Sunday. Her email asked three precise questions: was an automated employment decision tool used to assess her application; where is the bias-audit summary published, as NYC Local Law 144 requires; and where was the notice she should have received at least ten business days before the tool was used on her.

Nobody at Meridian could answer any of the three. HR didn’t know what tool the careers portal used. IT said it wasn’t their system — SaaS, bought by HR. Legal had never heard of Parsonix. The general counsel’s office spent the first two days simply establishing what the company was running, which is its own finding: the mean time to answer ‘what did this tool do to this person?’ was measured in days, for a decision the tool made in milliseconds, thousands of times a week.

The reconstruction. Outside counsel came in during week one; a two-person internal team (an HRIS analyst and a paralegal) spent ten days on archaeology. The vendor’s contribution was a two-page ‘AI explainability statement’ — marketing prose about ‘fair, skills-based matching’. The real record had to be rebuilt from the applicant-tracking system’s API logs, the Parsonix admin console (one recruiter had the only login), and the original contract, retrieved from the departed manager’s archived mailbox. What the review found, numbered because numbered findings get fixed:

F-1 — No owner, no register entry, no intake record

The tool existed in no inventory. There was no inventory. Procurement’s record classified it as ‘HR software — misc.’, so no security review, no privacy review, no AI questions — those questions didn’t exist in the intake form. Ownership had defaulted to whoever last held the admin password.

F-2 — Auto-advance mode: rejection without human review

61% of ~47,000 applications were rejected with no human in the loop, which is precisely the configuration that makes a tool ‘substantially assist’ a hiring decision under LL144 — the argument that it was ‘just a ranking aid’ died the moment the config export showed auto-reject was on.

F-3 — A threshold set by a sales engineer, never revisited

The 62-point cutoff was chosen in a one-hour onboarding call, with no validation study, no job-relatedness analysis, and no record of why 62. A number that determined tens of thousands of outcomes had less documented justification than the office coffee contract.

F-4 — No bias audit, ever — and the audit must precede use

LL144 requires an independent bias audit within a year before use, annually. Eighteen months of use meant the company had been out of compliance from day one, not merely late — there was no compliant day to point back to.

F-5 — No candidate notice, no posted summary

No 10-business-day notice on postings for NYC roles, no audit summary on the careers site. Two independent violation streams, each accruing per-violation, per-day penalty exposure with the DCWP.

F-6 — A contract with no audit rights and a liability cap at fees paid

The MSA had no audit or data-access rights, no obligation to support a bias audit, no notice of model changes, and a clause expressly disclaiming vendor responsibility for employment-law compliance — which is legally accurate (LL144 puts the duty on the employer) and operationally brutal, because Meridian now needed data the contract gave it no right to demand.

F-7 — Scoring features that proxy for protected characteristics

The feature documentation, once extracted, showed the model penalised employment gaps and rewarded continuous tenure — classic proxies for caregiving and disability. Nobody at Meridian had ever seen the feature list before the incident.

The audit. An independent auditor was engaged in week three — LL144 requires independence, so neither the vendor nor Meridian’s own counsel could do it. The audit took six weeks, most of it data work: 18 months of ATS records had to be joined to demographic data that only existed for the ~54% of applicants who had completed voluntary EEO self-identification. Scoring-rate and selection-rate impact ratios were computed by sex, race/ethnicity, and — the part that found the problem — intersectional categories.

Most ratios landed between 0.84 and 1.03. One did not: Black women showed a selection-rate impact ratio of 0.71 against the highest-selected group (white men). LL144 itself sets no pass/fail line — it forces the number into the open — but 0.71 sits well below the four-fifths rule of thumb (0.80) that federal disparate-impact practice uses as a red flag, and everyone in the room knew which number a plaintiff’s expert would circle. The employment-gap feature (F-7) was the leading suspect: in a follow-up ablation the auditor ran, removing it moved the ratio to 0.83. A feature nobody chose, in a tool nobody owned, produced a number nobody could defend.

The decision. With the audit in hand, three options went to a steering group of the CHRO, the GC, and the CIO — the first meeting the three had ever held about an algorithm, and not a warm one. The CIO opened by noting that SaaS bought by HR was not an IT system; the GC replied that it would be an IT system by Friday.

Remediate, rip out, or replace — the options as they actually looked
OptionWhat it costsWhat it fixesWhat it doesn’t

Defang and remediate

Auto-advance off within days; recruiters review every rejection; vendor pressed to drop the gap feature. Recruiter workload up sharply; time-to-fill up ~9 days for a quarter.

Stops unreviewed rejections immediately. Preserves the workflow recruiters like and 18 months of integration work.

The model is still the vendor’s black box; leverage to change it only arrives at renewal. The 0.71 history doesn’t go away.

Rip out entirely

Manual screening of 250 applications/day; either +3 recruiter heads ($240k/yr) or slower hiring in a business where driver seats empty cost real revenue.

Ends the LL144 exposure cleanly — no AEDT, no audit duty. Simple story for the regulator.

Human screening has its own bias problem and no audit trail at all. And the org learns nothing — the next tool gets bought the same way.

Replace via RFP

4–6 months of procurement while the incumbent keeps running (or hiring goes manual in the interim); migration and retraining costs.

A chance to buy audit rights, data access, and change-notification from day one.

A new vendor is not automatically a fairer model — the audit obligation and the intersectional risk transfer intact.

What was done. The steering group chose defang-and-remediate, with the RFP held in reserve as renewal leverage. Auto-advance was switched off within 72 hours of the audit landing; every below-threshold application now routed to a human queue. Recruiters, told they were getting a fairness safeguard, experienced a 60% workload increase and said so. Notices went onto every NYC posting with the 10-business-day clock respected before the tool touched another NYC application; the audit summary went onto the careers site — an uncomfortable publication, since it included the 0.71.

The contract was the slow fix. At renewal, with the RFP visibly warm, Meridian extracted audit and data-access rights, an obligation to support the annual bias audit at the vendor’s cost, 30-day advance notice of material model or feature changes, removal of the employment-gap feature for Meridian’s tenant, and a compliance-cooperation clause. The price went up 12%. Counsel called that cheap; the vendor’s counsel called it precedent-setting and fought for six weeks.

Worth naming the legal backdrop honestly: LL144 enforcement by the DCWP never actually arrived — the complaint didn’t convert into a proceeding. What arrived instead, four months after the audit summary was posted, was a letter from a plaintiff-side firm framing the 0.71 as a claim under the NYC Human Rights Law and Title VII. The audit you publish is discoverable; that is the design of the law, not a flaw in your handling of it.

What broke anyway. Three things, each instructive. First, mid-remediation, Parsonix shipped a platform-wide model update to all customers — improving the model, they said — which shifted score distributions enough to invalidate the audit baseline; the auditor’s ablation numbers no longer described the running system, and part of the analysis had to be redone. (This is why the change-notification clause exists; it didn’t yet.) Second, the litigation hold complicated everything: data the team wanted to clean and archive had to be preserved as-was, and remediation steps were suddenly being drafted with one eye on how they would read in discovery. Third, the register program that came out of the wreckage kept finding wreckage: an expense-report and SSO-log sweep surfaced 14 more AI-flavoured tools nobody had registered — a sales-call scorer, two ‘productivity analytics’ plugins, a chatbot on the benefits portal. The screening model was not an anomaly. It was a sample.

The bill — honest ranges, first 12 months from the complaint
ItemCostNotes

Independent bias audit (+ rework after the model update)

$45k–$70k

The audit fee was the small part; the ATS data archaeology to feed it consumed ~10 person-weeks internally.

Outside counsel

$90k–$150k

LL144 posture, the plaintiff-firm letter, litigation hold, contract renegotiation.

Internal time

~1.5–2 FTE-years

Spread across HR, legal, HRIS, and procurement — mostly invisible on any budget line, all real.

Recruiting drag

Time-to-fill +9 days for ~one quarter

The operational price of turning auto-advance off before process fixes caught up.

Vendor renewal uplift

+12% on ~$30k/yr

The price of audit rights, data access, and change notice bought retroactively instead of at signature.

Political capital

Substantial

A CHRO–CIO ownership fight settled by the GC; a published 0.71 with the company’s name on it; a board question at the next audit-committee meeting.

What was born. The lasting output was not the remediated screener — it was the program built so this never has to be reconstructed from an archived mailbox again. An AI register (a spreadsheet for the first quarter, then records in the existing GRC tool): every system that scores, ranks, filters, or decides about people, each with a named owner, a use description, and a review date. A procurement intake gate: six AI questions added to the vendor-intake form, with any ‘yes’ routing to a governance review before signature. A contract playbook: audit and data-access rights, bias-audit cooperation, change notification, and incident-notice clauses as standard asks for anything touching employment, credit, or customers. And an annual audit calendar, because LL144’s audit is annual and the first year taught everyone what happens when ‘annual’ has no owner.

The intake gate that came out of the wreckage

  1. Purchase request
  2. Six AI screening questions

    Does it score, rank, filter, recommend, or decide about people? Does it learn from our data? Any ‘yes’ leaves the fast lane.

  3. Any yes?
  4. Standard procurement
  5. Governance review

    Owner named, register entry drafted, legal duties mapped (LL144, state law), contract playbook clauses attached.

  6. Employment decisions in scope?
  7. AEDT track: audit before use, notices, posting

    The bias audit must precede use. The notice clock is 10 business days. Both are scheduled before the contract is signed, not after a complaint.

  8. Register entry + named owner

    Nothing goes live without an owner. Ownership was the original sin of this case.