Implementing an AI Strategy and Framework
With the EU AI Act classifying AI used in employment and worker management as high-risk, the question for recruitment organisations is no longer whether to govern AI but how to implement governance that functions. Part XI of the Manual prescribes a sequence, and this article summarises it.
First, inventory and classification. No control can attach to a system nobody has listed. Every AI tool in use — including those embedded in vendor products — is registered and classified against the Act's risk tiers, with recruitment-related systems treated as high-risk regardless of vendor positioning.
Second, human oversight by design. For every high-risk system, a named accountable person reviews outputs before consequential decisions are final. The Manual is explicit: no candidate is rejected by an automated system without human review. Oversight is documented — decisions, not intentions, are auditable.
Third, bias testing on a schedule. Tools are tested across protected characteristics before deployment and periodically thereafter, with suspension thresholds defined in advance. Testing bought once at procurement decays; the register entry for each system includes its next test date.
Fourth, management-system alignment. The framework is operated consistently with ISO/IEC 42001 for AI management and the NIST AI Risk Management Framework, inside ISO/IEC 27001-aligned information security. The strategic conclusion is simple: in recruitment, trustworthy AI is not a feature of the technology. It is a property of the governance around it — and governance, unlike hype, can be audited.