Compliance
What the law expects from a hiring test
Testing candidates is legal almost everywhere. Being unable to explain a rejection is the part that gets employers into trouble, and it is a records problem before it is a legal one.
This page is a summary of the business risk, written for a hiring team without a legal department. It is not legal advice, and rules in this area are changing quickly enough that a page written a year ago is already wrong in places. Where a date matters, check it with counsel.
The rule that actually governs testing
In the United States, the ground rule comes from Title VII of the Civil Rights Act and the EEOC Uniform Guidelines on Employee Selection Procedures (29 CFR Part 1607). It is short enough to state in a sentence:
Any procedure used to make a hiring decision is a selection procedure, and if it produces adverse impact against a protected group, you have to show it is job-related and consistent with business necessity.
Two consequences most teams miss:
- An unstructured interview is a selection procedure too. It is not exempt because it is informal. It is simply harder to audit, which is not the same as safer.
- The obligation is yours, not the vendor’s. Buying a test from a vendor with impressive documentation does not transfer the duty to justify a rejection.
Why work samples are the easiest test to defend
The Guidelines recognise several ways to show a test relates to the job. The one available to a small team without a validation budget is content validity: showing the test samples the actual work.
If the job is entering invoices and the test has someone enter invoices, the job-relatedness argument is not constructed after the fact by a consultant. It is visible in the task. That is why the test library is practical and job-knowledge tests, and why it deliberately contains no personality or cognitive tests: those need population norms and a validity argument behind them, and a score without either is precisely what leaves an employer unable to explain a rejection.
Adverse impact, in practice
You do not need a statistician to run the basic check:
- Count how many candidates from each group you assessed, and how many you advanced.
- Divide each group’s advance rate by the highest group’s advance rate.
- Anything under 80 percent is worth a closer look before you keep using that cut score.
Small numbers make this noisy, and at ten candidates a ratio means very little. The habit still matters, because the alternative is discovering a pattern years later with no records to explain it.
Three things reduce risk more than any vendor feature:
- Fix the scoring rules before the first candidate. A rubric written afterwards is indistinguishable from a rationalisation.
- Use the same tests and the same cut score for everyone in the role. Different requirements for different candidates is the clearest way to lose.
- Keep the record. What was asked, what was answered, how it scored.
Disability and accommodation
Under the ADA, a test may not screen out a candidate with a disability unless the requirement is job-related and consistent with business necessity, and employers must provide reasonable accommodations for the testing process itself. In practice that usually means extra time, a different format, or an alternative way of demonstrating the same skill.
Time limits on a SharpAssessment test can be extended for an individual candidate, and a candidate is told before they start that they can ask for an adjustment. The candidate page says so in the candidate’s own words rather than in ours.
The AI hiring rules, and where this product sits
A wave of laws now targets automated employment decision tools specifically. The ones a small employer is most likely to meet:
| Rule | What it covers | What it asks of the employer |
|---|---|---|
| NYC Local Law 144 | Automated employment decision tools that substantially assist hiring or promotion for NYC roles | Independent bias audit within the past year, public summary, candidate notice ten business days ahead |
| Illinois AI Video Interview Act | AI analysis of recorded video interviews | Notice, explanation, consent, deletion on request |
| Illinois Human Rights Act amendments | AI use in employment decisions, including proxies for protected classes | Notice to candidates, no discriminatory use |
| Maryland facial recognition law | Facial recognition during interviews | Written consent |
| California civil rights regulations on automated decision systems | Automated decision systems used in employment | Records retention and anti-discrimination duties |
| Colorado AI Act | High-risk AI systems, including employment uses | Duty of care, notice, impact assessments; the start date has already moved once, so verify it |
| EU AI Act | Employment and worker management as a high-risk category | Transparency, human oversight and risk management, phasing in through 2026 and 2027 |
Where SharpAssessment sits, stated plainly:
- Scoring is rule-based, not a model that learns from your past hires. Criteria are fixed in advance and applied identically to every candidate, so there is no historical hiring pattern being reproduced.
- Nothing is rejected automatically. No candidate is filtered out by the platform. A score is reported, and a person decides.
- There is no video analysis, no facial recognition, no voice analysis, and no personality or cognitive inference.
- There has been no independent bias audit, and no page here claims one.
Whether a given use falls inside Local Law 144’s definition of an automated employment decision tool depends on how much your decision leans on the score. If it substantially assists the decision for a New York City role, the audit obligation is real and it is yours. Say so to counsel rather than relying on a vendor page.
GDPR, for candidates in the EU and UK
Assessing a candidate is processing their personal data. The parts that matter:
- Lawful basis. Usually steps taken at the candidate’s request before entering a contract, or legitimate interests. Consent is a weak basis in a hiring context, because a candidate cannot freely refuse.
- Transparency. Candidates must be told what is collected, why, how long it is kept, and who processes it. That is what the candidate page is for.
- Automated decisions. Article 22 restricts decisions made solely by automated means with legal or similarly significant effects. Since nothing here rejects a candidate automatically, the usual answer is that a human decides, and that answer needs to stay true in how you actually work.
- Retention. Results are kept for twelve months by default, then deleted. Details on the security page.
- Your role and ours. You are the controller of candidate data; we process it on your instructions under the data processing agreement. Infrastructure is in the EU.
What you get for the record
Every assessment produces the same artefacts, which is what turns compliance from a memory exercise into a filing one:
- The questions as presented to the candidate.
- The answers as given, with timestamps.
- The scoring rules applied, fixed before the assessment was sent.
- The score with its components, and what the test explicitly does not measure.
Exportable as PDF for a single candidate or CSV for a shortlist, so the record survives even if you stop being a customer.