Questions for a vendor
HR tools are almost always bought rather than built, so the diligence conversation is where most of the control sits. Eight questions, and how a vendor answers matters as much as what they say.
Are you the provider of this system under the AI Act, and how have you classified it? A vendor who cannot answer confidently has not done the analysis.
If you say it is not high-risk, which condition of Article 6(3) do you rely on, and how do you address the profiling limit? This is the question that separates vendors who have read the provision from those citing it.
What is the model trained to predict, and what generated that label? If the answer is past hiring decisions or performance ratings, the label problem applies and they should say so.
What is your disaggregated performance, by the groups relevant to our jurisdiction? For a high-risk system, Article 13 requires performance regarding specific groups in the instructions for use, so this is a disclosure rather than a favour.
Can we evaluate on our own applicant data before committing?
What happens to our candidate data, including whether it trains models serving other customers?
How do you notify material model changes?
And what does the candidate see, and what can they challenge?
A vendor claiming their tool is bias-free deserves particular scepticism. It is not a property any system has, and the claim indicates either no measurement or no candour.

