Back to Industries
HR compliance software · for HR tech

The compliance ask for HR tech isn’t just SOC 2 anymore.

It’s SOC 2 and an annual AEDT bias audit and a Colorado AI Act impact assessment and a BIPA consent program and quarterly regulatory reviews. The platform handles the base. Other20 advisory handles the AI-hiring layer that needs expert hands.

Enterprise procurement asked for your SOC 2 and the LL 144 URL today? Get on the calendar →

Why now

Five compliance asks stacked on your team in the last twelve months.

SOC 2 was the historic ask. It’s still on the table. But four AI-hiring pressures landed alongside it and none of them existed in your customer conversations two years ago. Each one arrives with a specific artifact your enterprise client’s HR compliance team now expects to see.

  1. 2023NYC LL 144 enforcement · EEOC AI hiring guidance affirmed · iTutorGroup Title VII settlement ($365K)
  2. 2024EU AI Act enters into force. Employment AI classified as high-risk under Annex III
  3. 2025BIPA settlements against HR tech vendors cross nine figures in aggregate
  4. NowColorado AI Act (SB 24-205) effective Feb 2026 · EU AI Act Article 12 applies to new-market AI Aug 2026
  1. The enterprise client wants SOC 2 in the master service agreement.

    The Fortune 500 procurement team stopped accepting hand-wave answers. The 40-question security questionnaire that used to close a deal now leads with 'attach your SOC 2 Type II report or ISO 27001 certificate.' Without one, the deal moves to the vendor that has it.

  2. NYC Local Law 144 wants an annual bias audit, by name.

    In force since July 2023. Any employer or employment agency using an automated employment decision tool (AEDT) on an NYC candidate must have an independent bias audit within the past year and publish the results. Fines are per-violation, per-candidate. Your enterprise clients now ask whether their AEDT vendor has one on file.

  3. Colorado's AI Act effective this quarter has real teeth.

    Effective February 2026. Any 'high-risk artificial intelligence system' making a consequential decision in employment triggers annual impact assessments, consumer notification, and appeal rights. AI-assisted hiring, promotion, discipline, and termination all qualify. The AG has enforcement authority. Every HR tech vendor selling into Colorado now needs an impact assessment on the shelf.

  4. BIPA class actions are already at settlement.

    Illinois BIPA settlements against HR tech vendors handling biometric data (interview facial analysis, fingerprint onboarding, voice authentication) have crossed nine figures in aggregate. The plaintiff's bar has automated discovery. Written consent, retention schedule, destruction workflow, and a public policy are the four things that stop the case at the pleadings.

  5. The EEOC is writing AI-hiring cases under Title VII.

    Since May 2023, the EEOC has affirmed that disparate-impact liability under Title VII applies to AI-assisted hiring decisions. The iTutorGroup settlement ($365K, 2023) was the first named case. If your platform's AI screens resumes, ranks candidates, or scores interviews, the employer's disparate-impact exposure is now your product's exposure by contract.

What the regulator sees in your product

Buyers and auditors don’t have to read your policies anymore. They can just use your product.

The AI-hiring compliance ask isn’t a questionnaire arriving in your inbox. It lives inside your own product — on the application page, the video interview, the AI-generated score. A regulator doesn’t have to subpoena documents; they can open your careers site and watch what happens to a candidate. Here’s what they see.

The application form

The 10-day notice and the written consent should live here. Neither does.

NYC Local Law 144 wants the candidate notification posted ten business days before this form goes live. BIPA wants written consent captured here, before the video interview fires. An unchecked terms box isn’t consent under either statute, and DCWP writes the notification miss as a per-candidate penalty.

NYC LL 144 · BIPA · $500–$1,500 per candidate
See the register + consent log

The video interview

Consequential-decision AI is running with no disclosure and no appeal link.

Facial analysis. Sentiment scoring. Response-quality classification. Colorado’s AI Act calls this consequential-decision AI and requires the appeal link at the point of processing. The EU AI Act adds a technical-documentation link and a human-oversight statement. Neither shows up on the screen where the decision is happening.

Colorado SB 24-205 · EU AI Act Art. 12 · state AG enforcement
See the impact-assessment library

The AI-generated score

The candidate’s right of access and the human-in-the-loop attestation both go missing.

The bias-audit summary URL and its most-recent date are supposed to be visible to the candidate right here. There’s no URL because there’s no audit — and LL 144 explicitly prohibits self-audit. An ATS reject click with no reviewer attestation is the exact fact pattern EEOC v. iTutorGroup ran on.

NYC LL 144 · EEOC Title VII · human-review attestation
See the signed evidence export

What you want them to see instead

Deals closed. Programs published. Assessments on the shelf. Cases stopped at pleadings.

Five outcomes, one per pressure above. Each one is what the enterprise customer’s HR compliance team actually asks to see — and what your sales team can now attach without a two-week scramble.

Close

The SOC 2 that unlocks the enterprise deal.

Type I in 8-12 weeks. Type II observation from day one. Auditor-ready evidence bundles from continuous integration collection. The Fortune 500 procurement questionnaire that stalled your deal last quarter is answered the same afternoon in the next one.

Publish

The LL 144 bias-audit URL that resolves.

AEDT inventory across your product. Independent auditor engaged (LL 144 explicitly prohibits self-audit). Annual bias audit conducted, reviewed, and published to the URL your enterprise customers link to in their candidate notification.

Attach

A Colorado impact assessment already on the shelf.

For every consequential-decision AI in your product. SB 24-205-aligned. Refresh cadence managed. When a Colorado enterprise client asks in the discovery call, the artifact is already exported and the consumer appeal workflow is already designed.

Defend

A BIPA program that stops the case at pleadings.

Written consent captured before collection. Retention schedule on the calendar. Destruction workflow tracked per candidate. Public policy posted. A class-action complaint filed against you meets four documented defenses, not four blank fields.

Prove

Title VII defense your customers' HR compliance team accepts.

EEOC-aligned risk documentation. Bias audit reports. Impact assessments. Human-oversight artifacts. All signed, timestamped, and independently verifiable. Your enterprise contract's disparate-impact liability clause has real documentation behind it.

What one program looks like

The four compliance asks come from four different regulators. One program answers all of them.

The program has two parts. vCISO Liteis our compliance platform — it handles continuous evidence collection, framework attestation, and regulatory calendar tracking automatically. Other20is our advisory team — they handle bias audit orchestration, impact assessment authoring, BIPA consent design, and appeal workflow. Both tracks work off the same evidence, and neither fakes what the other does.

Today
Platform + Other20

Enterprise procurement asks for your SOC 2 Type II.

Enterprise deals now condition on it · average deal cycle stalls 6+ months without one

You're two years into building the product, six months into signing your first enterprise clients, and zero months into a compliance program. Every questionnaire needs a report that doesn't exist yet.

01 vCISO Lite platform

SOC 2 continuous compliance, delivered by the platform.

50+ shipped integrations (Okta, AWS, GitHub, CrowdStrike, Google Workspace, Greenhouse, Workday) pull evidence continuously. Trust services criteria mapped and monitored. Auditor-ready export bundles. First Type I in 8-12 weeks, Type II observation starts the same day.

The client asks whether your AEDT has an LL 144 bias audit on file.

$500-$1,500 per violation, per candidate · public disclosure required within 30 days of the audit

You've never had one done. You don't know which of your ML models qualify as an AEDT. The candidate notification your customers are supposed to send names your product. The public bias-audit URL your customers link to is 404.

02 Other20 advisory + platform evidence

Bias audit orchestrated. Artifact held for every enterprise client's disclosure.

Other20 runs the AEDT inventory + engages an independent auditor (LL 144 explicitly prohibits self-audit). Platform stores the audit report, tracks the annual re-audit deadline, and generates the LL 144-compliant candidate notification your customers publish. Your product's bias-audit URL now resolves.

Your Colorado enterprise client wants an AI impact assessment.

Colorado AI Act, effective Feb 2026 · state AG enforcement authority · consumer appeal rights required

The impact assessment has to name every consequential decision your AI touches, quantify disparate-impact risk, describe mitigation, and cover appeal workflows. You've written zero of these. The templates online don't match the statute.

03 Other20 advisory + platform tracking

Impact assessment authored. Annual refresh on the platform calendar.

Other20 writes the impact assessment for each consequential-decision AI in your product, aligned to CO SB 24-205 requirements. Platform tracks the annual refresh cycle, stores prior versions, and surfaces regulatory changes that trigger interim updates. Consumer appeal workflow designed alongside your product team.

Your product collects biometric data on candidates.

BIPA settlements against HR tech peers running nine figures in aggregate · plaintiff's bar has automated discovery

Voice cloning in interview scoring. Facial analysis in async video interviews. Fingerprint on onboarding. You have no written consent flow, no retention schedule, no destruction policy, no publicly posted BIPA notice. Your enterprise contract says you handle biometric collection — that's your liability now.

04 Other20 advisory + platform policy

BIPA program designed. Consent flow shipped. Policy documented. Retention on the calendar.

Other20 designs the consent workflow (before-collection written consent, clear-purpose language, retention schedule). Platform generates the public BIPA policy, holds the signed consent artifacts, and tracks the 3-year destruction deadline per candidate. The full program at pleadings-stage-defensible depth.

Deliverables

Nine building blocks across two tracks.

Platform delivers the continuous compliance mechanics. Other20 delivers the AI-hiring governance substance. Each tile names what you get when the program is running.

vCISO Lite platform
SOC 2 continuous compliance
50+ shipped integrations (Okta, AWS, GitHub, CrowdStrike, Google Workspace, Greenhouse, Workday, Lever, iCIMS + 40 more) pull evidence continuously. Trust services criteria mapped and monitored. Type I in 8-12 weeks; Type II observation from day one.
vCISO Lite platform
AEDT bias-audit register
AEDT inventory across every AI feature in your product. Annual audit-cycle tracking. Publication-URL management. LL 144-compliant candidate notification generated for your enterprise customers to publish.
vCISO Lite platform
AI impact assessment library
Colorado SB 24-205 and EU AI Act Article 12 artifacts stored, versioned, and refresh-tracked. Regulatory-change surfaces prompt interim updates before the annual cycle.
vCISO Lite platform
BIPA consent + retention log
Before-collection written consent captured per candidate. Public BIPA policy generated and posted. 3-year destruction workflow tracked from last interaction.
vCISO Lite platform
Signed evidence exports
Hash-chained, timestamp-anchored artifacts your enterprise clients and their auditors can independently verify. Cryptographic proof that evidence hasn't been modified after capture.
Other20 advisory
AEDT bias audit orchestration
Other20 engages the independent auditor (LL 144 explicitly prohibits self-audit). Deliverables reviewed against the DCWP rules. Publication URL and candidate notification aligned. Annual re-audit calendar on the platform.
Other20 advisory
Colorado impact assessment authoring
Per consequential-decision AI in your product. SB 24-205-aligned documentation. Consumer appeal workflow designed alongside your product team. Refresh triggers named for regulatory changes.
Other20 advisory
BIPA program design
Consent-flow workflow, retention schedule, public policy, candidate notification templates, and internal training. Pleadings-stage-defensible depth from a designer who has faced the class-action bar.
Other20 advisory
Quarterly regulatory readiness review
State-law tracker (Colorado, Illinois, New York, California, Texas). Upcoming re-audit calendar. Impact assessment of new regulatory drafts. One 90-minute session per quarter with an assigned advisor.

The regulatory calendar

The AI-hiring compliance pressure, on one page.

Every date below is a published effective date from a real regulation or agency action. No invented enforcement events. If your product touches candidates in any of these jurisdictions, the calendar is already yours.

  1. Jul 2023
    NYC LL 144

    Automated Employment Decision Tools law enters enforcement. Annual bias audit + public disclosure + candidate notification required for AEDTs used on NYC candidates.

  2. May 2023
    EEOC guidance

    EEOC affirms Title VII disparate-impact liability applies to AI-assisted employment decisions. iTutorGroup ($365K) becomes the first named AI-hiring settlement later that year.

  3. Aug 2024
    EU AI Act

    Enters into force. Employment AI classified as high-risk under Annex III. Article 12 logging + human oversight requirements apply to systems newly on the EU market.

  4. Feb 2026now
    Colorado AI Act

    SB 24-205 effective. High-risk AI in consequential decisions (employment included) triggers annual impact assessments, notification, and appeal rights. State AG enforcement authority.

  5. Aug 2026now
    EU AI Act Art. 12

    Full high-risk regime applies to AI systems newly on the EU market. Logging, human oversight, and post-market monitoring required for employment AI serving EU candidates.

  6. Aug 2027
    EU AI Act full

    Full high-risk regime sweeps in systems already on the market. Every AEDT deployed in the EU now under Article 12 + Article 14 obligations.

Sources: NYC DCWP Local Law 144 implementing rules; Colorado SB 24-205; EU AI Act (Regulation 2024/1689); EEOC May 2023 + updated 2024 AI-hiring technical assistance; 740 ILCS 14 (BIPA); iTutorGroup consent decree.

Is this you?

Six HR-tech shapes this program was built to help.

If two or more of these describe your product or your Monday, the discovery call will be worth the thirty minutes.

  • You run an ATS or HR platform (20-500 people), your enterprise sales cycle now demands SOC 2 in the MSA, and your team has never built a compliance program.

  • Your product uses AI for resume screening, candidate ranking, or interview scoring — and your customers are starting to ask for the LL 144 bias audit URL.

  • You collect biometric data (interview facial analysis, voice authentication, fingerprint onboarding) and haven't yet built a BIPA-defensible consent + retention program.

  • You sell into Colorado (or the states copying the framework) and need an AI impact assessment on the shelf before enterprise procurement asks for one.

  • You're a video-interview / assessment / screening vendor with AI in the workflow and your customers' HR compliance teams are asking a set of questions that didn't exist 12 months ago.

  • You're a background-check / verification / onboarding tool handling PII + FCRA-covered data and want one compliance program that covers SOC 2, GDPR/CCPA, and the AI-hiring layer.

Frequently-raised questions

What HR-tech founders ask on the first call.

  • Do you perform the LL 144 bias audit yourselves?

    No, and by design. NYC Local Law 144 explicitly prohibits self-audit — the auditor has to be structurally independent from the AEDT provider. Other20 orchestrates the audit engagement (AEDT scope inventory, statistician selection, audit deliverable review), the platform holds the audit artifact + tracks the annual re-audit deadline, and the LL 144-compliant candidate notification is generated for your enterprise customers to publish.

  • Who authors the Colorado AI Act impact assessment?

    Other20 authors the impact assessment for each consequential-decision AI in your product. It's expert-hours work — the statute requires specific documentation on model function, training data, disparate-impact mitigation, human-override paths, and consumer appeal workflow. Platform holds the artifact + tracks the annual refresh calendar and surfaces regulatory changes that would trigger an interim update.

  • How long from zero to SOC 2 Type II ready?

    First Type I is 8-12 weeks from platform onboarding. Type II observation period starts the same day the platform starts collecting evidence — so a 90-day observation is 90 days from day one, not from Type I completion. Enterprise deals conditioned on SOC 2 usually accept a Type I report + a signed observation-period letter for the first cycle.

  • What about the EU AI Act if we sell into the EU?

    Employment AI is Annex III high-risk. Article 12 (logging) applies to systems newly on the EU market from Aug 2026, and to all systems by Aug 2027. Platform captures the required logs and the human-oversight artifacts; Other20 handles the CE-marking process + the technical documentation deliverable required for conformity assessment. If you're not selling into the EU today, we help you sequence when to add that scope.

  • How does this integrate with what we already use?

    The platform's continuous evidence collection pulls from Greenhouse, Workday, Lever, iCIMS, Okta, AWS, GitHub, CrowdStrike, Google Workspace, and 40+ more. Your ATS or HR platform stays where it is. Compliance evidence flows in continuously without ripping out existing tools.

  • What does the full program cost?

    Platform is subscription (auditee-side pricing). Other20 advisory is scoped by which layers apply to your product — SOC 2 base only, or SOC 2 + LL 144 + Colorado + BIPA + EU AI Act as needed. Discovery call sizes the scope in 30 minutes. Full pricing detail is on the roadmap-focused product page.

Your enterprise buyers are asking. Give them an answer instead of a stall.

Answer the SOC 2 questionnaire that stalled the deal last quarter. Publish the LL 144 URL your enterprise customers link to in candidate notifications. Show up quarterly with the AI-hiring readiness report already sent.