The Fine Is Per Day, and the Clock Is Your Own Job Postings
Most coverage of New York City's bias-audit rule stops at the audit. The part that decides what a violation costs is further down: who gets charged, how a complaint starts, and the sentence that makes each day of use a separate violation.
The shortest version: the per-violation figure is small and the multiplier is not. The regulated party is the employer, the trigger is usually a careers page anyone can load, and the count comes out of your own hiring calendar.
How the Enforcement Regime Is Shaped
The duty is the employer's, not the vendor's
The rule reaches employers and employment agencies that use an automated employment decision tool to substantially assist a hiring or promotion decision for a position in the city. The company that built the tool is not the regulated party. A vendor can run the audit, host the results and write the notice template, and the enforcement letter still arrives at the organisation that used it.
Three obligations, each independently breakable
A bias audit by an independent auditor within the preceding year; publication of a summary of results, together with the distribution date of the tool, on the employer's website; and notice to candidates and employees who reside in the city, given at least ten business days before use, describing the tool and the characteristics it assesses. Passing the audit and forgetting to post it is a violation. Posting it and skipping the notice is a violation.
Penalties are per violation, with a stated first-offence band
The law sets a lower figure for a first violation and a higher one for each subsequent violation, assessed by the Department of Consumer and Worker Protection. The number that matters is not the headline figure, it is the multiplier attached to it.
Each day is its own violation
The statute treats each day on which the tool is used in violation as a separate violation, and treats the failure to provide required notice as its own separate violation. A tool left running through a hiring season without a current audit does not produce one penalty; it produces a count equal to the number of days, and the record of those days is your own applicant-tracking log.
Enforcement is complaint-driven
There is no routine inspection regime here. The agency acts on complaints, and the population most able to file one is the applicant pool you already rejected, reading a careers page that either has a posted audit summary or does not. That makes the public artefact — the summary on your own site — both the compliance step and the trigger.
Five Things That Start a File
Each of these is visible from outside the company, which is what makes them the practical entry points rather than anything about the model.
The careers page with no summary on it
The summary of results must be publicly available on the employer's site. Its absence is checkable by anyone with a browser, requires no inside knowledge and needs no discovery. This is the single most likely origin of a complaint, and it is also the cheapest thing on the list to fix.
A summary that is stale
The audit must have been conducted no more than one year before the use. An audit from fourteen months ago posted prominently is worse than no claim of compliance, because it dates the violation for the reader and fixes the start of the per-day count.
Notice that went out after the screening ran
The candidate notice is a before-use obligation with a ten-business-day lead. A notice bundled into a rejection email, or surfaced only in a privacy policy nobody was pointed to, is a distinct failure from the audit obligations and is provable from your own send logs.
A rejected applicant who asks what screened them
The notice regime invites a request about the data collected and the source of it, and an unanswered or contradictory response is the kind of exchange that becomes an exhibit. Route these to a named owner with a prepared answer rather than to whoever monitors the careers inbox.
Your own marketing about the tool
A press release, a case study or a careers-page blurb describing how your AI ranks or scores candidates is an admission that the tool substantially assists the decision. Companies frequently argue the opposite to the regulator while their own marketing argues the other way in public.
Where Compliance Files Fall Apart
'Our vendor did the audit' is not a complete answer
The audit must be by an independent auditor, and independence is assessed against the people who built or used the tool. An audit performed by the vendor, or by a firm with a financial stake in the tool's continued sale, is the part of the file most likely to fail on inspection — and it fails in the employer's name, not the vendor's.
The audit is tool-and-use specific, not a certificate
A vendor's audit covering its general model on its own historical data may not correspond to how you configured it, the categories you score, or the roles you deploy it against. Ask which data the auditor used and whether it reflects your usage; where it does not, the summary you publish is describing something other than what candidates met.
Multiple employers share a vendor and a fact pattern
Because the duty attaches to use, a single deficient vendor audit can leave every customer independently exposed, each with its own careers page and its own per-day count. A complaint about one employer maps trivially onto its competitors, since the public artefact is public.
The city rule is not the only regime in the room
Federal anti-discrimination law and state legislation apply to the same tool independently of the city audit, and an audit disclosing a selection-rate disparity is a document about your own process that exists in writing. Treat a published disparity as a finding to act on, not as a compliance task completed.
Six Things to Put in Place
Inventory the tools honestly against the substantial-assistance test
List every system that scores, ranks, filters, sorts or recommends candidates anywhere in the funnel, including the resume parser nobody calls AI and the scheduling tool that deprioritises certain applicants. Write down, for each, whether a human could and did reach a different outcome — that sentence is the one that matters.
Get a current audit from someone with no stake in the tool
Independence is the failure mode. Engage the auditor yourself where you can, ask in writing what data was used and whether it reflects your deployment, and keep the engagement terms alongside the results.
Post the summary where a candidate would look
The careers page, linked from the application flow, with the distribution date. Not a PDF behind a login, not a compliance page nobody links to. The point of the artefact is that it is findable by the person the rule protects.
Move the notice ten business days upstream
The notice has to precede use with a lead time, so it belongs at the top of the funnel — on the job posting and in the application confirmation — rather than at the point of screening. Keep the send log; it is the only evidence that the timing was met.
Diary the audit expiry like a licence renewal
A calendar entry ninety days before the one-year mark, owned by a person rather than a team. Nearly every avoidable version of this violation is an audit that lapsed while hiring continued, and the per-day structure means the lapse compounds quietly.
Keep the file assembled
Audit report, auditor engagement and independence basis, published summary with its posting date, notice templates with send logs, and the tool inventory. A complaint response assembled in a week from an existing file is a different event from one reconstructed under a deadline.
Questions Hiring and Legal Teams Ask
How large can a Local Law 144 penalty actually get?
The per-violation figures are modest on their own — a lower amount for a first violation and a higher amount for each subsequent one. The exposure comes from how violations are counted rather than from the unit price. Each day on which a tool is used in violation is a separate violation, and a failure to provide the required notice is its own separate violation, so a screening tool left running through a hiring season without a current audit generates a count in the hundreds rather than a single fine. That is why the practical remediation advice is always about dates: when the audit was conducted, when the summary was posted, when the notices went out, and on which days the tool ran. Those four timelines, taken from your own applicant-tracking and email systems, determine the arithmetic more than anything about the model itself.
Our vendor ran the bias audit. Are we covered?
Partly at best, and the gap is in the word independent. The obligation is on the employer or employment agency that uses the tool, and the audit has to be conducted by an auditor who is independent of the people who developed or distributed it and of the people who use it. An audit performed by the vendor itself, or by a firm whose commercial relationship depends on the tool continuing to sell, is exactly the element most likely to fail when someone looks. There is a second problem underneath the first: a vendor audit typically covers the model as the vendor configured and trained it, while your exposure is about how you deployed it — which roles, which scored attributes, which thresholds. Ask the auditor in writing what data was used and whether it reflects your usage, and keep the answer.
What usually triggers a complaint?
Enforcement here is complaint-driven rather than inspection-driven, and the most common starting point is the simplest thing in the rule: a careers page that does not carry a published summary of results, or carries one that is visibly out of date. That is checkable by any member of the public in under a minute and requires nothing but a browser. The second common origin is a candidate who received no advance notice, or received it after the screening had already happened, and who has the emails to show the sequence. Both of these are artefacts you control. The uncomfortable implication is that the population best placed to file is the pool you rejected, which means the compliance artefacts are read most carefully by exactly the people with a reason to look.
We are not in New York. Does this reach us?
The relevant question is where the position is located rather than where the company is, so an employer headquartered elsewhere that hires for roles in the city is inside the rule, and remote roles tied to the city raise the same issue. The related and harder question is what to do about a candidate pool that spans jurisdictions, since the notice obligation runs to candidates and employees residing in the city. Most organisations conclude that maintaining a candidate-by-candidate geographic split in the application flow costs more than applying the notice and the published summary uniformly. Uniform application also has the advantage of removing the argument that you knew the rule applied to some candidates and chose not to identify which.
Is there a cure period before penalties start?
Do not plan around one. The rule contemplates an opportunity to cure in some circumstances for certain violations, but the availability and scope of that opportunity is not something to rely on as a compliance strategy, and it does nothing about days that have already accrued. The structurally safer position is to treat the audit as a renewable licence with a calendar owner, because the overwhelming majority of avoidable violations in this area are not decisions to skip the rule — they are an audit that lapsed while hiring continued and nobody noticed for a quarter. A diary entry ninety days before the one-year mark, held by a named person, removes more risk here than any amount of legal analysis of the cure provisions.
The Two-Date Test
Write down the date your current bias audit was conducted. Then write down the date of the oldest job posting still open for a role in the city.
If the first date is more than a year before today, the number of days between it and now is the multiplier — and every one of those days is documented in your applicant-tracking system rather than in anything a regulator has to prove.
Related Reading
- The bias audit itself — what the audit measures and what the summary has to say.
- Remote and out-of-state candidates — where the position sits, and why a geographic split is usually the expensive option.
- PEO and co-employer liability — when the entity that used the tool is not the one on the offer letter.
- Sourcing and talent pools — screening that happens before anyone becomes an applicant.
- Records retention — the logs that prove your dates, and the federal rules requiring you to keep them.