Join our Newsletter — 33% off our NHI Course

What is the difference between a bias audit under New York City Local Law 144 and a disparate impact analysis under New York State Assembly Bill A00567?

Local Law 144 requires an independent auditor, applies to hiring and promotion, and adds candidate notice plus public reporting. A00567 uses the broader term disparate impact analysis, focuses only on hiring, and appears to allow impartial internal analysis if the required method is used. Both aim to surface discriminatory selection effects, but their governance and disclosure rules differ.

How the two rules split on scope and governance

The practical difference starts with who must do the review, what gets reviewed, and what must be disclosed. Local Law 144 is built as a compliance regime for automated employment decision tools, so it adds an independent audit layer, candidate notice, and public reporting. A00567 uses a broader analysis label, but the current reading is narrower on process governance and disclosure.

That difference matters because the same screening system can be legally similar in intent while still being handled very differently. Under SOC 2 Trust Services Criteria (AICPA), the key question is whether the control environment is independently verifiable and consistently operated, not just whether the model exists.

Local Law 144 also extends to promotion decisions, which makes the governance surface wider. A00567, by contrast, is framed around hiring only, so it focuses the analysis on one employment outcome rather than the broader lifecycle of talent selection.

Why the analysis method is not the whole story

Both regimes are trying to detect discriminatory selection effects, but they get there through different administrative mechanisms. A rule that allows an impartial internal analysis can be less burdensome operationally, yet it also places more weight on the organisation’s own method, documentation, and defensibility. That makes the quality of the method more important than the label attached to it.

For teams implementing controls, the lesson is to separate methodological compliance from governance obligations. In the employment context, a well-run analysis still fails if notice, reporting, or independence requirements are missed, while a formally independent review can still be weak if the underlying selection data is incomplete or the model is not tested against the actual hiring workflow.

This is why practical review programs often sit alongside NHI compliance and audit requirements and broader access governance work, because the evidence burden is what makes the control credible.

What practitioners should verify before treating either as compliant

The most important verification step is to confirm the exact legal trigger, because the two laws do not ask for the same control package. Local Law 144 requires an independent auditor and adds public-facing transparency obligations, while A00567 appears to rely more heavily on the substance of the disparate impact analysis itself and less on external disclosure. If a team assumes the two are interchangeable, it is likely to miss at least one required process step.

  • Verify whether the tool is used only for hiring or also for promotion, because scope changes the compliance posture.
  • Verify who performed the analysis and whether independence is required by the applicable rule.
  • Verify whether candidate notice, reporting, or publication duties attach to the use case.
  • Retain the selection criteria, data inputs, and test outcomes so the analysis can be defended later.

For organisations with broader governance obligations, Cloud Compliance Pulse 2025 is useful as a reminder that auditability and access governance are operational disciplines, not paperwork afterthoughts. The same logic applies here: if the process cannot be reconstructed, it is difficult to trust the result.

Practitioner takeaway: Treat Local Law 144 as the more procedural and disclosure-heavy regime, and A00567 as the more analysis-centred one, then design your workflow so the same evidence set can satisfy both without assuming one automatically covers the other.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

CIS Controls v8 and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.

Framework Control / Reference Relevance
CIS Controls v8 CIS 6 — Access Control Management Screens selection systems and reports through controlled access and auditable approvals.
CIS 8 — Audit Log Management The laws depend on defensible records of analysis, notice, and reporting.
Recommendation — Restrict and review access to hiring analytics, models, and reports before publication or decision use. Log model runs, reviewer actions, and disclosure events so the analysis can be reconstructed.
NIST CSF 2.0 GV.RM-01 — Risk Management Strategy Comparing the two laws is fundamentally about governance obligations and compliance risk.
PR.AA-01 — Identity and Access Management Employment analytics should be limited to authorised reviewers and decision makers.
GV.OC-01 — Organizational Context The answer turns on which employment use case the rule covers and how it is governed.
Recommendation — Align hiring-tool governance to a documented compliance risk strategy. Limit who can execute, review, and publish biased-impact assessments. Map each automated employment use case to the correct legal and governance scope.