By NHI Mgmt Group Editorial TeamDomain: Identity Beyond IAMSource: FiddlerPublished July 2, 2026

TL;DR: When sensitive attribute data is unavailable, organisations use proxy methods such as Bayesian Improved Surname Geocoding to estimate race or gender group membership, but the technique is intended for group-level disparity analysis and can mislead if treated as individual classification, according to Fiddler. The governance challenge is not only statistical accuracy but also accountability for how proxy inference is used in high-stakes decisions.


At a glance

What this is: This is a deep-dive on proxy techniques for inferring protected characteristics when direct sensitive attribute data is missing, with BISG as the central example.

Why it matters: It matters because fairness, compliance, and decision governance can fail when teams infer identity attributes without clear scope, validation, and accountability.

👉 Read Fiddler's analysis of inferring protected characteristics without sensitive data


Context

Bias analysis often depends on data that organisations are not allowed, or not able, to collect directly. In lending, health care, and hiring, that creates a governance gap: teams still need to test outcomes across protected groups, but they must do so with proxies rather than self-reported sensitive attributes. The primary question is not whether inference is possible, but whether the resulting analysis is appropriate for the decision being audited.

Bayesian Improved Surname Geocoding is a statistical workaround that combines surname and geography to estimate group membership. The article shows why that approach can be useful for aggregate disparity assessment while remaining risky for individual classification. This is a classic identity-verification and fairness boundary case: when organisations infer protected traits, they are handling identity data indirectly and must be explicit about purpose, confidence, and limits.


Key questions

Q: How should organisations use proxy methods for protected characteristics in fairness analysis?

A: Use them only for aggregate bias testing, not as a substitute for self-reported identity. A proxy method can help reveal disparate outcomes, but it must be treated as probabilistic and documented with its confidence limits, data sources, and approved purpose. That keeps the analysis useful without turning approximation into identity truth.

Q: Why do proxy methods create risk in regulated decision-making?

A: They can be accurate enough for population analysis while still being wrong for individuals. That matters when teams move from measuring disparities to making or justifying decisions, because the inferred attribute may not reflect the person being assessed. The risk is scope creep from analytical support into operational classification.

Q: What do teams get wrong about inferring protected characteristics from available data?

A: They often confuse an estimate with evidence of identity. Proxy methods are designed to compensate for missing data in fairness reviews, but they do not replace direct self-identification and they do not eliminate bias risk. Teams should therefore control purpose, confidence, and reuse very tightly.

Q: Who should approve the use of inferred sensitive attributes in a fairness programme?

A: Privacy, legal, compliance, and fairness stakeholders should all review the method before it is adopted. The approval should cover whether the inference is necessary, whether the data inputs are appropriate, and whether the output will stay inside the intended analytic boundary.


Technical breakdown

How proxy inference works in fairness analysis

Proxy inference methods estimate a protected characteristic from observable features when self-reported data is unavailable. BISG is a common example: it uses surname distributions and geographic census data to generate probabilities for race or ethnicity, then combines those inputs through Bayesian updating. The output is not certainty, but a likelihood distribution that is best suited to aggregate analysis. The statistical strength of the method depends on how representative the inputs are and how much local demographic variation exists.

Practical implication: treat proxy outputs as probabilistic evidence for bias testing, not as authoritative identity records.

Why individual-level use creates governance risk

Methods designed for population disparity analysis can become problematic when repurposed to label specific people. A proxy may be directionally useful across a dataset while still being inaccurate for individuals, especially where surnames are ambiguous or communities are heterogeneous. That means a model can appear to support fairness work while introducing new error into underwriting, hiring, or benefit decisions. The governance failure is not only model error, but scope creep from analysis to operational decisioning.

Practical implication: restrict proxy methods to approved analytic use cases and block downstream use as a decision input.

Protected characteristic inference and accountability

When protected characteristics are inferred rather than collected, organisations must manage both statistical and legal exposure. The key issue is documentation: what was inferred, why, at what confidence threshold, and for which oversight purpose. This is especially relevant in regulated environments where identity and verification data can intersect with discrimination risk. Good governance requires a clear trail from proxy method to fairness conclusion, with explicit acknowledgement that inference is not self-identification.

Practical implication: require written method statements, confidence thresholds, and reviewable records for every proxy-based fairness assessment.


NHI Mgmt Group analysis

Proxy inference is a governance instrument, not an identity truth source. Techniques like BISG exist because organisations need to test for disparate outcomes when sensitive attribute data is missing. That use case is legitimate, but only when the output is treated as an analytic approximation rather than a statement about who a person is. The practitioner conclusion is straightforward: separate fairness measurement from identity assertion.

The named concept here is proxy-classification drift. That is the point at which a method designed for aggregate disparity analysis is quietly reused as if it were precise personal classification. Once that happens, model error turns into governance error, because decisions may be justified using inferred traits the system cannot reliably know. Practitioners should treat this as a boundary control problem, not just a data-science issue.

Fairness programmes break when confidence and purpose are not written down. The article shows that the same technique can support an antidiscrimination review and still be misapplied in a lawsuit or operational workflow. That tension is familiar across identity programmes: if the purpose of an attribute is not documented, downstream users will overreach. The practitioner conclusion is to hard-limit use cases and evidence standards.

Identity verification teams should recognise the overlap between protected-attribute inference and trust decisioning. Any process that infers sensitive traits from partial signals resembles broader identity assurance problems, where organisations infer trust from incomplete evidence. That does not make the use cases equivalent, but it does mean the same discipline applies: confidence scoring, auditability, and explicit scope. The practitioner conclusion is to design controls around inference limits, not just model performance.

Bias analysis needs lifecycle governance as much as statistical validity. Data collection, proxy inference, analysis, retention, and reuse all need ownership. Without that lifecycle view, a one-time fairness study can become a standing source of unreviewed identity assumptions. The practitioner conclusion is to govern proxy methods with the same lifecycle discipline used for other sensitive data processes.

What this signals

Proxy inference is likely to remain part of fairness and audit work wherever direct sensitive attribute collection is restricted, but teams will need stronger governance around purpose limitation and model confidence. The practical lesson is that analytic convenience is not the same as defensible identity evidence, especially when decisions affect regulated populations.

Inference trust gap: when organisations rely on proxy methods to fill missing identity data, they create a gap between statistical utility and operational trust. That gap should be managed with explicit review, retention limits, and clear prohibition on copying inferred traits into production decision systems.


For practitioners

  • Define approved proxy-use boundaries Write policy that limits inferred protected characteristics to fairness testing, research, or audit use cases, and explicitly forbids operational decisioning from proxy outputs.
  • Document method confidence and limitations Require every proxy-based analysis to record the inference method, confidence assumptions, data sources, and known error modes before findings are used in governance reviews.
  • Separate analysis from decision records Keep proxy-derived findings in an analytic layer that cannot be copied into case management, underwriting, hiring, or other production workflows without separate review.
  • Add legal and fairness review gates Route any new proxy method through privacy, compliance, and fairness stakeholders so the team can confirm the method is appropriate for the intended regulatory purpose.

Key takeaways

  • Proxy methods can support fairness analysis when sensitive attribute data is unavailable, but they must remain probabilistic and purpose-bound.
  • The main governance risk is scope creep, where an analytic approximation is reused as if it were a reliable individual identity attribute.
  • Teams need documented confidence limits, approval gates, and lifecycle controls before inferred protected characteristics are used in any review process.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-63 and NIST CSF 2.0 set the technical controls, while GDPR define the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST SP 800-63SP 800-63AIdentity proofing guidance is relevant when teams infer or verify protected characteristics.
NIST CSF 2.0GV.RM-01Governance and risk management apply to proxy use in regulated fairness programmes.
GDPRArt.5Lawful processing and purpose limitation matter when sensitive data is inferred from other signals.

Use SP 800-63A principles to separate evidence collection from assumptions about who a person is.


Key terms

  • Bayesian Improved Surname Geocoding: A statistical method that estimates a person’s likely race or ethnicity using surname and geographic information. It combines demographic patterns with Bayesian updating to produce probabilities rather than certainties, which makes it more suitable for aggregate disparity analysis than for individual classification.
  • Protected Characteristic Proxy: An indirect signal used to estimate a sensitive attribute when direct collection is unavailable or restricted. Proxy methods can help teams test for bias, but they introduce error and should never be treated as equivalent to self-reported identity data.
  • Fairness Analysis: A review process that checks whether a system produces unequal outcomes across protected groups. It often depends on demographic data, model output, and outcome comparisons, and it requires careful governance when the underlying group membership must be inferred rather than directly observed.

What's in the full article

Fiddler's full blog covers the methodological detail this post intentionally leaves for the source:

  • Bayesian Improved Surname Geocoding mechanics and the specific demographic inputs used to generate probability estimates
  • Examples of how proxy methods are applied in lending and health care fairness assessments
  • The article's cited research trail, including studies that question the accuracy and overstatement risk of proxy-based disparity analysis
  • Context on how the method has been used in real enforcement and litigation settings

👉 Fiddler's full post covers the BISG method, its intended use, and the limits of proxy-based fairness analysis.

Deepen your knowledge

The NHI Foundation Level course, the industry's only accredited NHI security programme, covers NHI governance, machine identity security, IAM, and secrets management. It is designed for practitioners who need a stronger control model for identity-related risk across modern programmes.
NHIMG Editorial Note
Published by the NHIMG editorial team on August 21, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org