Join our Newsletter — 33% off our NHI Course
Home Glossary AI Security Four-Fifths Rule
AI Security

Four-Fifths Rule

← Back to Glossary
By NHI Mgmt Group Updated September 1, 2026 Domain: AI Security

The four-fifths rule is a screening standard used to check for adverse impact in selection outcomes. If one group’s selection rate is less than 80 percent of the highest group’s rate, disparity may be present. It is useful, but not always sensitive enough to detect subtler model bias.

Expanded Definition

The four-fifths rule is a practical screening heuristic for identifying potential adverse impact in selection processes, especially hiring, promotion, lending, or other eligibility decisions. It compares selection rates across groups and flags a possible disparity when the rate for a protected or comparison group is below 80 percent of the highest group’s rate. The rule is best understood as an initial signal, not a legal conclusion and not proof of discrimination on its own.

In security and AI governance contexts, the rule is often used when evaluating model-assisted decisions, automated ranking systems, or workflow gates that influence access to opportunities. Definitions vary across vendors and jurisdictions because the rule itself is not a universal compliance standard; it is a statistical heuristic that appears in employment and fairness analysis. For broader governance language, teams often align the screening step with risk management principles described in the NIST Cybersecurity Framework 2.0, but the rule’s core purpose remains outcome disparity screening. The most common misapplication is treating a sub-80 percent result as automatic proof of unlawful bias, which occurs when teams ignore sample size, context, and the need for deeper validation.

Examples and Use Cases

Implementing the four-fifths rule rigorously often introduces interpretive overhead, requiring organisations to balance fast screening with careful statistical review and legal context.

  • A recruiting team compares interview-to-offer rates across demographic groups and flags a model if one group falls below the 80 percent benchmark.
  • An HR analytics team reviews promotion shortlists generated by an algorithm and uses the rule as an early warning before conducting deeper disparity analysis.
  • A financial services team tests whether an automated eligibility score disproportionately reduces approvals for a protected class, then investigates the underlying features and thresholds.
  • A procurement workflow uses the rule to assess whether vendor prequalification criteria create systematic exclusion across applicant categories.
  • An AI governance team applies the rule to human-in-the-loop decisions to identify whether downstream reviewers are reproducing upstream model bias.

Used well, the rule helps teams decide where to look next, not what final decision to make. It is most useful when paired with documentation of selection stages, confidence intervals, and business justification for decision criteria. It also helps separate true process inequity from randomness in small samples, which is why organisations should avoid reading a single threshold result in isolation.

Why It Matters for Security Teams

Security teams increasingly encounter the four-fifths rule when they oversee AI-enabled hiring, access screening, contractor vetting, or other identity-adjacent decision pipelines. If those systems are unfairly tuned, the result is not only compliance exposure but also trust erosion, challenge risk, and poor governance evidence. The rule matters because it gives analysts a lightweight first pass for spotting outcomes that may deserve deeper review under organisational risk controls.

For practitioners, the key issue is that biased screening logic can hide inside automation layers that look neutral on paper. A model may appear efficient while producing unequal outcomes through proxy features, threshold settings, or historical training data. That makes the four-fifths rule valuable as a triage tool in AI governance and selection review, even though it cannot prove intent or causation. Organisations typically encounter the operational cost of this issue only after a complaint, audit, or legal challenge, at which point the four-fifths rule becomes unavoidable as part of the remediation process.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0, NIST AI RMF, NIST AI 600-1 and NIST SP 800-63 set the technical controls, while EU AI Act define the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0GV.RM-01Risk management framing supports review of disparate outcomes in automated selection.
NIST AI RMFAI RMF addresses measuring and managing harmful performance and fairness risks.
NIST AI 600-1The GenAI profile informs governance of model outputs that may affect people.
NIST SP 800-63Digital identity assurance can intersect with selection decisions that gate access.
EU AI ActHigh-risk AI governance includes monitoring systems that affect employment and access.

Establish governance checks for selection models and document adverse impact reviews as part of risk management.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 1, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org