If an AI recruiting tool ranks, hides, or drops people in a discriminatory way, the staffing agency and the employer remain accountable to the client and to the candidate for the process they actually ran. A vendor may share contractual risk, and a badly written score can be evidence, but “the software decided” is not a complete defence. The operational answer is unglamorous: vendor contracts that name processing and audit rights, logs of who ranked and unlocked whom, and a human override that someone uses — not a button nobody touches.
Liability depends on facts, contracts, employment and anti-discrimination rules, and DPDP duties. This piece is a desk checklist. It is not an opinion on who would win a dispute.
Accountability does not travel with the software licence. It stays with the people who posted the JD, accepted the shortlist, and sent the CV.
The client still bought a hiring process, not a model
A staffing agency’s product is a shortlist and a placement motion. The client hired you to screen people. If that screen systematically disadvantages a group — because the JD encoded a proxy, because the ranker overweighted a campus, because recruiters rubber-stamped the top twenty — the client will look at you first. The candidate will look at whoever rejected them without a human look. The vendor is one layer down, behind a click-wrap and an indemnities clause that may or may not be worth the PDF.
That is why “AI-powered” is a marketing line and a risk line at the same time. You are allowed to use tools. You are not allowed to treat automation as a person who can take the stand. Keep a human in the loop who can explain, in plain language, why this profile moved and that one did not. If the only explanation is “82% match,” you do not have a process; you have a number.
You promised a fair, competent screen. A biased ranker that you did not review is still your delivery failure in the client’s eyes.
The hiring employer remains the party the candidate applied to work for. Outsourcing screening does not outsource the duty to run a defensible selection.
The vendor’s exposure is whatever you negotiated: service failure, IP, data, sometimes an indemnity. Silence in the MSA is not “they own discrimination risk.”
What belongs in the vendor paper, not in a sales deck
Before you put live JDs into a ranker, get four things in writing. One: the vendor processes candidate data on your instructions and does not reuse the pool to train a public model unless you agreed. Two: subprocessors and where inference runs, so you are not surprised by a third country or a third model host. Three: you can export or inspect logs of scores, unlocks, and user actions for a named requirement. Four: there is a path to turn a score off, re-rank, or proceed without the model if it misbehaves on a role.
Also write what “discrimination complaint” looks like operationally: who the vendor notifies, in how many days, and whether they will help reconstruct the prompt, the JD version, and the ranked list as it stood that Tuesday. Reconstruction is what you will need if a client or a candidate asks. A screenshot of a dashboard from memory is not a record.
JD version used for scoring, timestamp of the rank, which recruiter viewed and unlocked, whether a human overrode the order, and the reason field if you require one. If the product cannot produce that, you are flying without a black box.
Human override is a control only if it is used
An override that exists in the UI but is culturally forbidden (“never touch the AI rank”) is worse than no AI: you have a system that looks automated and a team that cannot correct it. Train recruiters that a must-have miss, a location lie, or a nonsense skill extraction is a reason to pull a profile up or knock it down — and to type why. That note is how you show a court, a client, or your own MD that a person judged the file.
Override also cuts the other way. If humans consistently override in a pattern that looks like name or photo bias, the log will show that too. That is a feature. Pair override with masked review so the human correction is about fit, not about identity. Masking and liability are related but not the same problem: masking reduces one input to bias; liability is about who answers when the whole process still goes wrong.
When a complaint arrives, freeze the requirement in the tool (do not “clean up” ranks), export the log, write a factual timeline, and involve counsel before you send a narrative to the client. Do not argue with the candidate on WhatsApp about how fair the model is. The model will not attend the meeting.
What recruiters and owners actually ask
Can we blame the AI vendor if a shortlist is discriminatory?
You can pursue the vendor under contract if they failed a promised control. You cannot treat that as the end of the story with the client or the candidate. The process was yours to supervise.
What should the vendor contract cover?
Processing instructions, secondary-use limits, subprocessors, incident notice, log access, override, and a reconstruction duty. Exact wording is legal work. The list of topics is operational work you can start this week.
Does a human override protect us?
Only if people use it, record why, and can retrieve that record. An unused override is a screenshot for a sales call, not a control.
Rank, mask, log, then decide
SafalHires is built so a recruiter can see match reasoning, keep identity masked until unlock, and leave an audit trail — with a human still on the hook for the shortlist.
See SafalHires