Deployer Checklist
Actionable compliance checklist for organisations using the Jaicob platform: what to do before go-live, what to do continuously, and how to handle candidate requests.
How to use this checklistThis is the practical companion to EU AI Act: Instructions for Use. That document explains the obligations; this one turns them into steps. Work through Section 1 before you put AI features into use, run Section 2 as a routine, and keep Section 3 next to your candidate-facing inbox.
This checklist is informational and does not constitute legal advice.
1. Before go-live
Governance
- Appoint an oversight owner. Name the person (or team) responsible for overseeing AI features: reviewing approval queues, monitoring agent runs, and acting on anomalies. They need the authority to overrule or stop the system, and management must know they have it.
- Train the reviewers. Everyone who approves AI-proposed actions or interprets match scores has read Instructions for Use Sections 4 (limitations) and 6 (oversight), and understands that an approval is a decision they own.
- Confirm the intended purpose. You are using the platform for recruitment and selection of adults, and nothing else (no evaluation of current employees, no non-recruitment screening).
Legal and privacy
- Sign the DPA. The data processing agreement with Jaicob (including the subprocessor list) is signed and on file.
- Run your DPIA. For AI-assisted recruitment a data protection impact assessment is typically required (Article 35 GDPR). Your DPO or privacy counsel has assessed and documented it.
- Update privacy notices and job postings. Candidates are told, before AI is used on them, that AI supports your recruitment process, that no decision about them is fully automated, and how to request an explanation or a human alternative. A sample notice text is in Instructions for Use, Section 7.
- Cover sourced candidates. For candidates you source (who did not apply themselves), your process delivers the GDPR Article 14 information within one month of obtaining their data, and no later than the first communication.
- Inform workers and their representatives. Before first use, affected workers and employee representatives (works council where you have one) are informed that an AI system will be used in the workplace (AI Act Article 26(7); in the Netherlands, check whether WOR Article 27 co-determination applies to your rollout).
- Public body? If you are a public body or provide public services, complete a fundamental rights impact assessment (FRIA, AI Act Article 27) before first use.
- Non-EU hiring locations. For hiring in the US or other non-EU locations, your counsel has checked local rules (e.g. NYC Local Law 144 bias audit and notice duties, Colorado AI Act deployer duties, Illinois hiring-AI rules).
Platform configuration
- Set your regulatory region correctly in company settings (EU or US); it drives retention and expiry behaviour.
- Review approval gates. Beyond the mandatory EU approval floor for negative decisions (which you cannot and should not try to disable), decide which additional agent actions require approval in your organisation, and configure them.
- Configure consent-dependent channels. SMS and AI-interview flows only run where the platform has recorded the candidate's opt-in; verify your application forms and flows capture it.
- Test the disclosures yourself. Run a test conversation and a test AI voice call to your own phone; confirm you are told you are talking to AI, and that STOP ends an SMS conversation.
2. Ongoing operation
Run these as a routine (weekly or per hiring campaign, depending on your volume):
- Work the approval queue properly. Approvals are reviewed individually, with enough context open (candidate, vacancy, agent rationale) to make a real decision. Refusals include a reason: the agent uses it. Watch your own approval statistics; a 100% approval rate at high speed is a warning sign of automation bias, not a sign of quality.
- Review agent runs. Spot-check completed runs (steps, tool actions, outcomes) for behaviour you did not expect.
- Watch outcomes for skew. Periodically review screening and rejection outcomes for unexpected patterns across candidate groups. If you see a suspicious pattern, pause the affected feature and contact us (see Incidents below).
- Keep inputs clean. Vacancy requirements and screening questions are current, job-relevant, and free of criteria that proxy for protected characteristics.
- Respect the log floor. Do not delete AI activity logs before six months; export them if your own policies require longer retention.
- Honour opt-outs immediately. A candidate's STOP, or a request to speak to a human, is executed, not queued.
- Keep your notices current. When you start using a new AI feature, your candidate-facing notices are updated before it goes live.
Incidents
- Know the trigger. A serious incident or risk signal includes: a suspected discriminatory output pattern, an action executed without its required approval, an AI conversation without disclosure, or unauthorized access to candidate data.
- Know the drill. Suspend the affected use, preserve the logs, and email [email protected] with subject "AI incident" without undue delay (AI Act Article 26(5)). We handle provider-side reporting (Article 73) and corrective actions with you.
3. Handling candidate requests
You are the data controller and the deployer; candidate-facing requests land with you. The platform is built to back you up on each of them.
"Was AI used on my application?"
Answer honestly and specifically: which features were involved (matching, screening conversation, outreach) and the fact that no decision about them was fully automated. Your privacy notice should already say this; the platform's run history shows you what actually happened for this candidate.
"Explain the decision about me." (AI Act Article 86, GDPR Article 22(3))
- Locate the candidate's assessment in the platform.
- Generate the platform's written explanation of the main elements that contributed to the AI-assisted assessment.
- Combine it with the human reasoning (who reviewed it, what they decided, and why) and respond. The decision you explain is your decision; the AI part is the support it received.
- Respond within a reasonable time; if the request is also a GDPR access request, the one-month deadline of Article 12(3) GDPR applies.
"I want a human, not an AI."
Offer a human alternative for AI conversations (interview, screening call). Declining AI may affect scheduling, but must not, by itself, disadvantage the candidate's application. Record the preference so agents do not re-approach the candidate by AI channels.
"Delete my data." (GDPR Article 17)
Use the platform's erasure flow; it fans out across the platform's stores (messages, documents, profile data). Anonymised assessment records are retained for bias monitoring; they can no longer be traced to the candidate, which is why erasure does not remove them. Say so in your response if asked.
"I want to complain."
Point candidates to your own complaints channel, and inform them of their right to complain to the data protection authority (in the Netherlands: Autoriteit Persoonsgegevens) and, for AI-specific complaints, the national market surveillance authority under the AI Act. Never present a complaint as inadmissible because "the AI decided": it did not; you did.
4. Frequently asked questions
Can I switch off the approval requirement for rejections?
No. For EU-governed tenants, human approval for candidate-negative actions (disqualification, rejection) is enforced server-side and is not configurable. This is deliberate: it is the platform's implementation of Article 14 AI Act and Article 22 GDPR, and it protects you as much as the candidate.
Can I run a fully automated funnel end-to-end?
Outreach, scheduling, and screening conversations can run autonomously within your configured approval rules. Decisions that negatively affect a candidate cannot. A funnel where nobody looks at anything is misuse of the system (see Instructions for Use, Section 2.3) and a liability for you.
Who answers a candidate's rights request: Jaicob or us?
You do, as controller and deployer. We supply the machinery: run history, generated explanations, erasure fan-out, exports, and help at [email protected]. If a candidate contacts us directly, we route the request to you and support you in answering it.
Do I need a bias audit?
Under the EU AI Act, no periodic external bias audit is prescribed for deployers, but you must monitor operation (Section 2). If you hire into New York City, Local Law 144 requires an annual independent bias audit of automated employment decision tools; request the anonymised assessment export (GET /agentic/audit/scoring-export) for your auditor.
Does the AI see a candidate's age, gender, or nationality?
No. Those attributes are withheld from AI evaluation features by design, and agents are instructed not to infer them. Do not attempt to reintroduce them through custom instructions; that is misuse.
We have a works council. Do we need their sign-off?
You must inform workers and their representatives before use (Article 26(7) AI Act). Whether formal consent is required (e.g. WOR Article 27 in the Netherlands, works constitution acts elsewhere) depends on your jurisdiction and how you deploy; check with counsel before rollout, not after.
What if we suspect the AI is behaving in a biased way?
Treat it as an incident: pause the affected feature, preserve logs, and report it to us without undue delay (Section 2, Incidents). Do not quietly keep using a feature you distrust.
Questions this checklist does not answer: [email protected].
Updated about 8 hours ago
