The Consequence Test
Risk tier does not follow how sophisticated a system is. It follows what happens to an identified person. Six scenarios — decide which ones carry consequence, then see how the standard reads them.
A rules-based filter removes any application that does not list a specific certification. It is about fifty lines of logic — no machine learning of any kind. Roughly a third of applicants are removed before a recruiter sees the list. Those candidates receive a standard rejection.
A model forecasts headcount and attrition by department for the next four quarters, using historical turnover and hiring data. Output is a planning dashboard the HR director reviews monthly. No individual is named anywhere in it.
A model scores 400 applicants and returns them ranked. The recruiter reviews the top 40 by default. When asked how often anyone below the cut-off gets pulled up, the talent lead says it happens "occasionally" but cannot give a number, and no record is kept.
A large, expensive, highly capable general model drafts job advertisements. A recruiter edits every draft before posting. The system never sees an application and never scores a person.
A platform scores employee "engagement" from calendar density, message response times, and survey answers. Where a score falls sharply, the employee's manager receives an alert. Managers say they use it "as a prompt for a conversation."
A chatbot on the intranet answers questions about leave entitlement and expense policy, trained on the employee handbook. It answers questions and routes nothing. If it cannot answer, it shows the HR inbox address.
