See what Trussed catches that your current tool misses, live in your stack

    No migration, no commitment, just a direct comparison in your environment.

    Set up a technical evaluation
    Compliance Comparison

    AI Bias Audit Requirements by Jurisdiction: A Comparison

    Bias audit obligations differ substantially by jurisdiction in scope, frequency, and evidentiary format. NYC Local Law 144 requires annual independent audits and public disclosure for employment tools. The EU AI Act imposes phased conformity assessment and technical documentation for high-risk systems, backed by turnover-based fines. Colorado and Illinois use a discrimination-risk-assessment model with self-conducted reviews, while California is developing FEHA-based testing and recordkeeping expectations. No single jurisdiction's audit satisfies the others.

    Key Takeaways

    • Scope, frequency, and evidentiary format vary substantially across jurisdictions.
    • NYC Local Law 144: annual independent audits with public disclosure for employment decision tools.
    • EU AI Act: phased conformity assessment and technical documentation for high-risk systems, enforced through turnover-based fines.
    • Colorado and Illinois: discrimination-risk-assessment model built on self-conducted reviews.
    • California: developing FEHA-based testing and recordkeeping expectations.
    • No single jurisdiction's audit satisfies the requirements of the others.

    Bias audit obligations differ substantially by jurisdiction in scope, frequency, and evidentiary format. Organizations deploying AI systems across multiple regions may need to satisfy several distinct audit regimes at once, since no single jurisdiction's audit requirement satisfies the obligations of the others.

    A Fragmented Compliance Landscape

    Rather than a single, harmonized standard, AI bias audit requirements have developed independently across regions, each shaped by different regulatory traditions. Employment-focused rules, risk-tiered product regulation, and civil-rights-based testing expectations have all emerged in parallel, leaving governance teams to reconcile requirements that were not designed to work together.

    Why Definitions Create Cross-Border Ambiguity

    The term "audit" itself carries different meanings across these frameworks. NYC Local Law 144 requires an annual independent audit and public disclosure for employment decision tools. The EU AI Act instead relies on a phased conformity assessment paired with technical documentation for systems classified as high-risk. Colorado and Illinois take a third approach, requiring self-conducted discrimination-risk assessments rather than independent third-party review. California has not yet finalized its approach, but is developing testing and recordkeeping expectations under FEHA. Because each jurisdiction defines the underlying obligation differently, a control built to satisfy one regime does not automatically satisfy another.

    Documentation, Methodology, and Enforcement Differences

    The table below summarizes how each jurisdiction's model differs in audit approach, timing, and the documentation or enforcement mechanism attached to it.

    JurisdictionAudit / Assessment ModelFrequency & TriggerDocumentation & Enforcement
    NYC Local Law 144Independent bias auditAnnual, required before tool usePublic disclosure of audit results required
    EU AI ActPhased conformity assessmentTied to high-risk classification and phased rolloutTechnical documentation required; enforced through turnover-based fines
    Colorado (SB24-205)Self-conducted algorithmic discrimination impact assessmentEffective date currently delayedInternal assessment; no independent audit mandate
    Illinois (HB3773)Restrictions on discriminatory AI use in employment decisionsEffective January 2026Self-conducted review model
    CaliforniaFEHA-based testing and recordkeeping (in development)Not yet finalizedRecordkeeping expectations under development

    Where Runtime Governance Fits

    Satisfying these varying obligations depends less on a single audit event and more on the underlying data and governance infrastructure that produces auditable evidence on an ongoing basis. Annual audits, conformity assessments, and self-conducted reviews all draw on the same underlying evidence: consistent logging, documented methodology, and traceable decision records.

    Recurring architectural need

    Several capabilities recur across jurisdictional requirements regardless of which regime applies: the ability to reconstruct how a decision was reached, maintain a defensible methodology record, and generate documentation on demand rather than only at audit time.

    Operationalize Multi-Jurisdiction AI Bias Audit Compliance

    Understand how runtime governance and audit logging can support the evidentiary requirements behind AI bias audit obligations across jurisdictions.

    Talk to an Expert