AI Governance Platforms and Local Law 144 Compliance
A governance platform manages AI risk broadly; LL144 is narrow and operational. Here's what a platform won't do for you.
By Rovaryn Digital · · 8 min read

The vendor demo that promises "LL144 covered"
Picture the pitch. A general AI-governance platform sales rep pulls up a dashboard mapped to ISO 42001 and the NIST AI Risk Management Framework, clicks into a module labeled "US State AI Laws," and tells you it has Local Law 144 covered alongside Illinois HB 3773 and the EU AI Act — and, if the module has not been refreshed lately, Colorado's SB 24-205, which was repealed and replaced on 14 May 2026 by SB 26-189, a narrower disclosure regime that drops the impact-assessment and duty-of-care requirements. It looks comprehensive. It probably is comprehensive — for enterprise AI risk management across a dozen jurisdictions.
Then you ask the actual operating question: who conducts the annual bias audit, and does the platform's report satisfy DCWP's independence requirement? That's where the demo usually gets vague.
This is the gap HR Directors at New York employers keep tripping over. An AI governance platform local law 144 compliance module is built for breadth — mapping AI risk across frameworks, jurisdictions, and model types. Local Law 144 is built for narrowness — one audit, one public posting, one 10-business-day notice, tied to one New York City statute. Confusing the two costs time you don't have before a filing deadline.
By the end of this piece, you'll know exactly which slice of LL144 a general governance platform can plausibly cover, which slice it structurally cannot, and what to put in place to close the gap.
What "AI governance platform Local Law 144 compliance" actually means
When a vendor markets ai governance platform local law 144 compliance, they're almost always describing a mapping exercise: LL144's text gets translated into a checklist item inside a broader risk-management taxonomy. That's a real and useful thing. It is not the same as satisfying the statute.
Local Law 144 defines an AEDT as any computational process derived from machine learning, statistical modeling, data analytics, or AI that issues a simplified output — a score, classification, or recommendation — used to substantially assist or replace discretionary employment decisions (Perkins Coie, 2023). The law took effect January 1, 2023, with enforcement beginning July 5, 2023 after a delay from an originally announced April 15 date (Epstein Becker Green / Workforce Bulletin, 2023). It imposes exactly three core obligations: an annual independent bias audit, a public summary of the most recent audit posted on the employer's website alongside the AEDT's distribution date, and candidate or employee notice at least 10 business days before use, with an alternative-process or accommodation avenue (Crowell & Moring LLP, 2023; Epstein Becker Green, 2023).
None of those three obligations is a governance question in the ISO 42001 sense — "does our organization manage AI risk responsibly." They're operational filing requirements with specific deadlines, specific posted artifacts, and one specific independence condition. A platform can remind you a deadline exists. It cannot make the audit independent, and it cannot post the notice for you.
Where Local Law 144 gets narrow — and platforms stop
General governance platforms are designed to flex across frameworks that ask conceptually similar but structurally different questions: Is your AI system's risk classified correctly (EU AI Act)? Have you documented model lifecycle controls (ISO 42001)? Have you classified and documented the system before deployment (the EU AI Act's high-risk regime)? LL144 asks something much narrower and much more mechanical: did an independent third party run the four-fifths test on your AEDT's actual selection rates, and did you post the summary and give notice on time?
The four-fifths rule is a good example of why this matters. Under the EEOC's Uniform Guidelines, a selection rate for any group that falls below 80% of the rate for the highest-selected group may indicate adverse impact (via Assessment Systems, 2024). That's a specific statistical test with a specific threshold — not a risk tier, not a maturity score, not a framework checkbox. A governance platform can display the number. It can't generate it without the underlying audit data, and it can't make the underlying audit "independent" just by running the math inside its own dashboard.
Penalties reinforce the narrowness. Civil penalties under LL144 run up to $500 for a first violation (and each additional violation on the same day), $500 to $1,500 for each subsequent violation, and they accrue per violation per day (Office of the NY State Comptroller, 2025). That's not an abstract "risk exposure" figure a governance dashboard scores on a heat map — it's a per-day, per-violation clock that starts running the moment a required posting or notice is missing.
The independent-auditor requirement no platform satisfies
This is the structural wall every general AI governance platform local law 144 compliance claim eventually hits. LL144 requires the bias audit be conducted by an independent auditor with no financial or employment relationship to either the employer or the AEDT vendor. That single sentence rules out a lot of otherwise-plausible one-stop-shop pitches: a vendor cannot audit its own AEDT, and — just as important — a platform that sells you documentation tooling generally cannot also be the entity that signs your independence attestation, because selling you both creates exactly the relationship the statute is designed to prevent.
That's the line WorkforceNewYork sits on deliberately. Our workbooks run the compliance operation around your audit — tracking vendor status, building your posting calendar, documenting your rationale — but we never perform, certify, or sign a bias audit, and we never score any individual candidate or employee. If you need help understanding what "independent" actually requires in practice, our breakdown of the independent bias auditor requirement under Local Law 144 walks through it in more depth, and our comparison of bias-audit platforms versus independent auditors goes further into where that boundary sits across the vendor landscape generally.
The enforcement record makes the independence question more urgent, not less. A December 2025 Comptroller audit covering July 2023 through June 2025 found LL144 enforcement "ineffective": DCWP had flagged only 1 of 32 companies reviewed as non-compliant, while the Comptroller's own auditors found 17 problems across those same companies (Office of the NY State Comptroller, 2025). Separately, an academic "Null Compliance" study of 391 employers found only 18 had posted audit reports and only 13 had posted transparency notices (ACM FAccT, Wright & Muenster et al., 2024). A governance platform's internal dashboard showing green checkmarks doesn't change what's actually posted publicly — and posting is what DCWP and outside plaintiffs can see.
FairNow, Holistic AI, VerifyWise: three different scopes
Naming names helps make the distinction concrete, without implying any of these platforms is doing something wrong.
FairNow (now part of AuditBoard) is a general-purpose AI-governance platform aligned to ISO 42001 and the NIST AI Risk Management Framework. It is not NY-statute-specific, and it does not publish a public price.
Holistic AI is a broad, multi-framework enterprise AI-governance platform covering AI risk across many jurisdictions and regulatory regimes at once, with custom, unlisted pricing.
VerifyWise takes a different shape: it's a source-available, self-hostable GRC tool that covers LL144 among many frameworks, and it also offers auditor services. It has a free self-hosted starting point that requires technical setup, alongside custom enterprise deployment.
All three are legitimate tools for what they're built to do: manage AI risk and compliance posture across frameworks at an enterprise scale. None of them replaces the specific, narrow, independently-audited mechanics LL144 demands — the four-fifths calculation, the public posting, the 10-business-day notice, tied to one New York City statute and one independence requirement. If you're evaluating any AEDT vendor's audit claims directly, our guide to verifying an AEDT vendor's bias audit covers the specific documents to request.
Where the operations gap actually lives
Here's the honest version of the gap. A general governance platform will tell you an audit obligation exists somewhere on your compliance calendar. It generally will not:
- Confirm your specific AEDT vendor's most recent bias-audit summary is actually posted where DCWP expects it, dated correctly
- Track the 10-business-day notice window against your actual hiring calendar for a specific role
- Document, role by role, why a given tool counts as an AEDT under the statutory definition — or why it doesn't
- Give you a paper trail you can hand a lawyer or a regulator showing you tracked the deadline, not just that a dashboard flagged it once
That last point is where most of the actual risk sits day-to-day — not in the audit science, but in the operational tracking around it. This is operational guidance, not legal advice; confirm your specific posting and notice obligations directly with DCWP, and confirm any legal determination about AEDT status with outside counsel.
If you want the full walkthrough of every LL144 obligation in one place before deciding how to close this gap, our Local Law 144 compliance guide is the place to start, and our compliance deadline calendar breakdown covers the specific dates you're tracking against.
Your first action item
Whether or not you're already paying for a general AI governance platform, the operational tracking underneath it — vendor audit status, posting dates, notice windows, role-by-role rationale — needs somewhere concrete to live. That's what the LL144 + WARN Compliance Calendar & Filing Tracker is built to hold: a downloadable workbook that runs the calendar and the paper trail around your independent audit, without ever claiming to be the audit itself.
We're also building toward a hosted version of this tracking — an always-on reminder engine and a live vendor audit-status lookup — for teams who'd rather not manage it in a spreadsheet. If that's you, join the waitlist and we'll let you know when it ships.
Related guides
- Vendor Due Diligence
Bias Audit Platform vs. Independent Auditor: The Distinction That Matters
Auditor or platform? They're not interchangeable under LL144. A factual map of who does what — and where WorkforceNewYork sits.
Rovaryn Digital · · 9 min read
- Vendor Due Diligence
Is There a Local Law 144 Vendor Audit Registry?
There's no official registry to look up. So verification falls to you — here's how to keep your own reliable record.
Rovaryn Digital · · 7 min read
- Vendor Due Diligence
Is This AI Hiring Tool Deployable in NYC?
A tool without a current audit isn't deployable in NYC. Here's the pre-launch gate to run.
Rovaryn Digital · · 6 min read


