Blog / Auditor Selection & Engagement
Scoping an Independent Auditor Engagement Under Local Law 144
A clear scope prevents surprises later. Here's how to define and document your auditor engagement.
By Rovaryn Digital · · 7 min read

The Engagement Letter That Left Too Much Unsaid
Three weeks before the audit deadline, the HR director gets an email from the auditor asking for historical data on a screening tool nobody mentioned during scoping. It turns out the engagement letter said "the AEDT used in hiring" — singular — but the company runs two separate tools, one for resume screening and one for video-interview scoring. The auditor only priced and planned for one. Now there's a change order, a delay, and a hard conversation about whether the second tool even gets audited before the deadline.
This is what happens when engagement scope gets treated as a formality instead of a document. The fix isn't a better auditor — most auditors will ask the right questions if you let them. The fix is defining the independent auditor engagement scope yourself, in writing, before anyone signs anything. By the end of this piece, you'll know exactly what to specify — tools, roles, data, deliverables — and how to log the engagement so it holds up if anyone asks what you agreed to and when.
What "Independent Auditor Engagement Scope" Actually Covers Under Local Law 144
Local Law 144 requires employers using an automated employment decision tool on NYC-resident candidates or employees to have that tool bias-audited by an independent auditor annually, publish a summary of the results, and give candidates notice at least 10 business days before the tool is used, with an alternative process available (Crowell & Moring LLP, 2023; Epstein Becker Green, 2023). The law defines an AEDT broadly: any computational process derived from machine learning, statistical modeling, data analytics, or AI that produces a simplified output — a score, classification, or recommendation — used to substantially assist or replace discretionary decision-making (Perkins Coie, 2023).
That breadth is exactly why scope matters. "The AEDT" is rarely one thing. It might be a resume-screening algorithm, a separate video-scoring module, and a ranking layer that combines both. Each of those can be a distinct tool for audit purposes, and each needs to either be named in the engagement or explicitly excluded with a documented reason. An independent auditor engagement scope that's vague on this point is the single most common cause of late-stage surprises.
There's a structural reason the auditor can't just fill in these gaps for you unilaterally, either. LL144 requires the auditor to have no financial or employment relationship with your company or your AEDT vendor — that's what "independent" means under the law. An auditor operating at arm's length will scope to exactly what you tell them, in writing. If you leave it loose, they'll price and plan to the loose version, and anything outside it becomes a change order later.
This is operational guidance, not legal advice. If you're unsure whether a specific tool or feature meets the statutory AEDT definition, that determination belongs with DCWP or outside counsel — the scoping discipline below just makes sure the question gets asked before the engagement starts, not after.
Which Tools and Roles Are In Scope
Start the scoping conversation with an inventory, not a contract. For each tool your company uses on NYC candidates or employees, document:
- The tool's name, vendor, and what stage of the employment decision it touches (screening, interview scoring, ranking, promotion).
- Which job roles or requisitions it's applied to — not every tool runs against every role, and the audit should reflect actual usage.
- Whether the tool has changed materially since the last audit cycle, which can trigger a fresh audit rather than a renewal.
That role-level detail matters for a second reason: the four-fifths rule that most bias audits test against measures selection rates by group, and those rates only mean something when they're tied to a specific tool and a specific decision point. A selection rate for one group under 80% of the rate for the highest-selected group is the standard the EEOC's Uniform Guidelines use to flag possible adverse impact (via Assessment Systems, 2024) — but that comparison has to be scoped to the right tool and the right population, or the audit is measuring the wrong thing. Get the tool-and-role list wrong at scoping, and the auditor's output won't answer the question you actually need answered.
If you're still narrowing down which auditor to bring this list to, the questions worth asking during selection are covered separately — see bias audit RFP questions for auditor selection — and the baseline qualifications an auditor needs are laid out in our guide to independent bias auditors under Local Law 144.
Data You Must Provide the Auditor
Scope isn't just what gets audited — it's what you're committing to hand over. Auditors typically need historical usage data: how the tool scored or ranked candidates by group, over what period, and against what outcomes. Defining this upfront avoids the mid-engagement scramble where the auditor asks for twelve months of data and you only have three, or the data lives in a system nobody thought to include in the request.
Decide and document, before signing:
- The lookback period the audit will cover.
- Which internal systems (ATS, HRIS, the AEDT vendor's own reporting) will be the source of record.
- Who on your team is responsible for pulling and formatting that data, and by when.
For the specifics of what auditors typically ask for and how to prepare it, see AEDT data provision for auditors: historical data requirements.
Deliverables to Specify Before You Sign
The engagement letter should name the deliverables, not just the activity. At minimum, that means the audit report itself, the public summary language you'll post on your website alongside the AEDT's distribution date (a posting obligation under LL144's public-summary requirement), and a timeline that gets you the results with enough runway to meet your candidate-notice window — remember, notice has to go out at least 10 business days before the tool is used, so audit results need to land well ahead of that, not the week before.
An engagement scope that doesn't name its deliverables in writing isn't a scope — it's a hope.
Also worth specifying: what happens if the audit finds a compliance gap. Will the auditor issue a remediation memo, a re-test window, or just the raw numbers? Knowing the answer before you sign avoids a second negotiation after you've already paid for the first one.
Cost is a natural next question once deliverables are clear, and it varies by tool count, data readiness, and auditor — see how much a bias audit costs in NYC for what drives that variation.
Documenting the Engagement for Your Own Compliance Record
None of this scoping work protects you if it only lives in an email thread. The engagement letter, the tool-and-role inventory, the data-provision plan, and the deliverables timeline should all sit in one place, dated and versioned, alongside your broader Local Law 144 recordkeeping — see the full compliance guide for how this fits the annual cycle.
Given the enforcement record so far, that internal discipline matters more than most employers assume. A December 2025 audit by the NY State Comptroller, covering the enforcement period from July 2023 to June 2025, found the city's own enforcement "ineffective": DCWP found only 1 of 32 sampled companies non-compliant, while the Comptroller's own auditors reviewing the same 32 companies found 17 (OSC, 2025). Separately, a 2024 academic study of 391 employers found only 18 had posted audit reports and only 13 had posted transparency notices (ACM FAccT, Wright & Muenster et al., 2024). Weak external enforcement doesn't mean weak risk — it means the paper trail you keep is often the only real record that the engagement happened on the terms you set. Penalties for the underlying violations still run up to $500 for a first violation and $500 to $1,500 for each subsequent one, accruing per violation per day (Office of the NY State Comptroller, 2025).
Your First Action Item
Scope the engagement before you scope the vendor conversation around it. Our Independent-Auditor Engagement RFP & Scoping Kit gives you the tool-and-role inventory template, the data-provision checklist, and the deliverables worksheet described above in one downloadable set, so the engagement letter reflects what you actually agreed to — not what got left out.
This kit runs the operational and documentation side of the engagement. It doesn't perform, certify, or sign the audit itself — that's your independent auditor's job — and nothing here substitutes for legal advice on whether a specific tool meets the statutory AEDT definition. Confirm that determination with DCWP or your own counsel, then use the kit to make sure the engagement you sign actually covers it.
Related guides
- Auditor Selection & Engagement
Historical Data vs. Test Data in a Bias Audit
Historical or test data? The choice shapes what you provide. Here's the difference and when each applies.
Rovaryn Digital · · 7 min read
- Auditor Selection & Engagement
What Data Does a Bias Auditor Need?
Before you hand anything over, know what the auditor actually needs. Here's the typical data list and how to prep it.
Rovaryn Digital · · 7 min read
- Auditor Selection & Engagement
AEDT Data Provision: What the Auditor Needs
The audit is only as good as the data you hand over. Here's how to prepare and document what the auditor receives.
Rovaryn Digital · · 7 min read


