Skip to content

Operationalizing NYC Local Law 144 in Modulos

Modulos ships Local Law 144 as a single application-level framework (templates 1.0.29): MFF-27 NYC Local Law 144, carrying the Regulation label and the nyc-ll144.svg icon. There is no organization-level twin. Every duty in the law attaches to the use of one specific automated employment decision tool, so the unit of compliance is the tool, and the unit of work in Modulos is the project.

Project structure

TemplateProject typeScopeRequirementsDistinct Controls
MFF-27 — NYC Local Law 144AI applicationOne automated employment decision tool used to screen candidates for employment or employees for promotion in New York City6 (MRF-476MRF-481)9 (4 new, 5 reused)

One MFF-27 project per AEDT. The audit clock, the posting, the distribution date, and the notice content are all tool-specific: a resume screener and a video-interview scorer each need compliant audit coverage, a tool-specific distribution date, complete published results, and timely notice describing what each tool assesses (a single report, posting, or notice may cover more than one tool if it contains every required tool-specific element). An employer that uses both runs two projects, each with its own control instances and Evidence library. Where a tool's project already carries the EU AI Act or another template, add MFF-27 to that project: the shared controls (MCF-32, MCF-42, MCF-43) are one instance there, serving both frameworks.

There is no scoping questionnaire and no framework-specific tag family. MRF-476 records the in-or-out decision inside the project; the existing Scope, AI System Lifecycle, and Framework tags on the controls suffice for a six-requirement template. The control questions address the deployer (the employer or employment agency), which is where the law places the duties; a vendor that arranges an audit of its tool by an independent auditor on behalf of deployers can still run the template, reading the questions from the deployer's side.

The six requirements — MFF-27

RequirementLegal anchorMapped controls
MRF-476 — AEDT applicability determination§ 20-870; 6 RCNY § 5-300; DCWP FAQ I, VMCF-16
MRF-477 — Annual independent bias audit§ 20-871(a)(1); 6 RCNY §§ 5-300, 5-301; FAQ II, IV, VMCF-684, MCF-42, MCF-43
MRF-478 — Bias audit data requirements6 RCNY §§ 5-300, 5-302; FAQ IIIMCF-684, MCF-32
MRF-479 — Publication of bias audit results§ 20-871(a)(2); 6 RCNY § 5-303; FAQ II.3MCF-685
MRF-480 — Candidate and employee notice§ 20-871(b)(1)–(2); 6 RCNY § 5-304(a)–(c); FAQ VIMCF-686, MCF-167
MRF-481 — Data transparency disclosures§ 20-871(b)(3); 6 RCNY § 5-304(d)MCF-687

Each requirement's detail content carries the source list, the obligations addressed with the operative statutory text quoted verbatim, the key concepts from the rules and the FAQ, and a modeling note stating why the mapped controls are new or reused. The requirements and the four new controls carry the Local Law 144-specific tests, calculations, conditions, and clocks; the reused controls stay framework-agnostic.

The four new controls

All four carry the tag Framework: Specific and Scope: Project. Each has a guidance component (what the law requires, key considerations, what would fail the control, relationships to other controls, and the evidence an auditor expects), an evidence upload, and a report template.

ControlCarriesControl question
MCF-684 — Independent AEDT bias auditThe annual bias audit by an independent auditor: the one-year window to each use, the three independence tests, the selection-rate and impact-ratio calculations for selection or classification functions (per classification group where the tool buckets people) and the median-score, scoring-rate, and impact-ratio calculations for scoring functions, both sets where the tool does both, across sex, race/ethnicity, and intersectional categories, the unknown-category count, the 2 percent exclusion from impact-ratio calculations with justification and reported counts and rates, and the data rules (historical data by default, pooling conditions, test-data fallback, no imputed demographics). Serves MRF-477 and MRF-478.Has an independent auditor completed a bias audit of this tool within the last year, with the required calculations and data basis?
MCF-685 — Public disclosure of bias audit resultsThe public posting on the employment section of the website, before the first covered use and, after each audit refresh, before continued use, of the audit date, the summary of results with all required elements (including the 2 percent-rule publication substitute and any test-data explanation), and the distribution date; the hyperlink option; retention for at least six months after the tool's last use. Serves MRF-479.Are the bias audit date, its summary, and the distribution date for this tool publicly posted as required, before its use?
MCF-686 — Pre-use notice to candidates and employeesThe notice to candidates and employees who reside in New York City at least 10 business days before the tool assesses them: AEDT use, the job qualifications and characteristics assessed, the alternative-process and accommodation instructions, through a channel the rules permit for each audience. Serves MRF-480.Do New York City candidates and employees receive complete notice at least 10 business days before this tool assesses them?
MCF-687 — AEDT data transparency disclosuresThe posting of the tool's data type, data source, and retention policy on the employment section of the website; posted request instructions with a 30-day response to written requests; mandatory withholding, with an explanation to the requester, where disclosure would violate law or interfere with a law enforcement investigation. Serves MRF-481.Are the data type, source, and retention policy for this tool posted, with a 30-day request route that discloses what it may and withholds, with an explanation, what the law forbids?

MCF-685's evidence is a public web page: the URL plus dated captures (screenshot or archived page) of the initial and refreshed postings, a record that the initial posting preceded the first covered use, and records that each refreshed summary was posted before continued use under the refreshed audit.

Control reuse — shared coverage from day one

The other 5 of the 9 mapped controls are reused from the platform's existing estate, and every one of them is shared with at least one other framework:

Reused controlRole in MFF-27Also mapped by
MCF-16 — Risk TieringRecords the binary AEDT-used-in-the-city determination (MRF-476)FINMA AI Governance, Singapore MGF for Agentic AI, Microsoft Supplier DPR
MCF-32 — Data Bias AssessmentThe representativeness judgment behind the audit's data sufficiency (MRF-478)EU AI Act, NIST AI RMF, IEEE 7003, MAS FEAT, UAE Consumer AI, Microsoft Supplier DPR
MCF-42 — Model Fairness MetricsThe deployer's own fairness-metric practice around the audit (MRF-477)EU AI Act, IEEE 7003, MAS FEAT, UAE Consumer AI, UAE AI Ethics
MCF-43 — Model Bias AssessmentThe deployer's own bias assessment for protected groups (MRF-477)EU AI Act, IEEE 7003, MAS FEAT, UAE Consumer AI, UAE AI Ethics
MCF-167 — Transparent Deployment at WorkplaceInforming employees before a workplace AI system affects them; the promotion-candidate side of the notice in substance (MRF-480)EU AI Act, NIST AI RMF, Microsoft Supplier DPR

An AI-application project already running the EU AI Act template operates four of the five reused controls (MCF-32, MCF-42, MCF-43, MCF-167); one running NIST AI RMF operates two (MCF-32, MCF-167); one running IEEE 7003, MAS FEAT, or UAE Consumer AI operates the three fairness and data-bias controls. Add MFF-27 to that project and each shared control stays one instance: Evidence attached to its components supports the same claims for every mapped Requirement in the project, under both frameworks. Evidence lives in a project-level library, so separate per-tool projects do not inherit it automatically. What is new is the four Local Law 144-specific outcomes: the independent audit itself, its public posting, the timed notice, and the data disclosures. Reuse is a control-layer economy, not an assertion of clause-level equivalence between Local Law 144 and any other framework. IEEE 7003's bias-profile controls (MCF-660MCF-667) are deliberately not reused; they are IEEE-specific by design.

Rollout sequence

  1. Decide whether the tool is in scope (MRF-476): apply the simplified-output test, the three prongs of "substantially assist or replace", the two-limb technique test, and the "used in the city" test; record the determination and its rationale in MCF-16, and revisit it when the tool, its output, or its role in the process changes.
  2. Secure the audit (MRF-477, MRF-478): engage an independent auditor who passes the three independence tests, decide which calculation set or sets the tool's functions require (both where it selects or classifies and scores), settle the data basis (own historical data; pooled historical data, contributing your own data if you have used the tool before, or without that contribution if you have never used it; or test data, with the required explanation, where insufficient historical data exists for a statistically significant audit), and record the audit date against the period of use it covers. Set the re-audit lead time so the one-year window never lapses mid-cycle.
  3. Publish before use (MRF-479): post the audit date, the complete summary, and the distribution date on the employment section of the website, or a clearly identified link to them, before the first covered use; after every audit refresh, post the refreshed summary before continued use, and record each publication date.
  4. Notify before use (MRF-480): choose the channel per audience that makes the 10-business-day gap structurally hard to miss (a standing website notice for candidates; a written policy provided to employees for promotion screening), keep the qualifications-and-characteristics list synchronized with what the tool assesses, and set up an intake route for alternative-process and accommodation requests.
  5. Disclose the data practices (MRF-481): post data type, source, and retention policy for this tool alongside request instructions; run the 30-day request clock; withhold, with an explanation, only where the statute mandates it.
  6. Keep it running: complete each new audit and publish its refreshed summary before continued use, keep the posting up for six months after the tool's last use, and re-run step 1 on any change to the tool.

Each requirement is evidenced through its linked controls; the Requirement Owner reviews the completed controls and marks the Requirement as Fulfilled. Framework versioning notifies projects when the template updates.

What the framework deliberately does not include

  • No remediation control. The law requires the audit and the transparency, not action on the results (DCWP FAQ II.2). Adverse ratios route into MCF-42 and MCF-43, which the deployer operates for its own reasons and under other law; the four-fifths benchmark of 29 C.F.R. § 1607.4 is federal context, not a Local Law 144 threshold.
  • No alternative-selection-process control. 6 RCNY § 5-304(a) requires instructions for requesting one, and states that nothing in the subchapter requires providing one.
  • No organization-level template, no tag family, no questionnaire. The framework is six requirements; the applicability decision is a requirement, not a questionnaire.

Where to go next

Disclaimer

This page is for general informational purposes and does not constitute legal advice. Always verify against the current published text of N.Y.C. Administrative Code §§ 20-870–874 and 6 RCNY §§ 5-300–5-304 and consult qualified advisers.