Short answer. A vendor-level audit can be commercially useful, especially when the same product is deployed across multiple customers. But the audit must still have a defined data basis, tool/version, output meaning and deployment context. It should not be marketed as automatically covering every customer in every configuration.
Why vendors commission audits
- Reduce friction in enterprise procurement.
- Give customers a current independent audit package to evaluate.
- Create a repeatable evidence package for a defined product/version.
- Support public Summary of Results workflows where appropriate.
Vendor audit does not eliminate employer responsibility
DCWP's FAQ states that employers and employment agencies are ultimately responsible for ensuring the required bias audit was completed before covered use. A vendor can support that obligation, but it does not transfer the legal responsibility away from the employer or agency.
What data can a vendor use?
6 RCNY §5-302 allows historical data from one or more employers or employment agencies that use the AEDT. Test data may be used only where the conditions in the rule are met. The data basis and explanation must be documented in the public summary where required.
Can one audit support multiple customers?
Potentially, but only if the audit actually maps to the product/version and use context the customer is relying on. Material differences in configuration, thresholds, outputs, decision workflow or population can create a re-scoping issue.
What employers should request from a vendor
- Most recent bias-audit date.
- Independent auditor identity and independence basis.
- Tool/version/configuration covered.
- Historical/test-data basis.
- Public Summary of Results.
- Any scope limitations or deployment assumptions.
Last legally reviewed: September 27, 2026.