Solutions / Compliance

Compliance through
visibility, controls, and oversight

Kempian supports compliance through explainable workflow controls, audit trails, and human review gates — not automated compliance verdicts. We cannot guarantee legal compliance. We can make every decision visible, reviewable, and auditable.

Important: Kempian provides workflow support tools — it does not automate compliance decisions or guarantee regulatory adherence. Compliance with employment law, GDPR, EU AI Act, and industry regulations is the responsibility of the operating organisation. Kempian is designed to support, not replace, compliance review processes.

Compliance controls in Kempian

Human review at every gate

A person approves every decision that affects a candidate, a client, or a hire. Every gate requires explicit human approval before the action proceeds, and every gate offers reject or hold with a required reason.

Decision log

Every decision is recorded with reviewer identity, timestamp, the AI output on screen at the time, the decision taken, and any override reasoning. Records are append-only: we add to the history, we do not rewrite it.

Override always available

Operators can override AI recommendations at any gate. The override reason is captured and stored alongside the decision, so the record shows what the AI proposed and what the human chose instead.

Candidate opt-out enforcement

Opt-out records are maintained per candidate, and the opt-out check runs before every outreach send, across every workspace.

Licence and certification checks

Compliance readiness is a named factor group in AI Confidence. Missing or expired credentials surface as explicit flags, not lower scores.

Workspace data isolation

Every workspace has its own isolated data scope. Requisitions, notes, and integration credentials stay inside the workspace that created them. Candidates are only shared when you opt in to the shared talent pool.

We follow GDPR and EU AI Act requirements. We hold no third-party certification yet.

EU AI Act posture

Kempian is designed to support the human oversight requirements under EU AI Act Annex III Article 14 for high-risk AI systems used in employment contexts.

The four-gate system is a structural mechanism — not a configurable preference. Every gate requires explicit human confirmation before the workflow proceeds.

Kempian does not claim to make your organisation compliant with the EU AI Act. That determination requires legal review of your specific deployment context. We provide the oversight infrastructure that compliance review will examine.

Full governance documentation →

Art.14 — Human oversight

Supported

Four mandatory human review gates in every workflow path.

Art.22 (GDPR) — Audit trail

Supported

Append-only decision log per candidate per workflow step: reviewer identity, timestamp, and reasoning.

Art.13 — Transparency

Supported

Named signals, factor groups, and reasoning access on every score.

Certification / conformity

In review

Formal conformity assessment is under evaluation. Not yet certified.

Request a compliance review

We provide architecture documentation, data processing agreements, and governance walkthroughs for compliance and legal review teams.