Compliance through
visibility, controls, and oversight
Kempian supports compliance through explainable workflow controls, audit trails, and human review gates — not automated compliance verdicts. We cannot guarantee legal compliance. We can make every decision visible, reviewable, and auditable.
Important: Kempian provides workflow support tools — it does not automate compliance decisions or guarantee regulatory adherence. Compliance with employment law, GDPR, EU AI Act, and industry regulations is the responsibility of the operating organisation. Kempian is designed to support, not replace, compliance review processes.
Compliance controls in Kempian
Human review at every gate
A person approves every decision that affects a candidate, a client, or a hire. Every gate requires explicit human approval before the action proceeds, and every gate offers reject or hold with a required reason.
Decision log
Every decision is recorded with reviewer identity, timestamp, the AI output on screen at the time, the decision taken, and any override reasoning. Records are append-only: we add to the history, we do not rewrite it.
Override always available
Operators can override AI recommendations at any gate. The override reason is captured and stored alongside the decision, so the record shows what the AI proposed and what the human chose instead.
Candidate opt-out enforcement
Opt-out records are maintained per candidate, and the opt-out check runs before every outreach send, across every workspace.
Licence and certification checks
Compliance readiness is a named factor group in AI Confidence. Missing or expired credentials surface as explicit flags, not lower scores.
Workspace data isolation
Every workspace has its own isolated data scope. Requisitions, notes, and integration credentials stay inside the workspace that created them. Candidates are only shared when you opt in to the shared talent pool.
We follow GDPR and EU AI Act requirements. We hold no third-party certification yet.
EU AI Act posture
Kempian is designed to support the human oversight requirements under EU AI Act Annex III Article 14 for high-risk AI systems used in employment contexts.
The four-gate system is a structural mechanism — not a configurable preference. Every gate requires explicit human confirmation before the workflow proceeds.
Kempian does not claim to make your organisation compliant with the EU AI Act. That determination requires legal review of your specific deployment context. We provide the oversight infrastructure that compliance review will examine.
Full governance documentation →Art.14 — Human oversight
SupportedFour mandatory human review gates in every workflow path.
Art.22 (GDPR) — Audit trail
SupportedAppend-only decision log per candidate per workflow step: reviewer identity, timestamp, and reasoning.
Art.13 — Transparency
SupportedNamed signals, factor groups, and reasoning access on every score.
Certification / conformity
In reviewFormal conformity assessment is under evaluation. Not yet certified.
Request a compliance review
We provide architecture documentation, data processing agreements, and governance walkthroughs for compliance and legal review teams.