Skip to content

Compliance — EU AI Act & GDPR

Scope

Scope: obligations of the Deployer (you, as a customer), obligations of the Provider (Omogen), and product-level implementation of the EU AI Act and GDPR for the AI voice pre-screening interview agent (Mio) and the AI CV scanner (CV Screener).

Intended audience: compliance and legal officers (Parts 1 and 2, full document), and recruiters / end users (Part 3, practical guide).

Classification: internal and customer use — confidential.

Document version1.0
DateJuly 2, 2026
Prepared forOmogen — Compliance & Legal
Systems coveredMio (AI voice pre-screening interview agent), AI CV Scanner
Classification (EU AI Act)High-risk AI system — Annex III, point 4(a) (employment/workforce management)
Next reviewJuly 2, 2027

How to use this page

This page describes, in three parts, the compliance obligations applicable to the deployment of Omogen's AI systems (Mio and CV Screener) in recruitment, as well as how these obligations are implemented in the product.

  • Part 1 is primarily addressed to your compliance and legal teams, and describes the obligations you assume as a Deployer of a high-risk AI system under the EU AI Act, as well as the related GDPR obligations as a Data Controller.
  • Part 2 is addressed to Omogen's internal compliance and legal function, and describes Omogen's obligations as a Provider of a high-risk AI system, as well as the related GDPR obligations as a Data Processor.
  • Part 3 translates Parts 1 and 2 into concrete product features and daily best practices, for recruiters and other end users of the platform, as well as for compliance officers who need to verify that the product's behavior matches the legal obligations.

Note

This page is a compliance reference document. It does not constitute legal advice. You should consult independent legal counsel to confirm how these obligations apply to your specific organization and jurisdiction.

Quick reference: who is responsible for what

AreaCustomer (Deployer / Data Controller)Omogen (Provider / Data Processor)
Legal role, AI ActDeployer of a high-risk AI system (art. 26-27)Provider of a high-risk AI system (art. 8-21, 43, 47-49, 72-73)
Legal role, GDPRData ControllerData Processor (+ independent controller for its own billing/analytics)
Candidate informationInforms candidates of AI use, and that phone interviews via Mio are recordedProvides the consent script, transparency materials
Final hiring decisionAlways the customer, never OmogenProvides a decision-support tool only
System compliance (CE marking, risk management, technical documentation)N/AFull responsibility
Data hosting and securityN/AFull responsibility
GDPR DPIA (art. 35)Customer's responsibility — likely applies to most deploymentsProvides system-level information to support the Customer's DPIA
FRIA (art. 27) — conditional, see §1.2.7Customer's responsibility, only if the Customer is a public-law body / public service providerProvides system-level factual data on request; does not complete the FRIA

Part 1 — Your obligations as Deployer of the AI system

This part is addressed to your compliance and legal officers. It sets out, article by article, what the EU AI Act and GDPR require of an organization deploying Omogen's Mio or CV Screener in its recruitment process.

Under Regulation (EU) 2024/1689 (the "AI Act"), any organization that uses Mio or CV Screener under its own authority, in the course of a professional activity, is a Deployer within the meaning of Article 3(4).

Since Mio and CV Screener are used to make or support decisions that have a material impact on the outcome of a recruitment process — including shortlisting, filtering, and evaluating candidates — the systems fall under Annex III, point 4(a) of the AI Act ("AI systems intended to be used for the recruitment or selection of natural persons, notably to place targeted job advertisements, to analyse and filter job applications, and to evaluate candidates"). This means the AI system is classified as high-risk, and Customers using it acquire the full set of Deployer obligations set out in Articles 26 and 27.

Legal basis: AI Act, Articles 3(4), 6(2), and Annex III, §4(a).

At the same time, for GDPR purposes, you are the Data Controller for all processing of candidates' personal data carried out via the Service, since you determine the purposes of the processing (who to recruit) and the essential means (which candidates to contact, which criteria to apply). Omogen is the Data Processor, acting only on your documented instructions.

Legal basis: GDPR, Articles 4(7) and 4(8), 24, 28.

1.2 Core Deployer obligations under the AI Act

Article 26 of the AI Act sets out a closed list of obligations for deployers of high-risk AI systems. Each is addressed below with its practical translation for recruitment.

1.2.1 Use the system in accordance with the instructions for use

Requirement: you must operate Mio and CV Screener strictly in accordance with the Instructions for Use (IFU) provided by Omogen, including the intended purpose, operating conditions, and configuration guidance.

In practice: job criteria must be defined honestly and specifically; the system must not be configured to ask prohibited questions; the system must not be used for job categories or purposes outside its documented intended use.

Legal basis: AI Act, Article 26(1).

1.2.2 Assign human oversight to competent, trained, and authorized natural persons

Critical obligation

You must designate specific individuals with the competence, training, and authority necessary to exercise human oversight, and ensure they exercise it in practice — not just on paper.

Requirement: human oversight must be meaningful. The reviewer must have the authority to overturn the AI's recommendation and the training necessary to do so knowledgeably.

In practice: you must complete Omogen's Customer Training Pack / "Playbook" before any user (e.g., a recruiter) is granted access to review candidate results. The reviewer's identity is recorded for every decision (see Part 3.2).

Legal basis: AI Act, Article 26(2), and Article 14.

1.2.3 Ensure input data is relevant and sufficiently representative

Requirement: where you exercise control over input data (e.g., by defining job criteria, uploading CVs, selecting candidate pools), you must ensure the data is relevant to the system's intended purpose.

In practice: job criteria must reflect real, job-related requirements. Criteria must not be defined in a way that functions as an indirect proxy for a protected characteristic (e.g., "must live within 2 km of the office" as an indirect way to exclude candidates with disabilities or from certain backgrounds).

Legal basis: AI Act, Article 26(4).

1.2.4 Monitor the system's operation and inform the provider of risks

Requirement: you must monitor the system's operation based on the instructions for use and, where you have reason to consider that use in accordance with the instructions may lead the AI system to present a risk, inform Omogen and the relevant distributor without delay, and suspend use.

In practice: if a recruiter observes a consistent pattern of poor transcription for a given accent group, unexpected scoring behavior, a confirmed data leak, or any output that appears discriminatory, this must be reported to Omogen (support@omogen.ai or by contacting your CSM) and use of the affected feature must be suspended pending investigation.

Legal basis: AI Act, Article 26(5).

1.2.5 Retain automatically generated logs

Requirement: where logs are under your control, they must be retained for a period appropriate to the system's intended purpose, of at least six months, unless otherwise provided by applicable law.

In practice: human review records (reviewer, date, decision, reasoning) must be retained by you for five (5) years. Since the AI tool is used for recruitment, you are exposed to potential discrimination claims. Under French labor law, the limitation period for discrimination claims is five years and only starts running from the discovery of the discrimination, which means you must keep this evidence to defend your hiring decisions.

Legal basis: AI Act, Article 26(6); French Labour Code, Articles L1471-1 and L1134-5.

1.2.6 Inform workers and their representatives

Requirement: before putting a high-risk AI system into service in the workplace, deployer employers must inform the workers/candidates concerned and, where applicable, worker representatives, that they will be subject to the use of the high-risk AI system.

In practice: candidates must be informed, before or at the start of the interaction, that an AI system (Mio and/or CV Screener) is being used, and directed to your privacy policy. A default transparency notice template is provided by Omogen.

Legal basis: AI Act, Article 26(7).

1.2.7 Carry out a Fundamental Rights Impact Assessment (FRIA) — where applicable

Scope — read before acting

Unlike the other obligations in this part, the Article 27 FRIA does not apply to all customers. You should carefully check whether it applies to your organization before assuming so — most private-sector employers using Mio or CV Screener to recruit their own staff will not be covered, although the GDPR DPIA below will still apply.

Who is covered: under Article 27(1), a FRIA is strictly mandatory only for:

  • public-law bodies, or private entities providing public services (e.g., public administrations, public hospitals, utility services);
  • deployers of certain specific high-risk systems in the banking/insurance sectors (credit scoring and risk pricing).

Note: recruitment tools fall under Annex III, §4(a), which means a private recruitment company is exempt unless it acts under public law or explicitly provides a delegated public service.

The requirement: where you determine that you are covered, you must carry out a FRIA assessing your specific processes, the categories of candidates concerned, the risks of harm, human oversight measures, and post-market mitigation measures. The assessment, as well as the decision on whether Article 27 applies to your organization, is your own legal determination to make, ideally with your own counsel.

Omogen's role: in accordance with Article 27(5), the EU AI Office provides the official, standardized FRIA template; Omogen does not provide a proprietary template. On request, Omogen will provide you with the system-level technical indicators (accuracy rates, known limitations, oversight anchor points) needed to complete the official EU questionnaire. Omogen does not complete the FRIA on your behalf.

Legal basis: AI Act, Article 27(1) and (5).

1.2.8 Cooperate with competent authorities

Requirement: you must fully cooperate with national supervisory authorities regarding any regulatory action taken in connection with the high-risk AI system. This includes providing the operational information and documentation requested, in the language reasonably requested.

Legal basis: AI Act, Article 26(9).

1.2.9 Register in the EU database (public bodies only)

Requirement: where you are a public authority, public body, or a private entity acting on their behalf, you must register your specific deployment of the high-risk system in the official EU database referred to in Article 71, before putting it into service.

Note: this is distinct from Omogen's own obligation to register the underlying software. Traditional private-sector recruitment agencies are exempt from this requirement.

Legal basis: AI Act, Article 26(8), and Article 49.

Independently of the AI Act, you bear full Data Controller responsibility under the GDPR for the processing of candidates' personal data carried out via the Service.

ObligationRequirementGDPR Article
Legal basisIdentify and document a legal basis for processing (typically legitimate interest for shortlisting, or consent for voice recording and optional steps)Art. 6
Special categories of dataMust not seek to process sensitive data (health, religion, ethnic origin, etc.); must cooperate with Omogen's detection/deletion protocol in case of inadvertent captureArt. 9
TransparencyProvide candidates with a privacy notice covering AI use, purposes, retention, and rightsArt. 13
Automated decision-makingEnsure that no decision producing legal effects or significantly affecting a person is based solely on automated processing, without meaningful human interventionArt. 22
Data subject rightsRespond to candidates' access, rectification, erasure, objection, and explanation requests within legal deadlinesArt. 15–22
DPIACarry out or contribute to a data protection impact assessment prior to deployment (automated screening + large-scale shortlisting creates a strong legal presumption of this requirement)Art. 35
Records of processingMaintain, or contribute data-flow information to, a record of processing activitiesArt. 30
Breach notificationNotify the supervisory authority of qualifying breaches within 72 hours of discovery (Omogen will inform you without delay to enable this)Art. 33

1.4 Consequences of non-compliance

WARNING

AI Act and GDPR penalties apply cumulatively and independently. A single incident (e.g., an unreviewed discriminatory rejection) can trigger exposure under both frameworks, as well as under French labor law.

InfringementRegulatory fineOther exposure
Breach of Deployer obligations (e.g., total absence of human oversight) — AI ActUp to €15 million or 3% of total worldwide annual turnover, whichever is higherCivil liability, permanent contract termination, and severe reputational damage
GDPR breach (e.g., unlawful processing of biometric voice data, absence of a DPIA)Up to €20 million or 4% of total worldwide annual turnover, whichever is higherFormal notice from the CNIL, mandatory public audits, or immediate processing ban
Hiring discrimination (French Labour Code)Up to €45,000 fine for individuals, plus possible imprisonmentCivil damages, mandatory candidate reinstatement orders, and company blacklisting
Unlawful voice recording (French Criminal Code, art. 226-1)Up to €45,000 fine and up to 1 year imprisonmentDirect criminal prosecution of the responsible individuals or executives

Part 2 — Omogen's obligations as Provider

This part is addressed to Omogen's internal compliance and legal function. It sets out Omogen's own obligations as Provider of a high-risk AI system, and as Processor of candidates' personal data.

Omogen SAS is the Provider, within the meaning of Article 3(3) of the AI Act, of Mio and CV Screener: it develops these high-risk AI systems and places them on the market under its own name. As Provider, Omogen bears the most extensive set of obligations under the Regulation, set out in Articles 8 to 21 (substantive requirements and general provider obligations), Article 43 (conformity assessment), Articles 47 to 49 (EU declaration of conformity, CE marking, and registration in the EU database), and Articles 72 to 73 (post-market monitoring and serious incident reporting).

For GDPR purposes, Omogen acts as Data Processor for personal data processed on behalf of Customers in the course of providing the Service, and as an independent Data Controller for its own account management, billing, and product-improvement analytics.

2.2 Core Provider obligations under the AI Act

2.2.1 Risk management system

Requirement: establish, implement, document, and maintain a risk management system as a continuous, iterative process throughout the AI system's lifecycle, identifying known and foreseeable risks to health, safety, and fundamental rights.

Implementation at Omogen: risks identified, assessed using a probability/impact matrix, documented mitigation plans, owner, and timeline. Risk register continuously monitored — and reviewed quarterly.

Legal basis: AI Act, Article 9.

2.2.2 Data and data governance

Requirement: training, validation, and testing datasets must be subject to appropriate data governance, be relevant, sufficiently representative, and, as far as possible, free of errors; examine biases likely to affect health, safety, or fundamental rights.

Implementation at Omogen: data governance policy covering data quality controls, monthly bias testing across accent/name/format dimensions, prohibition of special category data with automatic detection and a 48-hour deletion protocol, and documented data lineage for training datasets.

Legal basis: AI Act, Article 10.

2.2.3 Technical documentation

Requirement: draw up technical documentation before the system is placed on the market and upon significant internal/system changes, demonstrating compliance and providing authorities with the information needed to assess compliance.

Implementation at Omogen: technical documentation file maintained in accordance with Annex IV, covering system description, development process, risk management outcomes, performance metrics, and human oversight design.

Legal basis: AI Act, Article 11 and Annex IV.

2.2.4 Documentation retention

Requirement: keep the technical documentation referred to in Article 11, the quality management system documentation referred to in Article 17, and any decisions taken by notified bodies (where applicable), available to competent national authorities for a period of 10 years after the system is placed on the market or put into service.

Implementation at Omogen: technical documentation, QMS records, and conformity assessment documents retained for 10 years from placing on the market, in a controlled, version-tracked repository, accessible on written request from a competent authority.

Legal basis: AI Act, Article 18.

2.2.5 Automatically generated logging

Requirement: design the system to enable the automatic recording of events ("logs") throughout its lifecycle, appropriate to its intended purpose (art. 12). Providers must further retain logs automatically generated by their own high-risk AI system, insofar as such logs are under their control, for a period appropriate to the intended purpose, of at least 6 months, unless otherwise provided by applicable Union or national law, in particular Union data protection law (art. 19).

Implementation at Omogen: system logs retained for a minimum of 6 months (technical/operational logs) and up to 10 years (bias testing and compliance records). Human override records are retained for 3 years by the Customer (see Part 1.2.5).

Legal basis: AI Act, Articles 12 and 19.

2.2.6 Transparency and provision of information to deployers

Requirement: design the system to ensure sufficiently transparent operation, and accompany it with instructions for use containing concise, complete, correct, and clear information.

Implementation at Omogen: Instructions for Use (IFU) / "Playbook" provided to users, covering identification, intended purpose, technical specifications, deployment, operating conditions, human oversight requirements, known limitations, reasonably foreseeable misuse, and incident reporting.

Legal basis: AI Act, Article 13.

2.2.7 Human oversight by design

Requirement: design the system, including through appropriate human-machine interface tools, so that it can be effectively overseen by natural persons during the period it is in use, with a view to preventing or minimizing risks.

Implementation at Omogen: workflow blocking that prevents rejection notification until human review is recorded; override mechanism with mandatory reason entry; "Reviewed by [Name]" audit trail; monitoring of the override rate to detect deployer non-compliance.

Legal basis: AI Act, Article 14.

2.2.8 Accuracy, robustness, and cybersecurity

Requirement: achieve an appropriate level of accuracy, robustness, and cybersecurity, and perform consistently in these respects throughout the lifecycle.

Implementation at Omogen: documented performance benchmarks, regular penetration testing; AES-256 encryption at rest, TLS 1.3 in transit; multi-provider LLM failover for resilience.

Legal basis: AI Act, Article 15.

2.2.9 Quality management system

Requirement: implement a quality management system proportionate to the size of the organization, ensuring compliance, covering strategy, design control, examination and testing procedures, and post-market monitoring.

Implementation at Omogen: QMS documenting organizational structure, document control, change management, internal audit procedures, management review, and continuous improvement.

Legal basis: AI Act, Article 17.

2.2.10 Conformity assessment, CE marking, EU database registration

Requirement: carry out the applicable conformity assessment procedure (internal control, in accordance with Annex VI, for this category), affix the CE marking, and register the system in the EU database before placing it on the market.

Legal basis: AI Act, Article 16(e)–(h), Article 43(1)(a)/Annex VI, Articles 48 and 49.

2.2.11 Post-market monitoring and serious incident reporting

Requirement: implement a post-market monitoring system proportionate to the AI system, and report serious incidents to the market surveillance authority — generally within 15 days, or 2 days in the case of a widespread infringement or a serious incident as defined in Article 3(49)(b).

Implementation at Omogen: monthly bias testing, quarterly accuracy validation, continuous availability/error monitoring, and a documented incident classification and notification procedure with defined timelines.

Legal basis: AI Act, Articles 72 and 73.

2.2.12 Corrective action and duty to inform

Requirement: where Omogen has reason to consider that the system is no longer compliant, it must immediately take corrective action to bring it into compliance, withdraw it, or recall it as appropriate, and inform Customers and competent national authorities.

Legal basis: AI Act, Article 20.

2.2.13 Cooperation with competent authorities

Requirement: on the reasoned request of a competent authority, provide all information and documentation necessary to demonstrate compliance, in an easily understandable language, and, on request, give access to automatically generated logs, insofar as they are under Omogen's control.

Implementation at Omogen: single point of contact (DPO/Compliance — gillian@omogen.ai) designated for regulator requests; documented internal procedure to gather and provide requested documents within the requested timeframe.

Legal basis: AI Act, Article 21.

ObligationRequirementGDPR Article
Processing only on instructionsProcess candidates' personal data only on the Customer's documented instructions, including regarding transfers of data outside the EEAArt. 28(3)(a)
ConfidentialityEnsure that all Omogen personnel authorized to access or process candidate data are bound by strict contractual or statutory confidentiality obligationsArt. 28(3)(b)
Security measuresImplement robust technical and organizational measures to protect candidate data, including AES-256 encryption at rest, TLS 1.3 in transit, and strict role-based access controlArt. 32
Sub-processingObtain the Customer's prior written authorization (general or specific) before engaging sub-processors, and contractually flow down equivalent data protection obligationsArt. 28(2) and (4)
Assistance with data subject rightsProvide the technical and operational anchor points necessary to help the Customer respond to candidates' access, erasure, rectification, and explanation requestsArt. 28(3)(e)
Breach notificationNotify the Customer without undue delay (contractual target: within 24 hours) after becoming aware of any personal data breach concerning candidatesArt. 33(2)
DPIA and consultation assistanceProvide the system architecture, data-flow information, and security documentation necessary for the Customer to carry out its mandatory GDPR DPIAArt. 28(3)(f)
International transfersEnsure appropriate transfer mechanisms (such as standard contractual clauses) and carry out transfer impact assessments (TIA) for any sub-processor outside the EEAArt. 44–49
Fate of data at contract endAt the Customer's choice, return or securely delete all candidates' personal data at the end of the service, certifying deletion in accordance with NIST SP 800-88Art. 28(3)(g)
Facilitating AI transparencyProvide user-interface elements (e.g., built-in notifications or warnings) ensuring candidates are clearly informed they are interacting with an AI system, satisfying joint compliance needsGDPR art. 13 & AI Act art. 50(1)

2.4 The review-rate monitoring mechanism

INFO

This is a control specific to Omogen's compliance model, going beyond the literal text of the AI Act, designed to give Omogen visibility into whether Customers are actually exercising the human oversight required by Article 26(2).

Since Article 26 places the obligation to exercise human oversight on the Deployer, Omogen — as Provider — has no direct control over whether a Customer's reviewers actually engage with the review workflow, or simply click "accept" on every AI recommendation ("rubber-stamping"). To manage this residual risk, Omogen monitors, per Customer, the percentage of interview reports reviewed by a human reviewer and the AI recommendations that are overturned (the "override rate").

Override rateInterpretationOmogen's action
5%–30%Healthy range — indicates real, substantial human reviewRoutine monitoring
Below 5%, sustained over 2 monthsPossible risk of rubber-stamping / automated decision-makingAutomated alert to the Customer; documented follow-up
Above 30%, sustained over 2 monthsPossible system miscalibration for this Customer's use caseAutomated alert; root-cause investigation with the Customer
No improvement after alert + remediation periodOngoing risk of non-compliance with art. 26(2) for both partiesExercise of suspension rights under DPA art. 4.6 (14-day remediation period)

Part 3 — In practice: product features & best practices

This part translates the legal obligations set out in Parts 1 and 2 into concrete features built into Mio and CV Screener, as well as into daily practices expected of recruiters using the platform. It is written to be directly usable by recruiters, while giving compliance officers a way to verify that the product's behavior matches the legal obligations.

3.1 Obligation → feature mapping

The table below shows, for each major legal obligation, the specific product feature that implements it. This is the primary reference for compliance officers auditing the platform against Parts 1 and 2.

Legal obligationSourceProduct feature
Prohibited practice: no emotion/behavior inferenceAI Act, art. 5(1)(f) — a prohibited practice, not just high-riskMio only assesses the factual content of answers; no analysis of tone, emotion, micro-expressions, or behavioral signals. Disclosed on the report: "No emotion recognition"
Human oversight (100% review of rejections)AI Act, art. 14, 26(2)Workflow blocking: "Not recommended" results are locked until reviewed; cannot be sent to the candidate without review. The interview report is flagged "to review" in Omogen and there is no automatic move in the ATS to a rejection stage
Human oversight (sampling of accepted results)Internal best practice / art. 26(2)Random 10% sampling queue automatically generated every month
Audit trail of human decisionsAI Act, art. 12, 26(6)"Reviewed by [Name]" indicator + timestamped decision log (compliance tab: reviewer, date/time of review), retained for 3 years
Override rate monitoringArt. 26(2) (Omogen control — see §2.4)Override rate dashboard; automated alerts at <5% / >30%
Consent to voice recordingCriminal Code, art. 226-1, GDPR art. 7Mandatory voice consent script at the start of every Mio call; retained for 10 years; status shown in the compliance tab ("Consent obtained")
Transparency to candidates (AI use disclosed)AI Act, art. 26(7), GDPR art. 13In-call disclosure + email/portal notice before the interview; the report banner confirms no automated decision was made
No hidden or undisclosed evaluation criteriaAI Act, art. 26(4), art. 13The compliance tab discloses the exact number of criteria and confirms all were configured and validated by the recruiter ("No hidden or implicit criteria")
Protection of special category dataGDPR art. 9Automatic NLP detection → DPO alert (24h) → deletion (48h) → audit log
Data minimization and pseudonymizationGDPR art. 5(1)(c), art. 32Candidate identifiers are replaced with pseudonyms before any LLM API call
Storage limitationGDPR art. 5(1)(e)Automated deletion: 30 days (voice), 6 months (transcripts/data), 3 years (review logs); retention basis shown in the compliance tab
Candidate's right to human-only reviewGDPR art. 22Voice opt-out flagging system available to candidates during the interview, automatically triggering an email to the recruiter requesting human review
Candidate's right to an explanationGDPR art. 22, AI Act art. 86Per-criterion "Scores & Verbatims" explainability: exact transcript excerpt justifying each score, with "Listen in transcript" playback; explanation-request workflow generating a human-readable summary within 10 days
Flagging low transcription confidenceAI Act, art. 14 (effective oversight)Reports below 80% STT confidence are automatically flagged for priority human review
Technical performance monitoring (accuracy and robustness)AI Act, art. 15Per-call technical sheet (audio quality — agent/candidate, average latency) feeding the confidence signal and monthly system-level accuracy validation
Transparency on sub-processorsGDPR art. 28(2)Live list of sub-processors on the Trust Center; 30-day change notification

3.2 Best practices for recruiters

Recruiter tip

This section is written for you as a recruiter. It explains, in simple terms, what you're required to do when using Mio and CV Screener, and why it matters both for candidates and for protecting Omogen and your organization legally.

3.2.1 Before launching a campaign

  • Define job criteria clearly and specifically. Vague criteria ("good communicator") produce vague, less reliable AI assessments. Specific criteria ("minimum 3 years of B2B sales experience") produce better results and are easier to justify if challenged.
  • Never define a criterion that could function as an indirect proxy for a protected characteristic — for example, strict geographic restrictions (particularly under French recruitment law, subject to legal exceptions), graduation-year thresholds used as an age proxy, or name-based filtering.
  • Make sure candidates are informed, before the Mio call or CV submission, that AI will be used as part of the process.
  • Review the AI-generated interview script and refine it if needed. Never launch a campaign on real candidates before testing a call yourself.

Mandatory step

You must review 100% of candidates flagged "Not recommended" before any rejection communication. This is not optional and is enforced by the platform — the rejection action is blocked until your review is recorded.

  1. Open the candidate's full report: read the entire transcript, not just the summary score.
  2. Check the low-confidence signal. If transcription confidence was below 80%, treat the AI's recommendation with increased caution; poor audio quality or the candidate's accent may have caused transcription errors, not a genuine mismatch with the role.
  3. Ask yourself: does this candidate genuinely fail to meet the criteria, based on what they said, rather than how they said it?
  4. Make your decision: accept the AI's recommendation, or override it. If overriding, select a reason and add a brief note.

What to do: each month, review the random 10% sample of "Recommended" candidates shown in your queue.

Why it matters: this catches the reverse error (candidates overrated by the AI) and demonstrates to regulators and to Omogen that oversight is real, not limited to rejections.

3.2.4 Handling candidate requests

The candidate requests…What to doTimeline
A human-only interview instead of MioHonor the request without penalizing the applicationImmediate
An explanation of the non-recommendation based on the AI's evaluationForward to Omogen support; Omogen will help generate a compliant explanation10 business days
Access to their dataForward to the data subject rights process via Omogen30 days
Deletion of their dataForward the request; do not attempt to handle the deletion manually outside the process30 days

3.2.5 What to do if something seems off

When in doubt, report it

If you notice a concerning pattern, or unexpected system behavior — report it immediately and suspend use of the affected feature. Do not try to work around the issue or informally adjust criteria to compensate.

SituationContactResponse time
Technical error or bugsupport@omogen.ai< 24 hours
Suspected bias or discrimination patterngillian@omogen.ai (DPO)< 48h acknowledgment, investigation < 10 days
Suspected data breach / security incidentgillian@omogen.ai< 24 hours
Any candidate complaintsupport@omogen.ai< 5 business days acknowledgment

3.2.6 Training and certification

Requirement: no user may access Mio or CV Screener candidate results before completing Omogen's Customer Training Pack / Playbook.

This checklist supports periodic internal audit of the deployment against Parts 1 and 2 of this page.

3.3.1 Before deployment

  • DPIA carried out or contributed to for this deployment (GDPR art. 35 — applies to most Customers, see §1.3)
  • Confirmation of whether the Article 27 FRIA applies to your organization (public-law body / public service provider only, or a use case falling under Annex III §5(b)/(c) — see §1.2.7); if applicable, carried out and validated
  • DPA signed with Omogen, including the Article 4 human oversight obligations
  • Candidate privacy notice updated to reference AI use
  • All prospective reviewers have completed Customer Training and obtained certification
  • Job criteria reviewed for indirect (proxy) discrimination risk

3.3.2 Ongoing (monthly)

  • Confirm that 100% of "Not recommended" results were reviewed within the appropriate timeframe
  • Confirm that the 10% sampling queue was processed
  • Review your own override rate — is it within the healthy 5–30% range? If not, investigate the cause
  • Review any escalation or candidate complaint raised during the period
  • Confirm no unresolved special-category data flag remains open beyond 48 hours

3.3.3 Ongoing (quarterly / annual)

  • Internal audit of a sample of human review records for quality and consistency
  • Confirm compliance with retention schedules (spot-check automated deletion logs)
  • Review any post-market monitoring or bias testing report shared by Omogen during the period
  • Update the DPIA, and the FRIA where applicable, if the deployment's scope, volume, or candidate population has changed significantly
  • Confirm the sub-processor list (Trust Center) has not changed without appropriate notification

Last updated: 2026-07-15

Documentation Omogen