What screening does, and what it must not do

For a role with 150 applications, a first read of each takes an HR team two to three working days. A screening routine cuts that to a few hours by checking every application against the same short list of criteria and returning, for each one, which criteria were met, which were not, and where the evidence sits in the document. That last part is the point. A routine that returns a score without reasons saves time and destroys accountability at the same time.

What screening must not do in a German company is decide. It does not reject, it does not rank by a hidden weighting, and it does not learn from previous hiring decisions, because those decisions carry the bias of the people who made them. The system prepares a shortlist with reasons. A recruiter reads it, reads the borderline cases, and makes the call. The distinction sounds academic until the first candidate asks why they were rejected, and the answer has to come from a person who can explain it.

The criteria catalogue comes before the tool

The most common mistake I see is buying the tool first and writing the criteria afterwards, usually under time pressure, usually by copying the requirements list from the job ad. The result is a catalogue that nobody has checked for job relevance, and a works council that asks the obvious question in the first meeting: on what basis does this thing sort our applicants?

A usable catalogue has three layers and is written per role family, not per vacancy:

  1. Formal criteriaWork permit for Germany, willingness to work at the location, availability by the start date. Binary, verifiable, not open to interpretation.
  2. Job-related criteriaThe two to four qualifications and experiences the hiring manager will actually test in the interview. Each one with a written reason why the job requires it.
  3. Explicitly excludedAge, gender, origin, photo, gaps in the CV, name of the university, and any proxy for them. Written down so that the works council can see what the system is not allowed to look at.
  4. Evidence ruleFor every criterion, where in the application the system should look and what counts as met. A language level is met by a certificate or by professional experience in that language, not by a self-assessment.
  5. Owner and review dateWho maintains the catalogue for this role family and when it is reviewed. Criteria that were not used in the last three hiring rounds are removed.

Introducing screening in five steps

Weeks 1 to 3Criteria catalogue

Per role family, with the hiring managers, in the three layers above. This document is the basis for everything that follows.

Weeks 2 to 6Tool and data protection

Shortlist of vendors with an EU data processing agreement and a documented AI Act conformity statement. Impact assessment with the data protection officer.

Months 2 to 4Works council agreement

Use case, criteria, exclusions, human decision, audit rights, pilot, review. Negotiated, not presented.

6 to 8 weeksPilot with comparison

Two role families. The system's shortlist is compared with a recruiter's independent shortlist. Deviations are explained before going live.

QuarterlyAudit

Sample of shortlists against the applicant pool on protected characteristics. Results go to the works council and into the catalogue review.

Why the last step is always a person

It would be technically simple to let the system send rejections to everyone below a threshold. It is legally not allowed, and it is also bad recruiting. The applications the system marks as borderline are exactly the ones where a good recruiter finds the career changer, the returning parent, or the candidate whose CV format the parser misread. In my experience the shortlist from a well-configured system and the shortlist from an experienced recruiter overlap by roughly 80 percent. The remaining 20 percent is where hiring quality is decided, and no catalogue captures it.

Human oversight in the sense of the AI Act is therefore not a formality. It needs a named person with the competence and the authority to override the system, time budgeted for the borderline reads, and a record that shows a person made each decision. A recruiter who clicks approve on 150 system rejections in four minutes is not oversight, and a works council that sees the timestamps will say so.

Bias, proxies, and the quarterly audit

The known failure of screening systems is not that they look at gender or origin directly. Vendors exclude that. The failure is proxies: a gap in the CV that correlates with parental leave, a postcode, a university name, a sports club, a first name. A system trained on past hires learns those proxies from the people who were hired before, and it reproduces the pattern with perfect consistency.

Two defences work. First, the catalogue excludes proxies explicitly and the system is configured to see only the fields it needs. Second, the quarterly audit compares the shortlist with the applicant pool. If women made up 40 percent of applicants and 20 percent of the shortlist for three rounds in a row, something in the criteria is doing work it should not do, and the catalogue is revised. Under the General Equal Treatment Act (AGG), Germany's anti-discrimination law, the company is liable for the outcome regardless of whether the tool or a person produced it. The audit is how you find out before a claimant does.

Free · Excel

Screening criteria catalogue template

The three-layer catalogue as a workbook: formal, job-related, and excluded criteria per role family, with columns for the job-related reason, the evidence rule, owner, and review date. Plus a second sheet for the quarterly audit. The document the works council asks for in the first meeting.

You join the HR Briefing list on this topic. No sharing, unsubscribe anytime.

Frequently asked questions

May a tool reject applicants automatically?

No. Article 22 GDPR gives individuals the right not to be subject to a decision based solely on automated processing, and the EU AI Act requires human oversight for high-risk systems. Every rejection is made by a person who has seen the application, and the works council agreement should say so explicitly.

Is screening really high-risk under the EU AI Act?

Yes. Annex III lists AI systems used to recruit or select natural persons, including filtering or evaluating applications, as high-risk. The classification depends on the use, not on the technology. A general language model becomes high-risk the moment it is used to rank candidates.

Do we need a works council agreement even for a simple keyword filter?

In most cases yes. A filter that sorts applications by criteria is a technical device capable of monitoring under Section 87 (1) no. 6 of the Works Constitution Act. The threshold is low, and the works council's consent is required before the tool is switched on.

How do we stop the tool from discriminating?

By using transparent, job-related criteria instead of a black-box score, by excluding protected characteristics and their proxies from the input, and by sampling the results every quarter. If the shortlist looks different from the applicant pool on a protected characteristic, the criteria are reviewed.

Who counts as provider and who as deployer under the AI Act?

If you use a vendor's screening product as delivered, you are the deployer with the lighter set of duties: use as instructed, human oversight, informing candidates and the works council, keeping logs. If you build or substantially modify a system, you become a provider with far heavier obligations.

How long does the introduction take?

In my projects three to five months, most of it the works council agreement. The criteria catalogue takes two to three weeks, the data protection impact assessment runs in parallel, and the pilot with a human comparison group takes six to eight weeks.