Treadstone Associates
Article · Screening & bias

AI resume screening and the bias risk

It can be, and in Canada that is a legal exposure rather than a reputational one. A screening rule does not have to be intended to discriminate to be unlawful — it only has to have that effect on a protected ground.

Treadstone Associates · Updated 2026

Key takeaways

  • • Bias enters through proxies, not prejudice: neutral-looking fields that track a protected ground.
  • • “Canadian experience” is the clearest Canadian example — and it is now banned outright in Ontario postings.
  • • Accountability sits with whoever deploys the tool, not with the vendor who built it.
  • • The defence is written criteria, a real human review, and records — not a vendor assurance.

The honest answer

Yes, a resume screening system can be biased, and the mechanism is not that somebody built a prejudiced model. It is that a system trained or configured to reproduce past hiring will reproduce whatever produced past hiring, and a system configured against plausible-sounding criteria will enforce those criteria at a scale no individual reviewer could.

In Canadian law the intent is largely beside the point. What matters is whether a requirement, factor or rule has an adverse effect on people identified by a protected ground and cannot be justified as a genuine requirement of the job. That analysis does not change because the rule was applied by software.

The three routes in

The training signal. A model fitted to who was hired before learns who was hired before. If the historical pattern under-represents a group, that pattern is the target the model is optimising towards. This is why feeding past hiring outcomes into a ranking model is the single most dangerous configuration choice available.

The proxy. A field that looks neutral and is not. Postal code, continuity of employment, the name of a credentialing body, graduation year, employer names, gaps. Each of these can track age, place of origin, family status or disability, and each looks like a legitimate signal on a spreadsheet.

The criterion itself. Sometimes the rule is simply unlawful, and automating it only makes it faster and better documented.

The Canadian worked example everybody can check

“Canadian experience” is the cleanest illustration, because both a regulator and a statute have addressed it.

The Ontario Human Rights Commission’s position is that a strict requirement for “Canadian experience” is prima facie discrimination — discrimination on its face — which can only be used in very limited circumstances, with the onus on the employer or regulatory body to show that prior work experience in Canada is a bona fide requirement under the test the policy sets out.

Separately, from 1 January 2026 the Employment Standards Act prohibits an employer from including any Canadian experience requirement in a publicly advertised job posting or in any associated application form.

Now consider a ranking model that has never seen the phrase. Trained on a decade of a firm’s own hires, it learns that applicants whose employers are recognisable Canadian companies were hired more often. It scores them higher. Nobody wrote a rule, nobody typed the phrase, the posting is compliant — and the effect is the requirement the Commission calls prima facie discriminatory. That is proxy discrimination in one paragraph.

Where the grounds come from

The grounds are set out in provincial human rights legislation; the protected grounds at work in Ontario are the working list for an Ontario employer or agency. The right to equal treatment in employment covers applying for a job and recruitment, not only what happens after someone is hired, and the Commission’s guidance asks employers to look for barriers in recruitment and selection practices and to notice where decisions are made on subjective rather than objective considerations. An automated score feels objective. Whether it is depends entirely on what it was fitted to.

Where a complaint goes, and what it costs, is a separate question — the tribunal route and the court route differ in remedy, timing and procedure.

Who is actually on the hook

The employer, and the agency, and not the vendor. The ethical AI principles ACSESS endorses state it plainly: those deploying AI systems remain at all times responsible and accountable for their use, systems must remain under human direction and control, and fairness and inclusivity have to be designed in with risk assessments and mitigation across the system lifecycle. The Code of Ethics adds the operational corollary for agencies: members will not accept an order from any client that is discriminatory in any way, and will treat all candidates without prejudice, providing equal opportunity based on bona fide job qualifications.

The privacy commissioner reaches the same place from a different direction, listing profiling that may lead to unfair, unethical or discriminatory treatment among the “no-go zones” for generative AI systems, and expecting deployers to be able to demonstrate compliance rather than assert it (OPC principles).

What actually reduces the risk

Write the criteria first, from the job. Before the posting opens, list the requirements and tie each to a duty. If you cannot state why a requirement is necessary to do the work, it is not a requirement.

Keep the criteria out of the model. Knockouts belong in an explainable filter. A ranking model should order candidates against stated criteria, not infer its own.

Never train on past hiring outcomes. The pattern you are trying not to reproduce is exactly the pattern in that data.

Make the human review real. Read a sample from below the shortlist every time. If strong candidates keep appearing there, the system is not working, regardless of what the top of the list looks like.

Keep the records. Ontario now requires a copy of every publicly advertised job posting and any associated application form to be retained for three years after public access is removed, including each revised version (ESA guidance). Keep your criteria and shortlist reasoning with them. Records are what turn a defensible process into a demonstrable one.

Disclose. The Ontario posting disclosure is not optional for employers with 25 or more employees, and a candidate who learns about it later is a candidate with a grievance.

A worked example

A national agency reviews its own screening after a client asks how the shortlist was produced. Nothing about the tool is unusual: it parses applications, scores them against the requirement, and orders them.

The review finds two problems. First, the requirement text pasted from the client included “Canadian experience preferred”, which had survived four years of copy-and-paste. Second, the scoring rewarded uninterrupted employment history, which quietly penalised anyone with a parental leave or a period of illness.

Neither was designed. Both were fixable in an afternoon: the phrase removed and the template locked, the continuity factor deleted and replaced with a stated requirement for the specific supervisory experience the role needed. The agency then sampled 20 applications from below its recent shortlists and found three it should have called. That sample is now a standing step.

Questions we get asked

The vendor says the tool has been audited for bias. Are we covered?
No. Accountability sits with the organisation deploying the system — the principles are explicit that those deploying AI remain responsible and accountable for its use. An audit of a model in general says nothing about your criteria, your data or your review process, which is where most of the risk actually lives. Treat any performance claim a vendor cannot show you in their own documentation as marketing.

Can we test our own screening for bias?
You can test outcomes for adverse effect on the information you lawfully hold, and you can always test the process: are the criteria job-related, are they written down, is the human review sampling below the line, are the records kept. Collecting additional personal information purely to run a bias audit is itself a privacy question under PIPEDA and should not be done casually.

Is a human reviewer enough of a safeguard?
Only if the review is capable of catching the error. A reviewer who reads the top ten of a ranked list is confirming the ranking, not checking it. The safeguard is sampling from below the shortlist and recording reasons in words.

See where AI pays off first in your firm.

A 30-minute call is enough to tell you whether AI pays for itself here.