Dayforce
Dayforce is an enterprise human capital management platform whose Dayforce Recruiting module uses AI to assign letter grades to external job applicants, generate job descriptions, and automate screening and hiring workflows alongside HR, payroll, time, talent, and analytics.
HireAIScore rates Dayforce 57 out of 100 (grade F, Substantial gaps) under rubric v1.0, last reviewed August 2, 2026. Dayforce ranks 5 of 47 vendors rated in ATS-integrated AI, against a category average of 49. That score is drawn from 34 evidence items across 7 rubric criteria for Dayforce — 28 with a cited source, 6 recording that nothing was located.
§ 01 - Company facts
- Legal name
- Dayforce, Inc. (formerly Ceridian HCM Holding Inc.)
- Founded
- 1992
- Headquarters
- United States · US
- Pricing tier
- Enterprise
- Market side
- Employer-side (AEDT)
- Categories
- ATS-integratedScreening
- Website
- dayforce.com
These are company details, not findings. They are editable by a verified representative and carry no weight in the score, which is built only from the cited evidence below.
§ 02 - Score breakdown
§ Score breakdown
Category scoring
Weighted contribution shown to the right of each bar.
- 01
Article 11 Technical Documentation
Weight 20%74
+14.8 · category avg 53
- 02
Bias Audit Transparency
Weight 18%42
+7.6 · category avg 45
- 03
FRIA Support
Weight 15%40
+6.0 · category avg 33
- 04
Data Governance Disclosure
Weight 15%63
+9.4 · category avg 56
- 05
Human Oversight Design
Weight 12%68
+8.2 · category avg 57
- 06
Post-Market Monitoring
Weight 12%47
+5.6 · category avg 42
- 07
Customer Documentation
Weight 8%70
+5.6 · category avg 59
Category avg is the mean raw score on that criterion across the 47 ATS-integrated AI vendors in scope of this rubric, this one included.
§ 03 - Strongest · weakest
Strongest category
Article 11 Technical Documentation
Raw score 74 · contributes 14.8 to total.
74 against a 53 category average
Weakest category
FRIA Support
Raw score 40 · contributes 6.0 to total.
40 against a 33 category average
§ 04 - Cited evidence
Download diligence record→§ Evidence
Cited per category
Every score is backed by at least one cited piece of evidence.
Evidence ledger
- Items
- 34
- Documentation
- 20
- Audit report
- 1
- Public statement
- 7
- Absence
- 6
- With a source URL
- 28 of 34
- Source hostnames
- 2
- Fewest items
- 4
- FRIA Support
These figures measure how thoroughly Dayforce was reviewed, not how Dayforce performed — an absence row, recording that nothing was located, is counted like any other item.
Article 11 Technical Documentation
5 items74
- DocumentationCaptured Aug 2, 2026
A two-page versioned corporate policy (effective 27 July 2023, last reviewed 12 August 2024, owner Legal & Corporate Governance) setting out seven AI Ethics Principles including Transparency, Reliability, Inclusion, and Accountability, and defining what Dayforce counts as an AI system.
- Public statementCaptured Aug 2, 2026
Press release dated 10 February 2026 announcing that Dayforce achieved ISO 42001 certification and NIST AI RMF attestation, though it names no certification body and links to no certificate.
- DocumentationCaptured Aug 2, 2026
Public product documentation that functions as an explainability statement for the candidate grading model, disclosing the evaluation factors, the 20-positive/20-negative training-event threshold, the report-card weighting logic, and named bias-mitigation steps.
https://help.dayforce.com/r/documents/Recruiting-Guide/How-Candidate-Grades-Are-Determined
- DocumentationCaptured Aug 2, 2026
A nine-checkpoint AI Governance Cycle published 13 July 2026 describing risk tiering, AI Impact Assessments, internal 'explainability factsheets', a centralized AI inventory mapped to regulations, and named governance ownership under the Chief AI Officer.
- AbsenceCaptured Aug 2, 2026
No system card, model card, ISO 42001 certificate, or downloadable Article 11 technical documentation pack was found on dayforce.com (full sitemap scan of 1,282 URLs), in the ESG reporting hub document list, or in the public help.dayforce.com portal.
Bias Audit Transparency
5 items42
- Public statementCaptured Aug 2, 2026
Checkpoint 9 of the AI Governance Cycle states that for higher-risk AI models Dayforce commissions independent bias and fairness audits to assess adverse or disparate impact, but names no auditor, date, or published result.
- Public statementCaptured Aug 2, 2026
The AI Compliance page FAQ says Dayforce uses a repeatable, audited approach with pre- and post-release testing 'along with third-party audits for select features', without identifying which features or publishing any report.
https://www.dayforce.com/how-we-help/dayforce/leverage-ai-for-efficiency/ai-compliance
- DocumentationCaptured Aug 2, 2026
Documentation confirms that when Dayforce determines a candidate lives in New York City, from city or ZIP code, it shows a 'Restricted' icon instead of a letter grade to comply with New York City legal requirements - i.e. the AEDT is disabled in NYC rather than bias-audited.
https://help.dayforce.com/r/documents/Recruiting-Guide/View-Candidate-Grades
- DocumentationCaptured Aug 2, 2026
Documented bias controls state that candidate names are removed from applications before screening and that historical training data covers all candidates rather than only those hired, and that the scoring factors cannot be modified by customers.
https://help.dayforce.com/r/documents/Recruiting-Guide/How-Candidate-Grades-Are-Determined
- AbsenceCaptured Aug 2, 2026
No NYC Local Law 144 bias audit summary, and no report from BABL AI, DCI, ORCAA, Warden AI, Holistic AI, Credo AI, ConductorAI or any academic auditor, was found on dayforce.com (full sitemap scan), in the ESG reporting hub, in the newsroom, or in the public help portal.
FRIA Support
4 items40
- DocumentationCaptured Aug 2, 2026
A public acceptable use policy imposing deployer obligations: AI outputs may not be the only basis for decisions with legal or similarly significant effects including hiring and promotion, and a qualified human decision-maker must review output and decide using independent judgment.
- DocumentationCaptured Aug 2, 2026
The grading configuration procedure carries an Important notice telling administrators that enabling candidate grading involves the use of AI and to ensure job descriptions include this disclosure if required in their jurisdiction.
https://help.dayforce.com/r/documents/Recruiting-Guide/Configure-Candidate-Grading
- Public statementCaptured Aug 2, 2026
The AI Compliance page claims alignment with GDPR, ISO 42001, NIST AI RMF and the EU AI Act and says AI use can be tailored by region, but provides no Article 27 material or deployer-facing instrument.
https://www.dayforce.com/how-we-help/dayforce/leverage-ai-for-efficiency/ai-compliance
- AbsenceCaptured Aug 2, 2026
No Fundamental Rights Impact Assessment template, Article 26/27 deployer guidance, or EU AI Act readiness pack was found on dayforce.com or via keyword searches of the public help portal for 'fundamental rights impact assessment' and 'EU AI Act'; the AI Impact Assessment described in Dayforce's governance blog is an internal provider-side artefact.
Data Governance Disclosure
5 items63
- DocumentationCaptured Aug 2, 2026
Discloses the specific training inputs for candidate grading - application resumes, job requisition, posting and description details, candidate status progress indicators and decline reason types - plus exclusions: names stripped, internal candidates never graded, NYC residents excluded from display.
https://help.dayforce.com/r/documents/Recruiting-Guide/How-Candidate-Grades-Are-Determined
- Audit reportCaptured Aug 2, 2026
The 2025 Sustainability Report lists certifications and attestations including ISO/IEC 27001, 27017, 27018, 27701, 27036 and 22301, SOC 1 Type 2, SOC 2 Type 2 and NIST 800-171, and states the ISO 27001 certificate had no nonconformities and the SOC 2 Type 2 report no exceptions.
- Public statementCaptured Aug 2, 2026
States that Dayforce does not train the underlying LLM or use customer data to train models, and describes access controls, isolation and auditability as the data safeguards for Dayforce AI.
https://www.dayforce.com/how-we-help/dayforce/leverage-ai-for-efficiency/ai-compliance
- DocumentationCaptured Aug 2, 2026
The Information Security Statement confirms ISO and SOC 2 Type II certifications but states that certifications, redacted penetration test reports and attestations are available only on request through the customer Due Diligence Portal.
- AbsenceCaptured Aug 2, 2026
No public data processing addendum, subprocessor list, or downloadable certificate was located on dayforce.com (full sitemap scan) or in the public help portal; the published Global Privacy Statement covers Dayforce's own marketing and website data rather than customer HCM processing.
Human Oversight Design
4 items68
- DocumentationCaptured Aug 2, 2026
Clicking a candidate's grade opens a Grade subtab showing a report card detailing how the candidate was graded, and the report card provides the option to assign a new grade if the recruiter disagrees with the one assigned.
https://help.dayforce.com/r/documents/Recruiting-Guide/View-Candidate-Grades
- DocumentationCaptured Aug 2, 2026
States that AI-powered features are designed to support, not replace, human judgment, and prohibits using output as the only basis for decisions with legal or similarly significant effects including hiring, promotion, pay, discipline and termination.
- DocumentationCaptured Aug 2, 2026
Grading is an opt-in client property that must be explicitly enabled, and access to candidate grades and report cards is granted per role through the Recruiting > Job Requisitions > Candidate Grade feature permission.
https://help.dayforce.com/r/documents/Recruiting-Guide/Configure-Candidate-Grading
- Public statementCaptured Aug 2, 2026
Describes keeping a human in the loop after deployment and designing systems so a human remains in control of consequential decisions, with features routed back through the governance cycle if anything material changes.
Post-Market Monitoring
5 items47
- DocumentationCaptured Aug 2, 2026
A public vulnerability disclosure page, last updated 12 May 2025, setting out scope, researcher guidelines and a reporting form for security issues in the Dayforce HCM platform.
- DocumentationCaptured Aug 2, 2026
Publishes a direct security contact, cybersecurity@dayforce.com, for questions about the Dayforce information security program.
- DocumentationCaptured Aug 2, 2026
Reports a HackerOne bug bounty program, a SafeBreach control attestation program using real-world attack simulation, quarterly cybersecurity reporting to the board Audit Committee, and post-release AI reviews by an internal cross-functional working group.
- Public statementCaptured Aug 2, 2026
Describes ongoing post-deployment monitoring for model drift with region-specific compliance controls and re-entry into the governance cycle when behaviour changes materially, but no external monitoring output is published.
- AbsenceCaptured Aug 2, 2026
No public status or incident page exists (status.dayforce.com does not resolve in DNS), and no AI-specific incident channel, model-update changelog or continuous fairness-monitoring dashboard was found on dayforce.com or the public help portal; product release notes exist per version in the help portal but are general feature notes rather than AI model-change records.
Customer Documentation
6 items70
- DocumentationCaptured Aug 2, 2026
A full public recruiting product page describing AI-assisted candidate scoring, AI-generated job descriptions, and screening that 'helps you reduce unconscious bias at the top of the recruitment funnel by ignoring applicants' names, ages, and genders'.
- DocumentationCaptured Aug 2, 2026
A dedicated AI Compliance page with a responsible-AI FAQ covering data protection, customer control over AI by region and role, bias and fairness handling, and claimed framework alignment.
https://www.dayforce.com/how-we-help/dayforce/leverage-ai-for-efficiency/ai-compliance
- DocumentationCaptured Aug 2, 2026
A public buyer-guide chapter on AI governance in HCM listing the governance questions customers should ask vendors, including whether they align to NIST AI RMF or ISO/IEC 42001 and how they monitor for bias and model drift.
https://www.dayforce.com/resources/hcm-comprehensive-guide/ai-governance-in-hcm
- DocumentationCaptured Aug 2, 2026
A reporting hub linking publicly downloadable policy documents including the AI Ethics Principles, Code of Conduct, Human Rights Statement, Information Security Statement, Global Privacy Statement, and annual sustainability reports back to 2021.
https://www.dayforce.com/who-we-are/sustainability/reporting-hub
- DocumentationCaptured Aug 2, 2026
The help.dayforce.com portal is publicly accessible without login and contains full administrator and implementation guides, versioned release notes, and legal documents such as the AI-Powered Features and Insights Acceptable Use Policy.
https://help.dayforce.com/r/documents/Recruiting-Guide/Configure-Candidate-Grading
- AbsenceCaptured Aug 2, 2026
No public DPA, subprocessor list, NYC Local Law 144 guidance page, or EU AI Act deployer guidance was found; the Information Security Statement routes certification and diligence requests to a gated customer Due Diligence Portal.
§ 05 - Editorial notes
Company overview
Dayforce, Inc. is a global HCM vendor headquartered in Minneapolis, Minnesota with a co-headquarters in Toronto, Ontario. The company was founded as Ceridian in 1992, acquired the Dayforce cloud HCM product in 2012, and rebranded company-wide to Dayforce in 2024; it was taken private by Thoma Bravo affiliates on 4 February 2026 and delisted from the NYSE and TSX. Its recruiting-relevant AI includes candidate grading (an AI model that assigns letter grades and a weighted 'report card' to external applicants), AI-assisted screening and application summarization, AI-generated job descriptions, and AI agents across the wider suite. In February 2026 Dayforce announced ISO/IEC 42001 certification and NIST AI RMF attestation, and it operates an external AI Ethics Council launched in September 2025 whose members include Miranda Bogen (CDT AI Governance Lab), Merve Hickok (AIethicist.org), and Dr. Nicol Turner Lee.
Regulatory exposure
Dayforce candidate grading is squarely a high-risk employment AI system under EU AI Act Annex III and an automated employment decision tool under NYC Local Law 144 in substance, so Dayforce is a provider and its customers are deployers. Notably, Dayforce does not publish an LL 144 bias audit; instead its product suppresses grades entirely for candidates identified as residing in New York City (a 'Restricted' icon replaces the letter grade), which is compliance by avoidance rather than by audit. Illinois AIVI and HB 3773 and the Colorado AI Act create disclosure and impact-assessment duties that Dayforce addresses only through a one-line instruction telling administrators to add an AI disclosure to job descriptions 'if required in your jurisdiction'. The company claims alignment with GDPR, ISO 42001, NIST AI RMF, and the EU AI Act and says it commissions independent bias and fairness audits for higher-risk models, but no audit report, certificate, or auditor name is published, and no Article 27 FRIA template or deployer pack exists. Security and privacy certifications (ISO 27001/27017/27018/27701, SOC 1 and SOC 2 Type 2, NIST 800-171) are real but released only through a gated customer Due Diligence Portal.
Path to a higher score
The single highest-value move is to publish the artifacts Dayforce already says it holds: the ISO/IEC 42001 certificate and scope statement, the NIST AI RMF attestation letter, and at least a redacted summary of the independent bias and fairness audits of candidate grading, naming the auditor, date, sample size, and impact-ratio results by race and sex. Second, replace the NYC grade-suppression workaround with a published Local Law 144 bias audit so the feature can be used in New York City with transparency rather than switched off. Third, publish the internal 'explainability factsheets' referenced in the AI Governance Cycle post as public model cards for candidate grading and skills inference, and add an EU AI Act deployer pack containing an Article 27 FRIA template, an Article 13 instructions-for-use document, and per-jurisdiction disclosure templates. Finally, ungate the DPA and certification package, and stand up a public status/incident and AI model-change channel so post-market monitoring is externally observable rather than described only in prose.
§ Regulatory frame
What applies to ats-integrated ai.
Ranking features are inside EU AI Act Annex III §4 (high-risk) and inside NYC Local Law 144 when they affect NYC-based candidates. Customers should treat the AI surface as a distinct deployer-FRIA scope from the rest of the ATS.
§ Compare
Build any comparison→Dayforce against its nearest-scoring peers.
In ATS-integrated AI.
§ Others rated in ATS-integrated AI
All ats-integrated vendors→Ranked 5 of 47 by weighted total under rubric v1.0. The ordering is arithmetic on the rubric and carries no view on which tool suits a given hiring process.
- 02Eightfold AI64D
- 03SmartRecruiters62D
- 04Alva Labs61D
- 05DayforceThis profile57F
- 06Pinpoint57F
- 07Juicebox (PeopleGPT)57F
Conflicts of interest
No vendor pays for placement, scoring, or removal. Casework - the consulting firm that operates this directory - provides paid services to some vendors. Any active or recent (within 24 months) commercial relationship is disclosed on the affected vendor profile and the review is reassigned to an independent reviewer. See the full policy on About.
Casework has no commercial relationship with this vendor.