Personio
Personio is a European cloud HR platform for small and mid-sized companies that combines an HRIS with recruiting/ATS, time tracking, payroll and an AI assistant, and is adding agentic AI candidate sourcing and application screening through its 2026 acquisition of aurio.
§ 01 — Score breakdown
§ Score breakdown
Category scoring
Weighted contribution shown to the right of each bar.
- 01
Article 11 Technical Documentation
Weight 20%40
+8.0
- 02
Bias Audit Transparency
Weight 18%25
+4.5
- 03
FRIA Support
Weight 15%30
+4.5
- 04
Data Governance Disclosure
Weight 15%52
+7.8
- 05
Human Oversight Design
Weight 12%48
+5.8
- 06
Post-Market Monitoring
Weight 12%48
+5.8
- 07
Customer Documentation
Weight 8%50
+4.0
§ 02 — Strongest · weakest
Strongest category
Data Governance Disclosure
Raw score 52 · contributes 7.8 to total.
Weakest category
Bias Audit Transparency
Raw score 25 · contributes 4.5 to total.
§ 03 — Cited evidence
Download diligence record→§ Evidence
Cited per category
Every score is backed by at least one cited piece of evidence.
§ 04 — Editorial notes
Company overview
Personio SE & Co. KG was founded in 2015 in Munich by Hanno Renner, Ignaz Forstmeier, Roman Schumacher and Arseniy Vershinin, and sells a cloud HR platform to small and mid-sized European employers covering personnel administration, recruiting, time tracking and payroll; by June 2024 it reported roughly 12,000 customers across 70 countries and about 2,000 employees. Its ISO 27001 certificate identifies the certified entity as Personio SE & Co. KG at Seidlstrasse 3, 80335 Munich, with additional in-scope product-development sites in Madrid and Dublin. In April 2026 Personio acquired the Munich AI recruiting startup aurio, whose two agents — 'Kim' for active candidate sourcing and 'Alex' for application screening and prioritisation — bring agentic sourcing and pre-human ranking of applicants into a recruiting base of roughly 9,000 customers, with initial customer launches expected later in 2026.
Regulatory exposure
A Munich headquarters and an almost entirely European customer base place Personio's recruiting AI directly in EU AI Act scope: an independent May 2026 classification analysis treats Personio deployments with recruiting AI active as Annex III point 4(a) high-risk employment AI, with Personio as vendor and its SME customers as deployers. Personio's public compliance surface is a well-built but security-shaped SafeBase trust center: ISO/IEC 27001:2022 and ISO/IEC 27017:2015 certifications, a Statement of Applicability, TOMs, a GDPR DPIA, a DPA and a subprocessor list — nearly all gated behind an access request. Explicit searches of that trust center for 'ISO 42001', 'AI Act', 'FRIA', 'Fundamental Rights Impact Assessment', 'bias audit', 'Local Law 144', 'model card' and 'SOC 2' returned no matches. Three AI topic items exist (AI Overview, AI Training Data and Bias, AI Security) but their contents are not publicly rendered, and no bias audit, technical documentation pack or deployer guidance is published anywhere. US footprint is small, so NYC LL 144 exposure is limited, but no LL 144 audit exists either. Important research caveat: every personio.com and support.personio.de URL returned HTTP 429/403 bot-protection responses across repeated attempts, so vendor marketing and help-centre claims — including a widely quoted 'Responsible AI principles' statement — could not be verified and are deliberately not cited here.
Path to a higher score
The fastest credibility gain is to un-gate what already exists: publish the trust center's AI Overview and AI Training Data and Bias items as public pages stating plainly whether customer data trains models and what exclusions apply. Before the aurio-derived sourcing and screening agents reach general availability, Personio should ship an Annex IV-style technical documentation pack or system card for the ranking model, an explainability statement describing what drives a candidate's prioritisation, and documented human-override and reviewer-audit-log controls in the public help centre. Commissioning an independent bias audit with published disaggregated selection-rate results — from an established auditor such as BABL AI, Holistic AI or Warden AI — would move the weakest score materially. Adding an Article 27 FRIA template plus Article 26 deployer-obligation guidance would serve exactly the SME deployers who lack in-house counsel, and extending post-market monitoring beyond uptime and CVEs to an AI model-change changelog, plus pursuing ISO 42001 alongside the existing ISO 27001, would round out the picture.
§ Compare
Build any comparison→Personio against its nearest-scoring peers.
In ATS-integrated AI.
Conflicts of interest
No vendor pays for placement, scoring, or removal. Casework — the consulting firm that operates this directory — provides paid services to some vendors. Any active or recent (within 24 months) commercial relationship is disclosed on the affected vendor profile and the review is reassigned to an independent reviewer. See the full policy on About.
Casework has no commercial relationship with this vendor.