Personio
Personio is a European cloud HR platform for small and mid-sized companies that combines an HRIS with recruiting/ATS, time tracking, payroll and an AI assistant, and is adding agentic AI candidate sourcing and application screening through its 2026 acquisition of aurio.
HireAIScore rates Personio 40 out of 100 (grade F, Substantial gaps) under rubric v1.0, last reviewed August 2, 2026. Personio ranks 42 of 47 vendors rated in ATS-integrated AI, against a category average of 49. That score is drawn from 20 evidence items across 7 rubric criteria for Personio — 13 with a cited source, 8 recording that nothing was located.
§ 01 - Company facts
- Legal name
- Personio SE & Co. KG
- Founded
- 2015
- Headquarters
- Germany · DE
- Pricing tier
- Mid
- Market side
- Employer-side (AEDT)
- Categories
- ATS-integratedScreeningSourcing
- Website
- personio.com
These are company details, not findings. They are editable by a verified representative and carry no weight in the score, which is built only from the cited evidence below.
§ 02 - Score breakdown
§ Score breakdown
Category scoring
Weighted contribution shown to the right of each bar.
- 01
Article 11 Technical Documentation
Weight 20%40
+8.0 · category avg 53
- 02
Bias Audit Transparency
Weight 18%25
+4.5 · category avg 45
- 03
FRIA Support
Weight 15%30
+4.5 · category avg 33
- 04
Data Governance Disclosure
Weight 15%52
+7.8 · category avg 56
- 05
Human Oversight Design
Weight 12%48
+5.8 · category avg 57
- 06
Post-Market Monitoring
Weight 12%48
+5.8 · category avg 42
- 07
Customer Documentation
Weight 8%50
+4.0 · category avg 59
Category avg is the mean raw score on that criterion across the 47 ATS-integrated AI vendors in scope of this rubric, this one included.
§ 03 - Strongest · weakest
Strongest category
Data Governance Disclosure
Raw score 52 · contributes 7.8 to total.
52 against a 56 category average
Weakest category
Bias Audit Transparency
Raw score 25 · contributes 4.5 to total.
25 against a 45 category average
§ 04 - Cited evidence
Download diligence record→§ Evidence
Cited per category
Every score is backed by at least one cited piece of evidence.
Evidence ledger
- Items
- 20
- Documentation
- 11
- Public statement
- 1
- Absence
- 8
- With a source URL
- 13 of 20
- Source hostnames
- 5
- Fewest items
- 2
- Post-Market Monitoring
These figures measure how thoroughly Personio was reviewed, not how Personio performed — an absence row, recording that nothing was located, is counted like any other item.
Article 11 Technical Documentation
3 items40
- DocumentationCaptured Aug 2, 2026
Personio's SafeBase trust center carries a dedicated AI section with three items - AI Overview, AI Training Data and Bias, and AI Security - but their substantive contents are not publicly rendered and no technical documentation pack, system card or explainability statement is offered.
- DocumentationCaptured Aug 2, 2026
A publicly downloadable A-LIGN certificate (ISMS-PE-121523, ISO/IEC 27001:2013, original certification 15 December 2023, expiring 15 December 2026) covers the Personio SaaS HR platform for the PTech product-development organisation in Munich, Madrid and Dublin - an information-security management system, not an AI one.
- AbsenceCaptured Aug 2, 2026
No AI system or model card, Annex IV-style technical documentation, explainability statement or ISO 42001 certification was found on trust.personio.com (explicitly searched for 'ISO 42001', 'AI Act' and 'model card') or on the aurio product site Personio now owns.
Bias Audit Transparency
3 items25
- AbsenceCaptured Aug 2, 2026
No NYC LL 144 bias audit, independent algorithmic audit (BABL AI, DCI, ORCAA, Warden AI, Holistic AI, Credo AI, ConductorAI) or academic audit of Personio's recruiting AI was located; explicit trust-center searches for 'bias audit' and 'Local Law 144' returned no matches.
- DocumentationCaptured Aug 2, 2026
The trust center lists an 'AI Training Data and Bias' topic under its AI section, but it is an access-gated policy item rather than an audit report and no disaggregated selection rates or impact ratios are published.
- AbsenceCaptured Aug 2, 2026
The aurio sourcing and application-screening agents that Personio acquired in April 2026 publish no bias detection, fairness testing, mitigation measures or demographic outcome data on their product site.
FRIA Support
3 items30
- AbsenceCaptured Aug 2, 2026
No EU AI Act Article 27 Fundamental Rights Impact Assessment template, deployer checklist or Article 26 deployer-obligation guidance was found; explicit trust-center searches for 'FRIA', 'Fundamental Rights Impact Assessment' and 'AI Act' returned no matches, and no such material surfaced elsewhere.
- DocumentationCaptured Aug 2, 2026
Personio maintains a genuine trust package including a GDPR Data Protection Impact Assessment, Technical and Organisational Measures and a Data Processing Addendum, giving deployers partial GDPR-scoped assessment support, though all of it sits behind an access request.
- Public statementCaptured Aug 2, 2026
An independent 13 May 2026 EU AI Act analysis classifies Personio recruiting AI deployments as Annex III point 4(a) high-risk and advises SME deployers to request in writing what documentation exists and to document what is missing, indicating no ready-made FRIA support is available from the vendor.
https://www.aiactblog.nl/en/posts/ai-act-personio-classification
Data Governance Disclosure
3 items52
- DocumentationCaptured Aug 2, 2026
The trust center publishes ISO/IEC 27001:2022 and ISO/IEC 27017:2015 certifications plus an ISO 27001 Statement of Applicability, Technical and Organisational Measures, a DPIA, a Data Processing Addendum, a subprocessor list and a data flow diagram, though nearly all require an access request.
- DocumentationCaptured Aug 2, 2026
The publicly downloadable ISO 27001 certificate shows the certified scope is limited to the Personio SaaS HR platform within the PTech product-development department at Munich, Madrid and Dublin, so it does not extend to AI-specific data governance.
- AbsenceCaptured Aug 2, 2026
No public statement of what data trains Personio's AI models, no training-data exclusion list, and no ISO 42001 or SOC 2 were found; the 'AI Training Data and Bias' trust-center item that would address this is not publicly rendered.
Human Oversight Design
3 items48
- DocumentationCaptured Aug 2, 2026
The trust center lists Audit Logging under Product Security and Event & Audit Log Management under Continuous Monitoring, evidencing a documented audit-trail control, but describes no AI-specific override, score-explanation or per-jurisdiction toggle.
- DocumentationCaptured Aug 2, 2026
aurio, acquired by Personio in April 2026, describes its 'Alex' agent as processing and categorising applications and surfacing the most promising candidates for human review - a decision-support framing - while its 'Kim' agent sends candidate outreach on the recruiter's behalf, with no documented override controls or explainability.
- AbsenceCaptured Aug 2, 2026
No public documentation of in-product ranking explanations, reviewer override logging or jurisdiction-specific AI toggles for Personio Recruiting could be verified; personio.com returned HTTP 429 and support.personio.de HTTP 403 on every retrieval attempt.
Post-Market Monitoring
2 items48
- DocumentationCaptured Aug 2, 2026
A public Atlassian status page tracks per-component availability including Recruiting, Payroll and the API, carries a dated incident history and lets customers subscribe to update notifications.
- AbsenceCaptured Aug 2, 2026
Monitoring is security- and uptime-oriented only: no AI model-update changelog, model performance or drift dashboard, or AI-specific incident reporting channel was found on the trust center or the status page.
Customer Documentation
3 items50
- DocumentationCaptured Aug 2, 2026
A structured SafeBase trust center organises Compliance, Product/Data/App/Corporate Security, Policies, Legal (DPA, subprocessors, cyber insurance), Data Privacy, AI and ESG sections, though the substantive documents including the DPA and subprocessor list require an access request.
- DocumentationCaptured Aug 2, 2026
Customer-facing operational documentation includes a public status page with per-component incident history and subscription options, complementing the publicly listed vulnerability-disclosure route.
- AbsenceCaptured Aug 2, 2026
No EU AI Act deployer guidance, NYC LL 144 guidance, AI FAQ or published AI transparency notice was found; an independent May 2026 analysis observes that Personio publishes less detailed AI documentation than enterprise vendors, and every personio.com and support.personio.de page returned bot-protection errors during research.
§ 05 - Editorial notes
Company overview
Personio SE & Co. KG was founded in 2015 in Munich by Hanno Renner, Ignaz Forstmeier, Roman Schumacher and Arseniy Vershinin, and sells a cloud HR platform to small and mid-sized European employers covering personnel administration, recruiting, time tracking and payroll; by June 2024 it reported roughly 12,000 customers across 70 countries and about 2,000 employees. Its ISO 27001 certificate identifies the certified entity as Personio SE & Co. KG at Seidlstrasse 3, 80335 Munich, with additional in-scope product-development sites in Madrid and Dublin. In April 2026 Personio acquired the Munich AI recruiting startup aurio, whose two agents -'Kim' for active candidate sourcing and 'Alex' for application screening and prioritisation - bring agentic sourcing and pre-human ranking of applicants into a recruiting base of roughly 9,000 customers, with initial customer launches expected later in 2026.
Regulatory exposure
A Munich headquarters and an almost entirely European customer base place Personio's recruiting AI directly in EU AI Act scope: an independent May 2026 classification analysis treats Personio deployments with recruiting AI active as Annex III point 4(a) high-risk employment AI, with Personio as vendor and its SME customers as deployers. Personio's public compliance surface is a well-built but security-shaped SafeBase trust center: ISO/IEC 27001:2022 and ISO/IEC 27017:2015 certifications, a Statement of Applicability, TOMs, a GDPR DPIA, a DPA and a subprocessor list - nearly all gated behind an access request. Explicit searches of that trust center for 'ISO 42001', 'AI Act', 'FRIA', 'Fundamental Rights Impact Assessment', 'bias audit', 'Local Law 144', 'model card' and 'SOC 2' returned no matches. Three AI topic items exist (AI Overview, AI Training Data and Bias, AI Security) but their contents are not publicly rendered, and no bias audit, technical documentation pack or deployer guidance is published anywhere. US footprint is small, so NYC LL 144 exposure is limited, but no LL 144 audit exists either. Important research caveat: every personio.com and support.personio.de URL returned HTTP 429/403 bot-protection responses across repeated attempts, so vendor marketing and help-centre claims - including a widely quoted 'Responsible AI principles' statement - could not be verified and are deliberately not cited here.
Path to a higher score
The fastest credibility gain is to un-gate what already exists: publish the trust center's AI Overview and AI Training Data and Bias items as public pages stating plainly whether customer data trains models and what exclusions apply. Before the aurio-derived sourcing and screening agents reach general availability, Personio should ship an Annex IV-style technical documentation pack or system card for the ranking model, an explainability statement describing what drives a candidate's prioritisation, and documented human-override and reviewer-audit-log controls in the public help centre. Commissioning an independent bias audit with published disaggregated selection-rate results - from an established auditor such as BABL AI, Holistic AI or Warden AI - would move the weakest score materially. Adding an Article 27 FRIA template plus Article 26 deployer-obligation guidance would serve exactly the SME deployers who lack in-house counsel, and extending post-market monitoring beyond uptime and CVEs to an AI model-change changelog, plus pursuing ISO 42001 alongside the existing ISO 27001, would round out the picture.
§ Regulatory frame
What applies to ats-integrated ai.
Ranking features are inside EU AI Act Annex III §4 (high-risk) and inside NYC Local Law 144 when they affect NYC-based candidates. Customers should treat the AI surface as a distinct deployer-FRIA scope from the rest of the ATS.
§ Compare
Build any comparison→Personio against its nearest-scoring peers.
In ATS-integrated AI.
§ Others rated in ATS-integrated AI
All ats-integrated vendors→Ranked 42 of 47 by weighted total under rubric v1.0. The ordering is arithmetic on the rubric and carries no view on which tool suits a given hiring process.
- 39Harri41F
- 40Radancy41F
- 41Manatal41F
- 42PersonioThis profile40F
- 43Oleeo40F
- 44Loxo37F
Conflicts of interest
No vendor pays for placement, scoring, or removal. Casework - the consulting firm that operates this directory - provides paid services to some vendors. Any active or recent (within 24 months) commercial relationship is disclosed on the affected vendor profile and the review is reassigned to an independent reviewer. See the full policy on About.
Casework has no commercial relationship with this vendor.