Escalation Paths: When to Involve Legal, Compliance, DEI, or Leadership
Hassan is a senior recruiter at a 1,400-person regional health system, leading a team of nine on a high-volume nursing and allied-health pipeline that processes roughly 600 applications a month. His team adopted an AI resume-screening tool and an AI interview-scheduling assistant eighteen months ago, and for most of that time the tools just quietly saved everyone time. Then a string of small signals started landing on his desk in the same quarter: a screening pattern that looked off, an accommodation request he had never seen before, a vendor contract renewal with a blank where an audit should have been, and a question from a candidate in another country about where their data lived. None of these were Hassan's to decide alone. Every one of them belonged to someone with authority he did not hold. The skill that separated him from the recruiter he had been two years earlier was not knowing the answers. It was knowing, fast and without second-guessing, whose problem each of these actually was.
Escalation Is Routing, Not Alarm
The word "escalation" makes people picture a fire alarm, and that picture causes two opposite failures. Some recruiters never pull the alarm because nothing ever feels dramatic enough, so a discrimination signal sits in a spreadsheet for two quarters. Others pull it for everything, flooding Legal with routine questions until Legal stops reading their messages. Both failures come from treating escalation as an emotional event rather than a routing decision. You are not a lawyer, a compliance officer, a DEI specialist, or the CEO, and the point of escalating is not that you feel worried enough to involve one. It is that the decision in front of you belongs to a specific kind of authority you do not hold.
Hassan thinks of it as routing. A recruiter is the person closest to the data and furthest from the authority. He sees the signal first because he is in the pipeline every day. But the four functions he routes to each own a specific kind of decision he cannot make: Legal owns the question of legal exposure and what the law requires; Compliance owns whether a process or vendor meets a specific regulatory standard; DEI owns the analysis and remediation of bias patterns in hiring outcomes; Leadership owns policy, budget, and the authority to change how the organization hires. His job is to recognize which kind of decision each signal demands, package the evidence, and hand it to the right owner before the cost of waiting compounds.
The Four Owners and What Triggers Each
Before the worked signals, it helps to see the map whole. Most escalation failures are not failures of courage; they are failures of recognition, where a recruiter genuinely cannot tell whether the thing in front of them is a fairness question, a legal question, or a budget question, so they either sit on it or send it everywhere. The grid below is the one Hassan keeps, and the useful column is the middle one, because the trigger is what you actually notice in a workday.
| Function | Escalate when | Sounds like |
|---|---|---|
| Legal | AI is making decisions that could be discriminatory or expose the organization to liability; you are unsure whether a practice complies with employment law; the tool is generating discriminatory language or assumptions; there is potential adverse impact on a protected group; candidate data may be processed in ways that raise privacy obligations | "The screener keeps flagging candidates with employment gaps as probably not serious. That could be age or health discrimination." "We are using candidates' personal social media for assessment. Is that compliant?" |
| DEI | You notice patterns of bias in hiring outcomes; the tool is making cultural-fit assessments that could disadvantage underrepresented groups; you are worried a tool is perpetuating or amplifying existing bias; you want guidance on fair use; you are designing a new AI-assisted process and want input before you build it | "We are using AI to assess culture fit and I am concerned it is filtering for similarity." "Our AI summaries seem to describe male and female candidates differently." "We want to audit our AI-assisted hiring for bias." |
| Compliance | You are unsure about data handling and privacy; you are using a third-party tool and are uncertain about vendor compliance posture; you are considering a new AI capability and want review before launch; you have found data misuse or a breach | "This tool asks for candidate names and LinkedIn profiles. Are we compliant sharing that?" "We want to use AI to monitor candidate communication. Is that permitted?" |
| Leadership | You need a policy decision or authority you do not hold; you are proposing a significant change to the hiring process; you have found a serious, systemic problem; you need resources or approval for responsible-AI practices; you are setting strategic direction on AI in hiring | "Should we use AI to make the initial pass or fail screening decision?" "We have found a gender bias problem in our tool. How should we handle it?" "We want to invest in audit and monitoring infrastructure. Who approves?" |
Two things about this grid are worth stating plainly. First, the rows overlap constantly in practice, and that is normal rather than a defect in the map. An adverse-impact pattern is simultaneously a DEI analytical question and a Legal exposure question, and routing it to both on the same day is the correct move rather than a hedge. Second, the DEI row contains the one trigger that is not a problem at all: bringing DEI in while you are still designing a process. That is the cheapest escalation available to you, because a fairness question answered at design time costs a conversation, while the same question answered after launch costs a remediation, a backlog of affected candidates, and a paper trail you would rather not have.
The Adverse-Impact Signal: DEI and Legal Together
The clearest trigger in Hassan's world is an adverse-impact signal: an AI-assisted decision that disproportionately screens out a protected group. The standard test US enforcement agencies use is the four-fifths rule, set out in the Uniform Guidelines on Employee Selection Procedures. A selection rate for any group that is less than four-fifths (80 percent) of the rate for the highest-scoring group is generally treated as evidence of adverse impact worth investigating.
Here is the pattern that crossed Hassan's threshold. Over one quarter, the AI screener advanced applicants to the recruiter-review stage at these rates. Of 500 applicants who identified as white, 180 advanced, a selection rate of 36 percent. Of 200 applicants who identified as Black, 50 advanced, a rate of 25 percent. To run the four-fifths test, you divide the lower rate by the higher rate: 25 percent divided by 36 percent is 0.69, or 69 percent. That is below the 80 percent threshold, so the pattern is a flagged adverse-impact signal, not background noise. Hassan did not conclude the tool was illegal, and he did not try to "fix" the prompt himself. A four-fifths failure is a screening signal that says investigate, not a verdict. What he did was route it, because the analysis and the legal exposure both sat above his pay grade.
This trigger goes to DEI and Legal together, and the order matters. DEI owns the analytical question: is the disparity real once you control for legitimate, job-related factors like required licensure, or is it an artifact of the applicant mix? Legal owns the exposure question: if the disparity is real and the selection criterion is not demonstrably job-related and consistent with business necessity, the organization may face Title VII liability for disparate impact. Hassan brought both functions the same packet on the same day: the raw counts, the selection rates, the four-fifths calculation, the date range, and the specific tool and configuration involved. He explicitly did not bring a conclusion about intent, because intent is not what disparate-impact analysis turns on.
The ADA Accommodation Request: Legal and Compliance
The second signal arrived as a single email. A candidate for an ICU nursing role wrote that a vision impairment made the AI-driven, timed video interview the scheduling assistant had booked impossible to complete as designed, and asked for an alternative. Hassan recognized this instantly as something he could not improvise around, because it sits squarely inside the Americans with Disabilities Act (ADA).
Under the ADA, an employer must provide reasonable accommodation in the application process for a qualified individual with a disability, unless doing so imposes undue hardship. When an AI tool is the thing creating the barrier, the obligation does not disappear because a vendor built the tool. The EEOC has been explicit that employers remain responsible when algorithmic hiring tools screen out individuals with disabilities who could perform the job with reasonable accommodation. So the question is never "can the AI accommodate this," it is "what alternative does the law require us to offer, and who is authorized to approve it."
Hassan routed this to Legal and Compliance the same afternoon, and he did not let the candidate wait while he did. The cost of delay here is unusually sharp: a slow or fumbled accommodation response is itself a potential ADA violation, and it lands on a specific, identifiable person who is already disadvantaged. What he brought to Legal and Compliance was tight: the candidate's request verbatim, the exact step in the process that created the barrier, the alternatives the team could plausibly offer (a live structured interview, an untimed format, a different modality), and a request for a decision on which alternative to extend and how fast. He owned the candidate relationship and the timeline. He did not own the legal determination of what counted as reasonable.
The Vendor Audit Gap: Compliance and Leadership
The third signal came from procurement, not the pipeline. The AI screening vendor's contract was up for renewal, and Hassan noticed the renewal packet contained no recent bias audit. That matters because his health system runs a hiring office in New York City, and New York City Local Law 144 governs the use of automated employment decision tools (AEDTs) for candidates and employees in the city.
Local Law 144, in effect since July 2023, requires that an AEDT used to screen candidates undergo an independent bias audit within the prior year, that a summary of the audit results be published, and that candidates receive advance notice that an AEDT is being used. An employer that relies on a tool without a current independent audit is the party exposed, not just the vendor. So a missing audit is not a procurement footnote; it is a compliance gap that touches the organization's legal standing in a specific jurisdiction.
This one Hassan routed to Compliance and Leadership. Compliance owns the standard: does the tool, as used in the NYC office, actually meet the Local Law 144 requirements for a current independent audit, published results, and candidate notice. Leadership owns the consequence, because the realistic options all involve authority Hassan does not have: pause use of the tool in the affected jurisdiction until an audit exists, demand the audit from the vendor as a renewal condition, or switch vendors. Each of those is a budget and policy decision. Hassan's packet laid out the requirement, the specific gap (no audit within the prior year, no published summary), the jurisdictions affected, and the three options with their rough timelines, so Leadership could decide rather than discover.
The Data-Privacy Issue: Legal
The fourth signal was a question Hassan almost answered himself before he caught it. A strong candidate based in Ireland, applying for a remote coordinator role, asked where their application data was stored and processed, and whether it left the European Union. Because this candidate sits in the EU, the General Data Protection Regulation (GDPR) applies to how their personal data is collected, processed, and transferred, and the AI screening tool was processing exactly that data.
GDPR sets specific obligations around lawful basis for processing, transparency about how data is used, and restrictions on transferring personal data outside the EU without adequate safeguards. It also gives individuals rights, including, under Article 22, protections around decisions based solely on automated processing that produce legal or similarly significant effects. Hassan is not equipped to certify whether the vendor's data flows satisfy any of that, and a wrong answer to a candidate creates its own exposure. He routed it to Legal as a data-privacy question, bringing the candidate's exact question, the candidate's location, the tool involved, and what he already knew about where the data went. He left the determination of lawful basis and transfer adequacy entirely to Legal, because that is a legal interpretation, not a recruiter judgment.
How to Escalate: The Five Steps
Recognizing the owner is most of the skill, but the handoff has its own discipline, and a badly executed escalation of a correctly routed issue still stalls. Hassan runs the same five steps every time, and they take him under an hour for anything short of the adverse-impact packet.
Step one, identify the right person or team. Not the function in the abstract, the actual named person who holds that decision in your organization. Legal takes legal questions, compliance risks, and discrimination concerns. DEI takes bias patterns, fairness questions, and cultural-fit concerns. Compliance takes data privacy, vendor evaluation, and regulatory questions. Leadership takes policy decisions, resource allocation, and strategic direction. If you cannot name the person for each of those four rows right now, that gap is itself the finding, and closing it is the first practice exercise below.
Step two, gather information before you send anything. Have four things ready: what the issue is, what evidence you hold, what the impact is and who is affected, and what options you see. This step is where most escalations are won or lost, because it converts a worry into a decidable question. It is also the step that protects the relationship, since a function that receives well-prepared escalations from you will read your next message quickly.
Step three, present clearly. The failure mode is opening with "I'm worried about this," which asks the recipient to do your analysis and gives them nothing to act on. The contrast Hassan uses with his team is exact: "our screener may have an adverse-impact problem, here are the selection rates and the four-fifths calculation, I need DEI to assess and Legal to advise on exposure" gets action, while "I have a bad feeling about the AI tool" gets filed.
Step four, be explicit about what you need. Guidance, a decision, an approval, or resources are four different asks with four different response times, and the recipient cannot infer which one you want. Naming it removes an entire round trip, and it prevents the common outcome where you receive thoughtful commentary when what you needed was a yes or no.
Step five, document and follow up. Record what was decided and why, and check back to confirm the action actually happened. This closes the loop on your side and creates the record that lets the next person understand why the process looks the way it does. An escalation that produced a decision nobody wrote down will be relitigated within a year.
What to Bring, and the Cost of Waiting
Across all four signals, Hassan brought the same four things and never anything less: the issue stated in one plain sentence, the concrete evidence (counts, rates, the candidate's own words, the contract gap), the impact and who is affected, and a clear statement of what he needed, whether that was an analysis, a legal determination, a policy decision, or a budget approval. What he deliberately did not bring was a vague worry or a half-formed conclusion.
The reason speed matters is that the cost of escalating too late is not flat; it grows. An adverse-impact pattern caught in one quarter affects one quarter of applicants; left for a year, it affects four times as many, and every one of them is a person who was screened out and a potential claim. An accommodation request answered in a day is a candidate served; answered in three weeks, it is a candidate harmed and a documented delay. A missing bias audit found at renewal is a negotiating point; found after an enforcement inquiry, it is a liability with a candidate-notice trail attached. Routing early is cheaper than routing late in every single case, which is exactly why Hassan treats the recognition step, not the fixing step, as the real skill.
Anti-Patterns
Not escalating when you should. This is seeing something concerning and handling it alone, usually with a small local fix: rewording the prompt, manually pulling a few candidates back into review, quietly not using the tool for one requisition. It happens because escalating feels like admitting you cannot handle your own pipeline, and because the signal rarely arrives with a label on it. What goes wrong is that you do not hold the authority or the expertise the issue requires, so the local fix leaves the underlying problem running for everyone else, and the record now shows the organization knew and did not act. The counter is a written threshold rather than a feeling: if the issue is legal, compliance, or bias-related, it escalates, and the fact that you are unsure whether it qualifies is itself a reason to route it.
Escalating everything. This is the mirror image, where routine decisions get sent up for approval because senior sign-off feels safer than judgment. It happens most in teams that have just been burned by the first anti-pattern and have overcorrected. What goes wrong is that decision-making slows to the speed of the busiest executive's inbox, leadership stops reading your messages because most of them do not need a decision, and your own expertise gets discounted, which is expensive the day you have something genuinely urgent. The counter is to escalate when you actually need guidance you do not have or when the issue is significant by your written threshold, and to decide the rest yourself and document the reasoning.
Escalating without gathering information first. This is sending the worry rather than the case: no data, no impact statement, no options, and no clear ask. It happens because the worry feels urgent and assembling the evidence feels like a delay you cannot afford. What goes wrong is that the recipient cannot make an informed decision, so the first response is a request for the information you should have brought, which costs more time than gathering it would have. You also read as uncertain rather than as the person closest to the data, which affects how the next escalation is received. The counter is the four-part packet: issue, evidence, impact, ask. Assembling it usually takes less time than the round trip it avoids.
Practice
- Build your escalation map. Write down who, by name, handles legal, compliance, DEI, and leadership decisions for your recruiting function. Any row you cannot fill in is a gap that will cost you hours on the day it matters, and filling it is a fifteen-minute task today.
- Sort five realistic scenarios. Take five AI-related recruiting issues you could plausibly face this quarter. For each, decide whether you would escalate, to whom, and what evidence you would need. Where two functions apply, name both and say what each one owns.
- Write one real escalation. Choose the hardest of those five and draft the actual message: issue in one sentence, evidence, impact and who is affected, and the specific ask. Then check it against the "I'm worried about this" test and cut anything that reads as a feeling rather than a fact.
- Test the process with a live question. Ask yourself: if I found gender bias in our screening tomorrow, exactly who would I contact and what would I send? If the answer is not immediate and specific, your process needs work rather than your instincts.
- Publish an escalation guide for your team. Document the paths, the triggers, and the five-step process in one page, and share it. A map that exists only in the senior recruiter's head fails precisely when that person is on leave.
Reflection
- Have you encountered an issue that, in hindsight, you should have escalated? What actually stopped you at the time, and would that reason survive being said out loud?
- If you discovered evidence of bias in your AI-assisted hiring tomorrow, what would your escalation look like in concrete terms: to whom, with what attached, asking for what?
- How would you explain to a newer recruiter the difference between escalating and handling something independently, without giving them a rule so vague it means "escalate when nervous"?
- Which of the four functions do you have the weakest relationship with, and what has that cost you in issues you routed late or not at all?
- When did you last bring DEI into a process at the design stage rather than after a problem appeared, and what would it take to make that the default?
Glossary
- Escalation. Bringing an issue to someone with more authority or more expertise than you hold, because the decision belongs to them rather than because you feel alarmed.
- Adverse impact. When a practice, including an AI-assisted decision, disproportionately affects a protected group. It is about outcomes rather than intent.
- Four-fifths rule. The screen in the Uniform Guidelines on Employee Selection Procedures: a group's selection rate below 80 percent of the highest group's rate is treated as evidence of adverse impact worth investigating. A flag, not a verdict.
- Selection rate. The share of a group's applicants advanced at a given stage, which is what the four-fifths comparison uses rather than raw headcounts.
- Compliance risk. The potential for a legal or regulatory violation arising from how a process, tool, or vendor is used.
- Authority. The right and the responsibility to make a particular decision. Routing is the act of matching a decision to the authority that holds it.
- Automated employment decision tool (AEDT). The category of tool covered by New York City Local Law 144, which requires an independent bias audit within the prior year, published audit results, and advance candidate notice.
- Reasonable accommodation. The adjustment an employer must provide in the application process for a qualified individual with a disability under the ADA, unless it imposes undue hardship. The obligation stands even when a vendor's tool created the barrier.
Related Lessons
- Escalation Processes: How Concerns Flow Up and Decisions Get Made picks up exactly where this lesson stops. Once you have routed correctly, that lesson is the machinery that gives the concern an owner, a clock, and a documented decision that comes back to you.
- Decision Rules: Explicit Criteria for Escalation supplies the written thresholds that tell you a signal has crossed the line, so that recognizing the owner is a rule you apply rather than a judgment you agonize over.
- Red Flags and When to Reject or Escalate AI Output works at the level of a single output rather than a pattern, and it is what you use before a signal is big enough to route anywhere.
- Third-Party Tools and Vendors: Due Diligence and Contracts covers the vendor-side questions behind the missing bias audit, including what to require at contract rather than discover at renewal.
- Data Privacy Fundamentals: GDPR, CCPA, FCRA, and Regional Requirements goes deeper on the privacy obligations that made the Irish candidate's question a Legal matter rather than a recruiter's answer.
- Remediation and Escalation: When and How to Act on Findings takes over once a routed concern is confirmed, covering severity classification, the response menu, and how you verify the fix held.
Closing
Escalation is not weakness, and it is not an admission that you cannot handle your own pipeline. It is how systems work responsibly, and it is the specific way a recruiter converts proximity into protection. You are in the data every day, which means you see the pattern before anyone with the authority to act on it does. That position carries an obligation that has nothing to do with expertise: notice, name, and route.
Hassan's quarter is instructive because none of his four signals arrived labeled. A screening pattern looked slightly off. An email asked for something unusual. A renewal packet had a blank page. A candidate asked a polite question. Each one turned out to belong to a different owner, and in two cases to two owners at once. He did not solve any of them, and that was the point. What he did was recognize the kind of decision each demanded, assemble a packet worth reading, and hand it over while the cost was still small. Do that reliably and you become a partner to the functions that hold authority rather than a source of vague alarm, which is what makes them answer quickly the day something genuinely urgent lands on your desk.
Key Takeaways
- Escalation is routing, not alarm. You are closest to the data and furthest from the authority. Your job is to recognize which function owns each decision and hand them the evidence, not to feel sufficiently alarmed before you act or to flood every function with routine questions.
- Four owners, four kinds of decision. Legal owns exposure and what the law requires. Compliance owns whether a process or vendor meets a regulatory standard. DEI owns the analysis and remediation of bias in outcomes. Leadership owns policy, budget, and the authority to change how the organization hires.
- An adverse-impact signal goes to DEI and Legal together. Use the four-fifths rule as your trigger: divide the lower group's selection rate by the highest group's rate, and a result under 80 percent is a flagged signal to investigate. A 25 percent rate against a 36 percent rate is 69 percent, which is below threshold. It means investigate, not that the tool is proven illegal, and Title VII disparate-impact exposure turns on outcomes rather than intent.
- An ADA accommodation request on an AI tool goes to Legal and Compliance, fast. The employer owes reasonable accommodation in the application process even when a vendor's tool created the barrier, and the EEOC holds employers responsible for AI tools that screen out qualified individuals with disabilities. A slow response is itself a risk.
- A vendor bias-audit gap goes to Compliance and Leadership. New York City Local Law 144 requires an independent bias audit within the prior year, published results, and candidate notice for automated employment decision tools. The employer is exposed for using an unaudited tool, and the remedies (pause, demand audit, switch vendors) are Leadership budget and policy calls.
- A data-privacy or GDPR question goes to Legal. When a candidate sits in the EU, GDPR governs lawful basis, transparency, cross-border transfer, and automated-decision rights under Article 22. Lawful basis and transfer adequacy are legal determinations, not recruiter judgments, so route them rather than answering the candidate yourself.
- Run the same five steps every time. Identify the named owner, gather information, present clearly, state exactly what you need (guidance, decision, approval, or resources), then document what was decided and follow up to confirm it happened.
- Bring four things every time. The issue in one sentence, concrete evidence, the impact and who is affected, and a clear ask. A specific, evidence-backed escalation gets action; a vague worry gets filed.
- The cost of escalating late compounds. Each signal grows more expensive with time: more affected applicants, a harmed candidate, a liability instead of a negotiating point. Recognizing whose problem it is and routing early is the skill, because it is always cheaper than routing late.
Frequently Asked Questions
What if I am not sure the issue is real? Route it anyway, and say that you are not sure. Uncertainty about whether a pattern is genuine is exactly the condition the four-fifths screen exists to handle: it tells you whether something is worth investigating, not whether anything is proven. Hassan did not know his screening gap was real bias when he sent it, and he said so explicitly, bringing the counts and the calculation rather than a conclusion. The alternative, waiting until you are certain, means waiting until the pattern is large enough to be undeniable, which is also the point at which it has affected the most people and become most expensive to fix.
Two functions seem to own the same issue. Do I pick one? No, send it to both on the same day, and say in the message what you are asking each one for. Adverse impact is the standard case: DEI owns whether the disparity survives controlling for legitimate job-related factors, and Legal owns what the exposure is if it does. Picking one means the other finds out late and has to start from scratch, and it usually means the analytical question and the exposure question get answered weeks apart. The same applies to an accommodation request, where Legal determines what is reasonable and Compliance owns whether your process meets the standard.
How do I escalate without seeming like I cannot handle my own pipeline? By escalating the right things well rather than escalating less. The thing that damages your standing is not the escalation itself; it is sending a worry with no evidence, or sending routine decisions upward for approval. A message that opens with the issue in one sentence, attaches the numbers, states who is affected, and names a specific ask reads as competence, because it is the work product of someone who understood the problem well enough to route it. Escalation is how systems work responsibly, and the functions you route to will treat you as a partner if your packets are worth their time.
Is it worth escalating something I have already worked around? Usually yes, and the workaround is a reason to escalate rather than a reason not to. A local fix, rewording a prompt or manually pulling candidates back into review, addresses your requisition and leaves the same behavior running for every other recruiter using the tool. It also creates the worst evidentiary position available: a record showing that someone in the organization noticed the problem and handled it privately. Route it, and include what you did as an interim measure, because that is useful information for whoever decides on the durable fix.
When should I involve DEI before anything has gone wrong? When you are designing a new AI-assisted process, changing how an existing one scores candidates, or introducing anything that assesses fit rather than qualifications. That is the one trigger in the map that is not a problem, and it is the cheapest escalation you will ever make, because a fairness question answered at design time costs a conversation while the same question answered after launch costs a remediation and a backlog of affected candidates. Culture-fit assessment is the clearest example: the question of whether it is filtering for similarity is far easier to answer before it has been scoring people for two quarters.
Skill.re