FairGap®

The model card a board will actually read

A model card for directors states the decision, the boundary on use, the version and owner, and the rates with counts and dates, while the technical file and any required public summary remain separate records.

In many board packs, the model card is the document the modeling team wrote for other practitioners. It names the architecture, the training objective, the benchmark, and caveats written for people who already know the system. When a question arrives later about permitted use, or about a measured disparity, the person who can answer it is still the person who built the model. A model card for the board has to carry those answers in language a director can repeat, with enough detail that the description can be matched to the system that was running.

This note is for directors and senior compliance counsel. It is not legal advice. A model card is the standing description of a deployed model: the decision it informs, the population it is applied to, the evaluation that supports the current version, and the conditions under which that version should not be used. The technical file, which holds data lineage, the feature list, and the test procedures, remains with counsel and the audit team.

The front of the card

The decision should use the language the business already uses for the process, and an operator should be able to compare the sentence with the production configuration. Ranking applicants for a named requisition in New York City, after which a recruiter decides who advances, can be confirmed against that configuration. On an insurance pricing model, the card names the line of business, the jurisdiction, and whether the output sets the premium or is one input an underwriter may consider. On a credit model, the card names the product and whether the score is an input to a written policy or is the decision itself.

The boundary should be written beside the decision. A permitted use, recorded without the excluded use next to it, tends to be applied more broadly than the control in production allows. If recruiters may use a score to order a queue, and may not reject a candidate on that score alone, both constraints belong on the card, along with the control that keeps the rejection limit in force. An auditor can find that control later in a threshold that routes a case to review, in a field the reviewer has to complete, or in a log of overrides. The phrase "human in the loop" is specific enough to audit when the card also states what the person sees, what that person is permitted to change, and where the action is recorded.

The card should also name the model version, the owner accountable for the description, the date the description was confirmed against production, and the condition that will trigger the next review. The owner is a named person, or a named role with the current incumbent recorded on the card. A review condition an auditor can test names a material change in the population, the data, the threshold, or the use, and it names a calendar date on which the card is reconfirmed even if none of those have changed.

Rates, counts, and the window

A selection rate is the share of people in a group who received the favorable outcome during the measurement window. A rate of error among people who met a stated qualification is a different measurement, and the two need not move together when a threshold changes. The card should say which measurement was computed, which outcome counted as favorable, and, if a qualification was used, how that qualification was recorded in the data. When more than one measurement is shown, each one needs a reason tied to the decision the model informs.

Counts belong beside rates. A ratio of selection rates computed on a few dozen people in the smaller group is different evidence from the same ratio computed on several thousand people. The card should show how many people fell in each group. When a cell is too small for a stable comparison, the card says so. Two decimal places on a small cell overstate how stable the ratio is. If the sample is large enough to support a confidence interval, the interval shows how wide the estimate is. If the sample is too small for an interval, the card says the estimate is unstable.

Period and source belong with the counts. Figures from production decisions in the most recent complete quarter differ from figures taken from a vendor test set assembled in an earlier year. The card should name the source and the dates the window covers. If the model version or the decision threshold changed during the window, the card should split the window or state that the figures combine more than one configuration. Combined figures should be labeled as combined and kept distinct from any description of the version now in production.

If the evaluation covered applicants in one city, the card names that city as the population the figures describe. If demographic labels are missing for a portion of the people in the window, the card states how large that portion is and whether those people were excluded, imputed, or reported as their own category. The city rules under NYC Local Law 144 require the published bias-audit summary to report an unknown category. An internal calculation that drops those rows measures a narrower set than that summary. The card should record that choice so a reader can see which population each set of figures describes.

Under the Uniform Guidelines on Employee Selection Procedures, 29 C.F.R. section 1607.4(D), a selection rate for any race, sex, or ethnic group that is less than four-fifths of the rate for the group with the highest rate will generally be regarded by federal enforcement agencies as evidence of adverse impact. A rate greater than four-fifths will generally not be regarded by those agencies as such evidence. Smaller differences may still constitute adverse impact, including where they are significant in both statistical and practical terms, and larger differences may not constitute adverse impact where they rest on small numbers and are not statistically significant. The Guidelines address employment selection procedures. A card for a credit or insurance model that quotes the same cutoff should identify it as employment guidance. The card reports the rates, the counts, the group with the highest rate, and the window. Legal characterization of those figures belongs with counsel.

The technical file and the public summary

A shorter card for the board leaves the technical file in place. Data lineage, the feature list, validation tests, and the procedure behind each reported figure are what counsel and the audit team use when the card is questioned. In 2019, Margaret Mitchell and colleagues proposed model reporting that covered intended use, factors, metrics, evaluation data, training data, quantitative analyses, and caveats, so practitioners could see what a model was for and how it behaved across groups. Those headings are a sound contents list for the technical file. The board card draws on that file and cites it by version and date, so a change in either record can be compared with the other.

Statutory records keep their own scope. Where an organization is the provider of a high-risk AI system under the EU Artificial Intelligence Act, Regulation (EU) 2024/1689, Article 11 requires technical documentation to be drawn up before the system is placed on the market or put into service, containing at least the elements set out in Annex IV. Article 13 requires instructions for use that include concise, complete, correct, and clear information that is relevant, accessible, and comprehensible to deployers. A board card may rest on the same facts. It is a separate record for directors.

Under NYC Local Law 144, an employer or employment agency that uses an automated employment decision tool to screen candidates for employment or employees for promotion in New York City must obtain an independent bias audit conducted no more than one year before the use, publish a summary of the most recent results in the form the law and the city rules require, and give the notice the law requires. The published summary has a public audience and prescribed contents. In the board pack, that summary keeps its own heading.