A machine decided.Did you tell them?
A credit denial. An insurance tier. A tenant score. A benefits cut. A growing set of laws imposes different transparency, explanation, correction, opt-out, appeal, and human-review duties for certain automated decisions. Grade every automated decision system against a composite set of those controls before a regulator or a person asks.
Not legal advice. This is a readiness aid that grades your transparency process from your own marks. It is date-agnostic and people-blind: it encodes no statute’s deadline, grades a decision system rather than any person, files nothing, and renders no compliance ruling. Automated-decision duties (the CCPA ADMT rules, Colorado SB 26-189, GDPR Article 22, ECOA/FCRA adverse-action) vary by jurisdiction and change often — confirm which apply to you and every deadline with qualified counsel.
Correction notice — version 1.1.0 (2026-09-23). This package replaces version 1.0 of the Automated-Decision Transparency & Disclosure Scorecard. Version 1.0 contained a scoring-logic defect: a system marked with no human appeal and no opt-out was forced to UNDISCLOSED even where the person had been told an automated system was used. In 1.1.0 the no-notice condition is the only one that returns UNDISCLOSED; a missing appeal and opt-out raise a recourse-gap flag that does not change the score or verdict; and a score below 50 without the no-notice condition reads MATERIAL TRANSPARENCY GAPS. If you graded systems with version 1.0, re-grade them with this version. Existing buyers: the download link in your original purchase email now serves version 1.1.0.
“The system decided” is not an answer a regulator accepts.
The person was never told
A person who was never told an automated system decided cannot ask for an explanation or an appeal. Regimes differ on timing and content — some require notice before the system is used, some require an explanation after an adverse outcome, and some require both.
There’s no one to appeal to
A denial with no human who can reconsider it, and no way to opt out, leaves the person no recourse at all. A human-review path and an opt-out are not universally interchangeable. Confirm which recourse rights and conditions apply before relying on either one.
The rules keep moving
Colorado delayed its AI law, then replaced it outright before the original ever took effect. A checklist pinned to one statute’s text is wrong the moment it changes. So grade a composite set of controls drawn from several regimes, not one statute’s text.
Grade a decision system. Read whether you could defend it.
This is the live scoring logic from the engine. The insurance premium-tier preset scores 74 and still reads UNDISCLOSED — the person is never told an automated system decided. The tenant-screening preset reads GAPS and carries the recourse flag: no appeal and no opt-out.
No notice of automated processing is provided
A top mark records the user’s assessment against the mapped rule; it is not a certification that the notice is legally sufficient.
Meaningful logic/inputs/outputs + a specific reason
A trained reviewer can overturn and weighs what the person submits
Clear path offered and operationally honored
Mapped to domain, jurisdictions, and the duties owed
Some records, not per-decision or not retained
Disclosure gate fired: the person was never told an automated system made the decision. The score alone would read GAPS.
Fix first: Use of automation disclosed to the person
Weighted to 100. The gate forces UNDISCLOSED when the person was never told it was automated (⚡ disclosure). No human appeal AND no opt-out raises the recourse flag, which does not change the verdict. A human-review path and an opt-out are not universally interchangeable. Confirm which recourse rights and conditions apply before relying on either one. Date-agnostic and people-blind — it grades your process, never a person. Not legal advice.


How the gate works, in one image
How the Automated-Decision Transparency & Disclosure Scorecard scores disclosures and forces UNDISCLOSED when the subject isn't told — the same math the demo runs, as a diagram you can share or embed anywhere.
View & embed the full diagramThe same verdicts, from the runnable engine.
Verbatim output from the included Python engine on the six-system sample. The workbook reproduces these byte-for-byte.
==========================================================================
AUTOMATED-DECISION TRANSPARENCY & DISCLOSURE SCORECARD
==========================================================================
Credit-line approval model
verdict: DISCLOSED (score 100/100)
Tenant-screening score
verdict: GAPS (score 66/100)
Recourse-gap flag: Based on the user’s marks, neither a human-review
path nor an applicable opt-out path is shown. This flag does not
change the score or verdict and does not determine which form of
recourse applicable law requires.
fix first: Human review / appeal with authority to overturn
Same screening after adding a human appeal
verdict: DISCLOSED (score 84/100)
Insurance premium-tier model
verdict: UNDISCLOSED (score 74/100)
gate: UNDISCLOSED — the person was never told an automated system made the decision
fix first: Use of automation disclosed to the person
Dynamic pricing eligibility engine
verdict: GAPS (score 60/100)
fix first: Meaningful-logic & adverse-reason explanation
Benefits-eligibility auto-decision
verdict: MATERIAL TRANSPARENCY GAPS (score 23/100)
note: Based on the user’s marks, multiple transparency or recourse
controls are missing or incomplete. This result does not mean
the person received no notice; UNDISCLOSED is reserved for the
separate no-notice condition.
Recourse-gap flag: Based on the user’s marks, neither a human-review
path nor an applicable opt-out path is shown. This flag does not
change the score or verdict and does not determine which form of
recourse applicable law requires.
fix first: Meaningful-logic & adverse-reason explanation
--------------------------------------------------------------------------
PORTFOLIO: REVIEW BEFORE CONTINUED USE (1 of 6 undisclosed · 1 with material transparency gaps · exposure 33.3%)
One or more systems read UNDISCLOSED or MATERIAL TRANSPARENCY GAPS under
this instrument. Determine whether the missing controls are applicable and
whether continued use is appropriate before relying on the portfolio
result. This result does not itself direct suspension or establish a legal
violation.
--------------------------------------------------------------------------
Grades a composite set of transparency and recourse controls drawn from
multiple regimes, never a specific statute or deadline; it does not mean that
every regime requires every control. It grades a deployer’s process,
never a person, and renders no compliance ruling. A readiness aid, not legal
advice. Confirm which regimes apply, and every deadline, with counsel.Six controls, weighted to 100. Disclosure is non-tradeable.
⚡ Use of automation disclosed to the person
Were they told an automated system made or substantially drove the decision? Regimes differ on timing and content — some require notice before the system is used, some require an explanation after an adverse outcome, and some require both. Mark what your process actually does; confirm what yours requires with counsel.
Meaningful-logic & adverse-reason explanation
Can the person get meaningful information about the logic and a specific reason for an adverse outcome — not “the system decided”?
Human review / appeal with authority to overturn
A trained reviewer who can actually overturn the outcome and weighs what the person submits.
Opt-out and data-correction paths offered
A real way for the person to opt out of the automated processing, or to correct the data that drove it. Mark what the process actually offers. Whether either path is legally required depends on the applicable jurisdiction, decision, data, and organizational role and is not determined by this scorecard.
Scope & “significant decision” mapping
Have you determined — with counsel where the answer is not obvious — whether this is a significant or consequential decision under the regimes that reach you, in which domains and jurisdictions? This aid does not make that determination. It records whether you have made it.
Notice retention & decision recordkeeping
Notices, explanations, and decisions logged per person and retained, so you can produce them later.
⚡ = the gate control. The gate forces UNDISCLOSED if the person was never told it was automated, and it worsens only — it never promotes a verdict. No human appeal AND no opt-out raises the recourse flag, which does not change the verdict. A human-review path and an opt-out are not universally interchangeable. Confirm which recourse rights and conditions apply before relying on either one.
A readiness aid, not a compliance ruling.
It is
- A grade of your transparency process, from your own marks.
- Date-agnostic — it grades practices, not any statute’s deadline.
- People-blind — it grades a decision system, never a person.
It isn’t
- Legal advice, a certification, or a safe harbor.
- A ruling on whether a specific law applies to a decision.
- A score or ranking of any person or group.
Not legal advice. This is a readiness aid that grades your transparency process from your own marks. It is date-agnostic and people-blind: it encodes no statute’s deadline, grades a decision system rather than any person, files nothing, and renders no compliance ruling. Automated-decision duties (the CCPA ADMT rules, Colorado SB 26-189, GDPR Article 22, ECOA/FCRA adverse-action) vary by jurisdiction and change often — confirm which apply to you and every deadline with qualified counsel.
Whoever deploys AI that decides things about people.
- Privacy, compliance, and risk leads governing automated decisions.
- Lenders, insurers, landlords, and platforms making consequential calls with AI.
- Product and data teams who need to show disclosure, explanation, and recourse.
- Not for hiring tools — use the AEDT Deployer Dossier for those.
- Not a ruling on what’s in scope — confirm that with counsel.
- Not a content-labeling tool — that’s the Disclosure & Labeling Kit.
The rest of your automated-decision and disclosure coverage.
AEDT Deployer Compliance Dossier
The hiring-decision sibling: bias audit, candidate notice, employment rules.
ViewAI Disclosure & Synthetic-Content Labeling Kit
Disclosure for synthetic content — is this a bot, is this a deepfake — not decisions.
ViewNIST AI RMF / US AI Governance Readiness Kit
The governance program this transparency scorecard lives inside.
ViewAnswers before you buy.
It grades whether each of your automated decision systems meets six transparency and recourse practices drawn from several automated-decision regimes — system by system. For each one you mark six controls 0/1/2: whether the use of automation is disclosed to the person, whether there’s a meaningful-logic and adverse-reason explanation, whether there’s a human review/appeal with authority to overturn, whether an opt-out or data-correction path is offered, whether the decision’s scope and jurisdictions are mapped, and whether notices and decisions are retained. The six are weighted to a 0–100 score banded DISCLOSED, GAPS, or MATERIAL TRANSPARENCY GAPS; UNDISCLOSED is reserved for the separate no-notice condition, and the portfolio rolls up to ALL TRANSPARENT, CONDITIONS OUTSTANDING, or REVIEW BEFORE CONTINUED USE, a prompt to check whether the missing controls apply and whether continued use is appropriate, not a direction to suspend a system. It grades the deployer’s process, never a person.
Based on the user’s marks, multiple transparency or recourse controls are missing or incomplete. This result does not mean the person received no notice; UNDISCLOSED is reserved for the separate no-notice condition. A score below 50 can reflect weak explanation, records, appeal, opt-out, or correction controls even where notice was given; only the separate disclosure gate returns UNDISCLOSED.
Because of the disclosure gate. A system is forced to UNDISCLOSED regardless of score when the person was never told an automated system made the decision. In the worked example, an insurance premium-tier model scores 74 — its explanation, appeal, opt-out, and scoping are in place — and still reads UNDISCLOSED because the person is never told. The gate worsens only — it never promotes a verdict. A system marked with no human appeal AND no opt-out is flagged separately as a recourse gap: the flag identifies a gap in recourse and does not change the verdict, so the tenant-screening example reads GAPS with the flag. For this scorecard’s operational recourse flag, either a functioning human-review path or an applicable opt-out path counts as evidence that some recourse exists. That is a scoring convention, not a legal rule that one right always substitutes for the other. Applicable law may require a particular path, impose conditions on substitution, or require additional rights.
No — they’re siblings covering different lanes. The AEDT Deployer Compliance Dossier is locked to automated employment decisions and the controls specific to that lane (a qualifying independent bias audit where an applicable rule requires one, candidate notice, NYC/Illinois/California employment rules). This scorecard covers automated decisions everywhere else — credit, insurance, housing, pricing, benefits, education, health care — and grades them against a composite set of transparency and recourse controls drawn from multiple regimes. Run the AEDT dossier for hiring tools and this scorecard for the rest; together they cover your automated decisions about people.
Several regimes address transparency and recourse when an automated system makes a significant decision about a person, on different timetables and with different triggers: the CCPA’s ADMT rules in California (the prescribed pre-use notice, applicable ADMT access and opt-out rights, and a conditional human-appeal mechanism within the opt-out framework), Colorado’s SB 26-189 (notice at the point of interaction, specified plain-language information within 30 days after an adverse consequential decision, correction, and meaningful human review and reconsideration), the GDPR’s Article 22 right around solely-automated decisions, and US adverse-action duties under ECOA/FCRA. Those laws move constantly — Colorado delayed its AI law, then replaced it outright before the original ever took effect. So the engine grades selected practices that recur across those regimes rather than any single statute’s checklist — the CCPA’s ADMT rules and Colorado’s SB 26-189 attach on 1 January 2027, while GDPR Article 22 and US ECOA/FCRA adverse-action duties apply now, to different decisions. A control may therefore read low where nothing in your jurisdiction requires it. The specific regimes and dates are named in the playbooks as planning references. Confirm which apply to you, and every deadline, with counsel.
No. It is a readiness aid that grades your transparency process from your own marks. It connects to nothing, files nothing, makes no decision, renders no compliance ruling, and cannot tell you whether a specific law applies to a specific decision. It is deliberately people-blind — it grades a decision system, never the person the decision is about, and ranks no one. It is not legal advice, a certification, an opinion of counsel, or a safe harbor. Use it to find and close the transparency gaps in your automated decisions, then confirm scope and obligations with qualified counsel.
A runnable zero-dependency Python engine, a workbook that reproduces it exactly (Start Here, Dashboard, and a Disclosure Scorecard with the mark definitions built into each column), a six-system worked example, and two playbooks: a Disclosure Mapping Playbook for inventorying your decision systems and marking honestly, and a Transparency-Remediation Runbook that sets the controls beside several regimes as planning references and walks the disclose / explain / recourse / opt-out steps. Pick the automated decisions that affect people — credit, insurance, housing, pricing, benefits — grade each one, and, where a control is short, close the one the tool names first. Deterministic and offline; one-time purchase, lifetime access, 12 months of updates.
Find the decision you
couldn’t defend — first.
One purchase, lifetime access, 12 months of updates. $79, once.
Not legal advice. This is a readiness aid that grades your transparency process from your own marks. It is date-agnostic and people-blind: it encodes no statute’s deadline, grades a decision system rather than any person, files nothing, and renders no compliance ruling. Automated-decision duties (the CCPA ADMT rules, Colorado SB 26-189, GDPR Article 22, ECOA/FCRA adverse-action) vary by jurisdiction and change often — confirm which apply to you and every deadline with qualified counsel.
Sold by RedHub AI LLC · Secured by Stripe · redhub.ai