Compliance

Quarterly Compliance Update: Fall 2026

This quarter’s compliance article roundup highlights the latest updates from the federal government and a common theme: AI, cybersecurity, privacy, and employment practices are becoming increasingly interconnected compliance risks.

 

Employers are facing greater expectations around governance, documented controls, human oversight, and protection of sensitive information.

 

Additionally, as AI experiences increased scrutiny, the value of an evolving compliance program remains a consistent safeguard.

NATIONAL UPDATES

 

Federal Regulatory Views on Cybersecurity and AI Amidst a Growing Threat Landscape

 

On September 2-3, 2026, the Department of Health and Human Services (“HHS”) Office for Civil Rights (“OCR”) and the National Institute of Standards and Technology (“NIST”) hosted the Safeguarding Health Information: Building Assurance Through HIPAA Security 2026 conference.

 

Epstein Becker Green (“EBG”) was fortunate to attend and, below, shares takeaways in three key areas highlighted at the conference.

 

  • Update on Federal Viewpoints on AI Oversight

 

A clear cross-agency AI theme emerged during the conference: Trustworthiness continues to serve as an organizing principle for federal AI oversight in health care. NIST, the Food and Drug Administration (“FDA”), the HHS Office of the National Coordinator for Health Information Technology ONC (“ONC”), and OCR each signaled attention to trustworthy AI, positioning it as the connective tissue linking security, safety, and privacy obligations across the health data ecosystem.

 

Two key themes stood out.

 

First, ONC’s remarks centered on governance, echoing HHS’s newly released AI Strategy. As we previously explored here, HHS’s five-pillar AI Strategy elevates “Governance and Risk Management for Public Trust” as its lead pillar, formalizing a department-wide AI Governance Board and an “outcomes-first,” use-case-driven approach to adoption. ONC’s remarks reinforced that governance — not just technical safeguards — will anchor how health AI is deployed and overseen going forward.

 

Second, NIST panelists previewed the ongoing refresh of the NIST AI Risk Management Framework (“AI RMF”), still anchored in the concept of “trustworthiness” first codified in the National Artificial Intelligence Initiative Act of 2020 (“NAIIA”). Since its inception, as we discussed here, we have been tracking how the NAIIA impacts AI governance in the public and private sectors. In particular, the NAIIA directed NIST to develop voluntary standards and a risk management framework built around trustworthy AI — privacy, security, bias testing, and robustness among its pillars. NIST’s continuing maturation of the AI RMF, including sector-specific profiles, keeps that statutory trustworthiness mandate at its core.

 

Together, these themes suggest OCR’s HIPAA Security enforcement priorities will increasingly intersect with NIST, FDA, and ONC's parallel efforts to operationalize trustworthy AI across health care.

 

Click Here for the Original Article

Key Points

How Medusa Gets In, and Who It Hits

  • Medusa has hit 500+ victims, with healthcare the most targeted sector.
  • Attackers exploit unpatched software, sometimes within 24 hours of a vulnerability.
  • Access brokers sell entry to Medusa, which then extorts victims twice.

Medusa Ransomware Hitting Healthcare Industry’s Unpatched Software Vulnerabilities

On August 18, 2026, the Cybersecurity & Infrastructure Security Agency, Federal Bureau of Investigation, and U.S. Department of Health & Human Services issued an update to a previous advisory to the health care industry warning against Medusa ransomware. The advisory provided tactics, techniques, and procedures as well as the indicators of compromise gathered to assist with response and remediation.

Medusa ransomware has been hitting the healthcare space particularly hard, but it’s also affecting the defense industry, critical manufacturing information technology, and financial services.

The advisory outlines how Medusa is a ransomware-as-a-service (RaaS) variant that was first identified in June 2021. Since its inception, Medusa developers and affiliates have hit over 500 victims, including “medical, education, legal, insurance, technology, and manufacturing.”

Although Medusa originally operated as a closed organization, since 2023 it has developed into an affiliate model, selling RaaS to affiliates that are paid different amounts depending on their experience and how effective they are in extorting victims. Medusa is a double extortion program, where they deploy ransomware to decrypt data, then extort victims for payment to decrypt and suppress publication of the data.

Medusa recruits access brokers in cybercriminal forums and marketplaces. The access brokers are the ones who attack the company through phishing campaigns, or exploit unpatched software vulnerabilities, including ScreenConnect, Fortinet, Fortra, and BeyondTrust. They pay the access brokers between $100 and $1 million to break into the company and sell that access to Medusa operators. They leverage new vulnerabilities within 24 hours and sometimes before they are announced. Once in, the access brokers use legitimate tools to cover their tracks to give them time to sell their wares to Medusa (and other ransomware gangs). Medusa then uses legitimate remote monitoring software to evade detection to exfiltrate data, deploy the ransomware, and extort the victim.

Click Here for the Original Article

 

Employment AI Tools Raise New Bias, Privacy, and Compliance Challenges

As employers adopt artificial intelligence (AI) tools throughout the employee lifecycle, they must address evolving local, state, federal, and supranational requirements governing bias, privacy, transparency, and potential discrimination risks, while also providing meaningful human oversight.

There is an ever-increasing number of exciting AI tools that are available to companies to perform employment-related tasks, such as recruiting, hiring, employee evaluations, evaluating employee productivity and safety programs, and even offboarding employees. For example, AI tools can screen applications, parse resumes, rank candidates, create employee evaluations, evaluate pay equity, monitor drivers for fatigue, and spot fake candidates.

There are numerous advantages to using these technologies, but there is an important analysis that must be conducted when the AI is replacing human decision-making. If the technology will rank candidates and the professional who oversees reviewing resumes is unable to review all resumes, then the AI has effectively chosen the individuals who are eligible for the job. This would mean that the human decision-maker has been replaced by AI. Notably, however, many laws are not limited to tools that fully replace a human decision-maker; some also reach tools that substantially assist, materially influence, or facilitate human decisions.

Click Here for the Original Article

Cisive. Screen Smarter, Hire Safer. Get the Right Talent to Drive Your Success. Speak to an expert.Undetected HR Identity Fraud Compromises Company Networks

 

Our clients are increasingly experiencing HR identity fraud—when an imposter (sometimes from a foreign adversary nation like North Korea) poses as a candidate for a remote job, often in the information technology space, in order to obtain access to company information or divert funds for a nefarious purpose.

 

The website Hypr recently issued its “first annual report analyzing hiring and employee fraud in 2026.” The 2026 State of HR Identity Fraud Report outlines the increase of hiring fraud and identifies that a shocking 98% of the 500 U.S. HR executives surveyed “have experienced candidate fraud firsthand.” The report examines how HR identity fraud is detected, how long it takes to identify it, and how to mitigate the risk through established processes.

While 90% of HR leaders have heightened concern over hiring fraud in the last two years, surprisingly, 68% of hiring fraud is discovered by a basic gut instinct—that is, when someone in the process felt something was “off,” as opposed to having established security controls in place.

 

The survey showed that 42% of cases are not caught pre-hire, and that “less than 3% are flagged the same day.” In addition, only a third are detected between one and three days, “45% require four to six days, and 20% go undetected for up to three weeks, averaging 5.73 days of unmonitored access.” This means that “by the time a red flag is raised, the fraudulent hire has already been provisioned with corporate credentials and internal network access.”

 

Click Here for the Original Article

 

Don’t Text Without a Compliance Strategy - Getting Mobile Messaging Right

 

Mobile messaging is a necessity for any business. Customers and consumers prefer text messages and read them more than other forms of messages.

 

However, mobile messaging can present significant risks and liabilities. Compliance with federal and state legal requirements for mobile messaging, including the Telephone Consumer Protection Act (TCPA) and state marketing laws, is essential before undertaking any messaging campaign.

 

TCPA damages are statutory—ranging from $500 to $1,500 per unauthorized message—a number that can grow large when violations are aggregated into a potential class action lawsuit. State laws add an additional layer of complexity and compliance risk.

 

Managing the Risk: Obtain Prior Express Consent for Messaging

 

Always obtain “prior express consent” before undertaking a messaging campaign. The type of “prior express consent” depends on several factors:

 

  • The telephone line being contacted (Wireless vs. Wireline)
  • The method of delivering a message (Automated Systems vs. Manual)
  • The purpose of the communication (Marketing vs. Informational)
  • The sender's identity (e.g. health care providers, package delivery companies, financial institutions) and frequency of contact
  • The called party’s location and specific state-level exceptions

 

Advertising or marketing communications require “prior express written consent,” while other types of communications require “prior express consent.”

 

Click Here for the Original Article

STATE, CITY, COUNTY AND MUNICIPAL UPDATES

 

Key Points

States Are Still Enforcing Disparate Impact

  • Fourteen state AGs jointly reaffirmed disparate impact liability on September 17.
  • The guidance rests on Title VII and Griggs, not new authority.
  • Employers must still prove neutral hiring practices are job-related.

Fourteen States Remind Employers: Disparate Impact Enforcement Is Not Going Away

 

On September 17, 2026, the attorneys general (AG) of fourteen states issued joint guidance reaffirming that disparate impact liability remains lawful, constitutional, and enforceable under both state and federal law. The guidance responds directly to the federal government’s efforts over the past two years to narrow or eliminate disparate impact enforcement and signals those states’ commitment to continuing to enforce civil rights laws under disparate impact theories.

 

What the States’ Guidance Says

 

The guidance—issued by the AGs of California, Delaware, Hawaii, Illinois, Maryland, Massachusetts, Michigan, Minnesota, Nevada, New Mexico, New York, Oregon, Vermont, and Washington—does not claim to be and is not new authority. Rather, the core legal argument underlying disparate impact theory is already familiar. Title VII of the Civil Rights Act of 1964 recognizes two forms of unlawful discrimination: intentional discrimination and disparate impact. The disparate impact theory of liability traces to Griggs v. Duke Power Co., where the Supreme Court of the United States held that facially neutral employment practices that exclude a protected group are unlawful if the employer cannot show they are job-related. That framework is statutory. It has not been repealed.

 

While the guidance acknowledges that some more recent Supreme Court decisions, including Alexander v. Sandoval, have narrowed who can enforce disparate impact protections and in what forum, the states argue those decisions “do not disturb the legality of disparate impact liability itself.”

 

Click Here for the Original Article

 

 

CCPA Cybersecurity Audits Are Coming: What Companies Should Do Now

 

The California Consumer Privacy Act’s (CCPA) cybersecurity audit requirement marks a significant shift in privacy and security accountability. Beginning January 1, 2027, covered businesses will need to complete annual, independent, evidence-backed cybersecurity audits showing that their privacy and security controls are not only designed appropriately but operating effectively over time. For many companies, this will be the first recurring, regulator-visible audit cycle that ties cybersecurity governance, privacy compliance, executive accountability, and legal defensibility together. Businesses that meet the applicable revenue and data-processing thresholds, including those processing large volumes of Californians’ personal information or sensitive personal information, should be preparing now, because the first audit period is quickly approaching.

 

These audits will require more than a technical controls review. Covered businesses will need to define audit scope, identify relevant systems and data flows, assess third-party and vendor access, document control performance, and support scoping decisions with clear evidence. Legal teams, privacy leaders, security, technology, compliance, and business stakeholders should be aligned early on what is in scope, what evidence will be used, who will own remediation, and how decisions will be documented. Chief legal officers and legal departments have an important role to play here: helping the business interpret regulatory expectations, pressure-test assumptions, assess whether auditor independence requirements are met, and frame the organization’s risk posture in a way that can withstand external scrutiny.

 

Companies can start by revisiting their data maps, identifying systems that collect, store, transmit, or provide access to California residents’ personal information, and comparing existing cybersecurity frameworks against the CCPA’s required audit domains. Organizations with mature compliance programs may have a head start, but even well-resourced companies should expect meaningful work around documentation, evidence standards, remediation tracking, and executive certification. The key is to move from “we have a program” to “we can prove the program works.” By 2027, the CCPA cybersecurity audit requirement will not be just another compliance milestone, it will be a credibility test for how well companies understand, govern, and protect the personal information they hold.

 

Click Here for the Original Article

 

ShinyHunters Hits Florida DMV Database

 

Ransomware group ShinyHunters alleges on its online platform that it has compromised the Florida Department of Motor Vehicles’ Driver and Vehicle Information Database (DAVID) and stole the DMV records of over 200,000 individuals. The threat actor posted a screenshot of Jeffrey Epstein’s DMV record as proof.

 

The DAVID records of drivers include their name, address, Social Security number, birthdate, driver’s license ID, and other information. ShinyHunters told BleepingComputer they “breached DAVID through a password-reset flaw that let them compromise multiple accounts in the system. These accounts allegedly belonged to DMV employees and an FBI agent.” ShinyHunters no longer has access to the database and the “password-reset flaw used to compromise accounts is being patched.”

 

Click Here for the Original Article

Florida Court Reinforces Employer’s Ability to Enforce Marijuana Policies in Public Union Contract

 

On July 29, 2026, Florida’s Second District Court of Appeal (Second DCA) ruled that a county was not legally obligated to accommodate a firefighter-paramedic’s off-duty medical marijuana use under state law. Many Florida employers had been closely watching the status of the appeal as it could have significantly shifted accommodation requirements for medical marijuana in the state.

 

Recreational marijuana use remains illegal in Florida, but medical marijuana use is lawful for adults ages twenty-one and older with a valid Medical Marijuana Use Registry card for a qualifying medical condition. Increasingly, employees have sought to utilize the Americans with Disabilities Act (ADA) or the Florida Civil Rights Act (FCRA) to claim that their personal symptoms or limitations qualify as disabilities for which employers must accommodate medical marijuana usage.

 

In February 2019, Angelo Giambrone, a firefighter-paramedic for Hillsborough County’s fire department, tested positive for marijuana during a random drug test. He presented his employer with a valid medical marijuana card. He argued that his union contract permitted employees like him to present a medical marijuana card as evidence of a prescription medication authorized under state law, thereby providing a defense to an adverse employment action.

 

The county placed him on unpaid administrative leave and reported him to the Paramedic and EMT licensing board, which dropped its investigation based on his status as a medical marijuana cardholder.

 

Giambrone then sued, raising four claims: failure-to-accommodate under the FCRA, wrongful termination, failure to update the county’s drug-free workplace policy to comply with Florida’s constitutional amendment allowing medical marijuana, and breach of contract claim under the CBA. The county argued that a medical marijuana card does not exempt employees from complying with the CBA, the county’s drug-free workplace policy, and federal law, which bans marijuana use.

 

In December 2024, the trial court sided with Giambrone on every count. The Thirteenth Judicial Circuit Court of Florida ruled that the Florida Constitution requires a public employer to accommodate an employee’s off-duty, off-site medical marijuana use to treat a disability. This was in part because Giambrone’s EMT license was controlled by the state.

 

The opinion further pointed to the CBA’s language allowing employees to report the use of prescription medications authorized under both federal and state law upon testing positive on a drug test, finding that medical marijuana is akin to a prescription medication despite being illegal under federal law. It also entered a broad, forward-looking order that required the county to accommodate any employee who presented a medical marijuana card after a positive test, so long as there was no proof of on-duty use or impairment on the job.

 

Click Here for the Original Article

 

New Jersey Bans Sale of Sensitive Data and Creates Public Registry for Data Brokers and Collectors

 

On June 30, 2026, in a move that mostly went under the radar, just two days after being introduced in the state’s Assembly, New Jersey Governor Mikie Sherrill signed into law legislation (Assembly Bill 5328 (A5328)) that outright bans the sale of sensitive consumer data without regard to the type of business at issue with limited exceptions, and also creates a registration requirement for New Jersey data brokers.

 

A5328 is one of the most expansive bans in the country regarding the sale of sensitive data, and may lead to unintended consequences with legitimate uses of sensitive data caught up in the broad prohibition language and the significant penalties. A5328 bans the sale of “sensitive data,” which is defined as personal data that reveals information about an individual’s:

 

“… racial or ethnic origin; religious beliefs; mental or physical health condition, treatment, or diagnosis; financial information, which shall include a consumer’s account number, account log-in, financial account, or credit or debit card number, in combination with any required security code, access code, or password that would permit access to a consumer’s financial account; sex life or sexual orientation; citizenship or immigration status; status as transgender or non-binary; genetic or biometric data that may be processed for the purpose of uniquely identifying an individual; personal data collected from a known child; or precise geolocation data.”

 

Not limited to data brokers and data collectors alone, A5328 further modifies a portion of the New Jersey Data Protection Act, N.J.S.A. § 56:8-166.12, stating that individuals or entities may “not sell sensitive data, which shall apply to all individuals or legal entities regardless of the number of consumers whose data the individual or entity controls or processes.” Violators are subject to steep civil penalties of $50,000 “for each record sold, offered for sale, or licensed.”

 

A5328 maintains certain exceptions for the use of sensitive data. Among these exceptions, it does not limit the collection of protected health information by entities covered under the Health Insurance Portability and Accountability Act (HIPAA) and financial institutions and affiliates covered under the Gramm-Leach-Bliley Act.

 

Click Here for the Original Article

 

New York State Grants Employees the Right to Access Personnel Files

 

New York State has enacted a law granting employees the right to access their personnel records, receive notice when negative information is added, and submit written rebuttals. The law, which is expressly modeled on Massachusetts’s Personnel Record Law, takes effect on November 8, 2026.

 

On September 9, 2026, Governor Kathy Hochul signed Senate Bill S3460, adding new Section 210-b to the New York Labor Law. The law applies to both private- and public-sector employers and extends access rights to current and former employees alike. According to the governor’s office, New York now joins at least seventeen other states with a personnel-file access requirement.

 

Governor Hochul signed S3460 at the state’s annual Labor Appreciation Reception at the City University of New York’s (CUNY) School of Labor and Urban Studies, underscoring the labor-friendly legislative environment in Albany ahead of the upcoming gubernatorial election. The law takes effect on the sixtieth day after signing, or November 8, 2026.

 

Click Here for the Original Article

 

TRAIGA: Texas’s New AI Law Now in Effect

 

On January 1, 2026, Texas’s newest law addressing the growing issues of data privacy and the use of Artificial Intelligence went into effect. The Texas Responsible Artificial Intelligence Governance Act (TRAIGA) was passed by the 89th Texas Legislature and signed into law by Gov. Greg Abbott in 2025.

The law’s central focus is on restricting and regulating the use of Artificial Intelligence (AI) systems in Texas, which includes adding new prohibitions and requirements on anyone who develops or deploys AI systems in the private sector.

Under TRAIGA, private entities are prohibited from developing or deploying AI systems in a manner that:

 

  • Intentionally aims to incite or encourage a person to commit physical self-harm (including suicide), harm another person, or engage in criminal activity;
  • Serves the sole intent of producing, assisting or aiding in producing or distributing child pornography or certain sexually explicit “deep fake” videos or images;
  • Impairs a person’s individual rights guaranteed under the U.S. Constitution; or
  • Unlawfully discriminates against a protected class in violation of state or federal law.

 

TRAIGA also prohibits governmental entities from using or deploying AI systems for uniquely identifying a specific individual using biometric data or gathering images or other media without the individual’s consent if such gathering would infringe on the individual’s rights, as well as barring “social scoring” by government entities to evaluate or classify people based on social behavior or personal characteristics, or developing or deploying such systems for the purpose of identifying individuals using biometric data or data from the internet or other public sources without the individual’s consent.

 

Click Here for the Original Article

INTERNATIONAL UPDATES

Key Points

Global Rules Are Raising the Stakes for Employers

  • Red Notices aren't arrest warrants; extradition depends on local law.
  • EU AI recruitment tools require impact assessments and effective human oversight.
  • Belgium's new law may require licensing for in-house workplace investigations.

Interpol Red Notices and Extradition: What Happens After an International Alert

 

An INTERPOL Red Notice is one of the most powerful and most frequently misunderstood tools in international law enforcement cooperation. It is often described in the media as an “international arrest warrant,” but that characterization is not accurate. A Red Notice is not a warrant and, by itself, does not automatically authorize an arrest in most jurisdictions.

 

In practical terms, a Red Notice is a request circulated through the INTERPOL network asking law enforcement authorities worldwide to locate and provisionally arrest an individual, pending extradition or similar legal proceedings.

 

What happens next is not automatic. It depends on a combination of legal and practical factors, including:

 

    • the domestic law of the country where the individual is located
    • whether an extradition treaty exists between the relevant countries
    • the nature of the alleged offense
    • the level of judicial safeguards in the requested state
    • the availability of legal defenses, including political-offense protections

 

For executives, investors, international professionals, and individuals facing cross-border exposure, understanding how INTERPOL alerts interact with extradition law is not just helpful—it is essential to assessing real-world risk.

 

Click Here for the Original Article

 

Deployment of AI Recruitment Tools in the EU: Employer Obligations Under GDPR and EU AI Act

At a time when the regulation of artificial intelligence (AI) is a topic of hot debate Spain’s data protection authority, the Agencia Española de Protección de Datos (AEPD), has stepped in to remind organizations of their legal obligations under the General Data Protection Regulation (GDPR) and EU AI Act.

The AEPD recently issued a formal preventive warning to an organisation that was preparing to deploy an AI recruitment tool that would screen and evaluate job applications, and existing employee applications for internal mobility.

The AEPD acknowledged that AI can improve the efficiency and quality of hiring processes, although it stressed that data protection safeguards must be embedded from the very outset, reflecting the GDPR principle “data protection by design and by default.”

The AEPD highlighted several specific legal requirements when it comes to deploying an AI recruitment tool. Organisations must undertake a Data Protection Impact Assessment (DPIA) before the tool is used, where the processing is likely to result in a “high risk” to individuals’ rights and freedoms. Candidates and employees must receive clear and comprehensible information about how their personal data will be processed and the role the AI tool will play in evaluating them. Human oversight of outcomes is required by both the GDPR and the EU AI Act. This must be “effective,” meaning the decision-maker must be able to critically assess the score or output generated by the system and reach their own independent conclusion, rather than simply rubber-stamping the AI’s recommendation.

Click Here for the Original Article

 

No trench coat required: Belgium’s new rules on workplace investigations

On 16 December 2024, Belgium’s Private Investigations Act (the “PIA”) entered into force, replacing the Private Detectives Act of 1991. While this may sound like news for the detective industry only, the scope of the PIA is considerably wider. In fact, the most significant innovation in the PIA does not concern private detectives at all, but the companies that instruct them. Any business that conducts workplace investigations in-house may fall within the scope of the PIA and become subject to licensing requirements and procedural obligations.

What counts as a private investigation under the PIA?

The PIA defines private investigation activities by reference to four cumulative criteria. Such activities must:

    • be carried out by a natural person;
    • be undertaken on behalf of a principal;
    • involve the gathering of intelligence obtained by the processing of information about natural or legal persons, or the circumstances concerning acts committed by them; and
    • be carried out for the purpose of providing that intelligence to the principal, either to safeguard the principal’s interests in the context of an actual or potential conflict, or to trace missing persons or lost or stolen goods.

This definition is sufficiently broad to capture most internal investigations within companies. For example, when an employer investigates suspected fraud, theft, harassment or other misconduct by an employee, it is gathering information about a person in order to safeguard its interests in the context of an actual or potential conflict. Where such activity is organized on a structural basis, which is already the case where investigative tasks form part of the job description of a single employee, the business operates an “internal investigation service” within the meaning of the PIA.

Investigations that are carried out by a group function on behalf of affiliated companies within a multinational group are treated as being carried out for the business’s own purposes rather than for third parties. As a result, compliance, internal audit, security and HR teams investigating matters involving employees in Belgium may need to comply with the PIA, even where the relevant investigation function is located outside Belgium.

Not all workplace investigations undertaken by an employer fall within the scope of the PIA. Certain activities are excluded, including the typical reference checks by HR on job applicants as well as investigations carried out in performance of a legal obligation. This may include some whistleblowing investigations, provided they fall strictly within the scope of the Belgian Whistleblowing Act. The scope of this Act is quite narrow however and in practice many employers operate reporting channels that cover a broader range of concerns than the legislation requires. Furthermore, investigations that start with a report of whistleblowing regularly expand beyond that. If an investigation goes beyond what is required to discharge the relevant legal obligation, or where matters fall outside the scope of an applicable exclusion, full PIA compliance may be required.

 

Click Here for the Original Article

 

 

Managing Compliance in the AI Era

 

As compliance programs are forced to evolve with the ongoing shifts in legislation and AI-driven change, the strongest takeaway is a shift from having compliance policies to being able to demonstrate effective governance and controls.

 

AI-assisted employment decisions, cybersecurity, sensitive-data handling, and internal investigations are increasingly areas where organizations need documented accountability and meaningful human oversight.

 

Cisive helps you stay ahead of regulatory change, reinforce your compliance programs, and mitigate risk across the talent lifecycle. With proven expertise in background screening and global compliance, we help employers eliminate blind spots and hire with confidence.Lets Build a Smarter Screening Strategy Together

 

Ready to get started?

Book time with one of our screening experts to find out how we can streamline your talent process with a free assessment

Get your free assessment
Digital interface illustrations showing screening and hiring processes Professional woman illustration