Skip to main content
Category: Privacy and Security

Automated Decision-Making

Also known as: ADM, Algorithmic Decision-Making, Automated Decision Making
Simply put

Automated decision-making (ADM) is the use of data, algorithms, and computer systems to reach decisions, either entirely without human involvement or with only partial human input. It is applied across contexts such as public administration and business, where systems may suggest, support, or replace decisions that a person would otherwise make. Because these systems can affect individuals significantly, they are increasingly a focus of governance and regulatory attention.

Formal definition

Automated decision-making (ADM) refers to the use of data, machines, and algorithms to make or substantially assist decisions, ranging from systems operating without human involvement to hybrid arrangements where humans retain some role. In the framing of one academic analysis, the underlying algorithms may play a suggesting, offloading, or superseding role relative to human judgment, and this distinction matters for accountability and oversight. In several regulatory contexts ADM is characterized as the processing of personal data by digital means, and specific legal instruments define narrower subsets; for example, New York City's Local Law defines an Automated Employment Decision Tool (AEDT) as a computational process used to substantially assist or replace discretionary decision-making. The precise scope, thresholds, and obligations vary by jurisdiction and instrument, and this entry does not address implementation specifics, particular tooling, or associated legal advice.

Why it matters

Automated decision-making sits at the intersection of governance, risk, and compliance because it reallocates decision authority from human judgment to computational processes, which raises questions about accountability, oversight, and control that organizations must address explicitly. When an algorithm suggests, offloads, or supersedes a decision a person would otherwise make, the governance structures that assign decision rights and responsibility need to account for where meaningful human involvement remains and where it does not. This distinction is not merely technical; it shapes who is answerable when an automated decision affects an individual.

Because ADM systems can affect individuals significantly, they have become an early focus of regulatory attention. Some legal instruments target narrow subsets of ADM: for example, New York City's Local Law defines an Automated Employment Decision Tool (AEDT) as a computational process used to substantially assist or replace discretionary decision-making in an employment context. In several regulatory contexts, ADM is characterized as the processing of personal data by digital means, which brings it within the scope of data protection obligations. The precise thresholds, definitions, and obligations vary by jurisdiction and instrument, so organizations should not assume a single universal standard applies.

For compliance and risk functions, the significance lies in identifying where ADM is in use, determining which legal instruments apply given the organization's jurisdiction and sector, and ensuring appropriate oversight and documentation. Treating ADM as an emerging regulatory target rather than a settled area is prudent, as definitions and requirements continue to develop across jurisdictions.

Who it's relevant to

Governance professionals
Those responsible for decision rights and accountability structures need to establish where automated systems suggest, offload, or supersede human judgment, and to ensure that responsibility for automated decisions is clearly assigned. The degree of human involvement in hybrid systems is central to how oversight is designed.
Compliance officers
Compliance functions must identify where ADM is in use, determine which legal instruments apply given the organization's jurisdiction and sector, and track evolving obligations. Because some instruments define narrow subsets such as New York City's AEDT and others treat ADM as the processing of personal data by digital means, the applicable requirements depend heavily on context.
Risk managers
Risk functions have an interest in the uncertainty ADM introduces, including risks arising where algorithms substantially assist or replace discretionary decisions affecting individuals. Assessing where meaningful human involvement remains helps in evaluating and treating these risks.
Legal and regulatory specialists
Given that ADM is an early target of regulatory attention and that thresholds, definitions, and obligations vary by jurisdiction and instrument, legal specialists play a role in interpreting how specific instruments define and scope automated decision-making for their organization.
Internal auditors and assurance functions
Independent assurance providers may assess whether governance and controls over ADM are designed and operating appropriately, while remaining distinct from the management activities that deploy and operate these systems.

Inside ADM

Automated Processing
The use of technology, including algorithms, rules engines, or machine learning models, to process data and reach an outcome without human intervention at the point of decision. The degree of automation may vary, and some processes retain limited human involvement.
Solely Automated Decisions
Decisions made without meaningful human involvement in the outcome. Certain data protection regimes, such as the EU General Data Protection Regulation (GDPR), give particular attention to decisions based solely on automated processing that produce legal or similarly significant effects on individuals.
Profiling
A related form of automated processing that evaluates personal aspects of an individual, such as performance, behavior, or preferences, to make predictions or classifications. Profiling may feed into an automated decision but is conceptually distinct from the decision itself.
Human Oversight
Mechanisms through which a person reviews, can intervene in, or can override an automated outcome. The presence and meaningfulness of oversight commonly determine whether a decision is classified as solely automated under applicable law.
Legal or Similarly Significant Effects
Outcomes that materially affect an individual's rights, opportunities, or circumstances, such as credit, employment, or access to services. This threshold typically triggers heightened obligations, though its precise scope varies by jurisdiction.
Transparency and Explainability
The provision of meaningful information about the logic involved and the significance and envisaged consequences of automated processing. Requirements differ across jurisdictions and frameworks and do not necessarily mandate disclosure of full source code or model internals.
Data Subject Rights and Safeguards
Rights that may attach to automated decision-making in certain regimes, which can include the ability to obtain human intervention, express a point of view, and contest a decision. Availability and scope of these rights depend on the applicable legal context.

Common questions

Answers to the questions practitioners most commonly ask about ADM.

Does automated decision-making always mean there is no human involvement at all?
Not necessarily. The term is commonly used to describe decisions made by automated processing, but practice distinguishes between decisions that are fully automated with no meaningful human involvement and those where automated tools support or inform a human decision-maker. The governance and compliance implications typically differ between these cases, and some regulatory regimes treat solely automated decisions differently from decisions involving human review. The defining question is often whether a human exercises meaningful, rather than nominal, review over the outcome.
Is automated decision-making the same thing as artificial intelligence or machine learning?
No. Automated decision-making refers to the use of automated processing to reach or materially shape a decision, and it may rely on simple rule-based logic, deterministic algorithms, or more complex statistical and machine learning models. AI and machine learning are among the techniques that can drive automated decisions, but automated decision-making does not require them, and not all AI systems produce decisions in the sense relevant here. Conflating the two can lead to scoping errors when assessing obligations.
How should an organization identify where automated decision-making occurs within its processes?
Organizations commonly begin with an inventory or mapping exercise that traces where automated processing contributes to decisions affecting individuals or the organization. This typically involves cataloguing systems, the inputs and logic they use, the significance of the resulting decisions, and the degree of human involvement. The exercise often spans the governance pillar, through decision rights and accountability, and the compliance pillar, where applicable legal obligations attach. Scope and required detail vary by jurisdiction, sector, and the potential impact of the decisions.
What controls are commonly applied to automated decision-making processes?
Controls frequently discussed include documented design and logic, testing and validation before and during use, monitoring for performance drift or unintended outcomes, mechanisms for human review or override where appropriate, and audit trails supporting traceability. Access and change management controls are also common. This entry does not prescribe specific controls for any given system; the appropriate control set depends on the risk profile, applicable requirements, and the organization's risk appetite and tolerance.
How does automated decision-making relate to the three lines model?
In many organizations, the first line owns and operates the automated processes and their associated controls, the second line may provide oversight, policy, and risk and compliance monitoring over how such systems are governed, and the third line, internal audit, provides independent assurance over the design and operation of the related controls. Maintaining the independence of assurance functions is important, so those who build or operate an automated decision system are generally not the same parties providing independent assurance over it.
What documentation is typically maintained for automated decision-making to support compliance and assurance?
Commonly maintained documentation includes descriptions of the decision's purpose and logic, data inputs, validation and testing evidence, records of human involvement or review, monitoring results, and change history. Where legal obligations apply, additional records supporting transparency, individual rights, or explainability may be expected, and these requirements vary across jurisdictions and sectors. This entry does not address specific tooling or provide legal advice on the exact records required in a given regime.

Common misconceptions

Any use of software or algorithms in a decision constitutes 'automated decision-making' subject to special legal restrictions.
Heightened obligations in regimes such as the GDPR commonly apply to decisions based solely on automated processing that produce legal or similarly significant effects. Decisions supported by tools but subject to meaningful human involvement, or without significant effects, may fall outside those specific provisions. The applicable threshold varies by jurisdiction.
Automated decision-making is purely a technology or IT matter.
It spans multiple GRC pillars. Governance sets accountability and decision rights over how such systems are deployed, risk management addresses the uncertainty and potential harms they introduce, and compliance addresses adherence to applicable data protection and sector-specific obligations. Treating it solely as a technical issue can leave these responsibilities unaddressed.
Adding a person to click 'approve' automatically removes a process from the 'solely automated' category.
Many frameworks distinguish nominal human involvement from meaningful human oversight. Where a reviewer lacks the authority, information, or capacity to genuinely alter the outcome, a decision may still be treated as solely automated. The assessment is fact-specific and context-dependent.

Best practices

Maintain an inventory of processes involving automated decision-making and profiling, recording which produce legal or similarly significant effects and which involve meaningful human involvement, so that applicable obligations can be assessed by jurisdiction.
Assign clear governance accountability for each automated decision-making system, defining decision rights, escalation paths, and ownership across the relevant business, risk, and compliance functions.
Assess and document the risks associated with automated decisions, including potential for error, bias, or harm to individuals, and treat residual risk against the organization's stated risk appetite where applicable.
Ensure human oversight is meaningful rather than nominal by giving reviewers the authority, information, and time needed to intervene in, alter, or override outcomes.
Prepare transparency information appropriate to the applicable regime, describing the logic involved and the significance and consequences of processing, without overstating what can or must be disclosed.
Engage qualified legal and data protection expertise to confirm jurisdiction- and sector-specific obligations, and keep classifications under review as systems and applicable requirements change.
Promotional banner highlighting failures found in PCI audits and how to spot the gaps