Skip to main content
FORTISEU
Legal

Legal & Compliance

Transparency is the foundation of trust. Review our legal documents, data processing agreements, and compliance commitments.

All AI Systems

Peer Group Analysis

High Risk — Art. 6 + Annex III

Risk Classification Rationale

This system profiles and classifies employees as outliers based on entitlement patterns. Outlier classifications feed into access review decisions affecting employment access rights.

EU AI Act: Category 4(a) — Employment, workers management, access to self-employment

Purpose

Identify access entitlement outliers within department+role cohorts to support access governance reviews. Groups profiles by department and role, computes median entitlements per cohort, and flags profiles significantly above median.

Input Data

  • Identity profiles (department, role)
  • Identity entitlement assignments

Output Data

  • Peer group statistics (median, common entitlements)
  • Outlier profiles with prevalence percentages
  • Classification: common (>50%), review (<=50%), likely excessive (<=20%)

Model & Processing

Provider
Internal (statistical algorithm)
Model
statistical-algorithm-v1
Processing Location
EU (self-hosted)

Known Limitations

  • !Cohort grouping by department+role may create proxy discrimination if organizational structure correlates with protected characteristics
  • !Small cohorts produce unreliable statistics
  • !Does not account for legitimate business exceptions
  • !Thresholds (50%/20%) are not validated against external compliance expert judgment

Fairness Measures

  • +Minimum cohort size of 5 profiles before analysis runs
  • +Monthly monitoring of outlier detection rates by department
  • +Statistical algorithm, not ML — deterministic and reproducible
  • +Results are advisory only; no automatic consequences

Human Oversight

Outlier classifications are advisory only. No automatic access revocation based on outlier status. Results feed into access review campaigns where human reviewers make all final decisions.

Appeal Process

Employees flagged as outliers may request human review through the appeal mechanism. The compliance team reassesses entitlement assignments without algorithmic input.

Data Governance

Computed on-demand; results not persisted beyond request lifecycle. No personal data used for training. All processing within EU boundaries.

AI System Card · EU AI Act (Regulation (EU) 2024/1689) · Articles 11, 13 · Last updated: March 2026