AI hiring in Singapore: current rules and practical safeguards
Separate Singapore’s current AI-hiring obligations from planned guidance, then build a decision record linking job criteria, candidate evidence and human review.
· 8 min read

Rules and guidance checked 7 October 2026.
“The AI gave them a low score” does not explain why someone was rejected. The recruiter needs to identify the job requirement, find the relevant answer and check whether the assessment is right. Singapore employers remain responsible for fair hiring when they use AI; responsibility does not move to the software supplier. MOM on AI in hiring
Start with one rejected application. Can your team show the criterion, the candidate’s evidence and the reason for the decision? Those three records make the review below possible. The legal overview comes first; the worked example shows how to use it in everyday screening.
What applies now, and what is still developing?
| Source or development | How to use it |
|---|---|
| Law: Personal Data Protection Act (PDPA) | Check the obligations relevant to collecting, using, protecting, retaining and transferring candidate data |
| Tripartite guidelines: fair employment practices | Ground recruitment in job-related, merit-based criteria, including when software assists |
| Advisory guidance: PDPC’s AI recommendation and decision systems guidelines | Use it to examine how personal data is used and what information and safeguards are appropriate |
| Advisory guidance: PDPC’s July 2026 GenAI guidelines | Check responsibilities for model providers, system providers and employers using the systems, including training-data reuse |
| Announced work: September 2026 recommendation to develop responsible-AI recruitment guidance | Track the actual published guidance; do not invent a commencement date or mandatory checklist |
| Passed legislation awaiting implementation: Workplace Fairness Act | Prepare for the framework, but check commencement notices before treating its procedures as current obligations. Passage of a law and its start date are different. MOM’s implementation explanation |
The Personal Data Protection Commission (PDPC) oversees the PDPA. The Tripartite Alliance for Fair and Progressive Employment Practices (TAFEP) provides fair-employment guidance. Use the PDPA, TAFEP guidelines and PDPC’s AI guidance as the Singapore baseline. Other jurisdictions may matter to your hiring, but a US bias-audit requirement or European automated-decision rule is not automatically Singapore law.
MOM’s 24 September 2026 announcement recommends developing responsible-AI recruitment guidance. It does not supply a finished recruitment-specific code. The planned HR AI Playbook is a separate publication; its expected Q1 2027 timing should not be used as a commencement date for recruitment rules. MOM’s announcement; programme overview
PDPC’s generative AI (GenAI) guidelines, issued 20 July 2026, already address data responsibilities across model development and deployment. They are advisory guidance on the existing PDPA, not a separate AI hiring law. PDPC GenAI guidelines, sections 1–2
Start with the job requirement, not the score
Before screening starts, write down what the person must be able to do and what evidence would support that assessment. Distinguish a necessary capability from an easy-to-search proxy.
For a customer-support role, “can explain a billing problem accurately and decide when to escalate” is a capability. “Has worked at one of these five companies” is a different criterion. An AI system cannot repair an unjustified requirement merely by applying it consistently.
Keep the criteria version with the hiring record. When a manager changes the requirement, decide whether earlier applications need another review. Otherwise two candidates may be compared against different standards without anyone noticing.
Worked example: missing evidence is not evidence of poor judgement
The role requires someone who can investigate a billing discrepancy and escalate a correction beyond their authority. An applicant says they checked an invoice and asked a supervisor to approve a correction. The missing detail is how they knew the invoice was wrong.
A focused follow-up can resolve that gap:
Recruiter: What did you find when you compared the invoice with the account history?
Applicant: The invoice used the old plan price. I found an approved plan change dated before the billing period and asked my supervisor to approve the correction.
The answer now describes an investigation and escalation. It does not establish that a refund was approved or paid. A useful review note preserves both points:
Evidence: Compared the invoice with an approved plan change and escalated the correction.
Assessment: Supports the investigation and escalation criterion.
Limit: No evidence of the final refund outcome.
Next step: Assess the remaining criteria; do not keep the original “investigation detail missing” finding.
Now compare: “I assumed the customer was right and promised a refund before checking.” This supplies evidence of a different judgement. Assess it against the same standard rather than labelling both answers “unclear”.
Ask a follow-up when a missing detail could change the decision. Update a finding that evidence is missing when the answer supplies it, then assess the answer on its merits. Do not invent the detail yourself.
Human review: check the source and the exclusions
A person clicking “approve” is not necessarily checking the assessment. Give reviewers access to the relevant source, authority to change the result and clear instructions on which cases need attention.
For a pilot, one useful instruction is: “Review the source evidence for every proposed rejection based on the new criterion. Record whether it supports the result, is incomplete or was captured incorrectly.” This is a suggested safeguard, not a statutory test.
Include rejected applications, not just the shortlist. Otherwise you cannot see who was wrongly excluded. A small sample can uncover problems; it cannot prove that the whole system is fair.
Keep technical failures separate from assessment results. An interrupted interview, missing recording or mistranscribed answer does not establish that the candidate lacks a skill. Record what failed, give a named person the next action and decide whether the candidate needs a retry or another format before treating the missing evidence as a reason to reject them.
In the supplier demonstration, use a sample answer whose test transcript contains a deliberate error. Ask the recruiter to find the original, correct the record and show what happens to the assessment and decision. A correction button is not enough if the old result still drives the next step.
Map who receives candidate data and why
Follow one application through the applicant tracking system (ATS), interview service, transcription or AI provider, reviewers and exports. For each recipient, record the purpose, access, retention and any overseas processing. Ask your privacy lead to check the contracts against that actual route—not just the supplier’s headline privacy statement.
The PDPA contains distinct obligations concerning accuracy, protection, retention and overseas transfers. Keeping a server in Singapore, obtaining a security report or promising not to train a model does not answer every one of those questions. PDPA, Part 6
Confirm the basis for each use of personal data with the person responsible for privacy. Recruitment assessment, future-role contact and model training are different uses; one broad consent statement should not stand in for that assessment. PDPC AI guidance
Is the supplier assessing candidates or training a model?
Ask this explicitly. Under PDPC’s July guidance, using a model to process data on an employer’s behalf is distinct from a provider reusing that data to develop its own model. Where consent is relied on for large-scale GenAI training or fine-tuning, a generic product-development notice is insufficient; the purpose must be AI-specific. Consent exceptions require their own assessment. PDPC GenAI guidelines, sections 4 and 7–9
Ask the supplier to put the permitted uses in writing: which records it processes to deliver the service, whether it or its model providers reuse them for training, and which contract terms or settings control that reuse. Check that the answer covers recordings, transcripts and assessments—not just the original CV. A security certification does not answer this data-use question.
What should candidates be told?
Explain the actual step before asking someone to take part. For an employer that records AI interviews and has recruiters review the assessment, a starting explanation is:
We use an AI interviewer for this first conversation. It records your answers and creates a transcript and assessment against the role requirements for our recruiting team to review. Our candidate privacy notice explains the data handling. Contact our recruiting team if you need another format or think the record is wrong.
Use this only when it describes your process. Add a working privacy-notice link and contact route. The short explanation is not a complete privacy notice or permission to train a model.
When a candidate challenges the result
Preserve the relevant record and identify where the error occurred: the original data, transcript, assessment or final decision. Correct that stage, reconsider any affected outcome and record what changed. Where the same error could affect other applicants, review those cases too; fixing one complaint may leave the underlying problem in place.
Give the candidate a named contact or team, explain what information will help the review and say when they should expect an update. Assess any statutory request separately from this suggested service process. MOM identifies TAFEP as an avenue for applicants concerned about discriminatory employment practices. MOM’s explanation
Before using the workflow on live applicants
Test three cases before launch: a supported rejection, an incomplete answer and a technical failure. The recruiter should be able to distinguish them, explain the next action and change an incorrect outcome.
Keep the privacy review alongside that test. A decision can be explainable while the underlying data use still needs attention.
Discuss a role with Screened to examine the screening workflow and the evidence a recruiter would receive. Evaluate the proposed setup against your own hiring and privacy requirements; buying a tool does not settle those questions. Employers and providers each retain the responsibilities that apply to their role.
This guide provides general information, not legal advice, a complete compliance checklist or certification of a hiring process. Examples are illustrative, not validated assessments. Requirements depend on the organisation, data use and jurisdictions involved; obtain appropriate advice before relying on the guide for a specific decision.


