TL;DR: Ask every HR software vendor where its AI processes your data, whether personal information reaches the model, and whether your data trains it. Then ask who can see AI output, whether you can switch AI off, what needs human approval, and which standards it is certified to. Get the answers in writing, because your cyber team will ask for them.
Key takeaways
- According to the Australian HR Institute, 68 per cent of Australian organisations now have formal policies or guidelines for AI use, so vendors are being checked against those rules.
- According to Jobs and Skills Australia, cited by AHRI, 21 to 27 per cent of employees use AI without their manager knowing. That makes an approved, governed tool worth more.
- The Office of the Australian Information Commissioner says privacy obligations apply to any personal information put into an AI system, and to AI output that contains it.
- “Does personal information reach the model?” deserves a field-by-field answer, feature by feature. A blanket “no” is worth checking.
- Following a standard and being certified to it are different claims, and your auditor will ask for the certificate.
Why are AI questions now part of buying HR software?
AI questions are now part of buying HR software because AI in an HRIS reads the most sensitive data an employer holds. Many buyers now bring an AI policy, a vendor assessment form or a cyber team with veto into the evaluation. So the questions often arrive from outside the room, and the People and Culture lead has to relay them.
That shift is recent and fast. According to AHRI’s Quarterly Australian Work Outlook for the December quarter 2025, 68 per cent of organisations have formal policies or guidelines for AI use. Three-quarters are also training staff to use AI at work. Those policies usually name which tools are allowed, and a new HR system is one more tool to approve.
Meanwhile, shadow AI makes the question sharper. AHRI reports a Jobs and Skills Australia finding that 21 to 27 per cent of employees use AI tools behind their managers’ backs. As a result, an HR system with governed AI can reduce risk rather than add it, but only if its answers hold up.
Suppose your HR lead has chosen a preferred vendor and the IT provider sends back six questions about AI. If the vendor answers vaguely, the purchase stalls for a month. However, if the vendor answers in writing and in detail, the IT review takes a week.
Where does your employee data go when HR software uses AI?
When HR software uses AI, your employee data usually travels from the vendor’s system to a model provider, which returns an answer. So ask three things: where your data is stored, which company’s model processes it, and whether that company can keep or learn from it. A good answer names a country, a provider and a contract term.
Where is AI processing done, and where is our data stored?
Storage and processing can happen in different places. For instance, a vendor may store your records in Australia while its model provider processes requests offshore. Under Australian Privacy Principle 8, an organisation must take steps to protect personal information before disclosing it overseas. Therefore ask for the storage location and the processing location as two separate answers.
A weak answer is “the cloud”. By contrast, a strong answer names the storage country, the model provider and where that provider processes requests.
Does personal information ever reach the AI model?
This is the question that separates vendors. Some AI features work on pseudonymised data, with names swapped for internal IDs and restored on screen. Others send names, positions and compliance status to the model, because they need them to answer “who has not signed their contract?”. Both designs can be reasonable, but you need to know which one you are getting.
So ask for the answer per feature, and ask for the fields. “Summaries never see personal information” and “the assistant sends names and positions” can both be true in one product. In addition, ask what the vendor never sends, such as pay, bank details, tax file numbers and dates of birth.
Is our data used to train the model?
A good answer is a plain no, written into the contract as well as on a web page. Also ask whether the model provider keeps prompts, for how long, and for what purpose. Then read the contract clause, check it matches the web page, and file both with your assessment.
Who can see what the AI produces?
AI output about a person is a new kind of record, and different features show it to different people. Ask which roles see each AI output, whether AI respects the same permissions as the rest of the system, and whether generated content is marked as generated. A good answer names roles per feature, not “it follows your permissions”.
Which roles can see AI output about an employee?
Consider two features in one system. A summary of a whole review cycle that only account owners see carries one level of risk. By comparison, a summary of one employee’s review that the employee and their manager also see carries another. Both are fine, provided you know which is which before managers start using them.
Does the AI respect the same permissions as everything else?
An AI assistant should never reveal anything the person asking could not see by clicking around the system. Ask how the vendor enforces that, test it with a low-access account, and compare the answers with an admin’s. Enforcement in the system’s own permission model is stronger than an instruction in the AI’s prompt.
Is AI output marked, and can you trace it?
Ask whether AI content is visibly marked as generated, whether it records the model used, and whether answers link back to the underlying record so a person can check them.
What control should you have over AI in your HR system?
You should be able to switch AI off for the whole organisation, and ideally feature by feature. For any AI that takes actions, you should also know exactly what needs a person to confirm it first. A good answer names who holds the switch, what it covers, and which actions wait for confirmation.
Can we switch AI off?
Some organisations decide not to use AI at all, at least for now. That decision should be yours, and it should take one setting rather than a support ticket. Ask who controls the setting, what it covers, and whether switching it off also stops data leaving for the model.
Can the AI take actions, or only answer questions?
AI in HR software is moving from answering to acting: drafting paperwork, starting a review cycle, creating a workflow or updating a record. That is useful, because answering “who hasn’t completed their review?” is only half the job. However, an action changes your records, so ask what requires confirmation, whose permissions the action runs under, and whether it is logged. The guide to AI agents for HR covers what to insist on before one acts.
How do you test a vendor’s AI for accuracy and bias?
Ask what stops the AI inventing people, figures or policies, and what keeps protected attributes out of anything it writes about employees. A good vendor describes checks that run before output is shown, not just a disclaimer. Then test it yourself during the demo with questions whose answers you already know.
For instance, ask the assistant about a person who does not exist. A well-built tool says it cannot find them rather than inventing a record. Similarly, ask for a summary where you know the underlying data is thin. The honest result is “not enough data”, not a confident paragraph.
On bias, ask whether summaries are screened for protected-attribute terms such as age, gender, disability or ethnicity. Ask what happens when a check fails. The best answer is that the system blocks the output, logs the failure and shows nothing at all.
What should you ask about certification and AI governance?
Ask which security and AI standards the vendor is certified against, as opposed to “aligned with” or “following”. The two most relevant are ISO/IEC 27001 for information security and ISO/IEC 42001 for AI management. If your procurement requires certification, ask for the certificate and its scope, because your auditor will.
According to ISO, ISO/IEC 42001, published in December 2023, is the world’s first AI management system standard. It sets out requirements for establishing, running and continually improving an AI management system. ISO/IEC 27001 covers information security management more broadly.
The distinction that matters is between following a standard and being certified to it. A vendor can build its processes around ISO controls without an external audit, and many smaller vendors do exactly that. That can be perfectly adequate for your risk level. Even so, it is a different claim from certification, and a buyer whose policy requires a certificate should treat them differently.
How should you run these questions during an evaluation?
Send the questions in writing before the demo, ask who in your organisation signs off, and ask the vendor to complete your own assessment form if you have one. Then score every vendor’s written answers side by side. Verbal answers on a call are hard to relay and easy to misremember.
In practice, three people often need the answers: the HR lead running the evaluation, an IT or cyber reviewer, and sometimes an AI committee. Each wants a different format, so ask early. The broader HR software evaluation checklist covers the non-AI half of the same process, from payroll sync to reference calls.
| Question | What a good answer includes |
|---|---|
| Where is data stored, and where is AI processed? | A storage country, a named model provider and its processing location |
| Does personal information reach the model? | An answer per feature, with the fields sent and never sent |
| Is our data used for training? | A plain no, in the contract |
| Who sees AI output? | Roles named per feature |
| Does AI respect permissions? | Enforced by the permission model, not by prompting |
| Is AI output marked and traceable? | A visible marker, the model recorded, links to source records |
| Can we switch AI off? | One setting, and who controls it |
| What needs confirmation? | Every action that changes a record |
| What stops invented answers? | Checks before display, and honest “not enough data” results |
| Which standards are you certified to? | The certificate and its scope, or a clear “not certified” |
What does a field-level answer look like?
As an example of the field-level answer worth asking for, here is how Worknice answers the data questions. Customer data is processed in Worknice and stored locally in Australia. AI summaries are processed using Anthropic models. Those models never receive personal information, and customer data is not used to train them. Ask Worknice, the assistant, works differently. Ask Worknice is processed using Anthropic models, and customer data is not used to train them. To answer a question, Ask Worknice sends the model work details such as names, positions, employment dates, and compliance and paperwork status. It never sends remuneration, bank, tax or superannuation details, emergency contacts, contact details, dates of birth or addresses.
On certification, Worknice maintains ISO certification security standards. We are not certified as yet. So Worknice suits mid-sized Australian organisations that want AI answering questions from their own HR records, with fields disclosed and actions confirmed. By contrast, a buyer whose procurement policy requires ISO/IEC 27001 or ISO/IEC 42001 certification today should shortlist vendors that hold it. For the wider choice, see the guide to the best HRIS for mid-sized companies.
Frequently asked questions
What questions should I ask an HR software vendor about AI and employee data?
Ask where data is stored and processed, whether personal information reaches the model, and whether your data trains it. Then ask who sees AI output, whether AI follows the system’s permissions, and whether you can switch it off. Finally, ask what needs human confirmation and which standards the vendor is certified against.
Is it safe to use AI in HR software?
It can be, if you know what the AI sees and who sees its output. The OAIC says privacy obligations apply to personal information put into AI and to output containing it. So safety depends on the vendor’s answers: fields disclosed, permissions enforced, no training on your data, and a way to switch AI off.
What is the difference between ISO 27001 and ISO 42001?
ISO/IEC 27001 is the international standard for information security management. ISO/IEC 42001, published in December 2023, is the first international standard for managing AI systems, covering risk, transparency and oversight. A vendor can follow either standard without being certified, so ask for the certificate if your procurement requires one.
Should AI in HR software be able to take actions on its own?
AI in HR software can usefully draft paperwork, start a review cycle or update a record. However, anything that changes a record or reaches an employee should wait for a person to confirm it. The action should also run under that person’s permissions and be traceable, so you can see who asked for it.
Does HR software have to store data in Australia?
Australian law does not generally require HR data to be stored onshore. However, Australian Privacy Principle 8 sets out steps an organisation must take before disclosing personal information overseas. Many buyers therefore prefer Australian storage, and many internal policies require it. Check your own policy, then ask vendors where data is stored and processed.
About the author
Graham Martin is Co-founder of Worknice, an Australian HRIS built for mid-to-large organisations. He has spent more than a decade working with Australian People and Culture teams on HR systems, compliance and payroll integration, including many software evaluations from the buyer’s side of the table.
Related reading
- HR software evaluation checklist for Australian teams
- Best HRIS for mid-sized companies in Australia
- Switching HR systems without losing your data
- Security and privacy at Worknice
Sources
- Australian HR Institute. “Quarterly Australian Work Outlook, December Quarter 2025.” AHRI, November 2025. https://www.ahri.com.au/resources/hr-research/ahri-quarterly-australian-work-outlook-december-2025
- Junkeer, Amanda. “Around 1 in 4 employees are using AI tools without telling their managers.” Australian HR Institute, 19 January 2026, citing Jobs and Skills Australia. https://www.ahri.com.au/articles/1-in-4-employees-use-ai-without-telling-managers
- Office of the Australian Information Commissioner. “Guidance on privacy and the use of commercially available AI products.” OAIC, 21 October 2024, updated 17 January 2025. https://www.oaic.gov.au/privacy/privacy-guidance-for-organisations-and-government-agencies/guidance-on-privacy-and-the-use-of-commercially-available-ai-products
- Office of the Australian Information Commissioner. “Australian Privacy Principles quick reference.” OAIC. https://www.oaic.gov.au/privacy/australian-privacy-principles/australian-privacy-principles-quick-reference
- International Organization for Standardization. “ISO/IEC 42001:2023, Information technology, Artificial intelligence, Management system.” ISO, December 2023. https://www.iso.org/standard/42001