Skip to main content
Category: Trustworthy AI Principles

Human Rights Due Diligence

Also known as: HRDD, Human rights due diligence process
Simply put

Human Rights Due Diligence (HRDD) is an ongoing process businesses use to identify, prevent, mitigate, and account for how their activities affect people's human rights. Rather than a one-time check, it is typically treated as a continuous risk management practice that a reasonable and prudent company is expected to follow. It focuses on impacts on people, and it involves acting on what is found and tracking the results over time.

Formal definition

As commonly defined in the evidence, HRDD is an ongoing risk management process through which a business assesses actual and potential human rights impacts, integrates and acts upon the findings, tracks the effectiveness of its responses, and accounts for how it addresses those impacts. It is frequently described as a management system that an organization implements incrementally and improves continuously. Note that HRDD is oriented toward impacts on rights-holders (people) rather than risks to the organization, which distinguishes it from enterprise-focused risk processes; its precise scope, legal status, and mandatory versus voluntary character vary by jurisdiction and are not resolved by the evidence provided here.

Why it matters

Human Rights Due Diligence matters because it reframes how an organization thinks about harm: instead of asking only what risks a project poses to the business, HRDD asks what impacts the business may have on people whose rights could be affected. In the context of AI governance, this outward-facing orientation is significant, because AI systems can affect individuals and communities in ways that traditional enterprise risk processes are not designed to surface. HRDD provides a structured way to identify those effects on rights-holders and to act on what is found, rather than treating human rights as a one-time compliance box.

Because HRDD is described in the evidence as an ongoing process rather than a single assessment, it also matters for how organizations sustain accountability over time. The evidence characterizes it as something a reasonable and prudent company is expected to follow, involving continuous identification, prevention, mitigation, and accounting for impacts, as well as tracking the effectiveness of responses. This continuity distinguishes HRDD from static due-diligence exercises and aligns it with the iterative monitoring that AI governance increasingly demands.

It is important to note what the evidence does not resolve. The legal status of HRDD, and whether it is mandatory or voluntary, varies by jurisdiction and is not settled by the sources provided here. Readers should therefore treat HRDD as a recognized process and expectation rather than as a uniformly binding legal requirement, and should not assume that conducting HRDD eliminates human rights risk. As commonly framed, it is a measure that helps organizations reduce and manage those risks and account for how they address them.

Who it's relevant to

AI governance and compliance teams
Teams responsible for organizational oversight of AI systems can use HRDD as a structured process for identifying and acting on impacts to people affected by those systems. Because HRDD is oriented toward rights-holders rather than the enterprise, it complements internal risk processes rather than replacing them, and its ongoing nature aligns with continuous governance and monitoring expectations.
Legal and policy specialists
Legal and policy professionals need to track HRDD carefully because its status as mandatory or voluntary varies by jurisdiction and is not resolved by the evidence here. They should describe HRDD as a recognized process and expectation while confirming the specific legal obligations, if any, that apply in a given jurisdiction rather than assuming uniform requirements.
Risk and audit functions
Risk managers and internal auditors should note that HRDD focuses on impacts on people, which differs from enterprise-focused risk assessment centered on risks to the organization. This distinction matters when integrating HRDD findings into broader risk management, since the two processes ask different questions and should not be collapsed into one another.
Executives and accountable owners
Leaders accountable for how the organization addresses its impacts benefit from HRDD's tracking and accounting steps, which enable them to demonstrate how findings lead to action over time. They should understand HRDD as a continuous management system that reduces and manages human rights risk rather than one that eliminates it.

Inside HRDD

Human rights impact identification
A process step in which an organization identifies actual and potential adverse human rights impacts connected to its operations, products, or services, including impacts arising from AI systems. As commonly framed in international soft-law instruments such as the UN Guiding Principles on Business and Human Rights, this focuses on impacts to rights-holders rather than risks to the enterprise, though the two can overlap.
Impact assessment and severity assessment
Evaluation of identified impacts by reference to their scale, scope, and remediability, typically to prioritize the most severe potential harms. In an AI context this may consider affected populations, the reversibility of harm, and how the system's use could contribute to adverse outcomes.
Integration and action to address impacts
Taking the findings of assessment and embedding them into internal functions and decision-making so that the organization prevents, mitigates, or ceases activities causing or contributing to adverse impacts. This connects due diligence to operational governance rather than treating it as a standalone report.
Tracking effectiveness
Ongoing monitoring to verify whether measures taken are actually reducing adverse impacts. As commonly described, this is iterative rather than one-time, reflecting that human rights due diligence is understood as a continuous process.
Communication and transparency
Reporting on how impacts are identified and addressed, in a manner accessible to potentially affected stakeholders, subject to legitimate confidentiality and privacy constraints.
Stakeholder and rights-holder engagement
Consultation with those who may be affected, or their legitimate representatives, to inform each of the steps above. This is often distinguished from purely internal risk analysis because it centers the perspective of affected individuals.
Remediation or access to remedy
Where an organization has caused or contributed to an adverse impact, provision for or cooperation in remediation. This element is frequently identified as a component that distinguishes human rights due diligence from many enterprise-centric risk assessments.

Common questions

Answers to the questions practitioners most commonly ask about HRDD.

Is human rights due diligence the same as a data protection or privacy impact assessment?
No. Although the two can overlap where AI systems process personal data, they are distinct exercises. A privacy or data protection impact assessment typically focuses on privacy and data-related risks under applicable data protection regimes. Human rights due diligence, as commonly framed in business and human rights practice, examines a broader set of internationally recognized human rights that an AI system may affect, which can include but is not limited to privacy. Treating a privacy assessment as a substitute for human rights due diligence generally leaves other potential rights impacts unexamined.
Does completing human rights due diligence mean an organization has eliminated its human rights risks or guaranteed compliance?
No. Human rights due diligence is an ongoing process intended to identify, prevent, mitigate, and account for how an organization addresses adverse human rights impacts. It is a risk-management measure that reduces and manages risk rather than eliminating it. Completing a due diligence exercise does not, by itself, guarantee compliance with any particular legal regime, and its treatment varies across jurisdictions and evolving regulatory frameworks, so professionals should not present it as a settled guarantee of legal conformity.
How should human rights due diligence be integrated with existing AI governance and model risk management processes?
In many organizations, human rights due diligence is embedded into existing governance structures rather than run as a wholly separate track. It can inform impact assessments during AI system design, intake, and procurement, and connect to accountability and oversight functions within AI governance. Where model risk management processes exist, human rights considerations may feed into risk identification and control activities, though the two remain conceptually distinct: model risk management centers on risks arising from model use, while human rights due diligence centers on potential adverse impacts on people. Organizations typically define ownership across the relevant lines of defense to avoid gaps.
At what stage of the AI lifecycle should human rights due diligence be conducted?
As commonly described in business and human rights practice, due diligence is ongoing rather than a one-time event. It is often initiated early, at design, procurement, or intake, so that potential impacts can be identified before deployment, and then revisited as systems change, as usage expands, or as new information emerges. Because AI systems can drift and their contexts of use can shift, periodic reassessment is typically recommended, though the specific cadence depends on organizational policy and the nature of the system.
Who within an organization should be responsible for human rights due diligence for AI systems?
Responsibility is usually distributed rather than assigned to a single function. Business or product owners often hold first-line responsibility for identifying and addressing impacts, while governance, risk, legal, or ethics functions may provide oversight, review, and challenge. Some organizations also involve or consult affected stakeholders as part of the process. The precise allocation depends on the organization's governance model, and clearly documenting accountability helps avoid the assumption that responsibility rests with any one team by default.
What should organizations document as part of human rights due diligence?
Documentation practices vary, but organizations commonly record how potential adverse human rights impacts were identified and assessed, what mitigation or prevention measures were considered or applied, and how decisions were made, including who was involved. Maintaining a record supports the accountability element often associated with due diligence and can help demonstrate that the process was undertaken. The appropriate level of detail depends on the system's context and the organization's internal policies, and documentation itself should not be treated as evidence that all risks have been resolved.

Common misconceptions

Human rights due diligence is the same as an AI model risk assessment or AI impact assessment.
They can overlap but are not interchangeable. Human rights due diligence, as commonly framed, centers on adverse impacts to rights-holders and includes engagement and access to remedy, whereas model risk management typically centers on risks arising from model use to the organization and its objectives. Treating one as a substitute for the other can leave gaps in both directions.
Completing human rights due diligence eliminates the risk of human rights harm from an AI system.
Due diligence is a process for identifying, mitigating, and managing potential adverse impacts; it reduces and helps address risk but does not eliminate it. It is typically understood as ongoing and iterative rather than a one-time exercise that certifies a system as harm-free.
Human rights due diligence is a universally binding legal requirement for all organizations deploying AI.
Its status varies by jurisdiction and instrument. It originates largely from international soft-law expectations and is reflected in some domestic laws and proposals, but whether and how it binds a given organization depends on applicable law and sector. It should not be presented as a single settled obligation applying everywhere.

Best practices

Treat human rights due diligence as an ongoing, iterative process embedded in AI lifecycle governance rather than a one-time document produced at deployment.
Prioritize identified impacts by severity—scale, scope, and remediability—so that the most serious potential harms to rights-holders receive attention first.
Engage potentially affected stakeholders or their legitimate representatives when identifying and assessing impacts, rather than relying solely on internal analysis.
Distinguish human rights due diligence from model risk management in your documentation, mapping where they overlap while ensuring neither substitutes for the other.
Establish tracking mechanisms to monitor whether mitigation measures are actually reducing adverse impacts, and adjust when they are not.
Provide for or cooperate in access to remedy where the organization has caused or contributed to an adverse impact, and confirm applicable legal obligations in the relevant jurisdiction before characterizing requirements as binding.