Case Study

AI Governance for Business Professionals

The questions and vocabulary you carry into any room.

Executive Foundation Current Regime

*Originally prepared for graduate students in the Queens and McColl School of Business as companion reading for a guest lecture.

1 | Thesis

Have you ever used AI to make a life-changing decision? A job to apply for, a class to take, a loan, apartment, school, medical, or legal question.

The first business question is where AI output stops before it becomes action. A system may draft a rejection email, rank job applicants, recommend fraud review, summarize a disciplinary record, or flag a worker for low productivity. Those outputs matter because someone may rely on them. The legal and ethical risk usually appears at the moment the organization lets the output affect a person.

Model confidence does not solve that problem. Confidence is a signal generated by the system or around the system. It is not independent review. It does not tell the business that the output is lawful, fair, accurate, documented, or ready for use.

The core principle we will go over here:

AI outputdraft
Reviewerthe gate check
Can reject, revise, or escalaterelease gate
Can only watch it movedecoration

An AI model cannot certify its own work. The authority to release the work has to sit outside the model, with a person who is able to stop movement.

The control has to sit outside the model. That control can be a trained reviewer, a compliance process, a legal review, a technical audit, a manager with defined authority, or a structured workflow with escalation rules. The form can vary, the power cannot. The gate has to stop movement.

The practical test is simple. If the reviewer cannot reject, revise, or escalate the output before it affects someone, the organization has not created a release gate. It has created a ritual.

2 | Speed Needs Control

The risk is that weak controls scale with the same speed. A bad screening rule can reject qualified applicants at volume. A biased dataset can reproduce historical exclusion. A vendor claim can move through procurement without anyone testing what the tool actually does. A monitoring system can turn ordinary worker behavior into discipline before anyone asks whether the signal is valid.

The National Institute of Standards and Technology describes trustworthy AI through characteristics that include validity, reliability, safety, security, resilience, accountability, transparency, explainability, interpretability, privacy, and fairness. Its AI Risk Management Framework organizes AI risk work around 4 functions: govern, map, measure, and manage. That structure matters because business governance is a system of decisions, records, testing, review, and accountability. It is not a slogan.1

3 | The United States

The United States does not have one comprehensive federal AI statute. Businesses operate in a layered environment made of executive action, agency enforcement, state and local law, private litigation, and existing legal regimes such as employment discrimination, consumer protection, privacy, contract, procurement, and discovery. Federal agencies have continued to use existing authority while states move ahead with AI-specific rules.

That means a company does not need to violate an AI law to create AI liability. If a hiring tool creates discriminatory outcomes, employment law may apply. If a consumer scoring tool misleads people or treats them unfairly, consumer protection law may apply. If an AI system uses data in ways the business did not disclose, privacy law may apply. The old laws did not disappear when the new tools arrived.

Federal policy has moved toward national uniformity. Executive Order 14365, issued December 11, 2025, criticized state-by-state regulation, created an AI Litigation Task Force, directed Commerce to identify conditions on certain remaining BEAD non-deployment funds, and directed preparation of a legislative recommendation for a uniform federal framework that would preempt conflicting state AI laws.3,4

Step 1Executive order
Step 2No direct preemption
Step 3Congress or authorized agency
Step 4Possible preemption

An executive order does not erase state law by itself. Federal preemption usually comes from Congress, or from agency action when Congress has clearly delegated authority to the agency. At the time of this reading, the order itself had not displaced state AI laws, and Congress had not enacted the broad AI preemption requested by the administration.

Congress has also resisted broad state-law displacement. In July 2025, the Senate stripped an AI moratorium from a budget reconciliation bill by a 99 to 1 vote, and a later attempt to block state AI laws through the National Defense Authorization Act was dropped before enactment.5,6

The business answer is direct. Comply with the state and local AI rules that apply now, keep the program flexible, and do not treat a federal policy announcement as a compliance exemption.

4 | Four Jurisdictions

Employment AI and civil rights

California

California has several relevant AI laws and rules. SB 53 requires large frontier AI developers to publish frontier AI frameworks and make disclosures related to catastrophic risk and safety incidents. AB 2013 requires generative AI developers to post training-data documentation by January 1, 2026. AB 853 delayed parts of California's AI-generated-content transparency regime to August 2, 2026. California civil rights regulators also confirmed that state employment anti-discrimination law applies to automated decision systems used in employment, with rules effective October 1, 2025.8,9,10,11

Operational difficulty

Colorado

Colorado has enacted a narrower automated decision-making law focused on automated decision-making technology used for consequential decisions. The statute addresses developer documentation, records, consumer notice, correction, human review or reconsideration for certain adverse decisions, and enforcement by the state attorney general. Key provisions are set for January 1, 2027.7

Discriminatory employment AI

Illinois

Illinois folded AI into its existing civil rights law rather than writing a separate AI statute. The amendment, effective January 2026, makes it a civil rights violation for an employer to use AI in a way that discriminates in employment decisions, and it bars using zip code as a proxy for a protected class. Because the rule runs through the existing civil rights framework, its ordinary enforcement and remedies attach, and the violation turns on the discriminatory outcome rather than on proof that the employer intended it.12

Bias audits and enforcement

New York City

New York City's Local Law 144 regulates automated employment decision tools. Employers and employment agencies generally cannot use covered tools unless a bias audit has been completed, required information has been made public, and required notices have been provided. Enforcement began July 5, 2023. A later New York State Comptroller audit found weaknesses in enforcement, including an ineffective complaint process and limited detection of possible noncompliance.13,14

5 | Mobley v. Workday

Mobley v. Workday puts the abstract risk into a business setting. Derek Mobley alleged that Workday's algorithmic applicant-screening tools discriminated against applicants based on race, age, and disability. These are allegations. At the pleading stage, the court was deciding whether claims could proceed, not whether Workday violated the law.15

InputApplicant
Vendor toolWorkday tool
ProcessScreening
OutputRejection

The hiring steps an employer handed to the vendor's tool. Screening and rejection happen with no person deciding, which is how the discrimination claim could reach Workday, the vendor, and not only the employers.

Pleading stage

The earliest phase of a lawsuit. The court only decides whether the claims may move forward, not whether anyone actually broke the law. Here it let the case proceed against Workday on an agent theory: a company stays responsible for work it hands to an outside tool, so an employer cannot escape anti-discrimination law by letting a vendor's software do the screening. The court allowed disparate-impact claims (a neutral-looking practice that produces worse outcomes for a protected group, where the outcome matters, not the intent) and dismissed the intentional-discrimination claim, because the complaint did not show the tool was built to discriminate on purpose.

Group certified

The court let older applicants sue as a group. It used an opt-in collective (workers must actively join) rather than a Rule 23 class (which would automatically include everyone who fits unless they opt out). The difference decides how many people the case ultimately covers.

Discovery

The stage where each side can demand the other's documents. The court held that Workday's own bias testing (checking whether the tool produced skewed outcomes across groups) was shielded by attorney-client privilege, because lawyers directed and curated it for legal advice. The same test run as a routine business task would not have been protected. Who runs the test, and why, decided whether it stayed private or could be pulled into court.

Motion to dismiss

The court kept the strongest theories alive and trimmed the rest. Key claims under California's anti-discrimination law (FEHA, the Fair Employment and Housing Act) and a disability theory under the ADA (the Americans with Disabilities Act) moved forward, while weaker theories narrowed. AI cases rarely end in one clean yes or no; claims survive, narrow, and shift as the court tests them against the record.

Tap a milestone for a plain-English explanation

Scale on the record: roughly 1.1 billion applications rejected on the platform — Workday's account of scale, not a finding.

The important point for business professionals is the vendor theory. Workday argued that it was a software vendor rather than an employer. The court allowed certain federal discrimination claims to proceed under an agency theory, reasoning that anti-discrimination laws reach agents and that employers cannot avoid liability by delegating traditional hiring functions. The complaint plausibly alleged that Workday's customers delegated screening and rejection functions to Workday's tools.

The court dismissed the employment-agency theory, allowed disparate-impact claims to proceed, and dismissed intentional-discrimination claims because the complaint did not adequately plead discriminatory intent. That distinction matters. Disparate impact focuses on outcomes, so a tool can create risk even when nobody set out to discriminate.15

The case also shows how quickly scale changes the risk profile. In a preliminary collective-certification order, the court noted Workday's representation that roughly 1.1 billion applications were rejected using Workday during the relevant period. That was Workday's account of platform scale, not a finding that its AI independently rejected 1.1 billion people. The same order treated the certified older-applicant group as an opt-in collective, which is different from a Rule 23 class.16

The case kept moving. In a later order, the court allowed key California FEHA claims and a disability proxy-discrimination theory to go forward while dismissing other theories, including a race-based disparate-impact claim by one plaintiff and the direct-employer theory. The detail matters because AI litigation rarely moves as one clean yes or no. Claims survive, narrow, and change as the court tests the theory against the record.17

The discovery fight adds the governance lesson that many businesses miss. In May 2026, the court held that certain Workday bias-testing material was protected by attorney-client privilege because lawyers directed and curated the testing for legal advice. The ruling did not say that all bias testing is privileged. It showed that audit structure matters: who runs the test, why the test is run, who controls the records, and how the purpose is documented can change the legal posture of the evidence.18

The lesson is a design choice the business makes before the audit runs, not after it. A bias audit performed as a routine operational task creates an ordinary business record that an opposing party can request in litigation. The same test, directed by counsel for the purpose of legal advice, may carry privilege. A business cannot relabel the record once a dispute begins, and privilege can still be waived by how the results are circulated. The purpose, the owner, and the record path have to be decided at the start.

A bias audit
Run as routine operations
Ordinary business record
Discoverable by an opposing party
Directed by counsel for legal advice
Legal-advice work product
May carry privilege

6 | The EU AI Act

The EU AI Act matters to U.S. businesses because of its reach. It applies to certain providers placing AI systems or general-purpose AI models on the EU market, deployers located in the EU, and providers or deployers outside the EU when the AI system's output is used in the European Union. A U.S. company can therefore face EU AI Act obligations even when the company itself sits outside Europe.

For a U.S. company, the practical trigger is not where the company sits but where the output is used. If an AI system's results are used inside the EU, the obligations can apply even when the company has no European office. The company then faces a choice between building one product that meets the stricter standard and maintaining two versions for two markets. Because running two products usually costs more than complying once, the stricter rule tends to become the default, which is how an EU requirement reaches a business that never planned to operate in Europe.

The Act regulates practices, systems, and duties.

Banned outright. The business cannot use the system for these purposes at all. Examples include social scoring and certain uses that manipulate people or exploit vulnerable groups.
Allowed only after meeting heavy duties: risk management, technical documentation, human oversight, transparency, and ongoing monitoring. Most hiring, promotion, and worker-monitoring AI falls in this tier.
Allowed, but you must disclose. People have to be told when they are interacting with an AI system, or viewing content that AI created or altered.
Separate rules govern general-purpose models that can support many different uses, including generative AI, layered on top of the tiers above.

High-risk systems carry heavier obligations, including risk management, technical documentation, transparency, human oversight, accuracy, robustness, cybersecurity, monitoring, and recordkeeping. Employment uses listed in Annex III require Article 6 analysis, including the exceptions for certain narrow procedural or preparatory uses.19,20

The EU AI Act Business Check

Where will the output be used?

If the output will be used in the European Union, the Act may apply even when the company is based outside Europe.

Is the use prohibited?

Prohibited means the business cannot use the system for that purpose. Examples include social scoring and certain uses that manipulate people or exploit vulnerable groups.

Is the use high-risk?

High-risk means the business can use the system only after meeting specific requirements, including testing, records, ongoing checks, and a person with authority to stop the output. Many hiring and workforce systems fall into this category.

Does the use require disclosure?

Disclosure means telling people when they are interacting with certain AI systems or viewing certain content created or altered by AI.

Who can stop the output?

Name the person who can reject, override, or pause the system before it affects an applicant, worker, customer, or other person.

The timing has changed, and precision matters. In June 2026, the Council gave final approval to a Digital Omnibus package that moved certain high-risk AI obligations. Stand-alone high-risk systems move to December 2, 2027, and high-risk systems embedded in regulated products move to August 2, 2028. The same package sets December 2, 2026 for certain synthetic-content marking transition rules.

August 2, 2026 · transparency holds

The Act's transparency duties under Article 50 still take effect on this original date. Transparency here means telling people when they are dealing with an AI system, or with content that AI generated or altered. This date did not move.

December 2, 2026 · content marking

A short grace period for synthetic-content marking: labeling AI-generated or AI-altered content in a machine-readable way, for systems already on the market before August 2026. It is a transition allowance, not relief from the duty itself.

December 2, 2027 · stand-alone high-risk

The new deadline for stand-alone high-risk systems, meaning AI used on its own for consequential decisions such as hiring or credit. This moved from August 2026. The obligations themselves (testing, records, human oversight) did not get lighter; the authorities and standards needed to apply them were not ready in time.

August 2, 2028 · embedded high-risk

The deadline for embedded high-risk systems, meaning AI built into another already-regulated product such as a medical device, machine, or vehicle. These get the longest runway because they ride on top of existing product-safety rules.

Tap a date for a plain-English explanation

The delay is a readiness signal, not a reprieve.

The delay is a readiness signal, not a reprieve. The high-risk obligations moved because the standards, guidance, and national authorities needed to apply them were not ready in time, not because the requirements themselves got lighter. The core high-risk obligations remain, but the package also changes how parts of the regime apply and interact with sector-specific rules. The practical reading for a business is that the extra time exists for building the compliance framework, and treating the new dates as permission to wait leaves less runway than it looks.21,22

The Act also imposes transparency duties. People must be informed when they are interacting with certain AI systems, and certain AI-generated or manipulated content must be marked or disclosed.

The Act separately requires providers and deployers to take measures to ensure a sufficient level of AI literacy among staff and others involved in AI operation and use. AI literacy means that the people using the system understand enough about its risks, limits, and proper use to operate it responsibly.

AI literacy is an obligation, not a slogan. It means the people operating an AI system can judge its outputs, recognize when it is likely wrong, and understand where its limits fall, well enough to use it responsibly. That is the same capability this reading builds: the vocabulary to ask what the system did, who it affects, whether anyone tested it, and who can hold release authority. A workforce that cannot answer those questions is not AI literate, whatever the training record says.

The business answer is practical. If an AI tool is placed on the EU market, used in the EU, or produces output used in the EU, the company has to analyze EU obligations. If the tool affects hiring or workforce management, analyze whether the intended use falls within Annex III and build oversight into the workflow now. Retrofitting governance is expensive.19,20

7 | Carry Three Terms

They give you the tools for asking the right questions.

Explainability

Explainability answers a basic question: can the business understand and state why the system produced a particular output?

Explainability: A lender can state, in plain words, the main factors that drove a denial.

Adverse impact

Adverse impact, also called disparate impact, means that a neutral-looking practice produces significantly worse outcomes for a protected group.

Adverse impact: A screening tool advances 100 of one group and 72 of another at equal qualification.

Human release authority

Human release authority answers the governance question that matters most: who decides whether AI output becomes action?

Release authority: A named manager can pull a flagged file out of the queue before it triggers a rejection.

For business use, explainability does not always require exposing every internal mathematical feature of a model, just enough understanding to govern the system, challenge the result, document the decision, and explain the main drivers in ordinary language when a person is affected. A black box may be acceptable for low-stakes automation. It is much harder to defend when the system rejects, ranks, flags, disciplines, monitors, prices, or deprioritizes people.

Low stakesHigh stakes
explainability expected
Black box may be acceptableRoutine, low-consequence automation where no one is directly affected.
Hard to defendWhen the system rejects, ranks, flags, disciplines, monitors, prices, or deprioritizes people.

The four-fifths rule is an evidentiary screen: a selection rate below 80 percent may indicate adverse impact.23

One group 100
Another group 72

A rate below 80 percent is a screening indicator, not a dispositive finding.23

The AI-specific lesson is direct. A system can be facially neutral and still produce discriminatory outcomes. The organization does not solve that risk by saying the model did not know the applicant's race, sex, age, disability, or other protected trait. Proxy variables can carry the signal. Zip code, employment gaps, school history, commute patterns, medical-leave patterns, language, scheduling availability, or work history can operate as substitutes for protected traits in practice.

The federal Uniform Guidelines on Employee Selection Procedures define adverse impact in employment selection and require recordkeeping that allows employers and enforcement agencies to assess selection effects. The common rule of thumb is the four-fifths rule: if the selection rate for a race, sex, or ethnic group is less than 80 percent of the selection rate for the group with the highest selection rate, that difference is generally treated as evidence of adverse impact. Smaller differences may still matter where they are statistically or practically significant.23

A human in the loop is useful only when the person has real authority, enough information, and the power to stop the process. A reviewer who only watches the output move through the system does not create oversight. A manager who can rubber-stamp but cannot reject does not create oversight. A policy that says human review while the workflow auto-rejects people before review does not create oversight.

The EU AI Act's human-oversight provision for high-risk systems points in this direction. It requires oversight measures that allow a natural person to:19

Understand relevant capacities and limitations
Monitor operation
Remain aware of automation bias
Interpret outputs
Decide not to use or to disregard an output
Override or reverse an output
Interrupt the system where appropriate

8 | Procurement

The vendor review

A clean vendor review should answer 12 questions.

What decision or action will the tool influence?

Who is affected if the output is used?

Does the tool draft, recommend, rank, screen, reject, monitor, or trigger workflow movement?

What data does the tool use?

What data does the vendor retain?

Does the vendor use customer data to train or improve models?

What sub-processors or third parties receive data?

Can the vendor explain the main factors behind a consequential output?

Has the tool been tested for adverse impact?

Who performed the testing, for what purpose, and where are the records?

Who inside the business has release authority?

What challenge, correction, or reconsideration path exists for the affected person?

These questions do not slow the business for the sake of caution. They protect the business from adopting a system it cannot explain, defend, or stop.

9 | Implementation

The implementation checklist

A responsible AI implementation should produce clear answers before the system goes live.

AreaRequired answer
Use caseState what the AI system will do in ordinary language.
ConsequenceState what happens to a person, customer, employee, applicant, or business partner if the output is used.
Legal regimeIdentify the federal, state, local, international, sector-specific, and contractual rules that may apply.
Vendor roleDescribe the vendor's actual role in the workflow, not just the vendor's product category.
DataIdentify what data enters the system, what leaves the system, what is retained, and what may be used for training.
ExplainabilityConfirm whether the business can understand and explain the main drivers of consequential outputs.
Adverse impactTest outcomes across protected groups where the use case affects employment, housing, credit, education, benefits, or similar opportunities.
Audit postureDecide who runs the audit, why it is run, who directs it, who receives the results, and how the records are protected.
Human gateName the person or process with authority to approve, reject, revise, or escalate.
Challenge pathGive affected people a meaningful way to seek review, correction, or reconsideration where the use case requires it.
MonitoringRetest the system after deployment, especially when data, vendors, prompts, models, or business processes change.
DocumentationKeep records showing that the business governed the system rather than merely trusted it.

The checklist is only useful if the business can answer it with evidence. A policy statement is not evidence. A vendor assurance is not evidence. A release gate that cannot stop anything is not evidence.

10 | The Responsible Position

Efficiency

Use AI where it creates real value, because speed, scale, and consistency are legitimate business advantages.

Caution

Treat caution as a design principle, which means testing, documentation, challenge paths, and review authority exist before deployment.

Release

Keep final authority over consequential decisions outside the model, with a person or accountable process that can say no.

For business professionals, the point is operational. Do not say human oversight in the abstract. Name the person, the decision, the information available to that person, and the exact action that person can stop.

Sources and legal authorities

Sources are numbered in order of first appearance. Each entry identifies the claim location and a legal pinpoint where available. All links were accessed July 13, 2026.

  1. National Institute of Standards and Technology, Artificial Intelligence Risk Management Framework (AI RMF 1.0), NIST AI 100-1 (Jan. 2023). Pinpoint: pp. 1 to 5, 12 to 13. Supports pp. 4 to 5. doi.org/10.6028/NIST.AI.100-1
  2. Morgan Lewis, AI Enforcement Accelerates as Federal Policy Stalls and States Step In (Apr. 2, 2026). Supports p. 6. Secondary overview. morganlewis.com, Apr. 2, 2026
  3. Executive Order 14365, Ensuring a National Policy Framework for Artificial Intelligence (Dec. 11, 2025). Pinpoint: sections 1, 3, 5, and 8. Supports p. 7. whitehouse.gov, Executive Order 14365
  4. White & Case, State AI Laws Under Federal Scrutiny (2026). Supports p. 7. Secondary analysis of Executive Order 14365. whitecase.com, state AI laws analysis
  5. United States Senate, Roll Call Vote No. 363, amendment removing the proposed AI moratorium from the 2025 reconciliation bill (July 1, 2025). Supports p. 8. senate.gov, Roll Call Vote 363
  6. Fisher Phillips, Congress Again Drops Bid to Block State AI Laws (Dec. 2025). Supports p. 8. Secondary report on the NDAA provision. fisherphillips.com, NDAA report
  7. Colorado General Assembly, SB26-189, Automated Decision-Making Technology, signed act (May 14, 2026). Pinpoint: enacted bill summary and signed act. Supports p. 11. leg.colorado.gov, SB26-189
  8. California Legislative Information, SB 53, Transparency in Frontier Artificial Intelligence Act, 2025 to 2026 Regular Session. Supports p. 10. leginfo.legislature.ca.gov, SB 53
  9. California Legislative Information, AB 2013, Generative Artificial Intelligence: Training Data Transparency, 2023 to 2024 Regular Session. Supports p. 10. leginfo.legislature.ca.gov, AB 2013
  10. California Legislative Information, AB 853, Artificial Intelligence, 2025 to 2026 Regular Session. Supports p. 10. leginfo.legislature.ca.gov, AB 853
  11. California Civil Rights Department, Civil Rights Council Secures Approval for Regulations to Protect Against Employment Discrimination Related to Artificial Intelligence (June 30, 2025). Supports p. 10. calcivilrights.ca.gov, June 30, 2025
  12. Illinois Public Act 103-0804, amending the Illinois Human Rights Act, approved Aug. 9, 2024, effective Jan. 1, 2026. Pinpoint: sections 5 and 30. Supports p. 10. ilga.gov, Public Act 103-0804
  13. New York City Department of Consumer and Worker Protection, Automated Employment Decision Tools, Local Law 144 guidance and enforcement materials. Supports pp. 9 to 10. nyc.gov, Local Law 144
  14. Office of the New York State Comptroller, Enforcement of Local Law 144, Automated Employment Decision Tools (Dec. 2, 2025). Supports p. 10. osc.ny.gov, Audit 2025-N-3
  15. Mobley v. Workday, Inc., No. 3:23-cv-00770, Dkt. 80 (N.D. Cal. July 12, 2024). Pinpoint: agency and discrimination rulings. Supports pp. 12 to 13. courtlistener.com, case docket
  16. Mobley v. Workday, Inc., No. 3:23-cv-00770, Dkt. 128, Order Granting Preliminary Collective Certification (N.D. Cal. May 16, 2025). Pinpoint: ECF pp. 1 to 2 and 17 to 18. Supports p. 14. govinfo.gov, Dkt. 128 PDF
  17. Mobley v. Workday, Inc., No. 3:23-cv-00770, Dkt. 360, Order Granting in Part and Denying in Part Motion to Dismiss (N.D. Cal. June 22, 2026). Pinpoint: ECF pp. 1 to 12. Supports p. 14. Dkt. 360 hosted PDF
  18. Mobley v. Workday, Inc., No. 3:23-cv-00770, Dkt. 340, Discovery Order (N.D. Cal. May 29, 2026). Pinpoint: ECF pp. 1 to 13. Supports p. 15. govinfo.gov, Dkt. 340 PDF
  19. Regulation (EU) 2024/1689, Artificial Intelligence Act (June 13, 2024; OJ publication July 12, 2024). Pinpoint: Articles 2, 4 to 6, 9 to 15, 26, 50, 99, and 113; Annex III. Supports pp. 17 to 23 and 27. EUR-Lex, Regulation 2024/1689
  20. European Commission AI Act Service Desk, Annex III, High-Risk AI Systems Referred to in Article 6(2). Pinpoint: item 4, employment and worker management. Supports pp. 18 and 23. European Commission, Annex III
  21. Council of the European Union, Press Release 553/26, Artificial Intelligence: Council Gives Final Green Light to Simplify and Streamline Rules (June 29, 2026). Pinpoint: p. 1. Supports p. 20. consilium.europa.eu, Press Release 553/26
  22. Council of the European Union, PE-CONS 30/26, Digital Omnibus on AI (June 18, 2026). Pinpoint: recital 2 and amended Article 113. Supports pp. 20 and 22. data.consilium.europa.eu, PE-CONS 30/26
  23. 29 C.F.R. Part 1607, Uniform Guidelines on Employee Selection Procedures. Pinpoint: section 1607.4(D), adverse impact and the four-fifths rule. Supports p. 26. ecfr.gov, 29 C.F.R. Part 1607