The Need for Transparency in the Age of Predictive Sentencing Algorithms

I.     Introduction

As the United States faces unprecedented rates of incarceration,1 criminal law experts seek to decrease recidivism, believing that a small percentage of the population is responsible for a majority of crime.2 This theory, known as “selective incapacitation,” is based on the idea “that a small subset of repeat offenders is responsible for the majority of crime and that incapacitating that small group would have exponential benefits for the overall crime rate.”3 Researchers have started developing strategies that use objective evidence to identify criminals representing the most serious risk to the community based on their likelihood to reoffend.4 The process, known as “risk assessment,” has led to the creation of actuarial instruments, or statistical models that predict risk of recidivism by studying the common traits of paroled inmates responsible for committing multiple crimes.5

Prior to the use of actuarial instruments, predicting an offender’s risk of recidivism had been done by clinical assessment—“‘an informal, “in the head,” [and] impressionistic, subjective conclusion’ about the offender’s future dangerousness.”6 In the clinical model, assessments to evaluate a defendant are either made by mental health experts or other actors in the criminal justice system, such as judges or parole boards.7 The movement in criminal law has been away from these clinical methods based on the decision-makers’ subjective judgments, observations, and experiences, and toward the use of objective application of statistical models derived from large datasets of criminal offenders.8 This trend of objective risk assessment has led to the development of actuarial studies that attempt to isolate specific factors in estimating risk.9 Sometimes called “mechanical prediction,” actuarial methods consist of “the mechanical combining of information for classification purposes, and the resultant probability figure which is an empirically determined relative frequency.”10 The scores generated by actuarial risk assessment are now routinely used in all stages of the criminal proceeding, including parole determinations, prison classification, and sentencing.11

As the use of predictive risk assessment has increased, several states have turned to private companies to supply the algorithms needed to generate a defendant’s risk score.12 Although proponents of such methods claim the practice is efficient and effective,13 these predictive algorithms can be problematic in practice.14 Defendants have attempted to challenge the use of such algorithmic risk scores cited by judges in sentencing decisions since the defendants have no way of validating the accuracy of the formulas.15 So far, such attempts have been unsuccessful because the companies behind the formulas assert trade secret protection, ensuring that the formulas used to calculate risk score remain unknown.16 The problem is further complicated by the fact that most states themselves have taken no steps to ensure the accuracy of these formulas.17 Despite the recommendation that local governments conduct validation studies to ensure that an accurate correlation is produced on the population on which the formula is being used, very few jurisdictions have taken this step.18 This means that defendants must accept as accurate a formula that has typically not been validated by the state, and defendants are further prohibited from testing the accuracy themselves.

This Note argues that because private companies are benefitting financially by providing a public service, they should be required to conform to the same transparency requirements as public agencies. Part II first examines the development of predictive risk assessment models in the criminal justice system, particularly their use in sentencing. Part III then discusses the effect of privatization on defendants’ ability to challenge the validity of risk scores. Finally, Part IV explains the benefits of public access to risk assessment tools and proposes alternatives to privatized algorithms that would conform to freedom of information laws and keep the public fully informed of government actions.

II.     Background

In order to identify potential problems with predictive risk assessment tools, this Part reviews the objectives driving the development of risk assessment and the resulting implementation of risk assessment in criminal law. Part II.A details the recent growth in incarceration and the steps taken to counter recidivism. Next, Part II.B explains the basic structure of risk assessment tools, including a description of one of the most commonly used systems, COMPAS. Part II.C explores the expansion of actuarial risk assessment in the criminal sentencing phase, which has led to a competitive industry of privately owned, for-profit predictive sentencing formulas. Finally, Part II.D provides a brief explanation of freedom of information laws and the trade secret exemption that prevents the public from acquiring information on the proprietary risk assessment tools currently in use for criminal sentencing.

A.     Risk Assessment as a Response to an Overburdened Justice System

Criminal sentencing policy over the last 30 years has focused on punishment and imprisonment.19 As a result, the United States faces high levels of incarceration, increasing correction costs, and unparalleled recidivism rates.20 To counter the escalating costs of recidivism, policymakers have turned to predictive algorithms, which at their most basic level “mine personal information to make guesses about individuals’ likely actions and risks.”21 In the criminal context, predictive algorithms are used as a form of risk analysis “to constrain a dependence on imprisonment, encourage alternative rehabilitative programming, reduce recidivism risk, and improve public safety.”22 These analyses are based on “assessing an offender’s risk of reoffending, matching supervision and treatment to the offender’s risk level, and targeting the offender’s criminogenic needs or dynamic risk factors with the social learning and cognitive-behavioral programs most likely to effect change in the offender’s behavior given specific offender characteristics.”23 An actuarial risk assessment is a “statistical prediction[] about the criminality of groups or group traits to determine criminal justice outcomes for particular individuals within those groups.”24 Professor Ernest Burgess of the University of Chicago developed one of the first ever risk assessment methods in 1927—the “Burgess method”—which predicted an individual’s likelihood of success or failure on parole based on 21 factors.25 The principal competitor to the Burgess method was developed by Sheldon and Eleanor Glueck, a criminology professor and a criminology research assistant at the Harvard Law School, in 1930.26 The Gluecks examined 510 inmates and concluded that prediction methods should rely on a narrow set of factors, focusing on only seven.27 The competing methods led to a surge in research on the topics of behavioral analysis and sociology, eventually resulting in the adoption of modern risk assessment methods as a means “to inform post-conviction decisions and management strategies, such as parole determinations, supervised release conditions, provision of reentry services, decisions to revoke supervision, and judgments concerning probation and parole sanctions.”28 Instruments that calculate risk assessment are now used in most stages of criminal litigation, including sentencing in some states.29 In the past 20 years, advances in social science, as well as a growing national effort to curb repeat offenders, has resulted in a greater reliance on risk assessment tools.30 Prediction of risk has become a routine step in the criminal justice system, “seen as a necessity, no longer a mere convenience.”31 Proponents of such tools contend that they help relieve the burden of high incarceration rates by more efficiently allocating resources to prioritize correctional detention and supervision of high-risk criminals rather than low-risk individuals.32

 B.     The Basics of Predictive Risk Assessment Tools

There are over 60 different types of risk assessment tools currently in use in courthouses throughout the United States.33 The most widespread predictive tools are, at their core, questionnaires that assign points based on factors such as demographics, family background, and criminal history.34 Experts claim that recidivism is associated with a “central eight” risk-needs categories.35 Making up the “central eight” are “the ‘big four’[:] antisocial attitudes, antisocial associates, antisocial personalities, and criminal history” and “the ‘moderate four’[:] substance abuse, family characteristics, education and employment, and lack of prosocial leisure or recreation.”36 An offender receiving a low score will be designated as low risk to reoffend and will likely receive a lighter punishment than an individual designated as high risk to reoffend.37 The scores are derived from behavioral research involving examination of large populations of former prisoners for several years to determine which characteristics correspond with recidivism.38 The points are then weighed based on the statistical probability that the defendant’s behavior will correspond with the behavior of repeat offenders.39 Experts assert that factors indicative of repetitive criminal behavior include “feeling proud of breaking the law or having marital or substance abuse problems.”40 Researchers claim that the strongest indicators of reoffenders are sex, age, and prior criminal history, and therefore, these factors often have the most impact on an individual’s score.41

There are three main risk assessment instruments used in most jurisdictions: Correctional Offender Management Profiling for Alternative Sanctions (“COMPAS”), Public Safety Assessment (“PSA”), and Level of Service Inventory Revised (“LSI-R”).42 COMPAS is a “web-based tool designed to assess offenders’ criminogenic needs and risk of recidivism. Criminal justice agencies across the nation use COMPAS to inform decisions regarding the placement, supervision, and case management of offenders.”43 This
137-question evaluation collects data such as “criminal and parole history, age, employment status, social life, education level, community ties, drug use and beliefs.”44 Some of the questions include: “‘Did a parent figure who raised you ever have a drug or alcohol problem?’ and ‘Do you feel that the things you do are boring or dull?’”45 “The questionnaire also asks people to agree or disagree with statements such as ‘A hungry person has a right to steal’ and ‘If people make me angry or lose my temper, I can be dangerous.’”46 The questions are either answered by defendants or extracted from their criminal records.47 An interviewer will administer the questionnaire and “has some leeway in asking the questions in order to build rapport with the interviewee.”48 Some questions require interviewees to respond with a yes or a no, while other responses are scored on a numerical scale.49 The interviewer then scores the questionnaire, which determines the defendant’s risk level.50 These scores represent the odds that the defendant will reoffend within a certain time period.51 For states that use predictive algorithms in sentencing decisions, the questionnaire is generally completed after conviction during a pre-sentence investigation.52 The pre-sentence investigation report, which includes the defendant’s risk score, is then delivered to the judge to consider at the sentencing hearing.53

As the use of predictive risk assessments has become more widespread, critics have raised numerous objections to their use in the courtroom.54 For example, legal scholars believe that inherent biases result in higher scores for certain classes, races, and genders.55 Former U.S. Attorney General Eric Holder warned of potential bias, stating: “Although these measures were crafted with the best of intentions, I am concerned that they inadvertently undermine our efforts to ensure individualized and equal justice, . . . exacerbat[ing] unwarranted and unjust disparities that are already far too common in our criminal justice system and in our society.”56 Additionally, some critics claim that the results are inaccurate.57 A recent study of COMPAS by ProPublica found that “[t]he formula was particularly likely to falsely flag black defendants as future criminals, wrongly labeling them this way at almost twice the rate as white defendants.”58 Specifically, the study found:

[T]he algorithm is more likely to misclassify a black defendant as higher risk than a white defendant. Black defendants who do not recidivate were nearly twice as likely to be classified by COMPAS as higher risk compared to their white counterparts (45 percent vs.
23 percent). However, black defendants who scored higher did recidivate slightly more often than white defendants (63 percent vs. 59 percent).

The test tended to make the opposite mistake with whites, meaning that it was more likely to wrongly predict that white people would not commit additional crimes if released compared to black defendants. COMPAS under-classified white reoffenders as low risk 70.5 percent more often than black reoffenders (48 percent vs.
28 percent). The likelihood ratio for white defendants was slightly higher 2.23 than for black defendants 1.61.59

The study indicated that “[t]he score proved remarkably unreliable in forecasting violent crime: Only 20 percent of the people predicted to commit violent crimes actually went on to do so.”60 When considering the results broadly, looking at the score’s accuracy at predicting recidivism following any crime, including misdemeanors, “the algorithm was somewhat more accurate than a coin flip.”61 Despite legal challenges seeking to prevent the use of such tools in parole and sentencing decisions, courts have so far upheld the use of actuarial risk assessment tools.62

 C.     Expansion of Actuarial Assessments in Criminal Sentencing

While risk assessment tools first emerged as a method of weighing parole decisions, the Justice Department’s National Institute of Corrections now promotes the use of predictive algorithms for all phases of criminal cases, including sentencing.63 Virginia was the first state to implement an actuarial risk assessment tool at sentencing for the purpose of diverting low-risk offenders otherwise bound for prison into alternative sanctions.64 Now, at least 20 states require that judges be provided with a risk score at the sentencing phase.65 A 2010 national survey conducted by the Vera Institute of Justice monitored the growing use of risk assessment tools, finding “that almost every state uses an assessment tool at one or more points in the criminal justice system to assist in the better management of offenders in institutions and in the community. Overall, over 60 community supervision agencies in 41 states reported using an actuarial assessment tool, suggesting that an overwhelming majority of corrections agencies nationwide routinely utilize assessment tools to some degree.”66 A sentencing reform bill currently pending in Congress would mandate the use of such assessments in federal prisons.67

In 2006, after a survey revealed that 75% of respondents favored major sentencing reform to offset high incarceration rates, the Conference of Chief Justices (“CCJ”) and the Conference of State Court Administrators (“COSCA”) established a national sentencing reform plan called “Getting Smarter About Sentencing.”68 The most important objectives of the plan were: “(a) expanding use of evidence-based practices and risk and needs assessment tools and (b) promoting community-based alternatives to incarceration for appropriate offenders.”69 The following year, CCJ and COSCA adopted a resolution titled “In Support of Sentencing Practices that Promote Public Safety and Reduce Recidivism.”70 This resolution encouraged the use of predictive risk assessment in sentencing and corrections policies by urging states to adopt such tools that have been shown to reduce recidivism.71 “[T]he public desires and deserves criminal justice systems that promote public safety while making effective use of taxpayer dollars.”72 The CCJ resolution also “urge[d] all members of the judiciary to educate themselves about the effectiveness of community-based corrections programs in their jurisdictions and to advocate and, when appropriate, make use of those programs shown to be effective in reducing recidivism.”73 Missouri Chief Justice Ray Price echoed the sentiment in support of sentencing reform in his 2010 State of the Judiciary speech: “There is a better way. We need to move from anger-based sentencing that ignores cost and effectiveness to evidence-based sentencing that focuses on results—sentencing that assesses each offender’s risk and then fits that offender with the cheapest and most effective rehabilitation that he or she needs.”74

A 2009 discussion draft of the Model Penal Code also supported the use of predictive risk assessment tools in sentencing, stating that “[t]he commission shall develop . . . offender risk-assessment instruments or processes, supported by current and ongoing recidivism research of felons in the state, that will estimate the relative risks that individual felons pose to public safety through future criminal conduct.”75 The commentary suggested that sentencing decisions made by judges are “notoriously imperfect.”76 The decisions vary based on the ability and intuition of each individual decision-maker, who often lacks training in human behavior, and the conscious or unconscious bias of judges.77 The commentary encouraged the use of predictive formulas in the sentencing process, as

[a]ctuarial—or statistical—predictions of risk, derived from objective criteria, have been found superior to clinical predictions built on the professional training, experience, and judgment of the persons making predictions. The superiority of actuarial over clinical tools in this arena is supported by more than 50 years of social-science research.78

State legislatures have largely followed these recommendations for utilizing risk assessment tools in an effort to reduce recidivism, passing comprehensive corrections reform legislation requiring courts and correction agencies to adopt predictive risk assessment practices.79 The risk assessment is typically conducted during the pre-sentence investigation and subsequently included in a report given to the judge for consideration at sentencing.80 As a result of the growing trend to implement actuarial risk assessment in sentencing, risk assessment has become a competitive industry with both governmental and for-profit businesses developing instruments.81 “Recidivism prediction is ubiquitous. . . . There is an enormous body of academic and professional literature. Unprecedented private sector involvement has occurred in designing and marketing instruments and providing services to [the] government.”82

But a massive disadvantage of proprietary risk assessment tools is that for-profit companies do not publicly disclose the formulas used to arrive at a risk score, so neither the defendants nor the public are privy to the calculations.83 For example, Northpointe, the company that sells COMPAS, does not reveal how it weighs the answers to arrive at a risk score.84 The company has claimed trade secret protection to protect the secrecy of its formula.85 The Wisconsin Supreme Court recently addressed the use of predictive algorithms used in the sentencing phase of a case, noting the proprietary nature of the formula at issue.86 The Court stated that “Northpointe, Inc. . . . considers COMPAS a proprietary instrument and a trade secret. Accordingly, it does not disclose how the risk scores are determined or how the factors are weighed.”87 However, the court did not further analyze the problems created by the trade secret protection, and merely held that any pre-sentencing investigative report must note the proprietary nature of COMPAS in order to caution judges on the limitations of the risk assessment and enable them to better weigh the factors.88

 D.     Government Transparency and Freedom of Information

The invocation of trade secret protection to evade disclosure of proprietary information implicates issues of government transparency. The Freedom of Information Act (“FOIA”), enacted in 1966 to supplement the Administrative Procedure Act of 1946 (“APA”), promotes an open government by granting individuals access to government records.89 President Lyndon Johnson emphasized the importance of public access and transparency when signing FOIA, stating “that ‘this legislation springs from one of our most essential principles: a democracy works best when the people have all the information that the security of the nation permits.’”90 This view has been echoed by former President Obama, who has stated that “[a] democracy requires accountability, and accountability requires transparency.”91 FOIA serves as a means to achieve this accountability and transparency by allowing individuals access to information being used by the government.92 By providing information to the public, FOIA is essential to a democratic society as it prevents secrecy and corruption and allows citizens to hold the government accountable for its actions.93

FOIA permits members of the public to formally request documents from the federal government, including agency rules, opinions, orders, records, and proceedings, which the government must promptly make available.94 This includes “essentially anything reproducible over which an agency has possession and control, no matter the format in which the record is maintained.”95 To access information according to FOIA, an individual sends a request letter to the relevant government entity.96 If the request “reasonably describes” the information, the agency must “make a determination on the request within 20 business days.”97 There are certain limitations to disclosure, though. FOIA recognizes nine exemptions, one of which is trade secret protection.98 The Restatement of Torts defines “trade secret” as “any formula, pattern, device or compilation of information which is used in one’s business, and which gives him an opportunity to obtain an advantage over competitors who do not know or use it.”99 As discussed in Part II.C, Northpointe has claimed trade secret protection in COMPAS, thereby avoiding disclosure of its risk assessment algorithm.100

Despite these exemptions, FOIA still favors disclosure. The Supreme Court has held that the nine exemptions are mostly “discretionary” and are to be “narrowly construed.”101 In one case, a private company contracting with the government objected to the release of proprietary records sought under an FOIA request, arguing that the trade secret exemption barred such a disclosure.102 The Court rejected the argument and held that “[e]nlarged access to governmental information undoubtedly cuts against the privacy concerns of nongovernmental entities, and as a matter of policy some balancing and accommodation may well be desirable. We simply hold here that Congress did not design the FOIA exemptions to be mandatory bars to disclosure.”103 More recently, former President Obama issued a memorandum for the heads of executive departments and agencies clarifying FOIA, in which he stated that “[t]he Freedom of Information Act should be administered with a clear presumption: In the face of doubt, openness prevails.”104 This presumption of disclosure illustrates the extent to which an open and transparent government is valued in American society as a means to hold the government accountable to its citizens.105 It also suggests that nongovernment entities may lose some privacy protection when contracting to perform government functions.

III.     How the Private Sector is Capitalizing on Trade Secret Protection to Evade Public Disclosure of its Sentencing Algorithms

In order to fully understand the impact of actuarial risk assessment instruments, it is helpful to examine cases in which judges have fully embraced the use of risk assessment scores in sentencing criminal defendants. The cases described in this Part demonstrate the weight given to risk assessment scores and how judges then implement those scores at sentencing. Although these tools are routinely being used to make sentencing decisions, defendants cannot properly challenge their accuracy because they do not have access to the formulas. Compounding this problem is the fact that many jurisdictions do not validate the accuracy of the algorithms on the local population prior to use. Part III.A first discusses the full-scale adoption of predictive algorithms in the sentencing phase and looks at two Wisconsin cases in which the judges specifically cited risk assessment scores as a factor in determining length of incarceration. Part III.B then examines the effects of privatization, specifically the use of trade secret protection to prevent disclosure of the formula to defendants wanting to challenge the accuracy of their risk score. Part III.C then explains how the so-called “validation problem” further complicates the use of risk assessment instruments, noting that the lack of validation studies calls into question the decision to deny the public access to risk assessment formulas.

A.     A Look at Predictive Algorithms in the Courts

Wisconsin has been a major proponent of utilizing risk assessment tools in sentencing decisions, operating the COMPAS risk assessment software for use in each step in the prison system, from sentencing to parole.106 The Department of Corrections attaches the COMPAS risk assessment score to a confidential pre-sentence report given to judges prior to all felony sentencing decisions.107 The primary purpose of the test is to determine a defendant’s eligibility for probation or treatment.108 Theoretically, judges are not supposed to give harsher sentences to defendants with higher risk scores.109 However, in practice, this is not always the case. Two cases illustrate the ways in which Wisconsin judges have relied on risk scores, to the defendant’s detriment, when determining sentences. One case involved Paul Zilly, a man accused of stealing a push lawnmower and other tools.110 Zilly and his lawyer agreed to a plea deal with prosecutors, in which the state would recommend one year in a county jail followed by supervision to ensure Zilly would “stay[] on the right path.”111 However, Judge James Babler overturned the plea deal and sentenced Zilly to two years in prison, stating: “When I look at the risk assessment . . . it is about as bad as it could be.”112 The judge referenced the score generated by COMPAS, which calculated Zilly as high risk for future violent crime and medium risk for general recidivism.113 In an appeals hearing, Judge Babler explained his sentencing decision: “Had I not had the COMPAS, I believe it would likely be that I would have given one year, six months.”114

In a similar sentencing decision, another Wisconsin judge directly referenced the defendant’s risk score during sentencing.115 Eric Loomis agreed to plead guilty to two of the five criminal charges brought by the state; in exchange, the state agreed to dismiss the other counts.116 After accepting Loomis’s plea, the court ordered a “pre-sentence investigation report” (“PSI”).117 The sentencing judge reviewed the PSI, which included an attached COMPAS risk score.118 At sentencing, the judge stated: “You’re identified, through the COMPAS assessment, as an individual who is at high risk to the community.”119 After noting that the risk assessment score suggested that Loomis was at an extremely high risk to reoffend, the judge then sentenced him within the maximum of the two charges for which he entered a plea.120 Loomis appealed the sentencing court’s decision, specifically challenging the use of the risk assessment portion of the COMPAS report at sentencing, asserting that use of the tool “violates a defendant’s right to due process.”121 Although the Wisconsin Supreme Court ultimately held that use of the score did not violate Loomis’s right to due process, the case illustrates the extent to which sentencing judges incorporate the scores into their decisions, as well as a defendant’s lack of access to the algorithm.122 The court rejected Loomis’s argument that “he is in the best position to refute or explain the COMPAS risk assessment, but cannot do so based solely on a review of the scores as reflected in the bar charts.”123 The court found that Loomis was not entitled to review how the factors are weighed to determine risk score in order to verify its accuracy.124

 B.     Invoking Trade Secret Protection to Avoid Disclosure

The Wisconsin cases underscore not only the growing presence of risk assessment at sentencing, but also the protection afforded proprietary risk formulas. As the demand for risk assessment tools has grown, the private sector has drastically expanded its involvement in designing and marketing risk assessment tools to sell to the government.125 One judge noted the recognizable private interests at stake in Loomis, stating: “Northpointe has an obvious financial and proprietary interest in the continued use of COMPAS.”126 Responding to concerns related to the growing use of COMPAS in criminal proceedings, Northpointe claims that “[t]here’s no secret sauce to what we do; it’s just not clearly understood.”127 Despite these claims, defendants and the public do not have full access to Northpointe’s “future-crime formula” because Northpointe carefully guards the calculations used to generate the risk scores.128 The company considers the algorithm in its risk assessment tool a proprietary instrument and a trade secret.129 Consequently, as the court addressed in Loomis, Northpointe “does not disclose how the risk scores are determined or how the factors are weighed.”130 In response to Loomis’s argument that his due process was violated because the proprietary nature of COMPAS prevented him from assessing its accuracy, the court held that all PSI’s must now include a written advisement disclosing the proprietary nature of COMPAS.131 Professor David Levine argues that “[a]s public-private partnerships and government commercial activities increase, more frequent assertion of government trade secrets may leave us by default with policies and practices that would not stand up to public scrutiny if the policies were made by legislatures in an open, deliberative fashion.”132

 C.     The Validation Problem

Because companies can avoid disclosing the algorithms behind their risk assessment tools, defendants cannot challenge the accuracy of the results.133 In response, Northpointe General Manager Jeffrey Harmon stated that “[t]he outcome . . . is all that is needed to validate the tools.”134 A report drafted by the National Center for State Courts emphasized the need for states themselves to validate risk assessment tools prior to full-scale implementation: “Given the purpose for and potential judicial consequences of using assessment information at sentencing, research must provide evidentiary support that the tool can effectively categorize all types of offenders in the local population on which the instrument will be used into groups with different probabilities of recidivating.”135 The report recommends that the supervising agency validate the instrument on a sample of the local population before fully implementing the tool in its jurisdiction.136 The report states:

After identifying the most promising tool for use in a jurisdiction, the supervising agency should validate the instrument on a sample that is representative of the local population before undertaking full-scale implementation. Importantly, this should include empirical efforts to norm the tool on different groups of offenders in the target population to ensure that the tool produces accurate risk classifications across subgroups.137

Validation of risk assessment tools is a necessary step to full-scale implementation because a single algorithm is unlikely to have widespread applicability across multiple populations.138 A report by the Center for Criminal Justice Research at the University of Cincinnati found that only 30% of agencies utilizing these tools had validated them on the local population prior to widespread use in their jurisdiction.139 This has created the “validation problem,” where the government cannot fully approve the accuracy of the risk assessment tools implemented in its jurisdiction.140 Additionally, few independent studies have validated risk assessments.141 ProPublica cited research conducted in 2013 that examined 19 different risk assessment instruments used throughout the United States and reported that “in most cases, validity had only been examined in one or two studies” and “frequently, those investigations were completed by the same people who developed the instrument.”142 The researchers’ analysis found that the risk assessment instruments “were moderate at best in terms of predictive validity.”143 The results of such studies reveal that many jurisdictions have fully implemented proprietary risk assessment tools, such as COMPAS, without first testing their validity.144 Courts seemingly accept the accuracy of these formulas, even when no validation studies have been conducted, and in turn deny defendants the opportunity to challenge their accuracy. Consequently, critics of these proprietary risk assessments are requesting more transparency in order to challenge the validity of the results at sentencing hearings.145

IV.     Requiring Transparency for Risk Assessment Formulas Developed by Private, For-Profit Companies

This Part explains how denying the public access to information used in governmental proceedings frustrates the purpose of freedom of information laws, which serve as a tool to keep the public fully informed of government actions. Part IV.A argues that current application of FOIA, recognizing trade secret protection for risk assessment tools used in criminal sentencing, frustrates government transparency, while Part IV.B reviews state-generated predictive sentencing algorithms as an alternative to proprietary instruments and how the use of these government-created tools avoids the trade secret problems inherent in privatized formulas. Part IV.C argues that disclosure requirements should extend to proprietary risk assessment formulas.

A.     Access to Information

Despite government assertions that transparency and accountability are necessary for a functioning democracy, government actions in criminal sentencing decisions have been informed by proprietary risk assessment tools that are shielded from the public with trade secret protection.146 Because companies, such as Northpointe, receive a profit in performing a public service, FOIA and its state counterparts should be amended so that the trade secret exemption to disclosure does not apply to proprietary risk assessment tools used in criminal sentencing.

Although private companies provide government services by supplying the risk assessment tools used in criminal law, these companies simultaneously take advantage of commercial law protections.147 Professor David Levine argues “that we can and should expect such public disclosure when companies step out of the purely private commercial world and seek to reap the financial benefits of providing essential public infrastructure, and that trade secret law stands in the way of this goal.”148 Private firms that elect to provide public services should be subjected to the same transparency and accountability requirements as government agencies.149 This would ensure that the underlying theory of a transparent government would be maintained. The basis of American freedom of information laws can be traced to Jeremy Bentham, the 18th-century English philosopher, who wrote:

But in an open and free policy, what confidence and security—I do not say for the people, but for the governors themselves! Let it be impossible that any thing should be done which is unknown to the nation—prove to it that you neither intend to deceive nor to surprise—you take away all the weapons of discontent. The public will repay with usury the confidence you repose in it. Calumny will lose its force; it collects its venom in the caverns of obscurity, but it is destroyed by the light of day.150

Although legislation such as FOIA embodies the “open” policy described by Bentham, the trade secret exemption has effectively frustrated those goals.151 The Supreme Court attributed the creation of the trade secret exception to the fact that “private entities [were] seeking [g]overnment contracts.”152 Despite creating an exception for trade secrets, “FOIA sets a default of disclosure[,] . . . orient[ing] government towards disclosure” rather than secrecy.153 Once a private company deviates from purely commercial matters towards governmental matters, trade secrecy, and democratic values are in conflict.154 Law professors Danielle Citron and Frank Pasquale reason that “the logics of predictive scoring systems should be open to public inspection . . . . There is little evidence that the inability to keep such systems secret would diminish innovation.”155

The need for an amendment to FOIA is illustrated by the results of a 2015 study at the University of Maryland addressing the lack of access to proprietary risk assessment instruments.156 That study involved FOIA requests for documents or source codes related to predictive algorithms used in criminal proceedings.157 Oregon was the only state to disclose its predictive algorithm, providing “the 16 variables and their weights.”158 Some states provided documents with descriptions of their risk assessments, but no details regarding development or validation.159 Other states refused the request completely based on the trade secret protection.160 Because there is a growing acceptance that the trade secret protection exempts companies like Northpointe from FOIA disclosure requirements, an amendment to the Freedom of Information Act is needed to require disclosure of risk assessment formulas, thereby ensuring the presumption of disclosure that the government seems to advocate. As a result, companies that sell risk score assessment instruments, that are then utilized by public agencies and considered by judges in criminal sentencing decisions, would be subjected to the same transparency requirements of other public agencies.

Requiring disclosure would ensure that the risk scores generated by proprietary instruments, which are often not validated before implementation, are in fact accurate. This would also ensure public access to government information. As more public functions are contracted out to private entities that are not subject to the same standards of transparency imposed on government actors, the effectiveness of FOIA is undermined.161 Danielle Citron warns that preventing public access to data models “undermines the democratic process.”162 When the creators of proprietary algorithms refuse to reveal the method and logic behind their models, it leaves the tools “shrouded in secrecy.”163 In a statement before the Senate Committee on Governmental Affairs, David Sobel stated “public disclosure of this information improves government oversight and accountability. It also helps ensure that the public is fully informed about the activities of government.”164 Existing transparency procedures should be applied to risk assessment algorithms to ensure that freedom of information laws are not undercut.165

 B.     The Benefits of Public Access to Risk Assessment

Requiring the disclosure of proprietary risk assessment tools is good public policy because it allows for a close evaluation of the algorithm, which in turn guarantees its accuracy. For example, some states are avoiding proprietary trade secret problems by developing their own risk assessment algorithms. In Pennsylvania, the Pennsylvania Risk Assessment Project was created to help make criminal sentencing decisions.166 Act 95 of the project directed a commission to adopt a risk assessment tool that would consider risk of reoffending, potential threats to public safety, and the possibility of alternative sentencing programs, all based on empirical data believed to predict recidivism.167

Unlike other states that use proprietary algorithms in sentencing decisions, “the level of transparency around the Pennsylvania Risk Assessment Project is laudable, with several publicly available in-depth reports on the development of the system.”168 These reports include extensive analysis of the development of the risk assessment method, explaining the factors to be considered and the weight to be given each factor in calculating the risk scale.169 The transparency in providing widespread access to the reports provides the public an opportunity to evaluate the risk assessment method, which is lacking with propriety instruments.170 The Commission also published a comprehensive validation report, providing the results of focus group and beta testing.171

Similarly, the Ohio Department of Rehabilitation and Correction constructed its own statewide risk assessment system, the Ohio Risk Assessment System, to “improve[] consistency and facilitate[] communication across criminal justice agencies.”172 By creating its own risk assessment instrument designed around its local, target population, Ohio has avoided one of the problems associated with commercial risk assessment instruments, which are generally developed on samples from a different population.173 Like Pennsylvania, Ohio published an in-depth study that it made available to the public.174 The study outlines “the creation and validation” of the risk assessment tools.175 While some jurisdictions rely on commercially developed risk assessment instruments due to limited resources, an algorithm developed by the state in which it was developed, such as the Ohio Risk Assessment System, may be more accurate at predicting recidivism for the state’s local population since it is designed around that population.176

 C.     Extending Disclosure Requirements to Proprietary Risk Assessment Instruments

As the government relies increasingly on technology, Congress and the courts have conditioned technological expansion on government adherence to safeguards “designed to ensure the fairness, transparency, and accountability of agencies’ decisions about particular individuals.”177 As this technological expansion implicates both public and private interests, some have argued that “a reconsideration of the rules for [the] government is not only a good idea but a necessity.”178 The idea of allowing companies to maintain a competitive advantage through trade secret protection directly should not have the same force when applied to risk assessment tools like COMPAS, because the company’s private interests cannot be reconciled with public interests.179 Some courts have actually rejected trade secret protection the moment a private function is recognized as governmental.180 Despite this, transparency for the public good is often sacrificed for the protection of commercial interests. Professor Levine argues that “[a]s public-private partnerships and government commercial activities increase, more frequent assertion of government trade secrets may leave us by default with policies and practices that would not stand up to public scrutiny if the policies were made by legislatures in an open, deliberative fashion.”181 When using tools such as COMPAS in making sentencing decisions, the function of the risk assessment tool should be considered governmental rather than proprietary. Once this occurs, companies can no longer assert proprietary protections, such as trade secret protection, to prevent disclosure of the algorithms. This governmental function requires that companies submit to the same transparency requirements as other government agencies, ensuring transparency.

V.     Conclusion

As jurisdictions continue to incorporate scientific and technological methods as a means of reducing recidivism, they should consider the costs and benefits that result from incorporating proprietary risk assessment instruments. While the increased efficiency associated with systems like COMPAS are perhaps understandable, state governments should not abandon the values of open government on which the country was founded. As the cases above demonstrate, states have accepted the accuracy of proprietary algorithms without first validating their accuracy. Defendants in the criminal justice system are then forced to also accept the accuracy of these algorithms, as trade secret protection prevents the disclosure of the formulas.

In short, when private companies benefit from providing a public service, they should be subjected to the same transparency requirements as public agencies. Just as states that develop their own risk assessment instruments disclose to the public in-depth reports about their algorithms, private companies should adhere to the same requirements when they choose to contract with the government.


