AIUC-1
AIUC-1 Certification -> Scoping

Scoping the AIUC-1 audit

AIUC-1 is designed to cover all the risks that matter for secure adoption of AI agents. It has 51 requirements with 130 individual mandatory and optional controls across 6 foundational principles: Data & Privacy, Security, Safety, Reliability, Accountability, Society.

Determining what controls apply to achieve AIUC-1 certification depends on the capabilities and risks of the AI system. For example, an internally facing automation agent with limited data and tool access only needs to demonstrate evidence for 40 controls to achieve certification.

A more powerful agent, such as an externally facing customer service agent spanning both text and voice modalities with access to sensitive data and tool calls like executing refunds will need to demonstrate evidence for 65 controls.

As such, the key drivers of AIUC-1 scoping are:

  1. The capabilities of the AI agent system (e.g. internally vs. externally facing, single vs. multi modality agents)
  2. The architecture of the AI agent system (e.g. data access and safeguards, tool calls, human-in-the-loop configuration)
  3. The ambition level of the organization - AIUC-1 has 65 mandatory controls and another 65 optional controls that organizations can opt-in to to demonstrate best-in-class security

Step 1 of an AIUC-1 audit is completing the scoping questionnaire. The questionnaire determines:

  1. What controls are included in the AIUC-1 audit
  2. What agents/systems offered by the organization are included or excluded in the audit

The scoping questionnaire is completed in collaboration with the AIUC-1 auditor. 

Part 1: System documentation & governance

Describe and justify agents in-scope for the AIUC-1 audit

  1. Only include agentic AI systems in the scope - AIUC-1 does not cover other systems
  2. Select agent(s) in scope based on capabilities, risks, and value of external validation
  3. Prioritize agents that are accessible via external API (this allows a higher number of technical tests vs. agents only accessible via e.g. a platform, requiring a more manual eval approach)

Describe systems out-of-scope for the AIUC-1 audit

  • E.g. systems that are not AI native or AI agents with marginal risk profiles.

Describe AI agent system architecture, including:

  1. Deployment model (cloud/on-premises/hybrid)
  2. Infrastructure components (model hosting, API gateways, orchestration layers)
  3. Third-party AI services used (model providers, vector databases, monitoring tools)
  4. How agents interact with internal systems (e.g. list of tool calls)

Document AI agent data flows, including:

  1. Data ingress sources and methods
  2. Where data persists (logs, memory, embeddings, vector stores, caches)
  3. Data transformations and processing steps
  4. Data egress points (model outputs, integrations, external systems)

Has the organization obtained compliance certifications relevant to AI systems?

  1. ISO 42001
  2. NIST AI Risk Management Framework assessment
  3. EU AI Act conformity assessment
  4. FedRAMP authorization for AI systems
  5. HIPAA compliance for AI healthcare applications
  6. PCI DSS compliance for AI payment systems
  7. State-specific AI disclosures (e.g. NYC Local Law 144 bias audit report)
  8. Industry-specific AI frameworks (e.g., FDA AI/ML submissions, financial services AI governance)
  9. Other

Part 2: Agent configuration & capabilities

Are agents internally or externally facing?

  1. Internally / Externally / Both

Additional requirements for external agents

Externally-facing agents trigger A007: Prevent IP violations

List foundation models available to the agent(s)

  1. List - e.g. Claude Sonnet 4.5, ChatGPT 5.2, Gemini 3 Flash

Does your company train or fine-tune its own models?

  1. Y / N
  2. If yes, describe

What are the agent’s input modalities?

  1. Text
  2. Voice
  3. Image
  4. Video
  5. Other files (e.g. .pdf, .docx, .xls, .pptx)
  6. Code
  7. Other

What are the agent’s output modalities?

  1. Text
  2. Voice
  3. Image
  4. Video
  5. Other files (e.g. .pdf, .docx, .xls, .pptx)
  6. Code
  7. Other

A007: Prevent IP violations

B005: Implement real-time input filtering

B009: Limit output over-exposure

C003: Prevent harmful outputs

C004: Prevent out-of-scope outputsC010: Third-party testing for harmful outputs

C011: Third-party testing for out-of-scope outputsD001: Prevent hallucinated outputs

D002: Third-party testing for hallucinations

E002: AI failure plan for harmful outputsE003: AI failure plan for hallucinations

F001: Prevent AI cyber misuse

F002: Prevent catastrophic misuse

A007: Prevent IP violations B005: Implement real-time input filtering B009: Limit output over-exposure C003: Prevent harmful outputs C004: Prevent out-of-scope outputs C010: Third-party testing for harmful outputs C011: Third-party testing for out-of-scope outputs D001: Prevent hallucinated outputs D002: Third-party testing for hallucinations E002: AI failure plan for harmful outputs E003: AI failure plan for hallucinations F002: Prevent catastrophic misuse

A007: Prevent IP violations B005: Implement real-time input filtering C003: Prevent harmful outputs C010: Third-party testing for harmful outputs E002: AI failure plan for harmful outputs F002: Prevent catastrophic misuse

A007: Prevent IP violations B005: Implement real-time input filtering C003: Prevent harmful outputs C010: Third-party testing for harmful outputs E002: AI failure plan for harmful outputs F002: Prevent catastrophic misuse

Part 3: Guardrails

What party configures guardrails?

  1. Agent developer / platform (e.g. guardrails are configured automatically for all deployments of the agent)
  2. Agent deployer / customer (e.g. guardrails are configured by individual customers for each deployment)
  3. Both

If Customer/Both:

  1. Is guardrail implementation documented in docs?
  2. Describe

Are guardrails enabled by default?

  1. Describe

Does the agent builder offer support with guardrail implementation?

  1. Describe

Does agent builder offer evals of guardrails?

  1. Describe

Questions? Read the FAQ here or get in touch.