AIUC-1 is designed to cover all the risks that matter for secure adoption of agentic AI. The standard has 6 foundational principles: Data & Privacy, Security, Safety, Reliability, Accountability, Society. Within these principles are 50 requirements with a list of technical & policy controls for each requirement.
Not every control applies to every agent. Scoping an AIUC-1 audit answers two questions:
Scoping is completed upfront, with AIUC and your auditor of choice. The output is a defined boundary of AI systems in-scope and the controls they will be audited against.
Systems in Scope
Two questions determine your certification scope:
Systems in scope: Guidance
AI developers build the agentic platform and capabilities, and determine the safe-configuration defaults engineered into agents. AI deployers configure the agentic platform for their own use case, and deploy agents in their own environment. AI developers can be AI deployers and vice versa. Developers are responsible for making sure that secure defaults are in place and documented. Deployers are responsible for configuring AI systems securely given their deployment context.
AIUC-1 is most relevant for higher risk agentic AI systems that are:
An agent's risk profile is driven by three factors:
You can certify multiple agents at once, or start with one high-risk agent and expand your scope after your first certification.
Note: prioritize agents that are accessible via external API. Programmatic access enables the ability to run a high volume of automated technical tests - required to pass the AIUC-1 audit. Agents only accessible through a platform UI require a more manual evaluation approach which is often costlier.
Statement of Applicability
AIUC-1 has 50 requirements. Requirements are either mandatory or optional to earn AIUC-1 certification.
Each requirement comes with a list of:
Application of each of these controls depend on your AI system. The output is a Statement of Applicability, signed off by the auditor: the definitive list of requirements and controls your agents are audited against.
To guide organizations and auditors, each AIUC-1 requirement is tagged with “Capabilities”, e.g. “universal” or “code-generation”. If an agent does not have the capability, the AIUC-1 requirement should be viewed as optional.
Statement of Applicability: Guidance
Note: Scope is disclosed in your certification and audit report. Your audit report shows exactly which requirements and controls were tested - exclusions are documented, and opted-in requirements and controls are provided visibility. Customers reading your report can see precisely what your certification covers.
Get in touch to begin scoping your AIUC-1 audit.