AIUC-1
AIUC-1 Certification -> Scoping

Scoping the AIUC-1 audit

AIUC-1 is designed to cover all the risks that matter for secure adoption of agentic AI. The standard has 6 foundational principles: Data & Privacy, Security, Safety, Reliability, Accountability, Society. Within these principles are 50 requirements with a list of technical & policy controls for each requirement.

Not every control applies to every agent. Scoping an AIUC-1 audit answers two questions:

  • What AI systems are you certifying?
  • What AIUC-1 requirements must be met?

Scoping is completed upfront, with AIUC and your auditor of choice. The output is a defined boundary of AI systems in-scope and the controls they will be audited against.

Part 1: What AI systems are you certifying?

Systems in Scope

Two questions determine your certification scope:

  1. What is your role? Are you an AI agent developer, deployer or both? Which agentic AI systems (or “agents”) are in scope?
  2. Only include agentic AI systems in the scope - AIUC-1 does not cover other systems

Systems in scope: Guidance

AI developers build the agentic platform and capabilities, and determine the safe-configuration defaults engineered into agents. AI deployers configure the agentic platform for their own use case, and deploy agents in their own environment. AI developers can be AI deployers and vice versa. Developers are responsible for making sure that secure defaults are in place and documented. Deployers are responsible for configuring AI systems securely given their deployment context.

AIUC-1 is most relevant for higher risk agentic AI systems that are:

  • Critical to the business - for example, customer-facing agents, where brand is on the line
  • Highly capable - for example, agents with access to sensitive data or access to tools like a CRM or payment processing
  • Subject to legal, compliance, or stakeholder requirements - for example, an AI recruitment system classified as high-risk under the EU AI Act with legal obligations, which may require third-party validation before deployment

An agent's risk profile is driven by three factors:

  • Capabilities (what the agent can do) - for example, the modalities it supports (text, voice, image, video) and its level of autonomy
  • Architecture (how the agent is built) - for example, what data it can access or which tools it can call
  • Deployment context (where the agent operates) - for example, whether it is internally or externally facing, if it’s deployed by a large bank or a small YC company, or designed for consumer or business audiences

You can certify multiple agents at once, or start with one high-risk agent and expand your scope after your first certification.

Note: prioritize agents that are accessible via external API. Programmatic access enables the ability to run a high volume of automated technical tests - required to pass the AIUC-1 audit. Agents only accessible through a platform UI require a more manual evaluation approach which is often costlier.

Part 2: What AIUC-1 requirements must be met?

Statement of Applicability

AIUC-1 has 50 requirements. Requirements are either mandatory or optional to earn AIUC-1 certification.

Each requirement comes with a list of:

  1. Core controls: These are controls organizations should implement to pass AIUC-1. If core controls are not demonstrated, organizations must submit alternative evidence demonstrating how they meet the requirement
  2. Supplemental controls: These are controls organizations may implement in addition and are not required to pass AIUC-1. Instead, organizations opt-in to supplemental controls relevant given the AI agent’s capabilities, architecture, and deployment context.

Application of each of these controls depend on your AI system. The output is a Statement of Applicability, signed off by the auditor: the definitive list of requirements and controls your agents are audited against.

To guide organizations and auditors, each AIUC-1 requirement is tagged with “Capabilities”, e.g. “universal” or “code-generation”. If an agent does not have the capability, the AIUC-1 requirement should be viewed as optional.

Statement of Applicability: Guidance

  1. Baseline - all mandatory requirements and core controls apply by default.
  2. Scoping out - a mandatory requirement can only be excluded with a documented, legitimate business reason signed off by the auditor. A core control can be excluded if the organization demonstrates alternative ways of meeting the requirement.
  3. Opting in - organizations can add any number of optional requirements and supplemental controls to their scope. Typical reasons to opt in:
    1. Showcase strengths - demonstrate gold-standard controls beyond industry standard, in areas where your organization already excels
    2. Meet customer or regulatory demands - where specific buyers or regulations expect controls beyond the baseline given the deployment context & agent capabilities

Note: Scope is disclosed in your certification and audit report. Your audit report shows exactly which requirements and controls were tested - exclusions are documented, and opted-in requirements and controls are provided visibility. Customers reading your report can see precisely what your certification covers.

Get Started

Get in touch to begin scoping your AIUC-1 audit.