> ## Documentation Index
> Fetch the complete documentation index at: https://standard.aiuc-1.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Technical evaluations (evals)

export const InlineClock = ({city, timeZone}) => {
  const [time, setTime] = useState('--:--:--');
  useEffect(() => {
    const update = () => setTime(new Intl.DateTimeFormat('en-US', {
      hour: '2-digit',
      minute: '2-digit',
      second: '2-digit',
      hour12: false,
      timeZone
    }).format(new Date()));
    update();
    const id = setInterval(update, 1000);
    return () => clearInterval(id);
  }, [timeZone]);
  return <div className="aiuc-footer-clock">
      <span className="aiuc-footer-clock-city">{city}</span>
      <span className="aiuc-footer-clock-time">{time}</span>
    </div>;
};

Technical evaluations, or evals, are the independent technical testing that AIUC-1 requires for certification: thousands of benign, social engineering, and adversarial scenarios run against the agent and graded against the AIUC-1 risk and attack taxonomy.

<Info>
  **AIUC runs evals today. Auditor-led evals are in development.** Guidance for auditors who want to run evals themselves is coming soon. [Get in touch](https://www.aiuc-1.com/contact) to register interest.
</Info>

<div className="aiuc-facts-table" />

| | |
| - | - |
| Leads | AIUC |
| Client | Reviews the preliminary samples and Round 1 results, and remediates P0 and P1 findings |
| Auditor | Validates that testing took place, followed the methodology, and met the pass bar |
| Timing | Weeks 2 to 8, in parallel with [evidence collection](/auditors/deliver-and-certify/evidence-collection). <br />Round 2 runs only where Round 1 surfaces P0 or P1 findings; with a clean Round 1 the eval phase ends at week 4 |
| Inputs | The signed [scoping document](/auditors/deliver-and-certify/scoping/agent-and-evaluation-scope), covering the agent under test and the risk distribution, and stable technical access to the agent |
| Output | Final evaluation results for the audit report, with no open P0 or P1 findings |

<Steps>
  <Step title="Preliminary validation runs">
    *Week 2.* A small sample set is run to confirm the methodology and configuration. The client's technical reviewers spend about 30 minutes on it and give feedback on realism, methodology including grading, and debuggability. The final eval count is set from these runs by whoever runs the evals.
  </Step>

  <Step title="Round 1">
    *Weeks 3 to 4.* The full suite runs and results are shared with the client, followed by a roughly 30-minute results review.
  </Step>

  <Step title="Remediate">
    *Weeks 5 to 6.* The client remediates the P0 (Critical) and P1 (Major) findings, which are required to pass. Remediation of lower-severity findings, P2 to P4, is at the client's discretion. The environment stays representative and unchanged otherwise, so both rounds run against similar configuration.
  </Step>

  <Step title="Round 2, if needed">
    *Weeks 7 to 8.* Where Round 1 surfaced P0 or P1 findings, the suite is re-run after remediation with the same risk and attack categories and regenerated individual scenarios. Only final results are included in the audit report. The final results are needed by the fieldwork closing meeting.
  </Step>
</Steps>

## How results are graded

Every eval response is graded on the AIUC-1 severity scale, based on the potential impact of the agent's response:

| Grade | Meaning |
| - | - |
| Pass | No issues identified |
| P4 (Trivial) | Unlikely to cause harm |
| P3 (Minor) | Low potential for harm |
| P2 (Significant) | Moderate potential for harm |
| P1 (Major) | High potential for harm |
| P0 (Critical) | Severe harm imminent or active |

<Info>
  **Coming soon:** details on how grading is customized based on B2B vs. B2C agents
</Info>

<Check>
  **Pass bar.** No open P0 or P1 findings. Together with a pass on every applicable requirement in [fieldwork](/auditors/deliver-and-certify/fieldwork), this is what earns certification.
</Check>

## The auditor's role

Today, the auditor does not run or design the evals. The auditor's role is to validate that testing took place, that procedures followed the documented methodology, and that results met the AIUC-1 pass bar: review the methodology, sample the test documentation, and verify the results against the pass bar.

Auditor-led evals are currently in development.

<AccordionGroup>
  <Accordion title="What running evals requires">
    High-level, for auditors considering auditor-led evals once available. The work breaks into five jobs: eval scoping, connection, generation, running, and grading. Most of it is judgment about enterprise risk and software engineering.

    * **Enterprise risk judgment.** Understanding what a bad answer looks like for this client, in this industry; choosing which risks matter and weighting them; judging severity when grading. This majority of the work, and the hardest to train.
    * **Understanding the client's product.** Running a structured product walkthrough, mapping tools, data flows, guardrails, and tenancy.
    * **Platform operation.** Using AIUC's evaluation platform to generate, run, and grade evals, so results stay consistent across clients and auditors. 
    * **Connection engineering.** Connecting the platform to the client's agent, typically a plug-in when the client has a clean API and sometimes a small translation server. Needs an internal or client-facing technology team. 
  </Accordion>

  <Accordion title="Why one methodology">
    An AIUC-1 certificate has to mean the same thing whoever audited it. Evals run on one methodology so that results are comparable across clients and auditors; that is why they are centralized today and why auditor-led evals will follow the same methodology.
  </Accordion>
</AccordionGroup>

<Card title="Evaluation methodology" href="https://www.aiuc-1.com/methodology">
  The evaluation and grading methodology, and the risk and attack taxonomy.
</Card>

***

<Card title="Next: Fieldwork" href="/auditors/deliver-and-certify/fieldwork">
  Evidence walkthroughs and a verdict per requirement.
</Card>

<div className="aiuc-footer">
  <span className="aiuc-footer-corner aiuc-footer-corner-tl">
    <svg fill="none" stroke="currentColor" strokeWidth="1" viewBox="0 0 12 12" width="12" height="12">
      <line x1="0" x2="12" y1="6" y2="6" />

      <line x1="6" x2="6" y1="0" y2="12" />
    </svg>
  </span>

  <span className="aiuc-footer-corner aiuc-footer-corner-tr">
    <svg fill="none" stroke="currentColor" strokeWidth="1" viewBox="0 0 12 12" width="12" height="12">
      <line x1="0" x2="12" y1="6" y2="6" />

      <line x1="6" x2="6" y1="0" y2="12" />
    </svg>
  </span>

  <div className="aiuc-footer-strip">
    <span className="aiuc-footer-mono">37.782274° N -122.392147° W</span>
    <span className="aiuc-footer-strip-center">FIG. A (SITE INDEX)</span>

    <span />
  </div>

  <div className="aiuc-footer-row-main">
    <div className="aiuc-footer-wireframe-cell">
      <svg className="aiuc-footer-wireframe" fill="none" stroke="currentColor" strokeWidth="0.4" viewBox="0 0 200 150">
        <rect height="130" width="180" x="10" y="10" />

        <rect height="40" width="60" x="20" y="20" />

        <rect height="40" width="40" x="90" y="20" />

        <rect height="40" width="40" x="140" y="20" />

        <rect height="60" width="60" x="20" y="70" />

        <rect height="60" width="90" x="90" y="70" />

        <line strokeDasharray="2,2" x1="20" x2="180" y1="65" y2="65" />

        <line strokeDasharray="2,2" x1="85" x2="85" y1="20" y2="60" />

        <circle cx="50" cy="40" r="6" />

        <circle cx="110" cy="40" r="6" />

        <circle cx="160" cy="40" r="6" />
      </svg>
    </div>

    <div className="aiuc-footer-wordmark-cell">
      <div className="aiuc-footer-wordmark">Artificial Intelligence Underwriting Company</div>
    </div>

    <div className="aiuc-footer-clocks">
      <InlineClock city="SFO" timeZone="America/Los_Angeles" />

      <InlineClock city="NYC" timeZone="America/New_York" />

      <InlineClock city="LON" timeZone="Europe/London" />
    </div>
  </div>

  <div className="aiuc-footer-row-sub">
    <div className="aiuc-footer-codeblock-cell">
      <div className="aiuc-footer-codeblock">
        <span className="aiuc-footer-codeblock-header">Code</span>
        <span className="aiuc-footer-codeblock-header">Structural unit</span>
        <span className="aiuc-footer-codeblock-code">a.</span>
        <span className="aiuc-footer-codeblock-text">AIUC-1 requirements for agent data, privacy, security, safety, reliability, accountability, and societal risk.</span>
        <span className="aiuc-footer-codeblock-code">b.</span>
        <span className="aiuc-footer-codeblock-text">Evidence templates for technical implementation, legal policy, operational practice, and third-party evaluation.</span>
        <span className="aiuc-footer-codeblock-code">c.</span>
        <span className="aiuc-footer-codeblock-text">Crosswalks to AI regulations, standards, and security frameworks.</span>
        <span className="aiuc-footer-codeblock-code">d.</span>
        <span className="aiuc-footer-codeblock-text">Quarterly updates shaped by enterprise adoption, risk, regulation, and community input.</span>
      </div>
    </div>

    <div className="aiuc-footer-columns-cell">
      <div className="aiuc-footer-columns">
        <div>
          <div className="aiuc-footer-column-header">I. Standard</div>

          <ul className="aiuc-footer-column-list">
            <li><a className="aiuc-footer-column-link" href="/">Overview</a></li>
            <li><a className="aiuc-footer-column-link" href="/crosswalks">Crosswalks</a></li>
            <li><a className="aiuc-footer-column-link" href="/evidence">Evidence</a></li>
            <li><a className="aiuc-footer-column-link" href="/changelog">Changelog</a></li>
          </ul>
        </div>

        <div>
          <div className="aiuc-footer-column-header">II. Learn</div>

          <ul className="aiuc-footer-column-list">
            <li><a className="aiuc-footer-column-link" href="/learn/about">About AIUC-1</a></li>
            <li><a className="aiuc-footer-column-link" href="/learn/contribute">Contribute</a></li>
            <li><a className="aiuc-footer-column-link" href="/scoping">Scoping</a></li>
            <li><a className="aiuc-footer-column-link" href="/faq">FAQ</a></li>
          </ul>
        </div>

        <div>
          <div className="aiuc-footer-column-header">III. Office</div>

          <ul className="aiuc-footer-column-list">
            <li><a className="aiuc-footer-column-link" href="/consortium">Consortium</a></li>
            <li><a className="aiuc-footer-column-link" href="https://www.aiuc-1.com/contact">Contact</a></li>
            <li><a className="aiuc-footer-column-link" href="/legal/privacy">Privacy policy</a></li>
            <li><a className="aiuc-footer-column-link" href="/legal/terms">Terms of use</a></li>
          </ul>
        </div>
      </div>
    </div>
  </div>

  <div className="aiuc-footer-strip-bottom">
    <span className="aiuc-footer-mono">100</span>
    <span>© AIUC — ALL RIGHTS RESERVED</span>
  </div>

  <span className="aiuc-footer-corner aiuc-footer-corner-bl">
    <svg fill="none" stroke="currentColor" strokeWidth="1" viewBox="0 0 12 12" width="12" height="12">
      <line x1="0" x2="12" y1="6" y2="6" />

      <line x1="6" x2="6" y1="0" y2="12" />
    </svg>
  </span>

  <span className="aiuc-footer-corner aiuc-footer-corner-br">
    <svg fill="none" stroke="currentColor" strokeWidth="1" viewBox="0 0 12 12" width="12" height="12">
      <line x1="0" x2="12" y1="6" y2="6" />

      <line x1="6" x2="6" y1="0" y2="12" />
    </svg>
  </span>
</div>


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.