> ## Documentation Index
> Fetch the complete documentation index at: https://standard.aiuc-1.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Evidence collection

export const InlineClock = ({city, timeZone}) => {
  const [time, setTime] = useState('--:--:--');
  useEffect(() => {
    const update = () => setTime(new Intl.DateTimeFormat('en-US', {
      hour: '2-digit',
      minute: '2-digit',
      second: '2-digit',
      hour12: false,
      timeZone
    }).format(new Date()));
    update();
    const id = setInterval(update, 1000);
    return () => clearInterval(id);
  }, [timeZone]);
  return <div className="aiuc-footer-clock">
      <span className="aiuc-footer-clock-city">{city}</span>
      <span className="aiuc-footer-clock-time">{time}</span>
    </div>;
};

Evidence collection is where the client gathers proof, for every requirement in scope, that a control exists and works, and hands it to the auditor as a quality-assured evidence pack.

<div className="aiuc-facts-table" />

| | |
| - | - |
| Leads | Client |
| Supports | AIUC can provide inputs to the gap assessment, per-control guidance on request, and a quality-assurance pass (as needed).<br /><br />The auditor is available for an optional preliminary review |
| Timing | Weeks 1 to 6, in parallel with scoping and the [technical evaluations (evals)](/auditors/deliver-and-certify/evals) |
| Inputs | The [Statement of Applicability](/auditors/deliver-and-certify/scoping/requirements-in-scope) and the standard's control list |
| Output | An evidence pack for every in-scope control, on a shared platform with access for the auditor and AIUC |

<Steps>
  <Step title="Run the gap assessment">
    *Weeks 1 to 2.* The client assesses every in-scope control against what exists today, building on the gap assessment from [Introduce and scope](/auditors/introduce-and-scope/request-a-gap-assessment) and starting from the requirements it marked to be verified. AIUC supports by providing inputs as needed. The result is a remediation path agreed for every gap.
  </Step>

  <Step title="Confirm optional requirements and supplemental controls">
    *Week 2.* Opt-ins are proposed at [scoping](/auditors/deliver-and-certify/scoping/requirements-in-scope) and can be revised here until the evidence pack is handed over. Where evidence is readily available, include it: opted-in items are referenced directly in the audit report and shape how strong it reads. The Statement of Applicability is final at handover.
  </Step>

  <Step title="Collect and upload evidence">
    *Weeks 2 to 6.* Start with the core controls of each requirement. Evidence goes into a shared platform (for example, Drata, Vanta, or Fieldguide) with external access for the auditor and for AIUC. Evidence falls into four categories: 

    <CardGroup cols={2}>
      <Card title="Legal evidence" href="/evidence/legal-policies">
        Policies and contracts, such as ownership of inputs and outputs, or the agent's acceptable use policy.
      </Card>

      <Card title="Technical evidence" href="/evidence/technical-implementation">
        Safeguards in the codebase or tooling, such as sensitive data protection or hallucination guardrails.
      </Card>

      <Card title="Operational evidence" href="/evidence/operational-practices">
        Process documentation, such as accountability for agent changes or failure plans.
      </Card>

      <Card title="Third-party evals" href="/evidence/third-party-evals">
        The eval results. Provided by AIUC today; the auditor validates that scope and results meet the standard.
      </Card>
    </CardGroup>
  </Step>

  <Step title="Hand over">
    *Week 6.* The evidence pack is handed to the auditor together with the final Statement of Applicability. Evidence should be complete before handover so the auditor's follow-up questions during fieldwork are minimized.
  </Step>
</Steps>

## The auditor during evidence collection

Auditors clarify what a requirement needs and may review readiness, but do not design or implement controls. Within that boundary:

* **Preliminary review, optional.** A review of specific controls or evidence can be agreed where useful, for example on controls the client is unsure about, so issues surface before fieldwork rather than during it
* **Questions on what a requirement needs.** Answer against the intent of the requirement. The rules for judging whether a control meets a requirement are on the [Fieldwork](/auditors/deliver-and-certify/fieldwork#how-to-judge-whether-a-control-meets-a-requirement) page
* **Workshops, for new auditors.** You will be added to one or two evidence collection workshops with a client, to see how evidence is gathered in practice. Contact AIUC's delivery lead for details

<AccordionGroup>
  <Accordion title="Who is needed on the client side">
    One person can play several roles: a primary point of contact coordinating collection, often the security or governance lead; a policy or AI-governance owner for policy and accountability controls; legal or privacy counsel for data-protection and contractual evidence; and engineering for technical evidence such as architecture, access controls, logging, and guardrails.
  </Accordion>

  <Accordion title="Audit tooling and quarterly updates">
    GRC and audit tools are set up per client and must be updated each quarter with the standard's changes, so the version agreed at scoping is the one in the tool. If you use your own audit platform, AIUC shares an updated spreadsheet with the controls mapping each quarter. Which version applies to a given audit is on the [Requirements in scope](/auditors/deliver-and-certify/scoping/requirements-in-scope) page.
  </Accordion>
</AccordionGroup>

<Check>
  **Output.** Evidence against every in-scope requirement, quality-assured, on a shared platform, handed to the auditor with the final Statement of Applicability.
</Check>

***

<Card title="Next: Technical evaluations" href="/auditors/deliver-and-certify/evals">
  How the evals run, and what the auditor validates.
</Card>

<div className="aiuc-footer">
  <span className="aiuc-footer-corner aiuc-footer-corner-tl">
    <svg fill="none" stroke="currentColor" strokeWidth="1" viewBox="0 0 12 12" width="12" height="12">
      <line x1="0" x2="12" y1="6" y2="6" />

      <line x1="6" x2="6" y1="0" y2="12" />
    </svg>
  </span>

  <span className="aiuc-footer-corner aiuc-footer-corner-tr">
    <svg fill="none" stroke="currentColor" strokeWidth="1" viewBox="0 0 12 12" width="12" height="12">
      <line x1="0" x2="12" y1="6" y2="6" />

      <line x1="6" x2="6" y1="0" y2="12" />
    </svg>
  </span>

  <div className="aiuc-footer-strip">
    <span className="aiuc-footer-mono">37.782274° N -122.392147° W</span>
    <span className="aiuc-footer-strip-center">FIG. A (SITE INDEX)</span>

    <span />
  </div>

  <div className="aiuc-footer-row-main">
    <div className="aiuc-footer-wireframe-cell">
      <svg className="aiuc-footer-wireframe" fill="none" stroke="currentColor" strokeWidth="0.4" viewBox="0 0 200 150">
        <rect height="130" width="180" x="10" y="10" />

        <rect height="40" width="60" x="20" y="20" />

        <rect height="40" width="40" x="90" y="20" />

        <rect height="40" width="40" x="140" y="20" />

        <rect height="60" width="60" x="20" y="70" />

        <rect height="60" width="90" x="90" y="70" />

        <line strokeDasharray="2,2" x1="20" x2="180" y1="65" y2="65" />

        <line strokeDasharray="2,2" x1="85" x2="85" y1="20" y2="60" />

        <circle cx="50" cy="40" r="6" />

        <circle cx="110" cy="40" r="6" />

        <circle cx="160" cy="40" r="6" />
      </svg>
    </div>

    <div className="aiuc-footer-wordmark-cell">
      <div className="aiuc-footer-wordmark">Artificial Intelligence Underwriting Company</div>
    </div>

    <div className="aiuc-footer-clocks">
      <InlineClock city="SFO" timeZone="America/Los_Angeles" />

      <InlineClock city="NYC" timeZone="America/New_York" />

      <InlineClock city="LON" timeZone="Europe/London" />
    </div>
  </div>

  <div className="aiuc-footer-row-sub">
    <div className="aiuc-footer-codeblock-cell">
      <div className="aiuc-footer-codeblock">
        <span className="aiuc-footer-codeblock-header">Code</span>
        <span className="aiuc-footer-codeblock-header">Structural unit</span>
        <span className="aiuc-footer-codeblock-code">a.</span>
        <span className="aiuc-footer-codeblock-text">AIUC-1 requirements for agent data, privacy, security, safety, reliability, accountability, and societal risk.</span>
        <span className="aiuc-footer-codeblock-code">b.</span>
        <span className="aiuc-footer-codeblock-text">Evidence templates for technical implementation, legal policy, operational practice, and third-party evaluation.</span>
        <span className="aiuc-footer-codeblock-code">c.</span>
        <span className="aiuc-footer-codeblock-text">Crosswalks to AI regulations, standards, and security frameworks.</span>
        <span className="aiuc-footer-codeblock-code">d.</span>
        <span className="aiuc-footer-codeblock-text">Quarterly updates shaped by enterprise adoption, risk, regulation, and community input.</span>
      </div>
    </div>

    <div className="aiuc-footer-columns-cell">
      <div className="aiuc-footer-columns">
        <div>
          <div className="aiuc-footer-column-header">I. Standard</div>

          <ul className="aiuc-footer-column-list">
            <li><a className="aiuc-footer-column-link" href="/">Overview</a></li>
            <li><a className="aiuc-footer-column-link" href="/crosswalks">Crosswalks</a></li>
            <li><a className="aiuc-footer-column-link" href="/evidence">Evidence</a></li>
            <li><a className="aiuc-footer-column-link" href="/changelog">Changelog</a></li>
          </ul>
        </div>

        <div>
          <div className="aiuc-footer-column-header">II. Learn</div>

          <ul className="aiuc-footer-column-list">
            <li><a className="aiuc-footer-column-link" href="/learn/about">About AIUC-1</a></li>
            <li><a className="aiuc-footer-column-link" href="/learn/contribute">Contribute</a></li>
            <li><a className="aiuc-footer-column-link" href="/scoping">Scoping</a></li>
            <li><a className="aiuc-footer-column-link" href="/faq">FAQ</a></li>
          </ul>
        </div>

        <div>
          <div className="aiuc-footer-column-header">III. Office</div>

          <ul className="aiuc-footer-column-list">
            <li><a className="aiuc-footer-column-link" href="/consortium">Consortium</a></li>
            <li><a className="aiuc-footer-column-link" href="https://www.aiuc-1.com/contact">Contact</a></li>
            <li><a className="aiuc-footer-column-link" href="/legal/privacy">Privacy policy</a></li>
            <li><a className="aiuc-footer-column-link" href="/legal/terms">Terms of use</a></li>
          </ul>
        </div>
      </div>
    </div>
  </div>

  <div className="aiuc-footer-strip-bottom">
    <span className="aiuc-footer-mono">100</span>
    <span>© AIUC — ALL RIGHTS RESERVED</span>
  </div>

  <span className="aiuc-footer-corner aiuc-footer-corner-bl">
    <svg fill="none" stroke="currentColor" strokeWidth="1" viewBox="0 0 12 12" width="12" height="12">
      <line x1="0" x2="12" y1="6" y2="6" />

      <line x1="6" x2="6" y1="0" y2="12" />
    </svg>
  </span>

  <span className="aiuc-footer-corner aiuc-footer-corner-br">
    <svg fill="none" stroke="currentColor" strokeWidth="1" viewBox="0 0 12 12" width="12" height="12">
      <line x1="0" x2="12" y1="6" y2="6" />

      <line x1="6" x2="6" y1="0" y2="12" />
    </svg>
  </span>
</div>


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.