Skip to main content
Fieldwork: the auditor reviews the evidence for every requirement in scope, walks through it with the client, and issues a verdict per requirement.
1

Kick off

Hold a kickoff call with the client. In the same week, AIUC, the auditor, and the client fix a target certification date, typically about a week after fieldwork is expected to complete. Working back from a fixed date keeps the timeline predictable for the client and avoids the date being negotiated at the last minute. How the date is used is on the Audit report and certification page.
2

Review evidence per requirement

Work through the Statement of Applicability requirement by requirement, and hold evidence walkthroughs with the client. Judge each control against the rules below. Fieldwork can start on Round 1 eval results; the final results must be in hand by the closing meeting.
3

Give the client the chance to remediate

Gaps are remediable, not disqualifying. If issues are uncovered, the client remediates; to earn certification, all applicable requirements must pass, and every gap must be remediated or documented. Where the client passes but could do better, capture it in the Opportunities for Improvement note.
4

Closing meeting

The closing meeting is the formal stage gate: it marks that fieldwork and evidence collection are complete and that all applicable requirements pass. The certification date always falls on or after it, never before. Start writing the report during fieldwork so it is close to final by the closing meeting.

How to judge whether a control meets a requirement

  • Assess against intent, not just literal wording. AIUC-1 can be more prescriptive than a client’s context warrants, so flexibility is expected by design. Where the literal wording doesn’t fit, assess whether the control’s intent is met, and raise the case with AIUC rather than mechanically enforcing or unilaterally waiving the requirement. The quarterly update process exists to fix rules that don’t fit reality.
  • Delegated, client-configurable controls count as evidence. If the client has not implemented a control directly but gives its own customers the ability to configure it, such as data retention periods or specific guardrails, that meets the requirement, provided the delegation is documented in public docs, in-product guidance, or onboarding content.
  • Look for secure defaults. Where controls are configurable, the out-of-the-box configuration should be secure even if it can be changed. A secure default strengthens the evidence for a Pass; its absence is a flag to probe further.
  • Gaps are remediable, not disqualifying. The client is given the chance to remediate. All gaps must be remediated or documented to earn certification. Where the customer passes but could implement stronger controls, capture it in the Opportunities for Improvement (OFI) note issued alongside the report.

Verdicts

For each requirement in scope, the auditor issues one of: Supplemental controls the client opted into are highlighted in the report. Verdicts are always at the auditor’s discretion: client input is evaluated against the intent of the requirement, and AIUC feedback adds context and nuance, before the auditor decides.
Given the fast-paced nature of AI, AIUC-1 audits are conducted on a point-in-time basis. This differs from frameworks such as AICPA SOC 2 Type II, which establish an observation window. The auditor does not provide an opinion on whether evidence establishes a historical record of compliance, and the certificate represents a point-in-time evaluation, not a continuous guarantee.
Some auditors and clients spread fieldwork across three weeks with a week off in the middle. This gives the client time to act on early feedback, eases pressure during a busy period, and gives auditors flexibility where staffing is tight.
If evidence suggests a capability the Statement of Applicability excluded does exist, such as a text-only agent that accepts file uploads, raise it with AIUC rather than leaving the N/A in place. If the fix needs remediation or re-testing, reset the target certification date rather than working around it.
Output. A verdict per requirement, a closing meeting confirming all applicable requirements pass, a target certification date, and an Opportunities for Improvement note for the client.

Next: Audit report and certification

Finalize the report and certify on the target date.