> ## Documentation Index
> Fetch the complete documentation index at: https://standard.aiuc-1.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Auditor fieldwork

export const InlineClock = ({city, timeZone}) => {
  const [time, setTime] = useState('--:--:--');
  useEffect(() => {
    const update = () => setTime(new Intl.DateTimeFormat('en-US', {
      hour: '2-digit',
      minute: '2-digit',
      second: '2-digit',
      hour12: false,
      timeZone
    }).format(new Date()));
    update();
    const id = setInterval(update, 1000);
    return () => clearInterval(id);
  }, [timeZone]);
  return <div className="aiuc-footer-clock">
      <span className="aiuc-footer-clock-city">{city}</span>
      <span className="aiuc-footer-clock-time">{time}</span>
    </div>;
};

Fieldwork: the auditor reviews the evidence for every requirement in scope, walks through it with the client, and issues a verdict per requirement.

<div className="aiuc-facts-table" />

| | |
| - | - |
| Leads | Auditor |
| Supports | Client: a named point of contact fields questions, control owners stay on standby. <br />AIUC: evidence context, methodology questions, and weekly syncs as needed |
| Timing | Weeks 8 to 10 on the full timeline, typically two weeks depending on complexity. |
| Inputs | At kickoff: the [evidence pack](/auditors/deliver-and-certify/evidence-collection) and the final [Statement of Applicability](/auditors/deliver-and-certify/scoping/requirements-in-scope). <br />By the closing meeting: the final [evaluation results](/auditors/deliver-and-certify/evals) |
| Output | A verdict per requirement, a closing meeting, a target certification date, and an Opportunities for Improvement note |

<Steps>
  <Step title="Kick off">
    Hold a kickoff call with the client. In the same week, AIUC, the auditor, and the client fix a target certification date, typically about a week after fieldwork is expected to complete. Working back from a fixed date keeps the timeline predictable for the client and avoids the date being negotiated at the last minute. How the date is used is on the [Audit report and certification](/auditors/deliver-and-certify/audit-report-and-certification) page.
  </Step>

  <Step title="Review evidence per requirement">
    Work through the Statement of Applicability requirement by requirement, and hold evidence walkthroughs with the client. Judge each control against the rules below. Fieldwork can start on Round 1 eval results; the final results must be in hand by the closing meeting.
  </Step>

  <Step title="Give the client the chance to remediate">
    Gaps are remediable, not disqualifying. If issues are uncovered, the client remediates; to earn certification, all applicable requirements must pass, and every gap must be remediated or documented. Where the client passes but could do better, capture it in the Opportunities for Improvement note.
  </Step>

  <Step title="Closing meeting">
    The closing meeting is the formal stage gate: it marks that fieldwork and evidence collection are complete and that all applicable requirements pass. The certification date always falls on or after it, never before. Start writing the report during fieldwork so it is close to final by the closing meeting.
  </Step>
</Steps>

## How to judge whether a control meets a requirement

* **Assess against intent, not just literal wording.** AIUC-1 can be more prescriptive than a client's context warrants, so flexibility is expected by design. Where the literal wording doesn't fit, assess whether the control's intent is met, and raise the case with AIUC rather than mechanically enforcing or unilaterally waiving the requirement. The quarterly update process exists to fix rules that don't fit reality.
* **Delegated, client-configurable controls count as evidence.** If the client has not implemented a control directly but gives its own customers the ability to configure it, such as data retention periods or specific guardrails, that meets the requirement, provided the delegation is documented in public docs, in-product guidance, or onboarding content.
* **Look for secure defaults.** Where controls are configurable, the out-of-the-box configuration should be secure even if it can be changed. A secure default strengthens the evidence for a Pass; its absence is a flag to probe further.
* **Gaps are remediable, not disqualifying.** The client is given the chance to remediate. All gaps must be remediated or documented to earn certification. Where the customer passes but could implement stronger controls, capture it in the Opportunities for Improvement (OFI) note issued alongside the report.

## Verdicts

For each requirement in scope, the auditor issues one of:

| Verdict | Meaning | In the report |
| - | - | - |
| Pass | The client meets the requirement, with all core controls met, or with alternative controls the auditor accepts | Yes |
| Opportunity for improvement | Evidence meets the requirement, but there is room to make it more effective or efficient | No. Shared with the client as internal guidance in the Opportunities for Improvement note |
| N/A | The requirement was excluded during scoping, following the scoping methodology, because the agent lacks the capability | Yes, marked not applicable along with a 1-2 sentence justification |
| Fail | The client attempted but did not meet the requirement | Yes |

Supplemental controls the client opted into are highlighted in the report. Verdicts are always at the auditor's discretion: client input is evaluated against the intent of the requirement, and AIUC feedback adds context and nuance, before the auditor decides.

<AccordionGroup>
  <Accordion title="Point-in-time assessment">
    Given the fast-paced nature of AI, AIUC-1 audits are conducted on a point-in-time basis. This differs from frameworks such as AICPA SOC 2 Type II, which establish an observation window. The auditor does not provide an opinion on whether evidence establishes a historical record of compliance, and the certificate represents a point-in-time evaluation, not a continuous guarantee.
  </Accordion>

  <Accordion title="Spreading fieldwork over three weeks (if needed)">
    Some auditors and clients spread fieldwork across three weeks with a week off in the middle. This gives the client time to act on early feedback, eases pressure during a busy period, and gives auditors flexibility where staffing is tight.
  </Accordion>

  <Accordion title="If a scoped-out capability turns out to exist">
    If evidence suggests a capability the Statement of Applicability excluded does exist, such as a text-only agent that accepts file uploads, raise it with AIUC rather than leaving the N/A in place. If the fix needs remediation or re-testing, reset the target certification date rather than working around it.
  </Accordion>
</AccordionGroup>

<Check>
  **Output.** A verdict per requirement, a closing meeting confirming all applicable requirements pass, a target certification date, and an Opportunities for Improvement note for the client.
</Check>

***

<Card title="Next: Audit report and certification" href="/auditors/deliver-and-certify/audit-report-and-certification">
  Finalize the report and certify on the target date.
</Card>

<div className="aiuc-footer">
  <span className="aiuc-footer-corner aiuc-footer-corner-tl">
    <svg fill="none" stroke="currentColor" strokeWidth="1" viewBox="0 0 12 12" width="12" height="12">
      <line x1="0" x2="12" y1="6" y2="6" />

      <line x1="6" x2="6" y1="0" y2="12" />
    </svg>
  </span>

  <span className="aiuc-footer-corner aiuc-footer-corner-tr">
    <svg fill="none" stroke="currentColor" strokeWidth="1" viewBox="0 0 12 12" width="12" height="12">
      <line x1="0" x2="12" y1="6" y2="6" />

      <line x1="6" x2="6" y1="0" y2="12" />
    </svg>
  </span>

  <div className="aiuc-footer-strip">
    <span className="aiuc-footer-mono">37.782274° N -122.392147° W</span>
    <span className="aiuc-footer-strip-center">FIG. A (SITE INDEX)</span>

    <span />
  </div>

  <div className="aiuc-footer-row-main">
    <div className="aiuc-footer-wireframe-cell">
      <svg className="aiuc-footer-wireframe" fill="none" stroke="currentColor" strokeWidth="0.4" viewBox="0 0 200 150">
        <rect height="130" width="180" x="10" y="10" />

        <rect height="40" width="60" x="20" y="20" />

        <rect height="40" width="40" x="90" y="20" />

        <rect height="40" width="40" x="140" y="20" />

        <rect height="60" width="60" x="20" y="70" />

        <rect height="60" width="90" x="90" y="70" />

        <line strokeDasharray="2,2" x1="20" x2="180" y1="65" y2="65" />

        <line strokeDasharray="2,2" x1="85" x2="85" y1="20" y2="60" />

        <circle cx="50" cy="40" r="6" />

        <circle cx="110" cy="40" r="6" />

        <circle cx="160" cy="40" r="6" />
      </svg>
    </div>

    <div className="aiuc-footer-wordmark-cell">
      <div className="aiuc-footer-wordmark">Artificial Intelligence Underwriting Company</div>
    </div>

    <div className="aiuc-footer-clocks">
      <InlineClock city="SFO" timeZone="America/Los_Angeles" />

      <InlineClock city="NYC" timeZone="America/New_York" />

      <InlineClock city="LON" timeZone="Europe/London" />
    </div>
  </div>

  <div className="aiuc-footer-row-sub">
    <div className="aiuc-footer-codeblock-cell">
      <div className="aiuc-footer-codeblock">
        <span className="aiuc-footer-codeblock-header">Code</span>
        <span className="aiuc-footer-codeblock-header">Structural unit</span>
        <span className="aiuc-footer-codeblock-code">a.</span>
        <span className="aiuc-footer-codeblock-text">AIUC-1 requirements for agent data, privacy, security, safety, reliability, accountability, and societal risk.</span>
        <span className="aiuc-footer-codeblock-code">b.</span>
        <span className="aiuc-footer-codeblock-text">Evidence templates for technical implementation, legal policy, operational practice, and third-party evaluation.</span>
        <span className="aiuc-footer-codeblock-code">c.</span>
        <span className="aiuc-footer-codeblock-text">Crosswalks to AI regulations, standards, and security frameworks.</span>
        <span className="aiuc-footer-codeblock-code">d.</span>
        <span className="aiuc-footer-codeblock-text">Quarterly updates shaped by enterprise adoption, risk, regulation, and community input.</span>
      </div>
    </div>

    <div className="aiuc-footer-columns-cell">
      <div className="aiuc-footer-columns">
        <div>
          <div className="aiuc-footer-column-header">I. Standard</div>

          <ul className="aiuc-footer-column-list">
            <li><a className="aiuc-footer-column-link" href="/">Overview</a></li>
            <li><a className="aiuc-footer-column-link" href="/crosswalks">Crosswalks</a></li>
            <li><a className="aiuc-footer-column-link" href="/evidence">Evidence</a></li>
            <li><a className="aiuc-footer-column-link" href="/changelog">Changelog</a></li>
          </ul>
        </div>

        <div>
          <div className="aiuc-footer-column-header">II. Learn</div>

          <ul className="aiuc-footer-column-list">
            <li><a className="aiuc-footer-column-link" href="/learn/about">About AIUC-1</a></li>
            <li><a className="aiuc-footer-column-link" href="/learn/contribute">Contribute</a></li>
            <li><a className="aiuc-footer-column-link" href="/scoping">Scoping</a></li>
            <li><a className="aiuc-footer-column-link" href="/faq">FAQ</a></li>
          </ul>
        </div>

        <div>
          <div className="aiuc-footer-column-header">III. Office</div>

          <ul className="aiuc-footer-column-list">
            <li><a className="aiuc-footer-column-link" href="/consortium">Consortium</a></li>
            <li><a className="aiuc-footer-column-link" href="https://www.aiuc-1.com/contact">Contact</a></li>
            <li><a className="aiuc-footer-column-link" href="/legal/privacy">Privacy policy</a></li>
            <li><a className="aiuc-footer-column-link" href="/legal/terms">Terms of use</a></li>
          </ul>
        </div>
      </div>
    </div>
  </div>

  <div className="aiuc-footer-strip-bottom">
    <span className="aiuc-footer-mono">100</span>
    <span>© AIUC — ALL RIGHTS RESERVED</span>
  </div>

  <span className="aiuc-footer-corner aiuc-footer-corner-bl">
    <svg fill="none" stroke="currentColor" strokeWidth="1" viewBox="0 0 12 12" width="12" height="12">
      <line x1="0" x2="12" y1="6" y2="6" />

      <line x1="6" x2="6" y1="0" y2="12" />
    </svg>
  </span>

  <span className="aiuc-footer-corner aiuc-footer-corner-br">
    <svg fill="none" stroke="currentColor" strokeWidth="1" viewBox="0 0 12 12" width="12" height="12">
      <line x1="0" x2="12" y1="6" y2="6" />

      <line x1="6" x2="6" y1="0" y2="12" />
    </svg>
  </span>
</div>


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.