Skip to main content
Scoping decides which instance of the agent and which risks the technical evaluations (evals) will test, and which AIUC-1 requirements the agent will be audited against. The agent itself is agreed upon in Introduce and scope.
1

Agent and evaluation scope

With access to a representative instance of the agent in place before the first meeting, build its profile with an explicit out-of-scope list, and agree the risk distribution with a rough eval count.Open part →
2

Requirements in scope

Build the Statement of Applicability for the auditor to sign off, and agree the standard version, timeline, and ways of working.Open part →
Part 1 is led by whoever runs the evals: AIUC today, the auditor once auditor-led evals are available. As the process matures the client leads the agent-under-test profile within it.Part 2 is always client-led, with the auditor signing off. The auditor confirms both, because the report attests to the scope.
Output. A signed scoping document covering the agent under test and the risk distribution, a Statement of Applicability signed off by the auditor with a justification against every exclusion, and an agreed timeline and way of working.

Next: Agent and evaluation scope

Pin down the instance under test and the risks the evals cover.