Skip to main content
The Statement of Applicability is the list of AIUC-1 requirements and controls the client’s agent will be audited against, signed off by the auditor. Building it is the second part of scoping, and it is what the audit report is built from.
AIUC-1’s requirements are organized under six principles, and the set is updated each quarter; the current list is on the standard page. Each requirement is mandatory or optional, and comes with core controls (what organizations should implement to pass) and supplemental controls (opted into at the organization’s discretion). Each requirement is tagged with the agent capabilities it applies to, such as “universal” or “code-generation”.
1

Start from the baseline

All mandatory requirements and their core controls apply by default. Where a core control is not demonstrated, the client can submit alternative evidence showing how the requirement is met, subject to the auditor’s assessment.
2

Scope out only where the capability is absent

A mandatory requirement can only be excluded when the agent genuinely lacks the capability it is tagged with, never to reduce audit effort. This is what gives the certificate the same meaning across auditors. Each exclusion carries a one to two sentence justification.
3

Opt in to optional requirements and supplemental controls

Organizations opt in to showcase strengths beyond the baseline, or to meet buyer or regulatory demands. Opted-in items strengthen the report but are not required to pass. Opt-ins can be revised during evidence collection until the evidence pack is handed over.
4

Agree the standard version, timeline, and ways of working

Confirm which version of AIUC-1 the audit runs against (see below), the evidence platform (for example, Drata, Vanta, Fieldguide, or the auditor’s own), the cadence of syncs, the fieldwork dates, and whether a preliminary review of specific controls is useful.
5

Sign off

The auditor signs off the Statement of Applicability. It is the definitive list of requirements and controls the audit tests, it is documented in the audit record, and it drives the audit report, which covers exactly the requirements it lists. Exclusions are documented and opted-in items are given visibility.
AIUC-1 is updated quarterly, with releases on January 15, April 15, July 15, and October 15. Audits run against the latest version, with a grace period of up to 30 days so organizations can prepare against a constant version. For example, the January 15 version can be selected until May 15; after that, the April 15 version must be used.The version is fixed when the engagement starts, at kickoff and scoping, and stays constant through fieldwork and the report. Always advise clients to use the latest version as soon as it is published. See the changelog for what changed in each release.
An approved exclusion produces an N/A verdict. Every scoped-out mandatory requirement is explicitly documented in the audit record. If evidence during fieldwork suggests the capability does exist, raise it with AIUC rather than leaving the N/A in place.

Scoping methodology

The full scoping methodology, including the developer versus deployer distinction.

The standard

The full requirement and control list, downloadable from the AIUC-1 website.
Output. A Statement of Applicability signed off by the auditor, with a justification against every exclusion, and an agreed standard version, timeline, and way of working.

Next: Evidence collection

The client gathers evidence for every requirement in scope.