AIUC-1’s requirements are organized under six principles, and the set is updated each quarter; the current list is on the standard page. Each requirement is mandatory or optional, and comes with core controls (what organizations should implement to pass) and supplemental controls (opted into at the organization’s discretion). Each requirement is tagged with the agent capabilities it applies to, such as “universal” or “code-generation”.
1
Start from the baseline
All mandatory requirements and their core controls apply by default. Where a core control is not demonstrated, the client can submit alternative evidence showing how the requirement is met, subject to the auditor’s assessment.
2
Scope out only where the capability is absent
A mandatory requirement can only be excluded when the agent genuinely lacks the capability it is tagged with, never to reduce audit effort. This is what gives the certificate the same meaning across auditors. Each exclusion carries a one to two sentence justification.
3
Opt in to optional requirements and supplemental controls
Organizations opt in to showcase strengths beyond the baseline, or to meet buyer or regulatory demands. Opted-in items strengthen the report but are not required to pass. Opt-ins can be revised during evidence collection until the evidence pack is handed over.
4
Agree the standard version, timeline, and ways of working
Confirm which version of AIUC-1 the audit runs against (see below), the evidence platform (for example, Drata, Vanta, Fieldguide, or the auditor’s own), the cadence of syncs, the fieldwork dates, and whether a preliminary review of specific controls is useful.
5
Sign off
The auditor signs off the Statement of Applicability. It is the definitive list of requirements and controls the audit tests, it is documented in the audit record, and it drives the audit report, which covers exactly the requirements it lists. Exclusions are documented and opted-in items are given visibility.
Which version of the standard to audit against
Which version of the standard to audit against
AIUC-1 is updated quarterly, with releases on January 15, April 15, July 15, and October 15. Audits run against the latest version, with a grace period of up to 30 days so organizations can prepare against a constant version. For example, the January 15 version can be selected until May 15; after that, the April 15 version must be used.The version is fixed when the engagement starts, at kickoff and scoping, and stays constant through fieldwork and the report. Always advise clients to use the latest version as soon as it is published. See the changelog for what changed in each release.
How exclusions appear in the audit report
How exclusions appear in the audit report
An approved exclusion produces an N/A verdict. Every scoped-out mandatory requirement is explicitly documented in the audit record. If evidence during fieldwork suggests the capability does exist, raise it with AIUC rather than leaving the N/A in place.
Scoping methodology
The full scoping methodology, including the developer versus deployer distinction.
The standard
The full requirement and control list, downloadable from the AIUC-1 website.
Output. A Statement of Applicability signed off by the auditor, with a justification against every exclusion, and an agreed standard version, timeline, and way of working.
Next: Evidence collection
The client gathers evidence for every requirement in scope.