> ## Documentation Index
> Fetch the complete documentation index at: https://standard.aiuc-1.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Requirements in scope

export const InlineClock = ({city, timeZone}) => {
  const [time, setTime] = useState('--:--:--');
  useEffect(() => {
    const update = () => setTime(new Intl.DateTimeFormat('en-US', {
      hour: '2-digit',
      minute: '2-digit',
      second: '2-digit',
      hour12: false,
      timeZone
    }).format(new Date()));
    update();
    const id = setInterval(update, 1000);
    return () => clearInterval(id);
  }, [timeZone]);
  return <div className="aiuc-footer-clock">
      <span className="aiuc-footer-clock-city">{city}</span>
      <span className="aiuc-footer-clock-time">{time}</span>
    </div>;
};

The Statement of Applicability is the list of AIUC-1 requirements and controls the client's agent will be audited against, signed off by the auditor. Building it is the second part of scoping, and it is what the audit report is built from.

<div className="aiuc-facts-table" />

| | |
| - | - |
| Leads | Client |
| Signs off | Auditor. AIUC supports and is the escalation point for judgment calls |
| Timing | Weeks 1 to 2. Opt-ins can be revised until the evidence pack is handed over; the Statement of Applicability is final at handover, before fieldwork |
| Inputs | The [agent-under-test profile](/auditors/deliver-and-certify/scoping/agent-and-evaluation-scope) and the standard's requirement and control list |
| Output | A Statement of Applicability signed off by the auditor, and an agreed standard version, timeline, and way of working |

AIUC-1's requirements are organized under six principles, and the set is updated each quarter; the current list is on the [standard](/evidence/index) page. Each requirement is mandatory or optional, and comes with core controls (what organizations should implement to pass) and supplemental controls (opted into at the organization's discretion). Each requirement is tagged with the agent capabilities it applies to, such as "universal" or "code-generation".

<Steps>
  <Step title="Start from the baseline">
    All mandatory requirements and their core controls apply by default. Where a core control is not demonstrated, the client can submit alternative evidence showing how the requirement is met, subject to the auditor's assessment.
  </Step>

  <Step title="Scope out only where the capability is absent">
    A mandatory requirement can only be excluded when the agent genuinely lacks the capability it is tagged with, never to reduce audit effort. This is what gives the certificate the same meaning across auditors. Each exclusion carries a one to two sentence justification.
  </Step>

  <Step title="Opt in to optional requirements and supplemental controls">
    Organizations opt in to showcase strengths beyond the baseline, or to meet buyer or regulatory demands. Opted-in items strengthen the report but are not required to pass. Opt-ins can be revised during [evidence collection](/auditors/deliver-and-certify/evidence-collection) until the evidence pack is handed over.
  </Step>

  <Step title="Agree the standard version, timeline, and ways of working">
    Confirm which version of AIUC-1 the audit runs against (see below), the evidence platform (for example, Drata, Vanta, Fieldguide, or the auditor's own), the cadence of syncs, the fieldwork dates, and whether a preliminary review of specific controls is useful.
  </Step>

  <Step title="Sign off">
    The auditor signs off the Statement of Applicability. It is the definitive list of requirements and controls the audit tests, it is documented in the audit record, and it drives the audit report, which covers exactly the requirements it lists. Exclusions are documented and opted-in items are given visibility.
  </Step>
</Steps>

<AccordionGroup>
  <Accordion title="Which version of the standard to audit against">
    AIUC-1 is updated quarterly, with releases on January 15, April 15, July 15, and October 15. Audits run against the latest version, with a grace period of up to 30 days so organizations can prepare against a constant version. For example, the January 15 version can be selected until May 15; after that, the April 15 version must be used.

    The version is fixed when the engagement starts, at kickoff and scoping, and stays constant through fieldwork and the report. Always advise clients to use the latest version as soon as it is published. See the [changelog](/changelog) for what changed in each release.
  </Accordion>

  <Accordion title="How exclusions appear in the audit report">
    An approved exclusion produces an N/A verdict. Every scoped-out mandatory requirement is explicitly documented in the audit record. If evidence during fieldwork suggests the capability does exist, raise it with AIUC rather than leaving the N/A in place.
  </Accordion>
</AccordionGroup>

<CardGroup cols={2}>
  <Card title="Scoping methodology" href="/scoping">
    The full scoping methodology, including the developer versus deployer distinction.
  </Card>

  <Card title="The standard" href="/evidence/index">
    The full requirement and control list, downloadable from the AIUC-1 website.
  </Card>
</CardGroup>

<Check>
  **Output.** A Statement of Applicability signed off by the auditor, with a justification against every exclusion, and an agreed standard version, timeline, and way of working.
</Check>

***

<Card title="Next: Evidence collection" href="/auditors/deliver-and-certify/evidence-collection">
  The client gathers evidence for every requirement in scope.
</Card>

<div className="aiuc-footer">
  <span className="aiuc-footer-corner aiuc-footer-corner-tl">
    <svg fill="none" stroke="currentColor" strokeWidth="1" viewBox="0 0 12 12" width="12" height="12">
      <line x1="0" x2="12" y1="6" y2="6" />

      <line x1="6" x2="6" y1="0" y2="12" />
    </svg>
  </span>

  <span className="aiuc-footer-corner aiuc-footer-corner-tr">
    <svg fill="none" stroke="currentColor" strokeWidth="1" viewBox="0 0 12 12" width="12" height="12">
      <line x1="0" x2="12" y1="6" y2="6" />

      <line x1="6" x2="6" y1="0" y2="12" />
    </svg>
  </span>

  <div className="aiuc-footer-strip">
    <span className="aiuc-footer-mono">37.782274° N -122.392147° W</span>
    <span className="aiuc-footer-strip-center">FIG. A (SITE INDEX)</span>

    <span />
  </div>

  <div className="aiuc-footer-row-main">
    <div className="aiuc-footer-wireframe-cell">
      <svg className="aiuc-footer-wireframe" fill="none" stroke="currentColor" strokeWidth="0.4" viewBox="0 0 200 150">
        <rect height="130" width="180" x="10" y="10" />

        <rect height="40" width="60" x="20" y="20" />

        <rect height="40" width="40" x="90" y="20" />

        <rect height="40" width="40" x="140" y="20" />

        <rect height="60" width="60" x="20" y="70" />

        <rect height="60" width="90" x="90" y="70" />

        <line strokeDasharray="2,2" x1="20" x2="180" y1="65" y2="65" />

        <line strokeDasharray="2,2" x1="85" x2="85" y1="20" y2="60" />

        <circle cx="50" cy="40" r="6" />

        <circle cx="110" cy="40" r="6" />

        <circle cx="160" cy="40" r="6" />
      </svg>
    </div>

    <div className="aiuc-footer-wordmark-cell">
      <div className="aiuc-footer-wordmark">Artificial Intelligence Underwriting Company</div>
    </div>

    <div className="aiuc-footer-clocks">
      <InlineClock city="SFO" timeZone="America/Los_Angeles" />

      <InlineClock city="NYC" timeZone="America/New_York" />

      <InlineClock city="LON" timeZone="Europe/London" />
    </div>
  </div>

  <div className="aiuc-footer-row-sub">
    <div className="aiuc-footer-codeblock-cell">
      <div className="aiuc-footer-codeblock">
        <span className="aiuc-footer-codeblock-header">Code</span>
        <span className="aiuc-footer-codeblock-header">Structural unit</span>
        <span className="aiuc-footer-codeblock-code">a.</span>
        <span className="aiuc-footer-codeblock-text">AIUC-1 requirements for agent data, privacy, security, safety, reliability, accountability, and societal risk.</span>
        <span className="aiuc-footer-codeblock-code">b.</span>
        <span className="aiuc-footer-codeblock-text">Evidence templates for technical implementation, legal policy, operational practice, and third-party evaluation.</span>
        <span className="aiuc-footer-codeblock-code">c.</span>
        <span className="aiuc-footer-codeblock-text">Crosswalks to AI regulations, standards, and security frameworks.</span>
        <span className="aiuc-footer-codeblock-code">d.</span>
        <span className="aiuc-footer-codeblock-text">Quarterly updates shaped by enterprise adoption, risk, regulation, and community input.</span>
      </div>
    </div>

    <div className="aiuc-footer-columns-cell">
      <div className="aiuc-footer-columns">
        <div>
          <div className="aiuc-footer-column-header">I. Standard</div>

          <ul className="aiuc-footer-column-list">
            <li><a className="aiuc-footer-column-link" href="/">Overview</a></li>
            <li><a className="aiuc-footer-column-link" href="/crosswalks">Crosswalks</a></li>
            <li><a className="aiuc-footer-column-link" href="/evidence">Evidence</a></li>
            <li><a className="aiuc-footer-column-link" href="/changelog">Changelog</a></li>
          </ul>
        </div>

        <div>
          <div className="aiuc-footer-column-header">II. Learn</div>

          <ul className="aiuc-footer-column-list">
            <li><a className="aiuc-footer-column-link" href="/learn/about">About AIUC-1</a></li>
            <li><a className="aiuc-footer-column-link" href="/learn/contribute">Contribute</a></li>
            <li><a className="aiuc-footer-column-link" href="/scoping">Scoping</a></li>
            <li><a className="aiuc-footer-column-link" href="/faq">FAQ</a></li>
          </ul>
        </div>

        <div>
          <div className="aiuc-footer-column-header">III. Office</div>

          <ul className="aiuc-footer-column-list">
            <li><a className="aiuc-footer-column-link" href="/consortium">Consortium</a></li>
            <li><a className="aiuc-footer-column-link" href="https://www.aiuc-1.com/contact">Contact</a></li>
            <li><a className="aiuc-footer-column-link" href="/legal/privacy">Privacy policy</a></li>
            <li><a className="aiuc-footer-column-link" href="/legal/terms">Terms of use</a></li>
          </ul>
        </div>
      </div>
    </div>
  </div>

  <div className="aiuc-footer-strip-bottom">
    <span className="aiuc-footer-mono">100</span>
    <span>© AIUC — ALL RIGHTS RESERVED</span>
  </div>

  <span className="aiuc-footer-corner aiuc-footer-corner-bl">
    <svg fill="none" stroke="currentColor" strokeWidth="1" viewBox="0 0 12 12" width="12" height="12">
      <line x1="0" x2="12" y1="6" y2="6" />

      <line x1="6" x2="6" y1="0" y2="12" />
    </svg>
  </span>

  <span className="aiuc-footer-corner aiuc-footer-corner-br">
    <svg fill="none" stroke="currentColor" strokeWidth="1" viewBox="0 0 12 12" width="12" height="12">
      <line x1="0" x2="12" y1="6" y2="6" />

      <line x1="6" x2="6" y1="0" y2="12" />
    </svg>
  </span>
</div>


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.