Which version of the standard to audit against
AIUC-1 is updated quarterly, with releases on January 15, April 15, July 15, and October 15 of each year. At the start of your re-certification, you will receive guidance on how the standard has changed since your last audit - which requirements are new or updated, and what your organization needs to implement before auditor fieldwork. Audits are generally conducted against the latest version of AIUC-1. We allow up to 30 days of grace period, to enable organizations to prepare for an audit against a constant standard version.Re-audit process
- Choose your auditor: Continue with your existing auditor or select a new one.
- Scoping: Confirm which agents are in scope and update your Statement of Applicability. We recommend adding newly deployed high-risk agents at this point - your certification should evolve with your security posture.
- Red-teaming: AIUC re-runs technical evaluations against your in-scope agents, updated to reflect the current threat landscape.
- Full audit of control: Your auditor reviews evidence across all in-scope requirements and controls.
- Updated report and certification: You receive a new audit report and certificate, ready for your trust center.
Effort required
The re-certification is substantially lighter than the initial first audit:- Controls remain in place: Policies & technical controls implemented at the initial audit should still be in place, making evidence collection simple.
- Established evidence infrastructure: Evidence locations, owners, and formats are established from the previous audit.