What we actually test
Every organisation asks the same first question: what specifically will you assess us against? This is the answer, in full — all 44 requirements, what each one demands, and what evidence it takes to satisfy it. We publish it because a certification scheme nobody can read is a scheme nobody should trust.
Two things are deliberately not on this page
The verification method. How an auditor tests each requirement stays with AIC. What we test and what evidence it takes is public; the procedure for testing it is not.
The ISO/IEC 42001 clause mapping. It is drafted, but indicative until we have verified it against the purchased standard text. Publishing an unverified mapping to an international standard would be exactly the kind of unbacked claim this organisation exists to catch, so it stays off the page until it is checked.
This is version 1, issued 2026-09-04
The requirement set is settled enough to be assessed against and open enough to be argued with. Specific numeric thresholds — the empathy floor, the disparate impact ratio, correction response times — are provisional and will be confirmed before the first certificate is issued. Where a threshold moves, the revision record will say so and why. No organisation has been certified against this standard yet; the public register is empty and will stay that way until one has been.
Which of these apply to you?
Requirements are scoped by Division — how much human agency sits between the system and the person it affects. Pick yours to see the set you would actually be assessed against.
Evidence tiersA · Operational dataB · Third-party or observedC · Self-certifiedD · AttestationHow scoring works
Each requirement names the strongest evidence it admits. Providing the best evidence available earns full marks; providing weaker evidence than you could have earns proportionally less, and over-providing earns no bonus. This is why an organisation cannot buy its way to a score with paperwork.
- A×1.0
- Live system data, telemetry or records — the organisation's actual behaviour rather than its account of it.
- B×0.8
- Evidence an auditor observes directly, or that an independent party produced.
- C×0.6
- Documentation the organisation maintains and supplies.
- D×0.4
- A statement that something is so, with nothing behind it but the statement.
All 44 requirements
Every requirement in the standard.
Human Agency
HU · 11 shownA named individual is accountable, and can actually intervene.
- HU-1Tier C · Self-certifiedD1 · D2 · D3 · D4 · D5
An Accountable Person is named in writing, as an individual and not a role, for each registered AI system.
Evidence: System register or governance record naming a person
- HU-2Tier B · Third-party or observedD1 · D2 · D3 · D4 · D5
The Accountable Person has signed a declaration acknowledging personal accountability.
Evidence: Signed Accountable Person Declaration
- HU-3Tier C · Self-certifiedD1 · D2 · D3 · D4 · D5
A complete inventory of AI systems making or influencing consequential decisions is maintained and current.
Evidence: AI system register with purpose, risk category and affected population
- HU-4Tier C · Self-certifiedD2 · D3 · D4
A documented override or human intervention process exists for each system.
Evidence: Written override procedure
- HU-5Tier B · Third-party or observedD2 · D3 · D4
The override mechanism is functional and demonstrable in the production system.
Evidence: Live demonstration or screen-recorded walkthrough
- HU-6Tier A · Operational dataD2 · D3 · D4
Exercising an override requires a reason to be entered, and that reason is stored.
Evidence: Override records containing a populated reason field
- HU-7Tier A · Operational dataD2 · D3 · D4Hard to fake
Override events are evidenced during the assessment period. Zero overrides across material decision volume is not a pass — it triggers interrogation.
Evidence: System override records with reviewer identity
- HU-8Tier A · Operational dataD2 · D3 · D4
The observed human oversight ratio is consistent with the Division the organisation has declared.
Evidence: Human review completion rate from live telemetry
- HU-9Tier B · Third-party or observedD2 · D3 · D4
An escalation path exists and is traceable end to end.
Evidence: One escalation traced from initial flag through to outcome
- HU-10Tier B · Third-party or observedD1
A Shadow AI audit has been completed, establishing that no undisclosed AI operates in consequential decisions.
Evidence: Software asset register, procurement review, departmental questionnaires, and a CEO or MD attestation
- HU-11Tier B · Third-party or observedD1 · D2 · D3 · D4 · D5Hard to fake
The Accountable Person can describe operational reality unaided. Needing to check with someone else is a finding.
Evidence: Recorded walk-me-through interview
Tell us where this is wrong
This is version 1 and it is published to be challenged. If a requirement is unmeasurable, if a threshold is set in the wrong place, or if we have missed something that matters in your sector, we would rather hear it now than defend it later. Substantive challenges change the standard and are credited in the revision record.
Challenge a requirement