AI governance insight

AIUC-1 explained: six domains for safer, more reliable AI agents

AI agents can read files, call tools, connect to business systems and take actions. AIUC-1 provides a structured way to assess the safeguards around those capabilities. Tier 1 helps firms prepare the scope, controls and evidence, while formal certification remains with AIUC and its accredited process.

Scroll to explore
02Tier 1

Section 02

Start with what the AI system can do

AIUC-1 is a security, safety and reliability standard for organisations that develop or deploy agentic AI systems. Official scoping guidance for the 15 July 2026 release describes 50 requirements organised under six foundational principles.

The standard is refreshed quarterly. An assessment therefore starts with the current release, a defined boundary of in-scope agents and a Statement of Applicability that records which requirements and controls apply.

AIUC-1 is not a general badge for every use of generative AI. A drafting assistant still needs confidentiality, privacy and human-review rules, but formal AIUC-1 scope is aimed at systems that can access data, invoke tools or take actions.

03The six domains
04Tier 1 support

Tier 1 support

Turn the six domains into owned controls and evidence

Tier 1 provides independent AIUC-1 readiness and remediation support. The work connects governance, security, privacy, suppliers and technical owners so a firm can address real gaps before formal assessment.

Identify the scope

Separate ordinary assistants from agentic systems, then record purpose, users, data, tools, actions, environments, suppliers and accountable owners.

Assess the gaps

Compare current safeguards and evidence with the requirements likely to apply, while keeping the result clearly labelled as a readiness view.

Implement the controls

Coordinate policies, access restrictions, supplier checks, human review, monitoring, testing and failure processes with the people who operate them.

Prepare the evidence

Organise technical, operational and legal evidence so each safeguard can be traced to its owner, operation, review date and supporting record.

Prepare for assessment

Resolve evidence gaps and help the firm work effectively with AIUC, its accredited auditor and the required independent technical-testing process.

Maintain readiness

Reassess the agent when its model, permissions, tools, supplier, data or business purpose changes, and plan for the standard's quarterly updates.

05Tier 1

Section 05

Use formal assurance where the capability justifies it

A high-trust firm should begin with the system's access and possible consequences. Formal AIUC-1 certification is more relevant when an agent can reach confidential information, invoke business tools, affect clients or take action with limited human involvement.

ISO 42001 and AIUC-1 address different layers. ISO 42001 provides an organisation-wide management system for AI. AIUC-1 examines safeguards and testing around defined agents. A firm may use either or both, depending on its systems, clients and assurance needs.

06Clear boundary

Clear boundary

Readiness support is not certification

Tier 1 Consulting does not issue AIUC-1 certificates and is not presented as an AIUC-1-accredited auditor or official AIUC partner. Only the Artificial Intelligence Underwriting Company issues the certificate after its accredited audit and technical-testing process.

A readiness review does not guarantee certification. Its value is a more accurate scope, fewer unresolved gaps, working controls and evidence that is easier for the formal assessors to examine.

07Primary references
08Questions

Straight answers

Common questions

Is AIUC-1 relevant to every AI tool?

No. AIUC-1 is scoped to agentic AI systems. An ordinary writing assistant still needs appropriate governance, but formal AIUC-1 assessment is aimed at systems that can access data, use tools or take actions within a defined scope.

Can Tier 1 issue an AIUC-1 certificate?

No. Tier 1 supports readiness, remediation and evidence preparation. Formal assessment involves an AIUC-1-accredited auditor and AIUC technical testing, and only AIUC can issue the official certificate.

How is AIUC-1 different from ISO 42001?

ISO 42001 establishes an organisation-wide AI management system. AIUC-1 focuses on safeguards and testing for defined AI agents. They can complement each other when a firm needs both management-system discipline and agent-specific assurance.

Does a readiness review guarantee certification?

No. A readiness review identifies gaps and prepares controls and evidence. AIUC and the accredited auditor determine the formal scope, testing requirements and certification outcome.

A quiet first step

Know what your AI agents can access before they act

Tier 1 can help identify agentic AI, assess readiness across the six domains and prepare the controls and evidence needed for formal assessment.

Explore AI governance services