What we actually test
Every organisation asks the same first question: what specifically will you assess us against? This is the answer, in full — all 44 requirements, what each one demands, and what evidence it takes to satisfy it. We publish it because a certification scheme nobody can read is a scheme nobody should trust.
Two things are deliberately not on this page
The verification method. How an auditor tests each requirement stays with AIC. What we test and what evidence it takes is public; the procedure for testing it is not.
The ISO/IEC 42001 clause mapping. It is drafted, but indicative until we have verified it against the purchased standard text. Publishing an unverified mapping to an international standard would be exactly the kind of unbacked claim this organisation exists to catch, so it stays off the page until it is checked.
This is version 1, issued 2026-09-04
The requirement set is settled enough to be assessed against and open enough to be argued with. Specific numeric thresholds — the empathy floor, the disparate impact ratio, correction response times — are provisional and will be confirmed before the first certificate is issued. Where a threshold moves, the revision record will say so and why. No organisation has been certified against this standard yet; the public register is empty and will stay that way until one has been.
Which of these apply to you?
Requirements are scoped by Division — how much human agency sits between the system and the person it affects. Pick yours to see the set you would actually be assessed against.
Evidence tiers
Each requirement names the strongest evidence it admits. Providing the best evidence available earns full marks; providing weaker evidence than you could have earns proportionally less. Over-providing earns no bonus. This is why an organisation cannot buy its way to a score with paperwork.
Live system data, telemetry or records — the organisation's actual behaviour rather than its account of it.
Evidence an auditor observes directly, or that an independent party produced.
Documentation the organisation maintains and supplies.
A statement that something is so, with nothing behind it but the statement.
Human Agency
HU · 11 requirementsA named individual is accountable, and can actually intervene.
- HU-1
An Accountable Person is named in writing, as an individual and not a role, for each registered AI system.
Applies to D1 · D2 · D3 · D4 · D5System register or governance record naming a personC - HU-2
The Accountable Person has signed a declaration acknowledging personal accountability.
Applies to D1 · D2 · D3 · D4 · D5Signed Accountable Person DeclarationB - HU-3
A complete inventory of AI systems making or influencing consequential decisions is maintained and current.
Applies to D1 · D2 · D3 · D4 · D5AI system register with purpose, risk category and affected populationC - HU-4
A documented override or human intervention process exists for each system.
Applies to D2 · D3 · D4Written override procedureC - HU-5
The override mechanism is functional and demonstrable in the production system.
Applies to D2 · D3 · D4Live demonstration or screen-recorded walkthroughB - HU-6
Exercising an override requires a reason to be entered, and that reason is stored.
Applies to D2 · D3 · D4Override records containing a populated reason fieldA - HU-7Hard to fake
Override events are evidenced during the assessment period. Zero overrides across material decision volume is not a pass — it triggers interrogation.
Applies to D2 · D3 · D4System override records with reviewer identityA - HU-8
The observed human oversight ratio is consistent with the Division the organisation has declared.
Applies to D2 · D3 · D4Human review completion rate from live telemetryA - HU-9
An escalation path exists and is traceable end to end.
Applies to D2 · D3 · D4One escalation traced from initial flag through to outcomeB - HU-10
A Shadow AI audit has been completed, establishing that no undisclosed AI operates in consequential decisions.
Applies to D1Software asset register, procurement review, departmental questionnaires, and a CEO or MD attestationB - HU-11Hard to fake
The Accountable Person can describe operational reality unaided. Needing to check with someone else is a finding.
Applies to D1 · D2 · D3 · D4 · D5Recorded walk-me-through interviewB
Explanation
EX · 7 requirementsThe reason given is the reason that operated.
- EX-1
A decision explanation mechanism exists for each system.
Applies to D2 · D3 · D4 · D5Explanation process documentationC - EX-2
Explanations are produced in plain language rather than raw technical output.
Applies to D1 · D2 · D3 · D4 · D5Sample explanations actually issued to affected peopleB - EX-3
Explanations are retained and retrievable for each individual decision.
Applies to D2 · D3 · D4Decision records containing the explanation payloadA - EX-4
Explanations are accessible to the affected person on request.
Applies to D1 · D2 · D3 · D4 · D5Request process and evidence that requests were fulfilledB - EX-5Hard to fake
The stated reasons materially match the actual drivers of the decision. Divergence between the reason given and the dominant feature is a critical finding — it is post-hoc rationalisation, not explanation.
Applies to D2 · D3 · D4Issued adverse notices, alongside feature-attribution output on those same decisionsA - EX-6
Feature inputs are documented, including identification of proxy variables.
Applies to D2 · D3 · D4 · D5Feature documentation or model cardB - EX-7
System documentation equivalent to a model card is maintained and current — purpose, data, limitations, version.
Applies to D2 · D3 · D4 · D5Model card or equivalent, with version historyC
Empathy
EM · 10 requirementsAdverse decisions are communicated like a person receives them.
- EM-1Hard to fake
Adverse automated communications score at least 60 on the AIC Empathy Rubric. A score below 40 blocks certification outright.
Applies to D1 · D2 · D3 · D4 · D5Between three and ten real adverse communicationsA - EM-2
Communications meet the plain-language standard — an ordinary person of the intended class understands them without undue effort.
Applies to D1 · D2 · D3 · D4 · D5The same communication sampleB - EM-3
Adverse communications state the reason for the decision. Generic boilerplate fails.
Applies to D1 · D2 · D3 · D4 · D5The same communication sampleB - EM-4
Adverse communications provide an accessible human contact point that is specific and reachable.
Applies to D1 · D2 · D3 · D4 · D5The same communication sampleB - EM-5
Adverse communications provide clear, actionable next steps.
Applies to D1 · D2 · D3 · D4 · D5The same communication sampleB - EM-6
Bias and disparate impact testing has been conducted within the defined period.
Applies to D2 · D3 · D4 · D5Bias testing report, assessed for recency, methodology and scopeB - EM-7Hard to fake
The disparate impact ratio is at least 0.8 across tested protected characteristics. Refusal to supply the data is recorded as Not Testable, which is itself a finding.
Applies to D2 · D3 · D4 · D5Outcome data disaggregated by groupA - EM-8
Intersectional analysis has been performed across multiple attributes, not one at a time.
Applies to D3 · D4 · D5Multi-attribute outcome analysisA - EM-9
A mechanism exists to flag decisions where material human context was unavailable to the system.
Applies to D2 · D3 · D4Process documentation and sample flag recordsC - EM-10
Proxy variables are identified and either justified or removed.
Applies to D2 · D3 · D4 · D5Feature review recordB
Correction
CO · 9 requirementsGetting a decision wrong is recoverable, and demonstrably happens.
- CO-1
A correction or appeal mechanism exists and is publicly accessible.
Applies to D1 · D2 · D3 · D4 · D5Public-facing appeal route, which the auditor must locate unaidedB - CO-2
The mechanism is discoverable by an ordinary affected person, not only by someone who knows it exists.
Applies to D1 · D2 · D3 · D4 · D5User journey evidenceB - CO-3
A defined service level for correction response is documented.
Applies to D1 · D2 · D3 · D4 · D5Policy stating the response SLAC - CO-4
The service level is met in practice — median time to response falls within the stated SLA.
Applies to D2 · D3 · D4Correction request logs with timestampsA - CO-5
Correction requests are logged immutably, with their outcome.
Applies to D2 · D3 · D4Correction records, checked for ledger integrityA - CO-6Hard to fake
The overturn rate is non-zero and explicable. A pipeline where nothing is ever overturned is not a correction pipeline; a very high rate indicates a problem in the underlying model.
Applies to D2 · D3 · D4Correction outcomes across the assessment periodA - CO-7
Uptake is consistent with decision volume. Near-zero uptake indicates a mechanism nobody can find.
Applies to D2 · D3 · D4Appeals as a proportion of adverse decisionsA - CO-8
Upheld corrections result in a traceable change to the outcome.
Applies to D2 · D3 · D4Before and after decision recordsA - CO-9
A named human is responsible for correction responses.
Applies to D1 · D2 · D3 · D4 · D5Governance record, cross-checked against HU-1C
Truth
TR · 7 requirementsPeople know an AI is involved, before it affects them.
- TR-1
An AI disclosure policy is documented.
Applies to D1 · D2 · D3 · D4 · D5Written disclosure policyC - TR-2
Disclosure is present at each consequential decision point.
Applies to D2 · D3 · D4 · D5Screenshots of the decision points themselvesB - TR-3Hard to fake
Disclosure occurs before the interaction affects the person. Post-hoc disclosure fails, and a terms-and-conditions checkbox at signup generally fails for a decision made later.
Applies to D2 · D3 · D4 · D5Timed user journey evidenceB - TR-4
Disclosure is specific rather than generic legal boilerplate — it says what the AI does in this decision.
Applies to D2 · D3 · D4 · D5The disclosure text as shownB - TR-5
Disclosure is discoverable in the real user journey rather than buried.
Applies to D2 · D3 · D4 · D5Journey walkthroughB - TR-6
System metadata accurately describes the AI's role in each decision.
Applies to D2 · D3 · D4 · D5Decision records with role metadataC - TR-7
Public disclosure of AI use is maintained and current.
Applies to D3 · D4 · D5Published disclosures page or statementC
Tell us where this is wrong
This is version 1 and it is published to be challenged. If a requirement is unmeasurable, if a threshold is set in the wrong place, or if we have missed something that matters in your sector, we would rather hear it now than defend it later. Substantive challenges change the standard and are credited in the revision record.
Challenge a requirement