Sensiba Achieves Provisional AIUC-1 Auditor Accreditation

AIUC-1 Auditor Accreditation

Sensiba has earned provisional accreditation to audit against AIUC-1, the standard for AI agent security, safety, and reliability. Provisional accreditation reflects that a witness audit is already underway, with full accreditation to follow once that audit is completed to AIUC-1 standards.

Introducing AIUC-1: AI Agent Certification Backed by Adversarial Testing

Within two years, 40% of enterprise applications are expected to be powered by AI agents. Adoption is running well ahead of the ability to assess it.

Security teams are being asked to approve systems that behave differently on every run, call tools, hold credentials and act on instructions from untrusted inputs. The gap is not awareness. It is that there has been no consistent way to establish whether a particular agent is safe to deploy.

Most existing frameworks answer a different question. ISO 42001 governs how an organization manages AI across its lifecycle, and it does that well. But it does not measure whether a particular agent’s safeguards actually work, or how severely that agent fails when they do not. AIUC-1 was built to close that gap.

“Enterprises are asking their AI vendors questions that policies alone cannot settle,” said Chris Roe, Partner, Governance, Risk, & Compliance at Sensiba. “AIUC-1 pairs the documentation with technical testing of the agent itself, which is why we’re excited to add it to our AI assurance practice.”

AIUC-1 is the most technically grounded certification available for AI agents today. It is the only one that requires an accredited auditor to review production code, configuration and logs, and then requires the agent itself to undergo thousands of adversarial prompts before a certificate is issued.

It was developed with MITRE, the Cloud Security Alliance and Stanford’s trustworthy AI lab, and it is backed by a consortium of more than 250 CISOs and security leaders from Fortune 500 enterprises. The standard is updated quarterly to keep up with AI capabilities, new research, and real AI incidents.

AIUC-1 also operationalizes the frameworks enterprises already reference, including ISO 42001 and emerging AI legislations such as the EU AI Act.

Sensiba’s AI Assurance Practice

We have been building AI assurance capability since accredited certification for AI management systems first became possible. ANAB granted its first ISO 42001 accreditation in September 2024 and accredited us the following May, while the market for AI certification was still taking shape. That work sits inside a governance, risk and compliance practice covering SOC 2, ISO 27001, 27017, 27018 and 27701, HITRUST and penetration testing.

For companies building AI products, that history has a practical effect. Organizations that have already achieved certifications such as ISO 42001 have a head start, as they can leverage controls that overlap across both frameworks, particularly in governance and data security. This dynamic also makes it practical for many companies to pursue ISO 42001 and AIUC-1 in parallel, providing a clear path to assurance at both levels: high-level AI governance and the security posture of the agents themselves.

“Sensiba understood early that AI assurance would need real technical depth, and they have built the team to match,” said Rajiv Dattani, co-founder of Artificial Intelligence Underwriting Company. “Together, we’re defining what AI assurance should look like: independent, technically rigorous, and grounded in evidence of how AI systems actually behave.”

Sensiba joins Schellman, Coalfire, BDO, Grant Thornton and Mastermind in the AIUC-1 auditor ecosystem.

Getting started

AIUC-1 certification is relevant for any organization building or deploying agentic AI in environments where risk is real. This could mean customer facing agents, agents processing sensitive data, agents taking material actions, agents deployed in regulated environments, or other situations where trust and security is non-negotiable.

If you are considering AIUC-1 certification, the practical first step is a gap assessment against the standard’s requirements. Visit our AIUC-1 services page to learn more about the certification or to speak with one of our professionals.