ISO 42001 and AIUC-1: How Two AI Assurance Standards Work Together
AI agent vendors are starting to arrive at your procurement review with two certificates instead of one. A growing number hold ISO 42001 certification for their AI management system, and a smaller but visible group has added AIUC-1, a use-case-level standard for AI agent security, safety, and reliability published by the Artificial Intelligence Underwriting Company.
If you are deciding whether an agent gets access to your customer data, your internal tooling, or your brand, it is worth understanding that these are complementary standards. They certify different objects, and a vendor holding both is handing you a considerably more complete picture than either one produces alone.
Understanding ISO 42001
ISO 42001 certifies an AI management system. An accredited certification body evaluates whether the organization has built an AI management system (AIMS) across a defined organizational scope. Annex A of the standard lists 38 reference controls spread across nine control areas, from A.2 Policies related to AI through A.10 Third-party and customer relationships, and Clause 6.1.3 requires the organization to produce a Statement of Applicability justifying which of those controls it includes and excludes. Around that sits the machinery every management system standard carries:
- Competence
- Internal audit
- Management review
- Corrective action
Certification bodies performing this work operate against ISO 42006, and their audit cycles follow the ISO 17021-1 convention of a three-year certification period with annual surveillance.
Understanding AIUC-1
AIUC-1 certifies an agentic use case. Its requirements are organized into six domains, listed by AIUC as:
- Data and Privacy
- Security
- Safety
- Reliability
- Accountability
- Society
They are applied to a particular agent in a particular deployment. What sets it apart is third-party technical testing, covering adversarial robustness, harmful and out-of-scope outputs, hallucination, and tool-call safety.
When Cursor earned its certificate, AIUC reported that the company’s agents “went through thousands of technical evaluations across 12 categories” against coding-agent requirements it released in Q3 2026. AIUC also states that the standard “is formally updated each quarter,” and its assessment timeline is roughly four to eight weeks.
Where the two reinforce each other
The overlap here is by design. AIUC’s own technical comparison states that “most controls under AIUC-1’s accountability domain map directly to ISO 42001,” which means a vendor already certified to 42001 walks into an AIUC-1 assessment carrying a real head start on the governance requirements. What’s interesting is the reverse: AIUC-1’s testing evidence tends to fill in exactly the parts of an AIMS that organizations usually leave underdeveloped.
These are the places where you should expect to see one body of evidence serving both audits.
- Harm definition. Clause 6.1.4 and Clause 8.4 require an AI system impact assessment, supported by controls A.5.2 through A.5.5 and guided by ISO 42005. That assessment is where the harm categories behind AIUC-1’s Safety domain should come from. If a vendor maintains two unrelated lists of the harms its agent could cause, ask which one the engineers actually use.
- Verification and validation. Control A.6.2.4, AI system verification and validation, asks the organization to define measures and specify criteria for their use. The standard deliberately stops short of prescribing test methods, which is why this control is often satisfied with a minimal procedure. Adversarial and hallucination test results give it substance, and this is the single largest point of evidence reuse between the two regimes.
- Data governance. Controls A.7.3 through A.7.6 cover acquisition of data, quality of data, data provenance, and data preparation. AIUC-1’s Data and Privacy domain draws on the same underlying records, and where personal data is in scope, ISO 27701 extends that evidence further still.
- Logging and incident response. Control A.6.2.8 governs recording of event logs, and A.8.4 requires a documented plan for communicating incidents to users. Those pair naturally with AIUC-1’s accountability requirements around logging and failure planning, and one playbook should serve both.
- Supply chain. Controls A.10.2 and A.10.3 allocate responsibilities across the life cycle and require a process for governing suppliers. For an agent vendor, the supplier that matters most is the foundation model provider underneath the product, which is also what AIUC-1 vendor due diligence looks at. Ask to see that assessment, because their supplier risk becomes yours the moment you sign.
- Information for you. Control A.8.2 requires the organization to determine and provide the necessary information to users of the AI system. That is the same package AIUC-1 asks for as transparency documentation, and it is what you will need on hand if the deployment touches EU AI Act Article 50 transparency obligations.
What neither one does alone
An ISO 42001 certificate does not tell you the agent works. ISO 42005 makes the point plainly in its own guidance on Clause 6.1.4, describing that clause as one that “can be viewed at management system level” and concerned with looking at system impact assessments holistically. Governance maturity is genuinely valuable, and it is not the same thing as evidence about how a specific model behaves in a specific configuration under pressure.
An AIUC-1 certificate does not tell you the organization can hold the result. A four to eight week assessment produces a snapshot, and what keeps that snapshot meaningful three quarters later is competence under Clause 7.2, monitoring under Clause 9.1, and management review under Clause 9.3. Testing tells you where the agent stood on the day it was tested, while the management system is what determines whether anyone notices when that changes.
When read together, each one supplies what the other is structurally unable to produce. Test findings give the risk assessment something measured to work with, and the management system gives the test findings somewhere to go.
Five questions to ask an agent vendor
Governance frameworks are not there to penalize your vendor, they are there so everyone knows where it is safe to move fast. These questions tell you whether a vendor treats them that way or treats them as decoration:
- What is the scope of your ISO 42001 certificate, and does it cover the product I am buying? Organizational certificates routinely get read as though they cover everything the company does. Ask for the scope statement and the Statement of Applicability, then reconcile both against the product named in your contract.
- Which agent and which configuration were tested, and when? Use-case certification is only as good as the match between what was assessed and what you are about to deploy.
- What did the testing actually find? The outcome is a pass. The findings are the useful part, along with what the vendor changed in response to them.
- How do test findings reach your corrective action process? This is where you learn whether the two certificates are genuinely integrated or simply sitting next to each other in a trust center.
- Who provides your models, and what have you assessed them against? Control A.10.3 exists for this reason, and the answer flows directly into your own third-party risk file.
Buying the agent doesn’t buy you the compliance
There is one further point that buyers tend to skip past. Your vendor’s certificates cover your vendor. The moment their agent starts operating inside your business, you own the deployment decision, the human oversight design, the boundaries on acceptable use, and the consequences for your customers and employees. Controls A.9.2 through A.9.4, covering processes for responsible use, objectives for responsible use, and intended use of the AI system, were written for precisely the position you occupy. That is your AI management system to build, not theirs.
Say what you do and do what you say. The integrity check runs the same way for the organization buying the agent as it does for the one selling it.
Where A-LIGN fits
A-LIGN has been ANAB-accredited to certify AI management systems against ISO 42001 since October 2024, and our assessors help organizations work out how management system requirements line up against a technical assurance market that is moving quickly. Whether you are building an AIMS to govern the agents you deploy or preparing your own AI products for certification, getting the scope right at the start saves you from rework later.
A-LIGN also brings over 20 years of SOC, ISO, and federal auditing experience to AIUC-1 audits. In partnership with AIUC, A-LIGN transforms the new governance standard into a holistic compliance strategy for agentic AI assurance.
Contact our team to talk through where your program stands today.





