Key Insights
- Standard vendor reviews check how a company operates, not how its AI agent behaves on your client's data. AIUC-1 tests the agent directly against attempts to manipulate it.
- Certification isn't one-time. AIUC-1 pairs quarterly technical retests with annual recertification.
- Fieldguide holds AIUC-1 certification alongside ISO 42001 and SOC 2 Type 2, covering both agent behavior and organizational governance.
You spend your professional life evaluating other people's controls: whether they're designed properly, operating as intended, and able to hold up under real conditions. AI systems are now doing real work inside your engagements too, reading trial balances, matching evidence, and touching the same client data your firm is on the hook for. That system needs its own scrutiny, the same way any other control on an engagement would. This guide covers what AIUC-1 certification actually tests at the agent level, and how it complements the organization-level governance evidence (like ISO 42001 and SOC 2) your firm already relies on.
Why does AI on your engagements need its own certification, separate from vendor security reviews?
Your firm is the trust layer. When you sign off on a client's financials or their SOC 2, the market relies on your name. Any tool that handles client data inside that work inherits your reputation, whether you planned for that or not. A workpaper platform that mishandles a confidential earnings figure, a review tool that pulls the wrong prior-year balance into a memo, an assistant that quietly hallucinates a control conclusion: each becomes your problem long before it becomes the vendor's.
AI tools in audit have shifted from storing data to taking action
The stakes have shifted because the tools have shifted. Earlier waves of audit technology mostly stored, sorted, or summarized. The current wave acts. AI systems showing up in audit are increasingly agentic: they can act independently, affect consequential work, and are initiating actions and adapting based on context. Audit teams are already putting these agents into audit work for compliance workflow analysis and reconciliation across general ledgers and bank feeds.
Picture what that looks like in practice. An agent reads a client's trial balance, matches it against bank feeds, flags a variance, drafts the tickmark, and posts a request to the client portal, all before a senior has opened the file. That is useful. It is also a chain of consequential actions on sensitive data, any one of which can go wrong in ways a policy document cannot catch. When an agent can take real actions on sensitive data, policies alone stop being enough.
Engagement teams stay responsible when AI agents do the work
The professional responsibility does not shift with the tooling. Engagement teams remain responsible for GenAI-assisted work and documentation, and supervisors are expected to apply the same diligence they would for work done without it. That responsibility is also what makes firms cautious: trust is the main barrier to agentic AI adoption in finance and accounting. Partners will not put their name behind a system they cannot vouch for.
Vendor security reviews don't test how AI agents behave
Vouching for it means testing it: the same way you would test a client's access controls or reconciliation process before relying on the output. Vendor SOC 2 reports and enterprise security reviews cover the company. They do not cover how the specific agent behaves when a prompt is malicious, when a document is malformed, or when a user asks it to do something outside its scope. That is why the AI on your engagements needs its own security bar, separate from your firm's general comfort with the vendor.
What does AIUC-1 testing add beyond ISO 42001 and SOC 2?
Governance certifications tell you a vendor runs a responsible company. They do not tell you how the AI on your engagement will behave the moment something unusual happens. That is the gap agent-level testing fills, and it is the gap that matters when an agent is drafting your workpapers.
That gap, between what a vendor's policies say and what its AI actually does under pressure, is exactly what agent-level testing is built to close.
AIUC-1 is the standard built around that question. Created by the Artificial Intelligence Underwriting Company and developed with Stanford, the Cloud Security Alliance, Orrick, and MITRE, it is designed specifically to test how AI agents behave on real work under pressure. Here is what that testing actually looks like, starting with who or what gets certified.
AIUC-1 certifies the AI agent, not just the company behind it
The certification targets the specific AI agent, the actual system making decisions on your engagement, rather than the company's policies or org chart. It tests things like what happens when someone slips a malicious instruction into a client-uploaded PDF, or asks an agent to summarize a document it should not have access to. Those are properties of the deployed system itself, which is why testing has to target the product and not just the paperwork behind it.
AIUC-1 tests AI agent behavior, not paperwork
That testing happens through adversarial methods: someone actively trying to make the agent misbehave using documented attack patterns. Test scenarios cover prompt injection and data exposure through agent-driven workflows, run against the actual deployed system rather than a policy describing it. The failure modes it looks for are behavioral: an agent hallucinating a citation, following a hidden instruction, or leaking data across a workflow boundary.
AIUC-1 requires recurring testing because AI systems don't stand still
The standard pairs quarterly technical retesting with annual recertification, and updates itself every quarter to keep pace with new attack patterns and model changes. That cadence matters because models get updated and prompts get tuned constantly, so a pass from twelve months ago says very little about the system running on your engagement today. This sits on top of organization-level evidence like ISO 42001 and SOC 2, not in place of it: the company-level reports show the vendor is serious, and the agent-level testing shows the specific system can hold up under the conditions of a real engagement.
What should firms look for in an AIUC-1-certified AI vendor?
Plenty of vendors will tell you their AI is secure. AIUC-1 certification is one of the few ways to check that claim against evidence.
Certification scope should match your actual engagement work
Certifications quietly lose value when the scope does not match the service being deployed. An AI vendor can hold a certification against a general-purpose chatbot and still leave the agent doing your engagement work untested. A compliant vendor can show you scope that maps to the actual work: adversarial testing run against the specific agent configuration in production, with scenario categories that reflect audit and advisory conditions rather than a generic threat model.
For generative systems, the compliant vendor can also produce a transparency pack: documentation on how hallucinations are reduced in engagement outputs and how prompt injection is stopped before the system reaches your teams.
Fieldguide has earned AIUC-1 certification specifically in the audit and advisory category, rather than a general-purpose or industry-agnostic scope. That distinction matters because AIUC-1 scopes its testing to the industry an agent actually serves, and a certification built around a generic chatbot use case would say little about how an agent performs on engagement work. Because Fieldguide's certification is scoped to audit and advisory, the adversarial testing conditions mirror the conditions Field Agents actually operate in: engagement documents, client evidence, and audit-specific workflows, not a generic threat model borrowed from a different industry.
Testing should come from an independent, accredited third party
Independence matters as much in AI assurance as it does in the audit work your firm signs. A vendor self-attesting that its AI is safe is not evidence; it is marketing. Independent AI assurance only works when buyers can trust the accuracy and integrity of evaluation results, a standard that is foundational to auditing in every other field.
A compliant vendor can name the accredited third party that performed the audit and point to that party's credentials. The distinction matters because AIUC-1 relies on adversarial testing, meaning someone actively trying to break the system, and the value of that testing depends entirely on the independence and skill of the people doing it.
A real retest cadence keeps pace with how fast AI changes
AI systems drift. Models get updated, prompts get tuned, and new attack patterns surface every quarter. A stale point-in-time pass tells you little about the system running today, which is why evidence has to stay anchored to the specific deployed model.
A compliant vendor has a defined retest schedule and can show it. Under AIUC-1, that means quarterly technical testing and annual recertification against a standard that itself updates quarterly. A vendor that hands you a certificate from last year and cannot describe what happens between now and the next one is not operating at the cadence the technology requires.
Agent-level certification should sit on top of organization-level evidence
The compliant vendor treats agent-level certification as an addition to organization-level assurance, not a replacement for it. Buyers should still expect the underlying company-level evidence alongside the AIUC-1 certification for the agents themselves: ISO 42001 for management-system governance and a SOC 2 Type 2 for organizational controls.
Fieldguide's stack is built to that pattern: AIUC-1 certification for how the Field Agents behave, ISO 42001 certification for how AI is governed across the company, and a SOC 2 Type 2 for the operational controls around it. Each layer answers a different diligence question a firm should be asking.
Is Fieldguide AIUC-1 certified?
Yes. Fieldguide has earned AIUC-1 certification in the audit and advisory category, on top of its existing ISO 42001 certification and SOC 2 Type 2 report. Finance leaders name cybersecurity and data privacy as their top concerns about AI in audit, and this certification is Fieldguide's answer to that concern at the agent level.
See Fieldguide's AIUC-1-certified Field Agents on a real audit engagement
Fieldguide is the end-to-end AI-native platform purpose-built for audit and advisory engagement work, and half of the Top 100 US CPA firms, including members of the Big Four, already run on it. The platform covers the full engagement lifecycle on one system, from scoping through reporting, rather than adding AI on top of a legacy toolchain. Its certified agentic workflow reflects the operating model firms are moving toward: Field Agents execute engagement work while practitioners review and approve every output. That combination of behavioral certification and organizational governance is what makes the agents defensible on client engagements, not just capable. Explore the Agent Workforce or book a demo to see how it holds up on the kind of work your teams do every day.