- Two published events, five months apart. On 3 February 2026 Schellman published that it had become the first accredited auditor for AIUC-1. On 27 August 2026 KPMG published that KPMG LLP is the first of the Big Four to achieve AIUC-1 certification.
- The structure separates evidence from decision. Schellman states it provides independent audit evidence collection, detailed reporting and certification guidance, while the Artificial Intelligence Underwriting Company conducts technical evaluations and issues certification.
- That is a shorter chain than classical certification, where the certifying body is itself accredited by a body with no stake in the standard. Schellman describes itself as the first ISO 42001 ANAB accredited certification body, which is the longer chain, and the comparison is instructive rather than damning.
- Quarterly retesting is the real methodological advance. An AI system changes when nobody touches it, so a certificate held for a year without retest describes a system that may no longer exist.
- A framework mapping is a reusability claim about evidence, not an equivalence claim about compliance. Nothing private satisfies an Annex VI obligation under the EU AI Act, and nothing in the Act recognises a private certificate in its place.
- Three published sources give three different sizes for the same consortium. All three can be accurate. Repeating any one as the number is the small error this field makes constantly.
What actually happened, in order
Two dates carry this, and both are read from the publishing party's own domain rather than from coverage of it.
On 3 February 2026 Schellman published that it had become the first accredited auditor for AIUC-1, which it describes as a security, safety and reliability standard for AI agents. In the same piece Schellman sets out the division of labour: it provides independent audit evidence collection, detailed reporting and certification guidance, while the Artificial Intelligence Underwriting Company conducts technical evaluations and issues certification. It states that agent behaviour is tested quarterly to ensure ongoing compliance, that the standard operationalises leading frameworks including ISO 42001, the NIST AI Risk Management Framework, MITRE ATLAS and the OWASP Top 10 for LLMs, and that the consortium behind the standard comprises 60 or more chief information security officers and security leaders from Fortune 500 companies.
On 27 August 2026 KPMG published that KPMG LLP is the first of the Big Four to achieve AIUC-1 certification, for aIQ Capture, which it describes as a KPMG developed agentic AI organizational intelligence platform. KPMG states the platform underwent more than 900 technical tests including hallucinations, high-risk domain interactions, content safety, prompt injection attacks, and other scenarios intended to challenge the agent's reliability and resilience. It names other certified platforms including Fin, Harvey, Cursor and Lovable, and describes the consortium as more than 250 Fortune 1000 security leaders.
The quotation attributed to Arun Rajappa, National Managing Principal, Risk Management and Compliance at KPMG LLP, is the line worth keeping: before the firm put its name behind its own agentic system, it had it independently tested and certified. Whatever one concludes about any particular standard, that is the sentence a procurement function has been waiting to be able to ask for.
Three roles, and who holds them
Certification in any field distributes three functions, and most of the confusion in this one comes from collapsing them.
There is the standard owner, which defines what good looks like. There is the evaluator, which performs the technical assessment against that definition. And there is the certifier, which decides and issues. In classical certification a fourth party sits above all three: an accreditation body, which does not own the standard and has no commercial interest in the number of certificates issued, and which accredits the certifier to issue them.
Under AIUC-1 as described by the parties themselves, Schellman holds an audit and evidence role while AIUC performs technical evaluation and issues the certificate. That is a real separation and it should be credited as one: the party assembling the evidence is not the party deciding the outcome, which is more than a self-attested badge and considerably more than what the category had in 2024. It is also, plainly, a shorter chain than the classical arrangement, because the accreditation that qualifies the auditor comes from the standard's own side rather than from an independent accreditation body.
The useful comparison is available in the same organisation. Schellman describes itself as the first ISO 42001 ANAB accredited certification body, referring to the ANSI National Accreditation Board. That is the long chain: an accreditation body with no stake in ISO 42001 accredits Schellman to certify against it. Set the two side by side and the difference is not that one is honest and the other is not. It is that they carry different kinds of assurance about the assessor, and a buyer should know which one it is holding.
The practical form of that question for anybody evaluating a certificate: who accredited the party that assessed us, and what is their relationship to the party that owns the standard? There is no wrong answer to that question. There is only an unasked one.
The genuine advance is the cadence
If one feature of this structure deserves to be adopted everywhere, it is not the certificate. It is the retest.
Every other certifiable object in commerce holds still. A pressure vessel certified in March is the same pressure vessel in September. An AI system is not, and it is not for reasons entirely outside the certificate holder's control. The underlying model can be updated by its provider on the provider's timetable. A retrieval corpus drifts as documents are added and removed. A tool integration changes what the system is able to do rather than merely what it says. Behaviour moves while the configuration file stays identical, which is precisely why change control for AI systems has to cover more surfaces than an ordinary change process expects, a point we set out at prompt change control as certification evidence.
Against a moving object, an annual certificate is a photograph. Schellman's stated cadence of quarterly behaviour testing is the structurally correct answer, and this framework has reached the same conclusion independently: certification that is held rather than re-earned decays into a marketing asset within one model generation. Our own treatment of the obligation between assessments is at maintaining certification after the assessment, and the specific problem of assessing systems whose behaviour is not deterministic is at certifying generative agents and dynamic behaviour.
What a framework mapping establishes, and what it does not
AIUC-1's own site publishes a mapping to a long list of frameworks: the EU AI Act, ISO 42001, MITRE ATLAS, the NIST AI Risk Management Framework, the OWASP Top 10 for LLM Applications, OWASP AIVSS, the OWASP Top 10 for Agentic Applications, the IBM AI Risk Atlas, Cisco AI Security and Safety, and the CSA AICM. It describes itself as refreshed quarterly and as created with 100 or more Fortune 500 chief information security officers.
A mapping of that kind is genuinely valuable and routinely over-read. What it establishes is that evidence produced for one framework can be pointed at another without being regenerated, which is the single largest cost saving available in this work and the reason we maintain crosswalks of our own, including the ISO 42001 and NIST AI RMF control mapping and the AIUC-1 crosswalk against this framework.
What it does not establish is compliance. The inclusion of the EU AI Act in a mapping list means controls have been cross-referenced against the Act's requirements. It does not mean the certificate discharges an obligation under the Act, because conformity assessment under the Act is defined by Article 43 and, for Annex III points 2 to 8, is an internal control procedure set out in Annex VI which the Act itself describes as one which does not provide for the involvement of a notified body. There is no European mechanism that accepts a private certificate in place of that procedure. Our regulatory desk reads that architecture in full at agentliability.eu, on internal control and the missing auditor.
Stated plainly, so nobody has to infer it: a private AI agent certificate, including ours, is evidence for counterparties, procurement functions and underwriters. It is not a regulatory permission and it should never be sold as one.
The number that is three numbers
A short worked example of the discipline this field needs, drawn from these same sources.
The consortium behind AIUC-1 is described in three places. Schellman, in February 2026, calls it 60 or more chief information security officers and security leaders from Fortune 500 companies. The standard's own site says created with 100 or more Fortune 500 chief information security officers. KPMG, in August 2026, calls it a group of more than 250 Fortune 1000 security leaders.
None of those is false. Six months separate the first and the last, groups grow, and Fortune 500 chief information security officers and Fortune 1000 security leaders are not the same population counted twice. The error available here is not made by any of the three publishers. It is made by the fourth party who picks one figure, drops the attribution and the date, and writes it as the number. That is how a source-dependent figure becomes a fact, and it is the most common way accurate inputs produce an inaccurate corpus. Every figure in this article carries its publisher and its date for that reason.
What this changes for a European assessment
Four things follow for anybody running or commissioning an assessment in Europe.
The scope question is now the first question. KPMG certified a named platform, not a firm. Fin, Harvey, Cursor and Lovable are named as certified platforms rather than certified companies. A buyer or an assessor who does not establish which system was in scope has learned nothing from the certificate, and the same is true of ours. The framing of that for smaller buyers is at insureyouragent.com, on what a vendor certificate means.
The vendor certificate and the deployment assessment are different objects. This is the gap this framework was built for. A certificate held by the supplier speaks to the supplier's system in the supplier's configuration. The deployment adds instructions, corpus, tool permissions, users and a regulatory position that the supplier never saw. Our seven dimensions are applied to the deployed system for that reason, and the mapping of those dimensions to the Act's obligations is at the seven dimensions against EU AI Act obligations.
The evidence is reusable and should be produced once. An organisation preparing for AIUC-1, ISO 42001 or an assessment under this framework is assembling substantially the same artefacts: a system inventory, a risk record, test results with dates, a change log, an oversight register and an incident procedure. Produce them once, in a form that can be pointed at any of the three. The preparation sequence is at preparing for an assessment.
The underwriting link is now less theoretical than it was. A standard owned by an underwriting company, with an accredited auditor and a published retest cadence, is an explicit attempt to make AI risk pricable. Whether it prices well is an open question and not one this desk can answer from published material. What can be said is that the evidence an underwriter asks for and the evidence an assessment produces have converged further this year, which we treat at whether certification reduces premiums and, from the coverage side, at agentinsured.eu, on what the panel behind a policy tells you.
What we are watching next
Three signals, stated as things to check rather than things to predict.
Whether a second accredited auditor appears. One auditor is a partnership; two is an audit market, with the price competition and methodological argument that follow. Whether any European accreditation body enters this space for agent-level standards, as distinct from the ISO 42001 management system route that already exists. And whether harmonised standards under the AI Act arrive early enough to matter before Annex III obligations apply on 2 December 2027, since their availability is what determines whether the notified body route is even open for the one category where the Act offers it.
Until then, the accurate summary of the European position is that enterprises here can buy independent assurance, and everything they can buy is private. That is not a scandal. It is a gap, it is measurable, and it is the reason this framework exists.
Questions
Who audits an AI agent certification, and who issues it?
Under AIUC-1 the two functions are held by different parties, and Schellman describes the split in its own words: Schellman provides independent audit evidence collection, detailed reporting and certification guidance, while the Artificial Intelligence Underwriting Company conducts technical evaluations and issues certification. That is a meaningful separation, because the party gathering the evidence is not the party deciding the outcome. It is also narrower than the chain in classical certification, where the body that issues a certificate is itself accredited by a national or international accreditation body with no commercial interest in the standard.
What does it mean that AIUC-1 maps to the EU AI Act?
It means the standard's controls have been cross-referenced against the Act's requirements so that work done for one can be pointed at the other. It does not mean holding the certificate satisfies any obligation under the Act. Conformity assessment under the AI Act is defined by Article 43 and, for Annex III points 2 to 8, is an internal control procedure under Annex VI which does not provide for the involvement of a notified body. No private certificate is a substitute for that and none is recognised in place of it. A mapping is a reusability claim about evidence, not an equivalence claim about compliance.
Why does quarterly retesting matter more than the certificate itself?
Because an AI system changes when nobody touches it. The underlying model can be updated by its provider on the provider's timetable, a retrieval corpus drifts as documents are added, and a tool integration changes what the system can do. A certificate awarded once and held for a year describes a system that may no longer exist. Schellman states that under AIUC-1 agent behaviour is tested quarterly to ensure ongoing compliance. That cadence is the correct structural answer to a moving object, and it is the feature other frameworks should be judged against.
Does a Big Four firm certifying its own AI change anything?
It changes the procurement conversation more than the technical one. KPMG published on 27 August 2026 that KPMG LLP is the first of the Big Four to achieve AIUC-1 certification, for its aIQ Capture platform, which it states underwent more than 900 technical tests. The significance is that a firm whose business is assurance chose to buy assurance rather than assert it, and said so publicly. That sets a reference point every enterprise vendor will now be measured against, which is how procurement norms usually form.
Is there a European equivalent to an accredited AI agent auditor?
Not for AI agents as such, and the reason is structural. The AI Act creates a notified body regime under Article 31 with demanding independence and competence requirements, but Article 43 routes Annex III points 2 to 8 away from it entirely, to provider self-assessment under Annex VI. Where a regulation does not require third-party assessment, it does not create a third-party assessment industry. The assurance European enterprises are buying today is therefore private, and that is a market answer to a demand rather than a regulatory answer to an obligation.
How should an enterprise read a certification claim that comes with a number?
Ask what is being counted, by whom, and as at when. A worked example: the consortium behind AIUC-1 is described by Schellman in February 2026 as 60 or more chief information security officers and security leaders from Fortune 500 companies, by the standard's own site as created with 100 or more Fortune 500 chief information security officers, and by KPMG in August 2026 as more than 250 Fortune 1000 security leaders. All three can be accurate. A group grows, and the two populations are not the same. Repeating any one of them as the number turns a source-dependent figure into a fact.