ProvenantAI Get in touch
← Standards register Assessment

AIUC-1

Agent certification · 51 controls in six domains

The two controls this standard cares most about are stopping unauthorized agent actions and unsafe tool calls. Provenant handles both, and neither can be turned off by a configuration mistake.

20

Enforced

Provenant does it. You can show it before your agent runs.

7

Contained

Where the standard asks you to prevent something the model might do, Provenant limits how far it gets.

17

Evidenced

Where the standard asks you for a plan, a policy or a test, Provenant hands you what it needs.

RefRequirementHowMechanism
A1Establish input data policyEnforcedYou choose where every value comes from
A2Establish output data policyEnforcedYou choose what the agent sees
A3Limit AI agent data accessEnforcedYou choose what the agent sees, field by field
A4Protect IP and trade secretsEnforcedThe same control, applied to anything you mark proprietary
A5Prevent cross-customer data exposureEnforcedOne customer's session can't reach another's
A6Prevent PII leakageEnforcedYou choose what the agent sees, field by field
A7Prevent IP violationsContainedYour agent can only send things where you allowed
A8Prevent leakage of credentials and secretsEnforcedYour agent uses credentials without ever seeing them
B1Third-party testing of adversarial robustnessEvidencedYour testers get the full list of what to test
B2Detect adversarial inputN/A
B3Manage public release of technical detailsN/A
B4Prevent AI endpoint scrapingN/A
B5Implement real-time input filteringN/A
B6Prevent unauthorized AI agent actionsEnforcedYour agent can't do what you didn't allow
B7Enforce user access privileges to AI systemsEnforcedWho the agent acts for is settled before it starts
B8Protect AI system deployment environmentN/A
B9Limit output over-exposureEnforcedYour agent gets what you chose and nothing else
B10Promote secure patterns in generated codeContainedGenerated code can only reach what you allowed
C1Define AI risk taxonomyEvidencedYour risk categories come from the data you actually handle
C2Conduct pre-deployment testingEnforcedYou can see everything your agent could do before you ship it
C3Prevent harmful outputsContainedA bad answer can only reach what you allowed
C4Prevent out-of-scope outputsEnforcedYour agent can't step outside what you allowed
C5Prevent agent-specific high-risk outputsEnforcedThe steps that matter stop for a person
C6Prevent output vulnerabilitiesContainedLimited to what you allowed
C7Flag high-risk outputs for human reviewEnforcedYou choose what the approver sees before they decide
C8Monitor AI risk categoriesN/A
C9Enable real-time feedback and interventionEnforcedA person can step in at the moment it matters
C10Third-party testing for harmful outputsEvidencedYour testers get the full list of what to test
C11Third-party testing for out-of-scope outputsEvidencedYour testers get the full list of what to test
C12Third-party testing for customer-defined riskEvidencedYour testers get the full list of what to test
D1Prevent hallucinated outputsContainedA wrong answer can only reach what you allowed
D2Third-party testing for hallucinationsEvidencedYour testers get the full list of what to test
D3Restrict unsafe tool callsEnforcedWhat your agent can do next depends on what it has done and who approved it
D4Third-party testing of tool callsEvidencedThe tests come straight out of what you allowed
E1AI failure plan for security breachesEvidencedYour plan gets both halves — what could have happened, and what did
E2AI failure plan for harmful outputsEvidencedThe same two halves
E3AI failure plan for hallucinationsEvidencedThe same two halves
E4Assign accountabilityEvidencedYou know who approved what, and what they saw
E5Document data storage securityEvidencedYou choose what is sent and what is kept
E6Conduct vendor due diligenceEvidencedYour vendor list writes itself
E7Review internal processesEvidencedEvery change to what your agent can do is tracked and attributable
E8Monitor third-party accessEnforcedA signed record of every access
E9Establish AI acceptable use policyEvidencedYour policy and your enforcement are the same document
E10Record processing locationsEnforcedRecorded for every system your agent touches
E11Document regulatory complianceEvidencedWritten for you
E12Implement quality management systemEvidencedEvery change is tracked and attributable
E13Log AI system activityEnforcedEvery decision recorded as it happens, and it can't be altered later
E14Implement AI disclosure mechanismsN/A
E15Document system transparency policyEnforcedThe document is written for you, and it is the policy
F1Prevent AI cyber misuseContainedLimited to what you allowed
F2Prevent catastrophic misuseContainedLimited to what you allowed