AI governance frameworks: Compare

A learning aid, not legal advice.

Depth, from 0 (least) to 3 (most)0123Under review
Frameworks to compare

Pick two or three frameworks.

Dimension
AIUC-1, the standard for AI agent security, safety and reliability (Q3 2026 release)
certifiable standard
Nature
Depth 2 of 3.

A private certification standard, not law: voluntary to adopt, and the Artificial Intelligence Underwriting Company, which maintains it with a consortium, is the only body that issues the certificate.

Accredited AIUC-1 auditors, "What body issues the AIUC-1 certificate?"; FAQ, "Who can certify organizations against AIUC-1?"
Where and to whom it applies
Depth 2 of 3.

Agentic AI systems only, built or deployed by any organisation in any country; the organisation chooses which agents are certified, and may start with one high-risk agent.

Scoping the AIUC-1 audit, Part 1 (Systems in scope)
Roles addressed
Depth 2 of 3.

Separates the agent developer, which sets and documents secure defaults, from the deployer, which configures the agent securely for its own context; one organisation can be both.

Scoping the AIUC-1 audit, Part 1 (Systems in scope: Guidance)
Risk approach
Depth 2 of 3.

Each agent gets a risk taxonomy built from its capabilities and deployment context (C001); requirements apply by capability tags such as universal, automation or code generation. No legal risk tiers.

C001 (Define AI risk taxonomy); Scoping, Part 2 (Statement of Applicability)
Inventory and documentation
Depth 2 of 3.

Logs of agent processes, actions and outputs (E015) and a record of data processing locations (E011) are mandatory; a repository of model cards and datasheets is supplemental (E017).

E011; E015; E017 (domain E, Accountability)
Risk or impact assessment
Depth 2 of 3.

A risk taxonomy (C001) and internal pre-deployment testing across risk categories (C002); the standard's own ISO/IEC 42001 crosswalk grades the impact assessment clauses as a partial gap.

C001; C002; AIUC-1 x ISO 42001 crosswalk, clauses 6.1.4 and 8.4
Human oversight
Depth 1 of 3.

Human review of flagged high-risk outputs (C007) and real-time feedback and intervention (C009) are supplemental, not mandatory; E004 names an accountable lead for each change that needs approval.

C007; C009 (domain C, Safety); E004
Transparency and notices
Depth 2 of 3.

Users must be told when they deal with an AI system rather than a person (E016, mandatory); a transparency policy with model cards and datasheets is supplemental (E017).

E016 (Implement AI disclosure mechanisms); E017
Data governance
Depth 3 of 3.

A whole domain of eight mandatory requirements: input and output data policies (including training on customer data), limits on agent data access, and safeguards against leaks of personal data, IP, customer data and secrets.

Domain A (Data & Privacy), A001 to A008
Testing, robustness and security
Depth 3 of 3.

Mandatory technical evals, unique on this wheel: third-party adversarial testing (B001) and third-party tests of harmful and out-of-scope outputs, hallucinations and tool calls at least every three months (C010 to C012, D002, D004).

B001; C010; C011; C012; D002; D004
Monitoring and incident reporting
Depth 2 of 3.

Failure plans for security breaches, harmful outputs and hallucinations (E001 to E003) and logging of third-party access (E009); risk monitoring is supplemental (C008). No duty to report to a regulator.

E001; E002; E003; E009; C008
Assurance and enforcement
Depth 3 of 3.

An accredited auditor audits the controls and the publisher runs the technical tests; a certification committee issues a certificate valid for 12 months, kept valid by technical testing at least every three months.

Accredited AIUC-1 auditors; FAQ, "How long is an AIUC-1 certificate valid?"
Effort to implement
Depth 3 of 3.

Heavy: evidence across legal, operational and technical controls plus evals. The standard's pages give four to eight weeks (certification page) or five to ten weeks (FAQ), then quarterly testing and a yearly re-audit.

AIUC-1 Certification (process table); FAQ, "How long does it take?"
Key dates
Depth 1 of 3.

Released each quarter on 15 January, April, July and October; the current release is dated 2026-07-15, the site was last updated 2026-09-17, and the next release is due 2026-10-15. No legal dates.

AIUC-1 changelog; Re-certification, "Which version of the standard to audit against"

A learning aid, not legal advice. Where AI SENTINEL is mentioned, it supports or maps to the dimension; it does not certify anything. Dates are those the official texts state on the date shown.