Skip to content
IAC Verifiable Registry
Verify code
IAC AI Trust · Verified AI Auditor · Scheme v1.0 — 2026-06-29

Verified AI Auditor. Competence is demonstrated.

Three grades of competence to audit artificial-intelligence management systems, recognized through evidence of real work — not an exam — and open to lookup in a live registry.

Scheme v1.0 · 2026-06-29 · IAC verifies and recognizes under its own scheme · it does not accredit or certify

Nature of this scheme

IAC verifies evidence and recognizes competence under its own published scheme; it does not accredit or certify the person. This scheme is neither an ISO standard nor a formal accreditation, nor a certification of persons under ISO/IEC 17024. It recognizes competence demonstrated through real work and keeps it open to lookup in a live registry.

The problem

Anyone can call themselves an AI auditor.

The field is new, and demand is growing faster than genuine competence. Calling yourself an auditor of AI management systems is not enough: you have to be able to prove it with real work — to whoever commissions the audit and to whoever trusts its outcome. Trust is demonstrated, not declared.

What the credential is

It recognizes competence to audit AI management systems.

The scheme recognizes a person's competence to audit artificial-intelligence management systems: to plan the audit, gather and evaluate evidence, write findings and, at the top grade, lead the team and sign the report. What is recognized is the auditor's competence — not the conformity of the audited organization, nor the technical quality of any AI model.

Built on ISO/IEC 42001

The primary basis is ISO/IEC 42001:2023, the standard for AI management systems. The EU AI Act and the NIST AI RMF are taken as regulatory and methodological references — each treated as what it is.

Evidence of real work

The grade is recognized through evidence of having audited or governed AI systems, not through an exam. An exam would be a declaration disguised as proof.

A live, verifiable registry

Every credential is born with a code and a status anyone can look up. Anyone can verify grade, scope, standard, scheme edition and validity — without asking us for permission.

How it works

Three grades, evidence of real work, two doors.

The credential is a three-grade ladder over the AI domain. The rule that governs it: the standard sets the subject; the evidence sets the grade.

The three grades
Grade 1 · Internal

Verified Internal AI Auditor

Competence to audit the AI management system from inside the organization. Audits its own system; contributes, does not lead third-party audits.

Grade 2 · Auditor

Verified AI Auditor

Competence to audit as part of a third-party team. Works within the audit team; executes, does not sign alone.

Grade 3 · Lead

Verified Lead AI Auditor

Competence to lead the team and sign the report. Runs the audit, decides findings, signs. The top.

The evidence we accept

The candidate builds a file of real, traceable work. Recorded training is background, never a grade: a course shows that a person studied, not that they audited.

E1

AIMS audit reports

Internal or third-party audits, with the candidate's role clearly identified.

E2

AI risk assessments

Risk assessments the candidate produced or reviewed.

E3

EU AI Act high-risk cases

Documented review of a high-risk use case: reading Annex III and placing the obligations that apply.

E4

ISO/IEC 42001 implementation

Having led or contributed to an implementation, distinguishing the role: the consulting track does not qualify you to audit.

E5

AI governance

Participation in committees or governance functions: minutes, appointments, risk-treatment plans.

E6

Verifiable records and references

Logbooks, anonymized extracts, team-lead statements, and plans or reports put to the test.

The two doors

There are two doors to the credential. Both end in the same registry, with the same verb; they differ by who assessed the competence.

Door 1 · Recognition by agreement

Validated method

Have you already been assessed by a body whose method IAC validated?

IAC validates the method of the training or assessment body — its rubric, its evidence, its separation of duties — not its brand. Whoever was assessed under a validated method enters the registry without being re-assessed, with a pointer to the originating assessment. It is an open standard: any body whose method passes the public criteria enters through the same door.

Door 2 · Direct IAC assessment

Assessment under IAC's own scheme

Coming on your own, with no validated method behind you?

IAC assesses directly: self-diagnosis, application, evidence upload, integrity check before charging, documentary and active assessment, independent decision and registry. The signature is placed by someone who neither assessed nor trained the candidate.

The credential

Looked up by code. It states what was verified — nothing more.

The credential states holder, grade, standard, scope, scheme edition, status and date. Any third party resolves the code in the IAC verifier and sees the live record. It is also issued as an Open Badges 3.0 / W3C Verifiable Credential, signed with Ed25519, so its issuance and integrity can be checked cryptographically.

If a printed card contradicts the record, the record prevails: paper is not the source of truth — the registry is.

How a credential is verified
Verified AI AuditorCompetence recognized under IAC's own scheme Active
Holder— name —
GradeGrade 2 · AI Auditor
Standard / scopeISO/IEC 42001 · AIMS auditing
Schemev1.0 · 2026-06-29
CodeIAC-V-42A-····-·····
Limits

What the scheme does not promise.

The scheme's credibility depends on stating its limits precisely. A scheme that inflates itself loses exactly the value it means to create.

This scheme does not

  • It is not a formal accreditation by a recognized accreditation body. It is a recognition under a scheme published by IAC.
  • It neither certifies nor accredits the person. It recognizes their competence, with evidence, at a given date, under a declared scope and edition.
  • IAC is not an EU AI Act notified body and does not carry out the conformity assessment the Regulation reserves for those bodies.
  • It confers no regulatory authorization of any kind, and does not legally entitle anyone before any regulator.
  • It does not certify any organization's management system: that certification is issued by a certification body. The scheme recognizes the person who audits it, not the system.
  • It is not an AI product certification: it does not evaluate models, measure their technical performance or guarantee the absence of harm.

It states what it verifies — the competence of an auditor of AI management systems, demonstrated through real work — and not an inch more.

Frequently asked questions

Worth being clear on before you apply.

Tap each question to see the answer.

Is this an accreditation?
No. It is a recognition of competence under a scheme published by IAC. The word "accredit" describes an attribute of bodies under ISO/IEC 17011 and does not apply here: IAC verifies evidence and recognizes competence; it does not accredit or certify the person.
Is it a certification of persons under ISO/IEC 17024?
No. The scheme is IAC’s own and is not accredited under ISO/IEC 17024. Where the scheme mentions 17024, it does so as a reference for rigor — to explain which assessment discipline it adopts — never as its own framework or a source of authority.
Is there an exam?
No. The grade is recognized through evidence of real work: AIMS audit reports, risk assessments, EU AI Act high-risk cases, AI governance, logbooks and verifiable references. An exam would be a declaration disguised as proof. The assessment does include an active part: an AI audit case, an interview and a defense of the file.
What grade will I be given?
The one the evidence demonstrates. The credential has three grades — Verified Internal AI Auditor, Verified AI Auditor and Verified Lead AI Auditor. Someone who applies for grade 3 and only evidences grade 2 receives grade 2, not a rejection. Signing the report is the line between grade 2 and grade 3.
I took a 42001 course — does that give me the credential?
No. Recorded training is traceable background, never a grade. A course shows that a person studied, not that they audited. The grade comes from evidence of real work.
I’m a consultant and I implement ISO/IEC 42001 — can I be a Verified AI Auditor?
The consulting track is a separate recognition, not a grade on this ladder. Preparing or implementing an AIMS does not qualify you to audit it: whoever builds the system cannot be the one who judges whether it works. If you also hold evidence of your own auditing work, that evidence does count toward the auditor ladder.
Can I enter without being assessed by IAC?
Yes, through Door 1: recognition by agreement. IAC validates the method of a training or assessment body — not its brand — and whoever was assessed under a validated method enters the registry without being re-assessed, with a pointer to the originating assessment. It is an open standard: any body whose method passes the public criteria enters through the same door.
How long does the credential last?
The scheme sets a two-year renewal cycle, with annual confirmation of practice — audits conducted, not hours declared — and update triggers tied to regulatory milestones of the EU AI Act, the NIST AI RMF and ISO/IEC 42001. A missing confirmation moves the status (active, in grace, suspended, expired), but the grade itself is only changed by a documented formal decision.
Does it entitle me before the EU AI Act or any regulator?
No. The scheme confers no regulatory authorization of any kind. IAC is not an EU notified body and does not carry out the conformity assessment the Regulation reserves for those bodies. A person being a Verified AI Auditor does not mean any system is compliant with the Regulation.
Does it certify my organization’s management system?
No. ISO/IEC 42001 certification is issued by a certification body. This scheme recognizes the person who audits the system, not the system. It also does not evaluate AI models or guarantee the absence of harm.
How do I verify a credential?
Any third party resolves the code — IAC-V form, branch 42A — in the IAC verifier and sees the live record: grade, scope, standard, scheme edition, status and date. The credential is also issued as an Open Badges 3.0 / W3C Verifiable Credential signed with Ed25519. If a printed card contradicts the record, the record prevails.
Who decides, and is it independent?
The scheme is governed by a Scheme Committee with five separated functions: committee, assessment, decision, appeal and impartiality oversight. The golden rule: whoever assesses does not decide, and whoever trained does not decide. The file’s integrity check happens before anything is charged.

Apply for the Verified AI Auditor credential.

If you have audited or governed AI systems and can prove it with real work, the scheme recognizes your grade and keeps it open to lookup in the registry.

Scheme v1.0 · 2026-06-29 · IAC verifies and recognizes under its own scheme · it does not accredit or certify