SETTING GLOBAL STANDARDS FOR TRUSTED AI CREDENTIALSAI Competence Framework v1.29 · current release
You are reading the current version of the framework, v1.29.Permanent address for this version

Review an incident involving AI output and identify the assurance gap that allowed it.

Type Judgement · introduced in version 0.1

Performance indicators

Normative. These state what would be observed in a person who holds the statement.

Traces the incident to the evaluation, monitoring or criterion that did not catch it
Distinguishes a gap in evidence from a gap in process
Produces a change to the assurance approach, not only to the system
Evidence examples

Non-normative. Illustrative of evidence an awarding body might accept; not a required form.

A worked artefact produced in the course of normal duties, with the reasoning recorded at the time
Attestation by a competent supervisor against the indicators above, not against a general impression
Relationships

Assumes

Statements a candidate is taken to hold already. Never at a higher level than this one.

This statement assumes no other statement. It is a starting point within its domain.

Assumed by

Derived inverse. Statements that take this one as given.

No published statement assumes this one at version 1.29.

Related

Cross-domain relationships, stated in both directions and typed in the content model.

D7.L3.01

Assess the impact of a proposed AI use on the people it affects.

D7.L3.02

Design fairness requirements for a system and the evidence they require.

D7.L3.03

Establish transparency and explanation requirements for a system.

D7.L3.04

Advise on a use that is permitted but should not proceed.

D7.L3.05

Design the route by which an affected person can challenge an AI-influenced decision.

D7.L3.06

Assess the labour and skill effects of an AI deployment.

D7.L3.07

Apply the obligations of a regulated or professional context to AI use.

D7.L3.08

Review an AI-related incident for the ethical failure, not only the technical one.

D8.L3.01

Design an AI feature so that untrusted content cannot cause privileged action.

D8.L3.02

Threat model an AI feature, identifying assets, entry points and adversaries.

D8.L3.03

Design controls that limit what a system can do when its instructions are compromised.

D8.L3.04

Evaluate the effectiveness of guardrails and output controls under realistic conditions.

D8.L3.05

Diagnose how sensitive data reached a prompt, context window, log or output.

D8.L3.06

Evaluate supply chain risk in models, tools, extensions and connectors.

D8.L3.07

Design least-privilege access for systems acting on behalf of people.

D8.L3.08

Resolve an incident in which an AI system was the vector, and identify the control that failed.

D8.L3.09

Advise on unsanctioned AI use, addressing the need that produced it.

Referenced by

Entries on the register of conformance claims whose coverage map cites this statement.

No entry on the register cites this statement. This block is populated from the coverage maps of register entries as they are listed.

Provenance
IntroducedVersion 0.1
Last modifiedNot modified since introduction
Statusactive · stable
Version displayedv1.29
Permanent URLaicertificationstandards.org/framework/statements/D6.L3.08
Cite this statement

AI Certification Standards (2026) AICF D6.L3.08, D6 Evaluation and assurance, version 1.29. Available at aicertificationstandards.org/framework/v1.29/statements/D6.L3.08 (accessed date).

Propose an amendment

Statements change through the published process, not by correspondence

An amendment to this statement, its indicators or its relationships is proposed through the contribution process. Every submission is answered on the record, and the reasoning for acceptance or rejection is published in the release record for the version that follows.

Propose an amendment to D6.L3.08

Writing rules and the controlled verb list that govern how this statement is worded are published in the methodology.

This page displays version 1.29 · last reviewed 30.08.2026