SETTING GLOBAL STANDARDS FOR TRUSTED AI CREDENTIALSAI Competence Framework v1.29 · current release
You are reading the current version of the framework, v1.29.Permanent address for this version

Build a credential

For any organisation issuing a credential against the framework. Eight steps, one published standard for the specification document, and a conformance checklist you can run against your own draft before we see it.

Coverage map fields
01

Decide what the credential is for

Name the person it is for, the work they do, and the decision an employer would make on the strength of it.

Produces

A scope statement of two to three sentences.

02

Select the statement set

Choose statements from the framework at the level you intend to certify, plus any overlay or extension statements.

Produces

A list of statement identifiers, pinned to a framework version.

03

Verify prerequisites the framework does not publish

Some statements presume competence defined elsewhere. D8 presumes general information security competence.

Produces

A prerequisite section naming each prerequisite and the verification method.

04

Design assessment per statement type

Knowledge, Skill, Judgement and Practice statements need different instruments.

Produces

An assessment plan mapping instruments to statements and indicators.

05

Set and document the pass mark

Choose a standard-setting method, run a panel, record the judgements and the date.

Produces

A standard-setting record: method, panel, date, judgements, adjustments.

06

Write the coverage map

Fill in the template: coverage values, weightings summing to 100, assessment method per group, exclusions with rationale.

Produces

A complete coverage map, published at a stable public address.

07

Write the specification against the published standard

The credential specification is a document with a defined structure.

Produces

A specification document plus a completed checklist.

08

Publish, then apply if you want it listed

You may issue the credential without ever contacting us; the licence permits it.

Produces

A published credential, and optionally a conformance application.

Statement types and assessment

The four types are not assessable by the same method

TypeReaches itCannot reach it
KnowledgeSelected-response items, short written answers, structured oral questions.Over-assessed Knowledge is the usual way a credential looks rigorous while testing little.
SkillPractical tasks with an observable product; simulation with a marked artefact.Multiple choice about how the task would be done.
JudgementScenario with competing constraints, requiring a decision and a defended justification.Any item with one correct answer.
PracticePortfolio of real work with provenance; workplace observation with attestation.Examination of any kind. A two-hour exam cannot see habit.
PREREQUISITE THE FRAMEWORK DOES NOT PUBLISH

D8 requires general information security competence

The framework covers AI-specific security competence. It does not restate general information security competence, because that competence is already defined by other standards bodies. Verify the prerequisite at entry, by an external credential or by documented assessment, and record how you verified it in the specification.

D8General information security competence

External security credential at entry, or documented assessment covering access control, secrets handling, logging and incident response.

D6 at L3+Basic quantitative literacy

Entry assessment or prior qualification.

D2Applicable data protection obligations in the learner's jurisdiction

Not certifiable by us or by you as competence in law; state the jurisdiction assumed.

D4 and D5Working familiarity with the systems being integrated

Stated experience requirement, or a practical entry task.

Pass marks

A defensible pass mark, and the record that makes it defensible

60% is not a standard. What makes a pass mark defensible is a documented method, a panel who applied it, and a date.

Angoff or modified Angoff

A panel judges, item by item, the proportion of minimally competent candidates who would answer correctly.

Bookmark

Panellists order items by difficulty and place a cut where the minimally competent candidate stops.

Analytic rubric with borderline definition

Define the borderline performance in writing, then set the mark that performance would earn.

Compensatory or conjunctive

Decide whether components compensate — for Practice and Judgement statements a conjunctive rule is usually right.

Recertification

The technology moves faster than your validity period

A five-year certificate in this field is a claim about years ahead made today. Some competences decay because the systems change, and some do not decay at all.

Knowledge statements about system behaviour2–3 years
Skill statements tied to current tooling patterns2 years
Judgement statements3–5 years
Practice statements evidenced by portfolioContinuous, reviewed 3-yearly
Specification standard · conformance checklist

Run this against your draft before submitting

Every item is checkable by you, in advance. An application that fails an item is returned rather than reviewed.

01Scope statement names the person, the work and the employer decision.
02Every claimed statement is listed by identifier.
03Framework version and extension versions pinned.
04Coverage values are taught, assessed or both, with no blanks.
05Weightings sum to exactly 100 across assessed statements.
06Assessment method stated per statement group.
07Instrument type suits the statement type.
08Exclusions listed with a rationale each.
09Assessed proportion stated per domain.
10Prerequisites named with verification method.
11Pass mark has method, panel, date and judgements recorded.
12Validity period stated with the reason for its length.
13Recertification requirement stated and achievable.
14Appeals and reassessment policy published to learners.
15Certificate wording does not imply we certified the learner.
16A named signatory has signed the coverage map.