Independent AI Certification

Certify the system that actually exists.

Clause5afe certification attaches to a defined AI system, version, deployment context, and evidence boundary. The process is designed to produce a controlled certification decision, not a general endorsement of an entire company.

We certify. We do not consult. The client owns implementation and remediation.

Four-stage lifecycle

From defined scope to controlled decision.

The approved certification pricing model defines the core engagement as Scoping, Forensic Audit, Finding Classification, and Certification Decision. Public process language will remain synchronized with the governing certification policies and master documents as those are finalized.

01

Scoping

Define the AI system, version, deployment context, intended use, relevant jurisdictions, organizational boundary, and evidence required for the engagement.

02

Forensic Audit

Qualified evaluators examine the in-scope technical, governance, oversight, privacy, security, operational, and lifecycle evidence using the Clause5afe certification methodology.

03

Finding Classification

Identified gaps are documented and classified by severity so the certification record distinguishes consequential deficiencies from lower-severity findings.

04

Certification Decision

The evidence and findings move through the controlled decision process. Commercial activity and client preference do not determine the certification outcome.

Evidence architecture

Certification examines more than runtime telemetry.

Technical signals can be important evidence, but certification also depends on governance, documentation, human oversight, privacy, security, lifecycle, and organizational evidence that telemetry alone cannot establish.

System and architecture

  • System identity and version
  • Intended use and deployment context
  • Model or component architecture
  • Interfaces, dependencies, and material technical boundaries

Data, privacy, and rights

  • Data provenance and governance
  • Privacy and consent controls
  • Rights-impact evidence
  • Retention, access, and sensitive-data safeguards

Governance and human oversight

  • Accountability and decision ownership
  • Human review and escalation
  • Risk governance and approvals
  • Policies, roles, training, and control evidence

Operations, security, and change

  • Testing and operational evidence
  • Security and resilience controls
  • Incident and exception handling
  • Logging, monitoring, release, and material-change controls

Finding Classification

Not every gap carries the same consequence.

Clause5afe's approved pricing guide identifies three finding classifications: Critical, Major, and Minor. The governing methodology determines how findings affect the certification decision and any later re-assessment.

Critical

A highest-severity finding requiring controlled treatment under the applicable certification methodology and decision rules.

Major

A material deficiency that is documented distinctly from lower-severity issues and considered through the certification decision process.

Minor

A lower-severity finding that remains part of the documented audit record and applicable follow-up requirements.

Decision authority

Evidence can be gathered collaboratively. The certification decision cannot be bought.

Commercial engagement, evaluation activity, quality review, and certification decision authority are separated through the Clause5afe governance model. The client can provide evidence and correct factual inaccuracies, but the client does not choose the certification outcome.

Evidence & evaluationQuality reviewCertification decision

Scope of service

Independence is partly defined by what Clause5afe refuses to sell.

Included in certification
  • Full four-stage independent certification audit
  • Detailed Findings Report with severity classifications
  • Board-ready certification summary
  • Certification Mark issuance when the applicable certification criteria and issuance conditions are satisfied
  • Continuous monitoring availability throughout the certification validity period, with optional activation and no additional monitoring charge
Not included
  • Remediation plans or implementation guidance
  • Consulting, advisory, or certification-preparation services
  • Vendor recommendations or tool-selection advice
  • Pre-certification readiness assessments
  • Legal opinions or guarantees of regulatory compliance

After the decision

Certification has a lifecycle, not an infinite shelf life.

Under the current approved pricing model, high-risk AI certifications are valid for one year and standard AI certifications for a maximum of two years. Re-certification is required at the applicable interval, and material system changes may create additional review or re-assessment requirements before that date.

High-risk systems1 year

Annual re-certification cadence.

Standard systemsUp to 2 years

Re-certification no later than 24 months.

Continuing evidence

Every certification fee includes the option to activate continuous monitoring for the certified system during the certification validity period at no additional charge. Monitoring can surface new evidence; Clause5afe retains the judgment about what that evidence means for the certification.

Explore Continuous Monitoring

Begin with the real system

Scope determines the engagement.

Organization scale matters, but so do system risk, deployment scale, regulatory exposure, architecture, and the evidence required to reach a defensible certification decision.