AI Level 3 Certification
The standard, published in full: an AI Level 3 Certification is a company-level certification, asserting that an organization has the AI governance policies and procedures required by IEU's rigorous standards and is implementing them. The requirements are set out here so that an organization can assess itself against them before entering an engagement.
What does an AI Level 3 Certification prove?
That your organization has the right AI governance in place and is operating it.
An AI Level 3 Certification asserts two things:
- The AI governance policies and procedures required by this standard are in place.
- The organization is implementing them, so assessment requires evidence that each control operates, not only that it is documented.
The assessment is human-led. IEU practitioners review the organization's policies, procedures, and supporting evidence, and reach a determination. An organization either meets the AI Level 3 standard or it does not; all seven requirements must be met, and no partial result is issued or published.
What do we check?
Seven requirements across three areas of AI governance.
Each requirement must be met, and each is assessed against the evidence standard set out above.
Governance and accountability
Accountability for the organization's use of AI is formally assigned, and the organization maintains a record of its AI uses and a defined response to incidents.
Requirement 1: A formal, adopted AI policy
A written AI-use policy, formally adopted by the organization, identifying the version in force and the date and authority of its approval.
Requirement 2: A named accountable person
One named individual is accountable for AI governance. That individual is the organization's AI Level 2 Certified individual and can escalate AI concerns directly to senior leadership.
Requirement 3: A register of AI uses, each risk-classified
A maintained register of the organization's AI uses, in which each use is classified for risk against the high-stakes test set out below.
Requirement 4: An incident procedure with a named owner
A documented procedure for responding to incidents in which an AI use causes harm or a system behaves unexpectedly, with a named individual who is responsible for the procedure and has accepted that responsibility.
Human oversight
AI uses classified as high-stakes are subject to human review, can be halted, and are overseen by personnel trained for the responsibility.
Requirement 5: Human review and an emergency stop for high-stakes uses
Each AI use classified as high-stakes is subject to meaningful human review before its output takes effect, and can be stopped promptly by the organization.
Requirement 6: Training records for the people who oversee AI
Records demonstrating that the personnel responsible for overseeing AI have completed training for that responsibility.
Data protection and third-party AI
Confidential information is not disclosed to third-party AI tools.
Requirement 7: Controls preventing confidential data reaching public AI tools
Technical or procedural controls that prevent confidential, personal, or client information from being entered into public AI tools.
Ready to get certified?
AI Level 3 Certification is tailored to your organization and arranged through a human audit. Tell us about your organization and we will be in touch.
What counts as high-stakes?
Any AI use where a mistake could affect people's rights, their safety, or can't be undone.
Requirement 3 requires every AI use to be risk-classified. The test below determines what counts as high-stakes, and requirement 5 sets out the obligation that classification creates.
An AI use is high-stakes when a plausible error could do any one of the following.
- A plausible error could deny or restrict a person's rights, opportunities, or access to essential services.
- A plausible error could endanger safety or critical operations.
- A plausible error could cause consequential harm that cannot be reversed.
The test applies to errors the system could plausibly make, rather than to worst-case hypotheticals. Where a plausible error meets any of the criteria above, the use is classified as high-stakes.
Who can be certified?
Any company with at least one AI Level 2 Certified individual.
There is no prerequisite for beginning an AI Level 3 Certification engagement. Certification is issued only once the company has at least one currently-valid AI Level 2 Certified individual. This follows from requirement 2: the individual accountable for AI governance is that certified individual, so the capability must exist within the organization before its use of AI can be certified.
An AI Level 3 Certification is valid for one year. Only currently-valid certificates appear in the public registry. The full program, including how an individual earns AI Level 2 Certification, is set out in how it works.
A certified company may display the AI Level 3 Certification mark while its certification is valid. What that mark certifies, and how anyone can check one against the registry, is set out on the certification mark page.
Discuss an engagement.
AI Level 3 Certification is tailored to the organization and arranged through a conversation rather than a purchase.
Engagement details, including timelines and fees, are scoped with the organization and will be published here once they are settled.
