Cybersecurity

Sierra Earns AIUC-1 Certification After Independent Audit

mm
Add Unite.AI to your preferred sources on Google

Sierra announced on September 17, 2026, that its AI agent platform has achieved AIUC-1 certification following an independent audit by Schellman and extensive testing by the Artificial Intelligence Underwriting Company (AIUC).

AIUC-1 is a standard designed specifically for AI agents that tests how agents actually behave, including what happens when someone tries to manipulate them, access protected information or push beyond what they are authorized to do, according to the company. Sierra said agents built on its platform do more than answer questions: they coordinate patient care, troubleshoot technical issues, resolve insurance claims and refinance mortgages. The company said over 40% of the Fortune 50, one in three of the leading banks and five out of 10 of the largest healthcare companies in the world work with its platform.

Testing Scope and Recurring Evaluations

As part of the certification, AIUC tested Sierra’s chat and voice agents across everyday interactions and adversarial scenarios, including attempts to manipulate agents or expose protected information, plus a range of real-world voice conditions. Separately, Schellman reviewed Sierra’s technical, legal, operational and governance controls and found that Sierra met all applicable AIUC-1 requirements, the announcement said. The technical evaluations recur at least quarterly, with a full audit every year, so the certification continues to reflect changes in both Sierra’s platform and the broader AI risk environment.

The AIUC-1 Standard

AIUC describes the AIUC-1 standard as the standard for AI agent security, safety and reliability, and says it was built with more than 250 Fortune 500 security leaders. The standard spans six risk domains: Data & Privacy, Security, Safety, Reliability, Accountability and Society. Covered threat categories include prompt injection, jailbreaks and unauthorized actions under Security; harmful outputs and human oversight under Safety; hallucinations and unsafe tool calls under Reliability; data leaks and PII protection under Data & Privacy; incident response, logging and governance under Accountability; and cyber misuse and catastrophic risk under Society.

Certification proceeds through four steps: Scoping, Evals, Audit and Certification. During Evals, AIUC conducts thousands of real-world scenarios testing against jailbreaks, prompt injection, data leakage, hallucinations and unsafe tool calls, with red-teaming typically involving 1,000 to 5,000 different test scenarios. The Audit step is a full review of policy, operational and technical controls across the six domains, conducted by an accredited auditor such as Schellman or Coalfire. The issued certificate and audit report are valid for one year, with quarterly retests against the standard version locked in during scoping.

The standard is crosswalked to ISO 42001, MITRE ATLAS, the EU AI Act, the NIST AI Risk Management Framework and the OWASP Top Ten. The AIUC-1 site lists Cursor, Fin, ElevenLabs, Harvey, UiPath and KPMG among certified organizations and says certified companies receive an independent audit report of more than 50 pages covering how guardrails are implemented and the results of red-teaming.

Schellman stated in its own release that it became the first authorized AIUC-1 auditor on February 3, 2026. Under the partnership, AIUC conducts technical evaluations and issues certification while Schellman provides independent audit evidence collection, detailed reporting and certification guidance. The release describes AIUC as founded by experts from Anthropic and developed with law firm Orrick, the Cloud Security Alliance and MITRE. Danny Manimbo, Schellman’s AI practice leader, said AIUC-1 “fills a critical gap with its technical, auditable approach to AI agent assurance.”

Sierra’s Layered Safeguards

Sierra said security, safety and reliability are built into how agents on its platform are created, tested, released and improved, using a defense-in-depth approach that combines multiple safeguards rather than relying on any one control. Grounded content and customer-defined policies guide each agent’s behavior. Once an agent is live, supervisor models evaluate conversations in real time and can correct, block or escalate responses, while deterministic guards enforce absolutes that cannot be left to model judgment, such as authentication and access requirements.

An August 13, 2026, Sierra post on the architecture details four layers: retrieved content that grounds responses in the customer’s own knowledge, natural-language rules and policies the agent must follow, supervisor models that audit conversations and can block, rewrite or nudge the agent, and non-model deterministic checks, such as keeping account-modification tools unavailable until the customer has been authenticated. A single customer message can trigger half a dozen of these checks before any reply goes back, according to the post.

Sierra said it also works with third parties on regular adversarial and red-team assessments totaling millions of attempts in aggregate, with findings feeding back into the platform. It monitors live traffic through platform-level Threat Detection and per-agent Agent Monitors, and uses Simulations to stress-test agents for guardrail regressions before any changes ship.

Existing Compliance and Next Steps

Sierra said the certification complements its existing SOC 2 Type II attestation and ISO 27001 and ISO 42001 certifications, which validate its security and AI management systems, while AIUC-1 adds recurring technical testing designed specifically for AI agents. The Sierra Trust Center lists ISO/IEC 27001:2022, ISO/IEC 42001:2023, SOC 2, HIPAA, PCI DSS 4.0.1, GDPR, CCPA, CSA STAR, the EU AI Act and FedRAMP High among its compliance listings, with 2026 SOC 2 Type II and HIPAA audit reports available on request.

Sierra said businesses still decide how their agents behave, including what they know, which systems they can access, what actions they take and how they represent their brand, and that AIUC-1 provides independent validation of the platform underneath those agents. The company said it will continue investing in independent evaluation alongside its own testing, monitoring and product development.

Miles Okada is an AI-generated analyst at Unite.AI, covering artificial intelligence and cybersecurity with a focus on emerging threats, defensive architectures, and the evolving dynamics between attackers and automated systems. His work examines how AI is reshaping security operations, from autonomous threat detection and response to the rise of adversarial AI techniques.

With a technical and investigative perspective, Miles analyzes security research, incident disclosures, and real-world deployments to understand where AI strengthens defenses—and where it introduces new vulnerabilities. He pays particular attention to model exploitation, data poisoning, attack automation, and the operational realities of securing AI-powered systems at scale.

Articles authored by Miles Okada are AI-generated and reviewed by Unite.AI’s editorial team to ensure accuracy, rigor, and responsible coverage of the rapidly changing AI security landscape.