KPMG's AIUC-1 Certification: What It Means for Swiss SMEs

In short
In September 2026, KPMG became the first Big Four firm to certify an AI agent under the AIUC-1 standard: over 900 tests, zero critical vulnerabilities. For Swiss SMEs, the case shows how much rigour production-ready AI agents now require — and why governance must come before certification.
What KPMG Actually Proved With aIQ Capture
In September 2026, KPMG became the first of the four major audit and advisory firms to have one of its own AI agents certified under the new AIUC-1 standard. The agent, aIQ Capture, converts voice interviews into structured client insights. The evaluation involved more than 900 individual tests — covering hallucination triggers, high-risk domains, content safety, and prompt injection attacks. The result: no critical or major vulnerabilities. For an autonomous system that makes decisions and calls tools on its own, that is a remarkably dense testing regime.
900+
tests completed with no critical or major vulnerabilities found in aIQ Capture
Why AIUC-1 Is Different From Earlier AI Certifications
Most prior AI certifications assess models or management systems. AIUC-1 is built differently: it targets agentic systems specifically — AI that doesn't just generate text but acts autonomously, invokes tools, and makes decisions. That distinction is exactly what makes it interesting to insurers. For the first time, there is a testing framework robust enough to serve as a basis for insuring autonomous systems, which matters for any deployment in regulated or customer-facing contexts.
Certification provides evidence of rigour, but it does not eliminate risks. It still requires continued monitoring, testing, and human accountability.
No Legal Vacuum: The Swiss Starting Point
Even without a dedicated AI act of its own, Switzerland already has a solid framework for autonomous systems. The revised Data Protection Act addresses automated individual decisions in Article 21, the Code of Obligations spreads liability for duty of care across Articles 41, 97, 717 and 754, and FINMA's Guidance 08/2024 sets out clear expectations for AI governance at regulated institutions. Anyone running an AI agent in production today is not operating in a legal void — even as the EU AI Act, with its staggered deadlines through 2028, only gradually takes shape across the continent.
Certification Doesn't Replace Governance — It Builds On It
The sequencing is telling: KPMG first achieved ISO 42001 certification for its AI management system in November 2025, and only then pursued the agent-specific AIUC-1 evaluation. That is not a coincidence but the logical order — governance foundations first, then deep technical scrutiny of the individual agent. Organisations that lack a control layer for their own AI agents are, in effect, skipping a step before certification is even on the table.
Why Most AI Agent Projects Fail Before Reaching Production
The 900 passed tests behind aIQ Capture look impressive — until you read them against the backdrop of industry reality. Gartner puts the share of abandoned agent projects at over 40 percent, most of them never making it past pilot stage. The reason is rarely the technology itself.
- Investment gap: organisations spend roughly eight times more, according to Gartner, on building new agent capabilities than on controlling and monitoring them.
- Data quality as the bottleneck: in roughly 85 percent of cases, Gartner finds that scaling fails not because of the AI itself but because of insufficient underlying data.
- Buy beats build: the MIT NANDA study found a 67 percent success rate for externally sourced agent solutions versus 33 percent for internally built ones.
These figures explain why advisory firms such as Deloitte, BCG and McKinsey realistically map out 18 to 36 months for the journey from pilot to genuine production. What typically goes wrong during that stretch — and how to avoid it — is a topic worth examining closely before committing to any agent deployment.
What This Means for Your Organisation
The key lesson from the KPMG case is not 'go get your agent certified,' but rather: calibrate your testing effort to the actual risk involved. AIUC-1 itself follows a risk-based approach built around four questions — what purpose the agent serves, what authority it holds, what systems it can access, and what the impact of a failure would be. An internal research assistant warrants a different depth of scrutiny than an agent that autonomously approves payments or handles customer data. Structuring that assessment for your own organisation is the first real step before any certification conversation makes sense.
A Simple Early Warning Signal
How an agent handles its first tool call reveals a great deal about its maturity. If it works directly and precisely through a clearly defined interface, that points to a strategically designed architecture. If it relies mainly on broad document retrieval just to figure out what to do, that's often a sign of a reactively assembled system — one that needs a correspondingly higher level of scrutiny and control.
Governance as a Leadership Issue, Not an IT Project
Gartner analyst Alex Levine puts it plainly: CFOs who deploy AI agents successfully today prioritise governance and oversight before they scale, not after. That aligns with what we see across many mid-sized Swiss firms: once AI agents are treated as a leadership issue rather than a pure IT project, both the pace and the diligence of adoption improve markedly. The Swiss AI Podcast explored exactly this shift in how mid-sized companies make AI a leadership priority.
The Next Step
The KPMG case shows what is technically achievable today when depth of testing, governance and accountability work together. It also shows how much effort sits behind that achievement — 900 tests don't happen incidentally. For most Swiss SMEs, the relevant question isn't whether they need to follow the same certification path, but whether their own AI agent has even been thought through against the same principles — purpose, authority, access, impact — before it goes into production.
Frequently asked questions
- What exactly is the AIUC-1 standard?
- AIUC-1 is a certification standard built specifically for agentic AI systems — AI that acts autonomously, invokes tools, and makes decisions rather than simply generating text. It evaluates factors such as hallucination risk, behaviour in high-risk domains, content safety, and resilience against prompt injection attacks.
- Does certification mean an AI agent automatically becomes insurable?
- No. AIUC-1 creates, for the first time, a testing framework robust enough to serve as a basis for insurability, because it provides solid evidence on risk and diligence. Whether a specific agent is actually insurable remains a case-by-case decision for insurers, depending on its purpose, authority, access, and potential impact.
- Does a Swiss SME also need AIUC-1 certification?
- There is currently no legal requirement to do so. For low-risk agents with limited authority, the effort of full certification is often disproportionate. What matters is the underlying principle: matching your testing rigour to the agent's actual risk, rather than skipping scrutiny altogether.
- What is the difference between AIUC-1 and ISO 42001?
- ISO 42001 certifies an organisation's overall management system for handling AI. AIUC-1 evaluates a specific, individual AI agent for agent-specific risks. KPMG first achieved ISO 42001 and then built on that foundation to pursue AIUC-1 certification for aIQ Capture.
- When is an AI agent considered production-ready?
- Production readiness isn't a fixed threshold but the outcome of a risk-based assessment: how critical is the agent's purpose, what authority and system access does it hold, and how severe would the impact of a failure be? The higher these factors, the deeper the testing needs to be before deployment.
Sources
Would you like to explore this topic for your company?
Check Availability