Skip to main content

      With the AI Audit and Assurance Assessment Architecture – or A5 for short – the Federal Office for Information Security (BSI) is developing a modular framework for assessing the trustworthiness of AI systems. For businesses, even the Community Draft opens up an important prospect: technical, organisational and regulatory requirements for artificial intelligence (AI) could in future be assessed more systematically and made transparent through independent assurance services.

      At a glance

      • BSI A5 provides the basis for systematically assessing the trustworthiness of AI systems using uniform criteria and for demonstrating this in a transparent manner.
      • BSI A5 combines AI-specific criteria with an audit methodology based on C5 and ISAE 3000.
      • BSI A5 is not currently a statutory audit requirement in its own right, but it provides a structured framework for robust controls and evidence.
      • BSI A5 does not replace any conformity assessment that may be required under the EU AI Act.
      • For organisations, BSI A5 is primarily relevant as a readiness and evidence framework until a final standard is in place.

      Why BSI A5 is relevant now

      AI is increasingly being applied to business-critical processes. This is driving a growing need not only to document risks, controls and technical evidence, but also to ensure these remain consistently available throughout a system’s lifecycle. BSI A5 already offers organisations concrete guidance on reviewing existing governance and control structures, identifying gaps in evidence at an early stage and preparing for potential future audit requirements.

      The consultation period for the Community Draft ran until 31 August 2026. Even though BSI A5 is not yet available as a final standard, the draft already provides a relevant framework for the systematic assessment of the trustworthiness of AI systems. In future, BSI A5 reporting could, for example,

      • be contractually required by clients,
      • be taken into account in procurement or supplier processes,
      • serve as evidence for governance, internal audit or supervisory bodies, or
      • form part of a company’s risk management framework for particularly critical AI systems.

      BSI A5 im Zusammenspiel mit Regulierung und Standards

      BSI A5, der EU AI Act und bestehende Normen und Kriterienkataloge adressieren unterschiedliche Ebenen. Der BSI A5-Entwurf weist ausdrücklich auf Überschneidungen mit dem EU AI Act, ISO/IEC 42001, BSI C5 (damit auch auf die Erweiterung AIC4) und weiteren Prüfungsstandards hin. Dokumentationen können organisatorisch abgestimmt werden. Bestehende Zertifizierungen, Prüfberichte und Dokumentationen können berücksichtigt und organisatorisch mit BSI A5 koordiniert werden. Die eigenständige BSI A5-Schlussfolgerung auf Basis der anwendbaren Kriterien ersetzen sie jedoch nicht. Für Unternehmen kommt es deshalb darauf an, die jeweiligen Funktionen zu verstehen und mögliche Überschneidungen bei Governance, Kontrollen und Nachweisen sinnvoll zu nutzen.
       

      EU AI Act

      The EU AI Act sets out legal obligations for providers, operators and other stakeholders. For high-risk AI systems, these include, amongst other things, requirements relating to risk management, technical documentation, record-keeping, human oversight, accuracy, robustness and cybersecurity.

      BSI A5 complements this regulatory perspective with a framework of criteria and assessment methods for the technical and organisational reliability of AI systems. This does not replace the conformity assessment required under the EU AI Act. However, BSI A5 can help organisations to systematically structure relevant controls and evidence.

      ISO/IEC 42001

      ISO/IEC 42001 addresses an organisation-wide management system for artificial intelligence. It focuses on an organisation’s overarching governance structures, responsibilities and management processes.

      BSI A5, by contrast, is more strongly focused on a specifically defined AI system, its operational context and the associated controls. The two approaches can therefore complement one another: the management system provides the organisational framework, whilst BSI A5 can support a system-specific assessment.

      AIC4

      With AIC4, the BSI has already published a set of criteria for cloud services that utilise machine learning methods. AIC4 is designed as an extension of C5 and addresses, amongst other things, security and robustness, reliability, data quality, data management, explainability and bias throughout the lifecycle of an AI cloud service.

      BSI A5 adopts a broader, modular architectural approach: the framework is not limited to AI cloud services, but is intended to encompass different AI systems, application contexts and stakeholders along the value chain. AIC4 and BSI A5 thus differ in scope and architecture: AIC4 focuses on AI cloud services, whilst BSI A5 has a broader and more modular design.

      BSI C5 und ISAE 3000

      BSI C5 addresses the security and internal control system of cloud services. There are two key links to BSI A5: the BSI A5 audit methodology is based on the established C5 audit framework, and the Cloud Infrastructure operational module establishes a direct link to C5.

      ISAE 3000 forms the methodological foundation for the proposed independent assurance engagement. The standard provides the audit methodology but does not itself contain a specific catalogue of criteria relating to cloud infrastructure.

      EU AI Act

      The EU AI Act sets out legal obligations for providers, operators and other stakeholders. For high-risk AI systems, these include, amongst other things, requirements relating to risk management, technical documentation, record-keeping, human oversight, accuracy, robustness and cybersecurity.

      BSI A5 complements this regulatory perspective with a framework of criteria and assessment methods for the technical and organisational reliability of AI systems. This does not replace the conformity assessment required under the EU AI Act. However, BSI A5 can help organisations to systematically structure relevant controls and evidence.

      ISO/IEC 42001

      ISO/IEC 42001 addresses an organisation-wide management system for artificial intelligence. It focuses on an organisation’s overarching governance structures, responsibilities and management processes.

      BSI A5, by contrast, is more strongly focused on a specifically defined AI system, its operational context and the associated controls. The two approaches can therefore complement one another: the management system provides the organisational framework, whilst BSI A5 can support a system-specific assessment.

      AIC4

      With AIC4, the BSI has already published a set of criteria for cloud services that utilise machine learning methods. AIC4 is designed as an extension of C5 and addresses, amongst other things, security and robustness, reliability, data quality, data management, explainability and bias throughout the lifecycle of an AI cloud service.

      BSI A5 adopts a broader, modular architectural approach: the framework is not limited to AI cloud services, but is intended to encompass different AI systems, application contexts and stakeholders along the value chain. AIC4 and BSI A5 thus differ in scope and architecture: AIC4 focuses on AI cloud services, whilst BSI A5 has a broader and more modular design.

      BSI C5 und ISAE 3000

      BSI C5 addresses the security and internal control system of cloud services. There are two key links to BSI A5: the BSI A5 audit methodology is based on the established C5 audit framework, and the Cloud Infrastructure operational module establishes a direct link to C5.

      ISAE 3000 forms the methodological foundation for the proposed independent assurance engagement. The standard provides the audit methodology but does not itself contain a specific catalogue of criteria relating to cloud infrastructure.

      For which organisations might BSI A5 be important?

      This development is particularly relevant for organisations that use AI in business-critical, regulated or security-related processes. The BSI has designed BSI A5 for stakeholders across the AI value chain, including providers, operators and roles in development, operations, supervision and procurement.

      • Organisations with AI systems on cloud platforms and existing C5 evidence
      • Organisations wishing to establish additional structured evidence of governance and trustworthiness as providers or operators of high-risk AI systems
      • Organisations with dependencies on model, data, platform or cloud providers
      • Companies that require robust evidence of AI governance and controls for customers, regulators or business partners

      FAQ on BSI A5

      BSI A5 combines a horizontal base module with supplementary profiles and modules. The base module covers fundamental organisational and technical requirements throughout the entire life cycle of an AI system, from governance, design and development, through verification, deployment and operation, to decommissioning. The starting point for the assessment is a clearly defined subject of investigation, referred to in BSI A5 as the ‘assessment object’. This may be a complete AI system, an AI application, a component, a model, a dataset or another clearly defined part of an AI system.

      The responsible organisation selects a suitable profile for this assessment object. This selection is not arbitrary: the profile must accurately reflect the assessment object and its intended use case; the criteria it contains are, in principle, considered binding. The profile determines the set of criteria to be applied and may

      • from individual BSI A5 criteria,
      • from one or more profile modules, or
      • from a combination of profile modules and additional criteria

      exist. Profiles and profile modules are, as a rule, defined and maintained by the BSI. A combination of published profile modules may also form an implicit profile in accordance with the Community Draft.

      For an AI system running on a cloud infrastructure, for example, a profile that combines criteria from the horizontal base module with the cloud infrastructure module may be relevant. Modules that are not relevant, on the other hand, do not automatically form part of the scope of the assessment.

      BSI A5 primarily specifies the verifiable criteria and the audit methodology. The responsible organisation designs the specific organisational and technical controls to suit its risks, its AI system and its operational context. An audit is then carried out to determine whether:

      • the system description accurately represents the subject of assessment and the controls,
      • the controls are appropriately designed and implemented to meet the applicable BSI A5 criteria,
      • in the case of an effectiveness test, the controls have functioned effectively over the audit period.

      The guidance within the BSI A5 basic module describes possible approaches to implementation and documentation. It is intended to support interpretation but does not establish any additional independent obligations beyond the binding text of the criteria.

      The audit methodology is based on ISAE 3000 and provides for an audit to provide reasonable assurance.

      What businesses can do now to prepare

      Even before a final version of BSI A5 is published, a structured readiness check can be useful. Based on the Community Draft, our experts support companies in developing a robust governance and evidence structure at an early stage, making targeted use of existing preparatory work and reducing the effort required for a subsequent BSI A5 audit. A readiness check can

      • document the AI inventory and roles along the value chain,
      • carry out a pilot comparison of a relevant AI system against the base module and relevant profiles,
      • consistently structure system descriptions, controls, test reports, logs, and change and incident records,
      • check existing records from C5, information security or ISO/IEC 42001 for reusability and interoperability, and
      • check contracts and interfaces to ensure that the necessary supplier information is available.

      BSI A5-Readiness auf Basis des KPMG Trusted AI Framework

      With the KPMG Trusted AI Framework, KPMG combines governance, technology and assurance into an integrated approach to trustworthy AI. For BSI A5, the framework can serve as a methodological and technological basis for translating requirements into specific control points throughout the AI lifecycle and for structuring existing evidence in a way that is compatible with the framework.

      Putting governance into practice

      Pre-structured control libraries and the KPMG Trusted AI model help to translate regulatory and ethical requirements into roles, controls, key performance indicators and monitoring mechanisms. The approach takes into account, amongst other things, the EU AI Act, ISO/IEC 42001 and other international frameworks. A supplementary mapping to BSI A5 can help to highlight overlaps and avoid parallel governance structures.

      Combining technology and controls

      KPMG considers not only guidelines and process descriptions, but also the technical architecture of the AI system. This encompasses data, model, integration and application layers, as well as control points for data quality, access, logging, model versioning, security and monitoring. Governance is thus not merely documented, but can be directly embedded within the architecture and operations.

      Making the most of supporting evidence

      Technology-enabled mapping and benchmarking can systematically align existing controls, documentation and evidence with the relevant requirements. This creates a consistent basis for evidence that governance and audit functions can utilise to meet various regulatory and audit-related requirements.

      From ad hoc checks to continuous monitoring

      This approach can be supplemented by automated data collection, test automation and continuous control monitoring. This enables control deviations and operational changes to be identified at an earlier stage, whilst reducing the manual effort involved in recurring documentation and testing tasks.

      Putting governance into practice

      Pre-structured control libraries and the KPMG Trusted AI model help to translate regulatory and ethical requirements into roles, controls, key performance indicators and monitoring mechanisms. The approach takes into account, amongst other things, the EU AI Act, ISO/IEC 42001 and other international frameworks. A supplementary mapping to BSI A5 can help to highlight overlaps and avoid parallel governance structures.

      Combining technology and controls

      KPMG considers not only guidelines and process descriptions, but also the technical architecture of the AI system. This encompasses data, model, integration and application layers, as well as control points for data quality, access, logging, model versioning, security and monitoring. Governance is thus not merely documented, but can be directly embedded within the architecture and operations.

      Making the most of supporting evidence

      Technology-enabled mapping and benchmarking can systematically align existing controls, documentation and evidence with the relevant requirements. This creates a consistent basis for evidence that governance and audit functions can utilise to meet various regulatory and audit-related requirements.

      From ad hoc checks to continuous monitoring

      This approach can be supplemented by automated data collection, test automation and continuous control monitoring. This enables control deviations and operational changes to be identified at an earlier stage, whilst reducing the manual effort involved in recurring documentation and testing tasks.


      The added value: BSI A5 readiness is not treated as a separate checklist, but is embedded within a scalable Trusted AI governance framework. This enables organisations to enhance quality and security, make better use of existing controls, and reduce the effort involved in management, documentation and future audits.

      Consultancy and readiness services must be clearly distinguished from any potential independent assurance service. The services that can be provided in a specific case must be assessed taking into account the applicable independence requirements.

      Outlook

      BSI A5 has the potential to become a key link between AI governance, technical assessment and independent assurance. It will be crucial to see how the BSI responds to feedback from the community, develops further profiles and clarifies how the framework aligns with the EU AI Act and international standards. In addition, the BSI is publishing the A5 criteria in the machine-readable OSCAL format. In the long term, this may facilitate the integration of the criteria framework into technology-enabled compliance and audit processes.

      Companies should therefore not currently regard BSI A5 as a finished quality mark. Rather, the Community Draft is an opportunity to review their own ability to demonstrate trustworthy AI at an early stage and in a structured manner.

      Would you like to assess the potential significance of BSI A5 for your AI systems and existing control structures? Our experts will be happy to assist you with an initial technical assessment. Get in touch with us now.

      More KPMG Insights

      Your contacts