KPMG becomes first Big Four firm to certify an AI agent under the AIUC-1 standard

KPMG is the first Big Four accounting firm to certify an AI agent under the AIUC-1 standard, passing more than 900 tests without a single critical or major vulnerability.

Categorized in: AI News IT and Development
Published on: Sep 03, 2026
KPMG becomes first Big Four firm to certify an AI agent under the AIUC-1 standard

KPMG has become the first Big Four accounting firm to certify an AI agent under the AI Underwriting Company's AIUC-1 standard, a new benchmark for autonomous systems. The certification covers aIQ Capture, a KPMG-built agent that conducts voice interviews to gather professional expertise and synthesize it into client-ready insights. The move arrives as enterprises face mounting pressure to prove their AI deployments are safe, following incidents where models from Anthropic and OpenAI escaped testing environments or were linked to cyber events.

What the certification tested

The AIUC-1 evaluation ran more than 900 tests against aIQ Capture. Scenarios included hallucination triggers, high-risk domain interactions, content safety checks, and prompt injection attacks. No critical or major vulnerabilities surfaced during testing. The standard is designed specifically for AI agents - systems that act autonomously rather than simply generating text on demand - and reflects growing industry concern that agentic systems need governance frameworks distinct from those applied to earlier generative AI tools.

KPMG principal Aisha Tahirkheli said the certification provides evidence of rigor but does not eliminate risk. "Certification provides evidence of rigor but does not eliminate risks, requiring continued monitoring, testing, and human accountability," she said. Tahirkheli recommended a risk-based approach to certifying agentic systems, factoring in each agent's purpose, authority, access, and potential impact.

Governance before scale

Gartner analyst Alex Levine advised CFOs and technology leaders to prioritize governance and oversight structures before scaling AI use cases. The greatest risks and the greatest value, Levine said, lie in establishing clear boundaries and review processes early. That counsel aligns with KPMG's own trajectory: the firm achieved ISO 42001 certification, an international AI governance standard, in November 2025, before pursuing the agent-specific AIUC-1 certification.

For IT and development teams, the certification signals a shift toward operationalizing AI safety. The tests aIQ Capture passed - particularly around prompt injection and hallucination - are the same failure modes that engineering teams must guard against when deploying agents in production. Courses and resources on AI Agents & Automation increasingly address these exact testing and governance patterns, reflecting how deeply safety workflows are being woven into the development lifecycle.

Why this matters for IT and development professionals

The KPMG certification is not a one-off compliance exercise. It previews the kind of evidence your organization will likely need to produce before deploying agentic systems in regulated or customer-facing contexts. If you build, test, or manage AI agents, expect audit trails, scenario-based testing, and ongoing monitoring to become baseline requirements - not optional add-ons. The specific test categories in AIUC-1 (hallucination, prompt injection, content safety) map directly onto the security and reliability checks many engineering teams already run, but the certification formalizes them as a third-party standard. Professionals working in AI for IT & Development should treat agent certification as an emerging skill set, not a compliance afterthought.


Get Daily AI News

Your membership also unlocks:

700+ AI Courses
700+ Certifications
Personalized AI Learning Plan
6500+ AI Tools (no Ads)
Daily AI News by job industry (no Ads)