BSI publishes Community Draft of A5 — AI audit and assurance assessment architecture — for public comment
Original title: 260706 KI A5 Community Draft
BSI has published the A5 (AI Audit and Assurance Assessment Architecture) as a Community Draft open for stakeholder feedback until 31 August 2026. A5 introduces a modular, extensible audit framework for AI systems, providing criteria and methodology to systematically assess and demonstrate trustworthiness in the context of the EU AI Act, the Cyber Resilience Act, and other standards. The initial release includes a horizontal base module with technology- and application-agnostic audit criteria, and adopts an audit methodology aligned with ISAE 3000 — the same approach used in BSI's C5 catalogue for cloud computing. Criteria are also published in OSCAL, making them machine-readable and compatible with existing compliance toolchains.
What changed
- BSI publishes A5 Community Draft — a new modular AI audit architecture (AI Audit and Assurance Assessment Architecture) — and opens a public comment period until 31 August 2026 (submissions to [email protected]).
- A5 provides a structured set of audit criteria and a methodology for the systematic, standardised assessment of AI system trustworthiness, positioned explicitly in the context of the EU AI Act and the Cyber Resilience Act.
- The initial release delivers a horizontal base module covering technology- and application-agnostic audit criteria; further modules (e.g. Cloud Infrastructure) are planned or referenced, including a cross-link to BSI's C5 catalogue.
- The audit methodology follows ISAE 3000, mirroring the approach established in the C5 catalogue, giving auditors and auditees a familiar assurance engagement framework.
- A5 criteria are made available in OSCAL (Open Security Controls Assessment Language), enabling machine-readable integration into existing OSCAL-based compliance and audit tooling.
What the document requires
The BSI invites stakeholders to submit comments on the A5 Community Draft by 31 August 2026 via email to [email protected].
Who is affected
AI system providers, operators, developers, and oversight bodies across all sectors operating in or supplying to the EU market; particularly those subject to the EU AI Act or the Cyber Resilience Act. Auditors and conformity assessment bodies assessing AI systems are also directly affected.
Summary generated by a language model; the official text prevails. Not legal advice.