Section navigation
Annex I: Independent Assessor Guidance
This annex provides guidance for organizations conducting or commissioning independent assessment of ARCS conformance. It is informative.
When independent assessment applies
Independent assessment is not required for Minimum Profile conformance. Organizations may self-assess against the Minimum Profile.
Independent assessment is recommended for Enterprise Profile conformance and for any conformance claim that will be presented to third parties in insurance, procurement, or regulatory contexts.
Assessor qualifications
An independent assessor should demonstrate:
Technical qualifications: understanding of AI system architecture, ability to read system logs and configuration files, familiarity with database systems and cloud storage.
Governance qualifications: understanding of records management principles, familiarity with discovery obligations and preservation requirements, understanding of multi-vendor custody fragmentation.
Professional qualifications: no undisclosed conflicts of interest with the operator, professional liability insurance or institutional backing where applicable.
Assessment scope
The assessor should review: record surface map, custody surface map, configuration exposure matrix, retention and deletion documentation, preservation procedures, agent runtime documentation where applicable, and any claimed non-creation verifications.
The assessor should verify that documented surfaces match actual system behavior where technically accessible.
Assessment output
The assessor should produce a written report identifying: the system assessed, the documents reviewed, the procedures performed, findings for each control area evaluated, and a conformance level recommendation with supporting rationale.
Limitations
Assessment confirms that controls appear to be in place at the time of review. It does not guarantee future behavior or vendor compliance beyond what was verified. Assessors are not responsible for legal outcomes or for changes in system behavior after the assessment date.