AI agent certification for Switzerland, built on evidence

AIA Guard is developing a certification scheme for AI agents used in Swiss healthcare and finance. Every result is tied to one exact agent version, one use and one environment — and states its limits in plain words. The scheme is a draft: a careful private assessment today, designed to grow into recognized certification. It is not a government approval.

What we assess

We assess a running agent, not a model name: its software version, instructions, knowledge sources, tools, permissions, data flows, human checkpoints and operating routines. The scope names the intended users, languages and actions — plus what is explicitly excluded. A product name alone is never enough.

Healthcare and finance come first, because a small mistake can expose sensitive data, misroute a case or create an unwanted commitment. A clinic assistant that prepares appointments and a bank assistant that drafts payment investigations are tested through complete workflows, not just sample answers.

What you receive

You receive a scope manifest: the exact release, workflow, environments, tools, data types, languages and exclusions. A finding register lists each issue with its control, severity, what was observed, who owns the fix and whether it is resolved. An evidence index links every conclusion to a dated record or a repeatable test — without publishing your confidential material.

A written decision states the result, the decision date, the method version, open findings, remaining risks and the reviewer. It also lists retest triggers: a changed model or instruction, a new data source, wider permissions, a new workflow, a serious incident or an expired review period. Only fields you authorize would ever appear in public.

  • Scope manifest for the assessed release
  • Finding register with owners and status
  • Evidence index with sources and access rules
  • Written decision, limits and retest triggers

What the result does — and does not — say

A positive result is our private, written statement about the tested scope on the tested date. It says: this version passed these checks, with these limits. It does not promise error-free operation, legal compliance or fitness for another use — and insurance cover always requires a separate policy from an insurer.

We state plainly where we stand: the scheme is a draft, no accredited certificate has been issued, and no insurer agreement has been signed. That honesty is part of the design: every claim on this site can be checked.

Keeping a result current

Agents change fast, so results expire. The draft asks for a fresh evidence review every three months, plus immediate reassessment after important changes, serious incidents or new powers given to the agent. A new model, instruction, data source, tool permission or approval step can change the result.

One rule protects every decision: the person who built the controls never signs off their own work. An independent reviewer makes the certification decision.

Are you ready to apply?

You are ready when you can point to the exact version going live, name who owns the workflow, replay representative tests and show cleaned operating records. You should also know which actions are impossible, which need approval — and who can stop the agent.

Missing evidence does not automatically mean a control failed, but the reviewer cannot mark the claim as verified. If you are unsure where you stand, start a conversation: choose “Discuss your agent” in the navigation and tell us what your agent needs to prove.

The mark certified agents display

Any organisation with a positive result receives the AIA Guard mark for its website: visible proof that links to the public registry check, where anyone can confirm its status, version and scope.

The mark may be used only while the record is valid, and only for the agent and version named in the certificate. Do not alter, imitate, or attach it to drafts or self-assessments: misuse leads to revocation and removal from the registry.

Common questions

Do you certify a model or a working agent?

We assess a working agent version: instructions, data sources, tools, permissions, human checkpoints and operating environment. A model name alone is not enough to define the scope.

Can a high score make up for a critical failure?

No. A critical blocker stays visible and overrides the score until it is fixed and retested.

What should we prepare first?

Start with a versioned list of your system parts, one complete workflow, data and tool boundaries, approval rules, representative tests and named owners.