BSI ART/1: The UK AI Testing Framework and What It Means for Procurement

BSI's AI Risk Toolkit (ART/1) is the UK's emerging operational standard for evaluating AI system risk before deployment. Unlike the EU AI Act's conformity assessment (which is statutory and carries market-access consequences), ART/1 is a voluntary framework — but fast becoming a de facto pre-qualification for UK public-sector AI procurement. The toolkit spans: (1) risk identification — mapping the AI system's failure modes across fairness, robustness, explainability, and data quality. (2) Risk scoring — assigning severity and likelihood to each identified risk using a structured taxonomy. (3) Mitigation planning — documenting controls, monitoring arrangements, and residual risk acceptance. (4) Evidence packaging — assembling the documentation into an audit-ready bundle.

For a Council of AI-credentialed provider, ART/1 conformity is largely satisfied by existing measurement infrastructure: the 14-axis board supplies per-model risk scoring (governance, safety, care, affect, detector-interop, jail-resistance, sandbox-escape resistance); the containment incident index supplies the operational risk history; and the verified measurement credential supplies the evidence packaging — one signed JSON object that an ART/1 assessor can verify offline against the Council's public key. The key procurement insight: UK public-sector buyers who reference ART/1 in their RFPs are signalling that they will accept structured, measurable evidence over narrative risk assessments. Providers who arrive with signed, per-axis board scores and a published containment index answer the ART/1 demand with operational data rather than policy prose.

The Council of AI positions the verified measurement credential as the evidence backbone for ART/1: prove you measured, not that you wrote a risk register.

Standards and sources referenced

  • BSI ART/1 — AI Risk Toolkit (phase 1, draft)
  • UK AI Regulation White Paper (2025) — sector-based approach
  • Council of AI Containment Incident Index (CONTAINMENT_INCIDENT_INDEX.json)
  • CSOAI Verified Measurement Credential standard (DEFONEOS-SEAL)
  • GSPC Governance Board v2 (237 items, UK public-sector procurement mapping)