Blackfort Technology
RegulationJuly 22, 2026·Christian Gebhardt

BSI A5: The New Audit Architecture for Trustworthy AI — and Its Bridge to C5

On 6 July 2026 the BSI published the community draft of the A5 audit architecture for AI systems. We explain how A5 is structured, who it addresses, how it connects to the cloud catalogue C5 through ISAE 3000 and which readiness steps make sense now.

Follow Blackfort on LinkedIn

Regulation, technical analyses and hands-on insights — straight to your LinkedIn feed.

Follow now →

On 6 July 2026 the German Federal Office for Information Security (BSI) published the community draft of the AI Audit and Assurance Assessment Architecture (A5) — a modular criteria catalogue with a matching audit methodology for demonstrating the trustworthiness of AI systems. The comment period runs until 31 August 2026, so A5 is still a community draft, not a binding catalogue.

Short analysis: how A5 is structured, who it addresses, how it connects to C5 through ISAE 3000 and which readiness steps make sense now.

For organisations already working with the BSI cloud catalogue C5, one point stands out: A5 connects to C5 directly through a dedicated operating module and uses the same audit methodology under ISAE 3000. This article explains how A5 is structured, who it addresses, and which steps make sense to prepare now — as professional context, not legal advice.

Context: what A5 is and why now

A5 is not a new law; it is an audit framework. The BSI describes a modular, extensible architecture for assessing the trustworthiness of AI systems in a structured way. Every module rests on two building blocks: a criteria catalogue (what is assessed) and an aligned audit methodology (how it is assessed). The methodology builds on the internationally established assurance standard ISAE 3000 — the same approach the BSI already uses for the cloud catalogue C5. The criteria are provided both as documents and in machine-readable OSCAL format, which makes tool-supported assessments easier.

The draft currently contains two modules: a horizontal base module that is technology- and application-independent, and an operating module for cloud infrastructure that creates the link to C5. The architecture is designed for further operating modules, which are outlined in the community draft but not yet fully available.

Modular structure of A5: horizontal base module and cloud-infrastructure operating module bridging to C5, sharing ISAE 3000 and OSCAL
Modular structure of A5 with its bridge to C5 through ISAE 3000 and OSCAL.

The base module aims to cover fair, secure and compliant AI systems across the entire lifecycle — from governance and development through validation and operation to decommissioning. The quality dimensions it addresses include robustness and reliability, explainability, bias, and AI-specific cybersecurity; trade press additionally names performance and human oversight. The list is open and not final in the community draft.

Assessment dimensions of trustworthy AI, evaluated across the entire AI lifecycle
Assessment dimensions of trustworthy AI across the entire lifecycle.

Who is affected — and in which regulatory frame

A5 addresses everyone along the AI value chain: providers who develop and supply AI systems, operators who deploy them, and people in auditing, oversight and procurement. If you develop, operate or procure AI, A5 gives you a reference point for demonstrating technical trustworthiness in a structured way.

Who A5 affects and the regulatory frame: EU AI Act, Cyber Resilience Act, future minimum standards
Who A5 affects and the regulatory frame around it.

The frame around this is formed by the upcoming regulatory requirements. The BSI explicitly names the EU AI Act and the Cyber Resilience Act, as well as future minimum standards, for example for the public sector. A5 supplies the technical evidence layer for them: a structured audit through which trustworthiness can be shown.

For timing — as context, not as individual legal advice: the A5 comment period ends on 31 August 2026. For the EU AI Act, the Digital Omnibus package (final Council approval on 29 June 2026) postponed the obligations for stand-alone high-risk AI systems (Annex III) to 2 December 2027, and for product-embedded systems (Annex I) to 2 August 2028.

Timeline context: A5 community draft, comment deadline, and the postponed EU AI Act dates
Timeline context: the A5 comment deadline and the postponed EU AI Act dates.

For cloud providers and their customers, the bridge to C5 is the practical core. C5 — the Cloud Computing Compliance Criteria Catalogue, currently in its C5:2020 edition — is the established BSI catalogue for cloud security. It is examined as an independent attestation under ISAE 3000 (in Germany IDW PS 951) and is organised into 17 topic areas. A5 attaches here through its cloud-infrastructure operating module. Anyone who already holds a C5 attestation therefore has a methodical and documentary foundation on which an A5 AI assessment can build.

A5 is a community draft

A5 is under public consultation until 31 August 2026 and may still change. It does not create new obligations of its own; the EU AI Act dates here are named only as context, not as individual legal advice.

Readiness: what makes sense now

While A5 remains a community draft, the point is not certification but preparation. Three steps hold regardless of the final wording.

Clarify exposure. Get an overview of which AI systems you develop, operate or procure, and which of them might fall into the high-risk category of the EU AI Act. That tells you where a later A5 assessment becomes relevant in the first place.

Connect to C5. Check whether you already operate or attest cloud services under C5. Because A5 uses the same ISAE 3000 methodology and connects to C5 through the cloud operating module, an existing C5 attestation is a solid starting point. Where it is missing, building C5 readiness is the investment that pays twice.

Plan for the assessment dimensions early. Robustness, explainability, bias and AI-specific cybersecurity cannot be retrofitted shortly before an audit. An early gap analysis along these dimensions shows where governance, documentation and technical evidence are still thin today.

From A5 and C5 to delivery: Blackfort services — C5 consulting and AI governance / AI Act readiness
From A5 and C5 to delivery: the matching Blackfort services.

We support this path at two points. C5 consulting and cloud security assessment covers readiness, control design and the preparation of an ISAE 3000 attestation — the foundation an A5 AI assessment builds on. AI governance and AI Act readiness brings together exposure and gap analysis and prepares the A5 assessment dimensions. Both are professional support, not legal advice.

Takeaway

A5 is a sensible step: it makes the technical trustworthiness of AI auditable and builds on proven structures rather than starting from scratch. For organisations with a cloud and AI footprint, it is worth reading the draft now, clarifying your own exposure and — where possible — using the comment period until 31 August 2026. Those already living C5 have a shorter path ahead.

Note

This article provides professional context on a regulatory topic and is not legal advice; Blackfort Technology is not a law firm. For legally binding guidance on the EU AI Act or C5, please consult a body authorised to provide it. Sources are the BSI A5 community draft (published on 6 July 2026), the BSI A5 topic page, the C5:2020 cloud catalogue, and the Council of the EU press release of 29 June 2026 on the Digital Omnibus. The graphics shown are our own diagrams derived from these sources. A5 is under public consultation and may still change. More about our services at www.blackfort-tec.de.

Kontakt aufnehmen

IT security for your organisation

Blackfort Technology supports organisations with NIS2 compliance, OT security and the protection of critical infrastructure – from analysis to implementation.