On 6 July 2026 the German Federal Office for Information Security (BSI) published the community draft of the AI Audit and Assurance Assessment Architecture (A5) — a modular criteria catalogue with a matching audit methodology for demonstrating the trustworthiness of AI systems. The comment period runs until 31 August 2026, so A5 is still a community draft, not a binding catalogue.
For organisations already working with the BSI cloud catalogue C5, one point stands out: A5 connects to C5 directly through a dedicated operating module and uses the same audit methodology under ISAE 3000. This article explains how A5 is structured, who it addresses, and which steps make sense to prepare now — as professional context, not legal advice.
Context: what A5 is and why now
A5 is not a new law; it is an audit framework. The BSI describes a modular, extensible architecture for assessing the trustworthiness of AI systems in a structured way. Every module rests on two building blocks: a criteria catalogue (what is assessed) and an aligned audit methodology (how it is assessed). The methodology builds on the internationally established assurance standard ISAE 3000 — the same approach the BSI already uses for the cloud catalogue C5. The criteria are provided both as documents and in machine-readable OSCAL format, which makes tool-supported assessments easier.
The draft currently contains two modules: a horizontal base module that is technology- and application-independent, and an operating module for cloud infrastructure that creates the link to C5. The architecture is designed for further operating modules, which are outlined in the community draft but not yet fully available.

The base module aims to cover fair, secure and compliant AI systems across the entire lifecycle — from governance and development through validation and operation to decommissioning. The quality dimensions it addresses include robustness and reliability, explainability, bias, and AI-specific cybersecurity; trade press additionally names performance and human oversight. The list is open and not final in the community draft.

Who is affected — and in which regulatory frame
A5 addresses everyone along the AI value chain: providers who develop and supply AI systems, operators who deploy them, and people in auditing, oversight and procurement. If you develop, operate or procure AI, A5 gives you a reference point for demonstrating technical trustworthiness in a structured way.

The frame around this is formed by the upcoming regulatory requirements. The BSI explicitly names the EU AI Act and the Cyber Resilience Act, as well as future minimum standards, for example for the public sector. A5 supplies the technical evidence layer for them: a structured audit through which trustworthiness can be shown.
For timing — as context, not as individual legal advice: the A5 comment period ends on 31 August 2026. For the EU AI Act, the Digital Omnibus package (final Council approval on 29 June 2026) postponed the obligations for stand-alone high-risk AI systems (Annex III) to 2 December 2027, and for product-embedded systems (Annex I) to 2 August 2028.

For cloud providers and their customers, the bridge to C5 is the practical core. C5 — the Cloud Computing Compliance Criteria Catalogue, currently in its C5:2020 edition — is the established BSI catalogue for cloud security. It is examined as an independent attestation under ISAE 3000 (in Germany IDW PS 951) and is organised into 17 topic areas. A5 attaches here through its cloud-infrastructure operating module. Anyone who already holds a C5 attestation therefore has a methodical and documentary foundation on which an A5 AI assessment can build.
A5 is under public consultation until 31 August 2026 and may still change. It does not create new obligations of its own; the EU AI Act dates here are named only as context, not as individual legal advice.
Readiness: what makes sense now
While A5 remains a community draft, the point is not certification but preparation. Three steps hold regardless of the final wording.
Clarify exposure. Get an overview of which AI systems you develop, operate or procure, and which of them might fall into the high-risk category of the EU AI Act. That tells you where a later A5 assessment becomes relevant in the first place.
Connect to C5. Check whether you already operate or attest cloud services under C5. Because A5 uses the same ISAE 3000 methodology and connects to C5 through the cloud operating module, an existing C5 attestation is a solid starting point. Where it is missing, building C5 readiness is the investment that pays twice.
Plan for the assessment dimensions early. Robustness, explainability, bias and AI-specific cybersecurity cannot be retrofitted shortly before an audit. An early gap analysis along these dimensions shows where governance, documentation and technical evidence are still thin today.

We support this path at two points. C5 consulting and cloud security assessment covers readiness, control design and the preparation of an ISAE 3000 attestation — the foundation an A5 AI assessment builds on. AI governance and AI Act readiness brings together exposure and gap analysis and prepares the A5 assessment dimensions. Both are professional support, not legal advice.
Takeaway
A5 is a sensible step: it makes the technical trustworthiness of AI auditable and builds on proven structures rather than starting from scratch. For organisations with a cloud and AI footprint, it is worth reading the draft now, clarifying your own exposure and — where possible — using the comment period until 31 August 2026. Those already living C5 have a shorter path ahead.