VAP-AT Overview
VAP-AT (Verifiable AI Provenance β Assessment Test) is a measurement-based scoring framework that evaluates AI systems for Auditability, Verifiability, and Regulatory Readiness.
Core Design Principle
VAP-AT is fundamentally a score-based assessment framework. Threshold Designations are optional interpretive labels provided to accommodate practical needs such as procurement requirements and regulatory reporting.
What VAP-AT Measures
| Property | Definition |
| Auditability | Can third parties independently verify audit trails? |
| Verifiability | Are records complete with proper observability? |
| Regulatory Readiness | Is evidence packaged for audit submission? |
What VAP-AT Does NOT Do
- β Evaluate AI model accuracy or performance
- β Assess business logic validity
- β Conduct security vulnerability testing
- β Guarantee AI decision correctness or legality
Critical Distinction
VAP-AT does not assess the correctness or legality of AI decisions, only the verifiability and auditability of the decision process.
Scoring Criteria
VAP-AT uses 10 criteria, each scored 0-2 points, for a maximum of 20 points.
Score Meanings
| Score | Meaning |
| 0 | Not implemented or fundamentally inadequate |
| 1 | Partially implemented with gaps |
| 2 | Fully implemented, required outcomes achieved |
Grade Thresholds
| Score Range | Grade | Interpretation |
| 16-20 | Strong | Demonstrates robust auditability |
| 11-15 | Moderate | Auditable but room for improvement |
| 6-10 | Limited | Significant auditability deficiencies |
| 0-5 | Inadequate | Fundamentally insufficient |
The 10 Criteria
- Third-Party Verifiability β Can external parties verify audit trails?
- Tamper Evidence β Can unauthorized modifications be detected?
- Sequence Fixation β Is chronological order immutably recorded?
- Decision Provenance β Can decision inputs/rationale be traced?
- Responsibility Boundaries β Are approvers/overriders clear?
- Documentation Completeness β Is documentation complete and current?
- Retention & Availability β Is evidence retained for required periods?
- Time Synchronization β Is system time synchronized?
- Failure & Recovery Logging β Are failures logged?
- Right to Erasure Compatibility β Can GDPR erasure be supported?
Assessment Levels
VAP-AT offers three assessment levels with increasing rigor and cost.
- Self-assessment using this tool
- Target: Low-risk AI
- Preliminary status
- Evidence Pack v1.0 output
- VSO-accredited CAB assessment
- Target: Medium-risk AI
- CAB-signed Score Report
- 1-year validity
- Ongoing monitoring
- Target: High-risk AI
- Automated verification
- Real-time status updates
Threshold Designations
Optional interpretive labels for procurement and regulatory reporting convenience.
| Min Score | Designation |
| 16+ | VAP-AT Auditability Threshold β EU AI Act Art.12/19 aligned |
| 14+ | VAP-AT Auditability Threshold β MiFID II RTS 25 aligned |
| 11+ | VAP-AT Baseline Auditability Threshold |
β οΈ Critical Disclaimer
Threshold Designations are interpretive labels within the VAP-AT scheme and are NOT guarantees of legal compliance.
- "EU AI Act Art.12/19 aligned" indicates a VAP-AT score aligned with auditability levels sought by those articles
- Legal compliance determination is the assessed entity's responsibility
- Final interpretation depends on regulatory authorities
Governance Structure
VAP-AT employs a 4-layer separation model to ensure independence and credibility.
4-Layer Structure
0
National Accreditation Bodies
UKAS, DAkkS, ANAB, JAB β ISO accreditation of CABs (Phase 2+)
1
Standard-Setting (VSO)
Maintains criteria, accredits CABs, does NOT perform assessments
2
Advisory Board
Technical advisory, regulatory monitoring, conflict oversight
3
Assessment Execution (CABs)
Independent CABs conduct assessments and issue reports
Key Principle
VSO does not perform assessments. This separation prevents "Pay-to-Pass" conflicts and maintains scheme credibility.
Frequently Asked Questions
What is the difference between VAP-AT and ISO 27001?
ISO 27001 certifies organizational information security management systems (ISMS). VAP-AT specifically evaluates AI system auditability and verifiability β whether audit trails are cryptographically sound and regulatory-ready. They are complementary, not competing.
Is VAP-AT Level 1 (Self) legally valid?
Level 1 produces a "Preliminary" status suitable for internal gap analysis and improvement planning. For regulatory submissions or procurement requirements, Level 2 (Verified) with CAB assessment is typically required.
How long does a Level 2 assessment take?
Typically 4-8 weeks depending on system complexity. Type I (point-in-time) is faster; Type II (period audit) requires 6-12 months of operational evidence.
What if my score decreases after initial assessment?
For Level 3 (Continuous), scores are monitored. If thresholds are breached, you receive 24-hour notification and 30 days to remediate before status changes to "Suspended."
Can I use VAP-AT for EU AI Act compliance?
VAP-AT helps demonstrate auditability aligned with Art.12/19 requirements. However, Threshold Designations are interpretive labels, not legal compliance certifications. Consult legal counsel for compliance determinations.