What Is FAIIR Certification? The AI Governance Standard Explained
By Zachariah Crabill, JD · FAIIR, LLC · Updated
The short answer
FAIIR (Foundation of AI Integrity & Regulation) is a private AI governance standard published by FAIIR, LLC for small and midsize businesses and AI vendors. FAIIR certification is an annual, evidence-based review of an organization's AI practices against 41 pass/fail controls in five pillars. FAIIR certification is not a government approval or legal advice, and Colorado law does not recognize any AI certification.
Key takeaways
- FAIIR stands for Foundation of AI Integrity & Regulation and is published by FAIIR, LLC, a private, independent Colorado standards company.
- The FAIIR standard has five pillars and 41 pass/fail controls: Fitness for Purpose (8), Accountability (7), Integrity of Data (9), Informed Use (7), and Risk Management (10).
- FAIIR certification is annual and firm-specific, based on submitted evidence, and covers an organization's AI practices, not AI models.
- FAIIR is benchmarked to the NIST AI Risk Management Framework and complements SOC 2 and ISO/IEC 42001 rather than replacing them.
- FAIIR controls are mapped to Colorado's ADMT Act and Chatbot Safety Act, but Colorado law does not require, create, or recognize any third-party AI certification.
What is FAIIR?
FAIIR is a private AI governance standard that defines what responsible AI use looks like inside a small or midsize business. The acronym stands for Foundation of AI Integrity & Regulation. The standard turns the question "did this organization use AI responsibly?" into 41 specific, pass/fail controls that a business can actually run and that an outside reviewer can check against evidence.
FAIIR is not a law and not a regulation. It is a professional standard of care, in the same family as other voluntary frameworks businesses use to show customers, insurers, and partners that they take a risk seriously. The full control list is published on the FAIIR framework page.
Who publishes FAIIR, and who is it for?
FAIIR is published by FAIIR, LLC, a private, independent standards company based in Colorado. FAIIR, LLC is not a government agency and not a law firm, and it does not give legal advice.
The standard is written for two audiences:
- Small and midsize businesses that deploy AI — firms already using chatbots, drafting assistants, AI features inside their software, or AI-assisted decision tools, and that want a defensible, documented way to govern that use without hiring a compliance department.
- AI vendors and integrators — companies that build or resell AI tools and need to show their customers a documented standard of care when their products are used in regulated or client-sensitive settings.
FAIIR is designed to be learned in about an hour, not studied for a week. Most controls can be satisfied with a short written document, a spreadsheet, or a signed acknowledgment.
What are the five pillars of FAIIR?
FAIIR organizes its 41 controls into five pillars, whose initials spell F-A-I-I-R: Fitness for Purpose, Accountability, Integrity of Data, Informed Use, and Risk Management. Each pillar asks one core question, and each control within it has a pass/fail bar.
| Pillar | Core question | Controls | Example control |
|---|---|---|---|
| Fitness for Purpose (F) | Is this AI actually suited to the task you are using it for? | 8 (F1–F8) | F1 — Use-Case Register: a written list of every AI system in use and the tasks it is authorized for. |
| Accountability (A) | When something goes wrong, who owns it, and can you prove that ownership existed before it went wrong? | 7 (A1–A7) | A1 — AI Officer Designated: a named role responsible for AI governance. |
| Integrity of Data (I) | What goes into the AI, where does it go, and how long does it live there? | 9 (I1–I9) | I3 — No-PII Default: no personally identifiable information goes into third-party AI without a data processing agreement covering it. |
| Informed Use (U) | Do the humans operating this AI, employees and customers, actually know what is going on? | 7 (U1–U7) | U1 — AI Acceptable Use Policy: written, distributed to all employees, and acknowledged in writing. |
| Risk Management (R) | If this all goes wrong, will you know it happened, contain it, and be able to prove what you did? | 10 (R1–R10) | R3 — Incident Response Playbook: a 1–2 page playbook covering who is called, what is logged, who is notified, and when disclosure is triggered. |
Fitness for Purpose
Most AI problems come from using a general-purpose tool for a job it was never validated for. This pillar requires a use-case register (F1), written out-of-scope boundaries (F2), documented accuracy expectations (F3), a basic bias check (F4), defined human-in-the-loop points (F5), model and version tracking (F6), a fallback procedure (F7), and an annual fitness review (F8).
Accountability
Accountability means a responsible person is named in writing before anything goes wrong. Controls include a designated AI officer (A1), an AI decision log (A2), vendor contract review (A3), a written summary of which vendors indemnify you (A4), an insurance coverage check (A5), a customer disclosure path (A6), and a named incident response owner (A7).
Integrity of Data
This is the pillar most small businesses fail, usually because employees paste customer data into free AI tools without anyone tracking it. Controls cover a data classification map (I1), which data classes each tool may receive (I2), a no-PII default (I3), vendor training-data opt-outs (I4), vendor retention terms (I5), data location and transfer (I6), a prompt logging decision (I7), training-data provenance (I8), and confirmed deletion when a tool is retired (I9).
Informed Use
Informed Use prevents surprise. It requires an acceptable use policy (U1), employee training with an annual refresh (U2), plain-language customer disclosure where AI is in the customer experience (U3), consent flows where required (U4), a path to a human (U5), labeling of AI-generated external content (U6), and a plan for telling customers about an AI incident that affects them (U7).
Risk Management
Risk Management is the audit-trail pillar: it converts "we are careful" into evidence. Controls include a quarterly-reviewed risk register (R1), a written incident definition (R2), an incident playbook (R3), output monitoring (R4), vendor failure plans (R5), closing insurance gaps (R6), retaining the decision log and use-case register for at least three years (R7), an annual attestation signed by the AI officer (R8), a change log (R9), and a breach notification procedure (R10).
What does FAIIR certification mean?
FAIIR certification means an organization submitted evidence that its AI practices meet the FAIIR controls, and that evidence was reviewed against the standard. It is documented proof of reasonable care at a point in time.
- Annual. Certification covers one year and must be renewed with fresh evidence.
- Firm-specific. A certificate applies to the named organization only. It does not transfer to affiliates, customers, or vendors.
- Evidence-based. Controls pass on documents, logs, and records the organization produces, not on self-description.
- Practices, not models. FAIIR certifies how an organization selects, deploys, and oversees AI. It does not certify any AI model or product as accurate, safe, or unbiased. An organization that adopts a new model still has to run that model through its own framework.
What does FAIIR certification not mean?
FAIIR certification is not a government approval, not a guarantee of legal compliance, and not legal advice. It is a private standard, and it should be described that way.
- Not a government approval. No state or federal agency issues, endorses, or reviews FAIIR certificates.
- Not recognized by Colorado law. Colorado law does not require, create, or recognize any third-party AI certification, including FAIIR. Holding a certificate does not by itself satisfy any Colorado statute or create any safe harbor.
- Not a guarantee. Passing FAIIR is evidence of reasonable care, not a promise that nothing will go wrong or that no claim will be brought.
- Not legal advice. FAIIR, LLC is not a law firm. Whether a specific statute applies to your business is a question for your own counsel.
How does FAIIR relate to NIST AI RMF, ISO/IEC 42001, and SOC 2?
FAIIR is benchmarked to the NIST AI Risk Management Framework and is designed to complement, not replace, ISO/IEC 42001 and SOC 2. Each of the four answers a different question.
| Framework | What it is | How FAIIR relates |
|---|---|---|
| NIST AI RMF 1.0 | A voluntary U.S. framework released by NIST on January 26, 2023, organized around four functions: Govern, Map, Measure, and Manage. NIST added a Generative AI Profile (NIST AI 600-1) on July 26, 2024. | FAIIR is benchmarked to the AI RMF and turns its principles into specific pass/fail controls sized for a small business. |
| ISO/IEC 42001:2023 | An international standard specifying requirements for establishing, implementing, maintaining, and continually improving an AI management system. Certification is performed by independent certification bodies, not by ISO itself. | FAIIR is a lighter-weight path toward similar outcomes. An organization can pursue both. |
| SOC 2 | An AICPA attestation report, performed by CPAs, on a service organization's controls relevant to security, availability, processing integrity, confidentiality, or privacy. | FAIIR covers AI-specific controls that SOC 2 does not address. An organization can hold both in parallel. |
For a deeper comparison, see FAIIR vs. ISO 42001 vs. SOC 2 and the NIST AI RMF for small businesses.
How does FAIIR align to Colorado's ADMT Act and Chatbot Safety Act?
FAIIR controls are mapped to the duties in Colorado's ADMT Act (SB 26-189) and Chatbot Safety Act (HB 26-1263), whose main duties apply from January 1, 2027. The mapping helps a business organize its work; it does not satisfy either statute on its own, and Colorado law does not recognize any AI certification.
Colorado ADMT Act (SB 26-189)
The ADMT Act, formerly known as the Colorado AI Act, applies to technology that processes personal data and whose output materially influences a consequential decision in seven domains: education, employment, Colorado residential real estate, financial or lending services, insurance, health-care services, and essential government services. It has no small-business exemption. The statute gives deployers five duties, and each maps to a FAIIR pillar:
| Deployer duty (SB 26-189) | FAIIR pillar and controls |
|---|---|
| Pre-use notice (§ 6-1-1704(1)) | Informed Use — U3, U4 |
| Adverse-outcome disclosure within 30 days (§ 6-1-1704(3)) | Informed Use — U3, U5 |
| Consumer data access and correction (§ 6-1-1705) | Integrity of Data |
| Meaningful human review and reconsideration, to the extent commercially reasonable (§ 6-1-1705) | Fitness for Purpose — F5; Informed Use — U5; Accountability — A2 |
| Records kept 3 years after each consequential decision (§ 6-1-1703) | Risk Management — R7 |
A covered deployer still has to build the statute's specific mechanics, such as the 30-day disclosure clock, and conform them to the Attorney General's final rules. The AG's proposed rules (4 CCR 904-6) are not final; written comments are open through October 26, 2026. Check coag.gov/ai for the current draft. See the Colorado ADMT Act compliance checklist for the step-by-step view.
Colorado Chatbot Safety Act (HB 26-1263)
The Chatbot Safety Act covers operators of consumer-facing conversational AI services, with no size threshold. Its duties include estimating user age, disclosing AI status (and answering honestly when asked "are you an AI?"), protections for minors, suicide and self-harm response protocols, a ban on representing outputs as coming from or equivalent to a licensed health-care, legal, or mental-health professional or dietitian, and an annual report to the AG starting July 1, 2027. AI disclosure maps to Informed Use (U3); scope limits map to Fitness for Purpose (F1, F2); crisis protocols and the reporting trail map to Accountability and Risk Management.
Where FAIIR fits
FAIIR gives a small business or AI vendor one organized, evidence-based way to show reasonable care in how it uses AI, and the same records answer the questions customers, insurers, and regulators ask in different forms. It is a private standard, not a legal determination; for questions about how a specific law applies to your business, talk to your own counsel. Start with the five-pillar framework or the practical 30-day plan.
Frequently asked questions
What does FAIIR stand for?
FAIIR stands for Foundation of AI Integrity & Regulation. It is a private AI governance standard published by FAIIR, LLC. The standard's five pillars are Fitness for Purpose, Accountability, Integrity of Data, Informed Use, and Risk Management.
How many controls are in the FAIIR standard?
The FAIIR standard has 41 pass/fail controls. They are split across five pillars: Fitness for Purpose (8), Accountability (7), Integrity of Data (9), Informed Use (7), and Risk Management (10).
Is FAIIR certification required by Colorado law?
No. Colorado law does not require, create, or recognize any third-party AI certification, including FAIIR. FAIIR controls are mapped to the duties in Colorado's ADMT Act and Chatbot Safety Act, but holding a certificate does not by itself satisfy either statute.
Does FAIIR certify AI models or products?
No. FAIIR certifies an organization's practices around selecting, deploying, and overseeing AI, not the AI models themselves. A certified organization that adopts a new model still has to apply its own framework to that model.
How long does FAIIR certification last?
FAIIR certification is annual and firm-specific. It is based on evidence the organization submits and must be renewed each year with current evidence.
Is FAIIR a replacement for SOC 2 or ISO/IEC 42001?
No. FAIIR is benchmarked to the NIST AI Risk Management Framework and is designed to complement SOC 2 and ISO/IEC 42001. SOC 2 does not address AI-specific controls, and ISO/IEC 42001 is a fuller AI management system standard; an organization can hold any combination of them.
Sources
This article is general information from FAIIR, LLC, which is not a law firm, and is not legal advice. Colorado law does not require or recognize any third-party AI certification, and FAIIR certification is not a government approval or a guarantee of compliance. For advice about your situation, consult a licensed attorney.