1No license, but liability
There is no regulated profession of "art. 10 auditor," no state-mandated diploma. Your signature is a professional attestation: its value comes from your credibility, and it commits you.
- Three pillars of credibility: AI Act (AIGP), GDPR (DPO/CIPP/E), audit (ISO 42001).
Perceived value ultimately comes from track record (shadowing / co-signing first) and from independence: knowing how to say "no, this goes back" is what gives weight to a "yes."
2Certifications, pillar by pillar
- AI Act / governance → AIGP (IAPP): the most directly relevant, with no prerequisites — the anchor of the profile.
- GDPR → DPO (CNIL framework, often eligible for CPF funding in France, with an experience prerequisite) or CIPP/E (IAPP, no prerequisites).
- Audit → ISO/IEC 42001 Lead Auditor (PECB): the posture of an auditor of an AI management system.
Starting point for a beginner: AIGP (no prerequisites) + the internal standard (the 8 sections). "Senior" credentials come with experience.
3PI insurance and liability
Professional Indemnity (PI) insurance covers harm caused to a third party by a fault in the service provided — typically a signed file that turns out to be wrong.
It does not replace competence or diligence: an insurer can pursue recourse in the case of gross negligence. And it's often an entry prerequisite with a regulated client — a bank's legal department will ask "who answers if the file turns out to be wrong?"
4Ethics and credibility
A signatory's credibility rests on their independence from whoever pays them: a signatory who always says "yes" is worthless. You refuse under pressure whatever doesn't hold up, and you don't sign what you designed yourself — nor what you previously advised the client on (designing or advising, then attesting = conflict of interest).
Value is built: certification(s), mastery of the standard, then a track record (shadowing / co-signing before signing alone). Neither a self-awarded title nor a rock-bottom price builds trust.