China–ASEAN AI Education Certification

The Trust Layer for AI Education Products in ASEAN

Independent certification for AI education products in ASEAN — from content compliance to pedagogical effectiveness.

14
Audit dimensions
4
Trust layers
5
Assessment methods

Check a certificate now

Any certificate, any time — status is live.

01The Problem

Why AI Education Products Need Certification

The AI education market in ASEAN is growing fast — but trust is lagging behind.

Compliance Across Borders Is Hard

Six major ASEAN markets, six different data laws.

Effectiveness Is Invisible

Buyers cannot tell good teaching from confident-sounding output.

Trust Is Built One Customer at a Time

Without a recognized signal, trust is rebuilt from zero on every deal.

02What We Do

Independent Certification, Built for AI Education Products

We set the standard, run the audit, issue the certificate, and keep the registry public.

01

Core Audit

Multi-dimension certification audit

02

Improvement Report

Optimization recommendations

03

Continuous Monitoring

Surveillance & change re-audit

04

Public Registry

Open verification & directory

03What We Audit

Comprehensive Multi-Dimension Audit

AccuracyPedagogyHallucinationTraceabilityMultilingualTimelinessMinorsOutcomesComplianceEthicsSecurityRobustnessPrivacyFairness14dimensions

Universal layer · 6

Applies to any AI product; unchanged when the standard extends elsewhere.

Product-form layer · 8

Specific to education AI assistants; another product type replaces this ring entirely.

Veto items · 3

Content compliance, security, privacy. A failure in any one means no pass.

01

Universal Layer

Applies to every AI product we certify.

  • Content Compliance
  • Ethics & Safety
  • Security (Prompt Injection & Jailbreak Resistance)
  • Robustness
  • Privacy & Data Compliance (PIPL + ASEAN PDP / PDPA / PDPD)
  • Fairness & Cross-Cultural Consistency

02

Education AI Assistant Layer

Specific to the education AI assistant product form.

  • Knowledge Accuracy (vs licensed course material)
  • Pedagogical Adaptation
  • Hallucination Suppression
  • Traceability to Source Material
  • Multilingual Consistency (EN / ZH / VI / TH / ID / MS)
  • Timeliness
  • Minor Protection
  • Learning Outcome Evidence
04Method

Five Assessment Methods

The first four determine the verdict of a single audit; the fifth runs continuously after the certificate is issued.

01Document review02Benchmarktesting03Red-teamtesting04Double-blindscoring05ContinuousmonitoringOne auditfive methods

Document review

Six required classes of material, from the model card to the data transfer plan.

Benchmark testing

A fixed, versioned test bank — that is what makes retests and cross-product comparison hold.

Red-team testing

Coaxing out instructions, bypassing limits, crossing ethical lines — judged against preset criteria.

Double-blind scoring

Education and AI specialists score independently; divergence goes to arbitration.

Continuous monitoring

Periodic sampling after certification; material changes must be reported.

Every run is versioned and every raw response retained — any verdict traces back to its record.

05Decision Rules

Decision Rules

Three rules decide a pass. The latter two were written after the first real audit surfaced cases the original rules missed.

Rule 1

Veto items

Among content compliance, security, and privacy, a failure in any one means no pass. A high composite score does not offset it.

First case

On re-audit, privacy and data compliance scored 40 while most other scorable dimensions sat between 88 and 95. The verdict was still fail.

Standard 6.2.1

Rule 2

Undeterminable is not a pass

A dimension that cannot be determined for lack of evidence is excluded from the composite score and never counted as compliant. If it is a veto item, it is treated as not passed.

First case

In the first round five dimensions could not be scored for lack of evidence, one of them a veto item, so no pass was issued. Once filed, three of them fell into the failing range.

Standard 6.1.4 / 6.2.3

Rule 3

Out-of-scope must be refused

For questions outside the course, answering first and adding a redirect is graded as a fail. Such content lies outside the material under review, so no source can be checked.

First case

On the same case, the first response gave "Paris, about 2.2 million" then redirected, scoring 55. After remediation it stated the question was out of scope and stopped, scoring 90.

Standard 4.2.3

Pass, conditional pass, or fail — no grades. A re-audit covers only undetermined and remediated items.

06Feedback

How an Audit Feeds Back Into the Standard

Each audit also revises the criteria. Five such revisions came out of the first one.

  • No definition of what counts as a valid refusal

    Standard 4.2.3: refusal criteria and counter-examples added

  • Cases were improvised: not reproducible or comparable

    Test Bank V0.1 created; 12 cases structured and stored

  • No rule for how undeterminable dimensions count

    Standards 6.1.4 and 6.2.3 written

  • Raw responses were not retained for later review

    Evidence field activated; raw responses stored with each audit

  • Testing ran entirely by hand and did not scale

    Automated harness built, with decisions split into three tiers

An audit produces two things: a verdict on the product, and revisions to the criteria themselves. Both are filed by version and can be reviewed independently.

07Process

From Application to Certification — Five Steps

  1. 1

    Apply

    Submit entity documents, product materials, the model card, and API evaluation credentials.

  2. 2

    Audit

    Document review, automated benchmark testing, red team evaluation, and double-blind scoring.

  3. 3

    Report

    A verdict — pass, conditional pass, or fail — together with an improvement report.

  4. 4

    Issue

    Signed PDF certificate, a public directory entry, and an in-product trust mark.

  5. 5

    Monitor

    Sampling audits across the 12-month term; model version changes are subject to mandatory reporting.

Typical timeline — 4 to 8 weeks per application.

08Trust Layers

Certification You — and Anyone — Can Verify in Real Time

The real binding force isn't the format. It's that anyone, anywhere, can check the current status of any certificate at any time.

L4L3L2L1
  1. Blockchain Attestation (Optional)

    Certificate events can additionally be anchored on AntChain BaaS. Planned as a paid add-on, not part of the default package.

    Planned

  2. In-Product Trust Mark

    A certified product may embed the trust mark under its certification agreement; once a certificate is revoked, the agreement requires mandatory takedown.

    Contractual

  3. Public Verification Page

    Look up any certificate number and see its live status: Active, Suspended, Revoked or Expired.

    Governs validity

  4. PDF Certificate with Unique ID

    A PDF certificate carrying a unique number in the form CERTVIA-EAA-YYYY-NNNN, checkable against the verification page at any time.

    Always included

09Registry

Certified Products

Every certificate is public, every status is live.

The first certifications are in progress. The registry opens publicly with the first certificate issued — every entry public, every status live from day one.

10Why Certvia

Why Certvia

Years in ASEAN Education

We build on a parent education-outbound programme that has been operating in ASEAN education for years.

Operating Within the SEAMEO Ecosystem

CATECP is our own platform and operates within the SEAMEO ecosystem.

Dual-Expert Review

Scored double-blind by an education expert and an AI expert.

11FAQ

Frequently Asked Questions

Which AI models can be certified?

Any mainstream or in-house model — Qwen, DeepSeek, GPT and others — as long as you can provide a callable evaluation endpoint.

How long does certification take?

Typically 4 to 8 weeks from submission to issuance, depending on how quickly the applicant responds during the audit.

What happens if my product fails?

You still receive an improvement report setting out the gaps found and what to remediate. Re-tests are available within an agreed number of attempts.

How long is the certificate valid?

12 months. Sampling audits continue throughout the term.

What if I update my model?

Model version changes are subject to mandatory reporting. A material change triggers an interim re-audit.

Is Certvia affiliated with SEAMEO or any government?

CATECP is operated by our own team and runs within the SEAMEO ecosystem. Certvia itself is an independent third-party certification body.

Where is data stored?

Audit data is held on infrastructure inside China; product data stays with the applicant. Cross-border handling follows PIPL together with the applicable ASEAN data protection regimes.

Can my certificate be revoked?

Yes. Suspension and revocation are published on the public verification page in real time, with the reason on record.

Ready to Get Your AI Product Certified?

Now accepting applications for the first certification cohort.