AI governance

ISO/IEC 42001 artificial intelligence governance

Published in 2023, ISO/IEC 42001 is the first certifiable international standard for an Artificial Intelligence Management System. It brings to AI the same logic of management, risk and continual improvement that ISO/IEC 27001 brings to information security.

Typical duration
6 to 12 months
Standard
ISO/IEC 42001:2023
Integrates with
ISO/IEC 27001 and 27701
Local framework
National AI Strategy · Law 18.331

Objective and scope

We support the organisation’s AI strategy and governance: we inventory actual usage —including what nobody declared— measure the gap against the standard, define principles and guidelines for responsible use, assess the risks and impacts of each system on people and on the business, and implement the AIMS integrated with the existing ISMS and aligned with the local regulatory framework.


Project phases

Phase 1

Maturity assessment

We inventory AI usage across the organisation —developed in-house, contracted, and informally adopted by teams— and measure the gap against the requirements of ISO/IEC 42001.

Phase 2

AI strategy and policy

We define principles, guidelines and a responsible-use framework: which uses are allowed, which require authorisation, which are prohibited, and who decides in each case.

Phase 3

Risks and impacts

We assess the risks of each AI system and its impact on people —bias, explainability, privacy, human oversight— and on the business, with a level of rigour proportional to the use.

Phase 4

AIMS implementation and culture

We roll out the management system integrated with the ISMS, with life cycle and data governance, traceability and internal audit, and train the teams in safe, ethical and critical use of AI.


What the implementation includes

  • Inventory of AI systems and uses
  • Maturity assessment against ISO/IEC 42001
  • Responsible-use policy and principles
  • Roles, responsibilities and decision-making
  • Risk assessment of AI systems
  • Impact assessment on people
  • AI life cycle governance
  • Governance of the data feeding the models
  • Transparency, traceability and human oversight
  • AI supplier management
  • Alignment with data protection law
  • Training in safe and critical use of AI

Frequently asked questions

Does it apply if we only use third-party AI tools?

Yes, and that is the most common scenario. The standard distinguishes between developing, providing and using AI systems. For a user organisation the focus is on the usage policy, supplier assessment, protection of the data being entered, and human oversight of decisions.

How does it integrate with the ISMS we already have?

Naturally: they share the high-level structure, risk management, competence, internal audit and management review. What the AIMS adds is the impact assessment on people and governance of the model life cycle and its data.

How does it relate to Uruguayan regulation?

The work aligns with the National Artificial Intelligence Strategy 2024–2030 and the regulatory sandboxes promoted by AGESIC, and with the personal data protection framework of Law 18.331 supervised by the data protection authority.

Can it be certified?

Yes. ISO/IEC 42001 is certifiable by accredited bodies, under the same scheme of certification and surveillance audits as ISO/IEC 27001.

your business partner

Protecting you today, innovating for tomorrow