Skip to content
KNOWLEDGE CENTER

Knowledge to decide better.

Todo el material está en esta página: sectores, regulación, datos del mercado, cobertura, artículos, prensa, glosario y preguntas. Cada dato dice de dónde sale.

G-CERTI exhibition at the UNLP School of Economic Sciences.

Each sector asks for something different.

Eight chains with published situations. Choose one to see its cases, what its market asks for and the standards that respond.

Technology and software

SaaS, fintech, cloud and digital service companies that need to demonstrate security and governance maturity.

WHEN THE REQUEST COMES UP
  • A software vendor demonstrates its information security system to an enterprise customer
  • A SaaS company prepares evidence for a tender
WHAT THIS MARKET ASKS FOR
  • Information security requirements in enterprise procurement
  • Evidence of service continuity in critical contracts
STANDARDS THAT ANSWER

Qué exige hoy la regulación.

Cinco marcos públicos vigentes y la norma de sistema de gestión que ayuda a llegar preparado a cada uno.

Artificial intelligenceGobernanza de sistemas de IA

AI Act de la Unión Europea (Reglamento 2024/1689), primer marco regulatorio integral sobre inteligencia artificial.

El AI Act clasifica los sistemas de IA por nivel de riesgo y exige a quienes desarrollan o despliegan sistemas de alto riesgo gestión de riesgos, gobernanza de datos, supervisión humana, documentación técnica y trazabilidad a lo largo del ciclo de vida.

ISO/IEC 42001:2023 define un sistema de gestión de inteligencia artificial con un enfoque de riesgo y de ciclo de vida muy próximo al espíritu del AI Act. Operar este sistema ayuda a una organización a ordenar su gobernanza de IA y a llegar mejor preparada cuando deba demostrar control sobre sus modelos.

Datos personales y privacidadProtección de datos personales

GDPR en la Unión Europea (Reglamento 2016/679), LGPD en Brasil (Ley 13.709/2018) y un conjunto creciente de leyes nacionales de protección de datos en América Latina.

Estos marcos exigen una base legal para tratar datos personales, principios de minimización y finalidad, derechos de los titulares, gestión de brechas y demostración de responsabilidad proactiva sobre cómo se gobierna la privacidad.

ISO/IEC 27701:2025 define un sistema de gestión de privacidad de la información (PIMS) certificable, con controles para responsables y encargados del tratamiento; opera de forma autónoma o integrada con un SGSI ISO/IEC 27001. Adoptar esta estructura ayuda a una organización a ordenar sus prácticas de privacidad y a respaldar con evidencia su responsabilidad proactiva.

Information securityCiberseguridad y resiliencia digital

Directiva NIS2 en la Unión Europea, regímenes sectoriales de ciberseguridad y exigencias contractuales de clientes y cadenas de suministro que piden controles demostrables.

Estos marcos piden gestión del riesgo de seguridad, control de accesos, respuesta ante incidentes, continuidad y evidencia de que los controles existen y se mantienen en el tiempo, no solo en el papel.

ISO/IEC 27001:2022 establece un sistema de gestión de seguridad de la información basado en riesgo, con un catálogo de controles auditables. Operarlo ayuda a una organización a estructurar su postura de seguridad y a responder con evidencia cuando un cliente, un regulador o una auditoría la exigen.

Compliance y anticorrupciónPrevención del soborno y la corrupción

Marcos anticorrupción de alcance extraterritorial como la FCPA (Estados Unidos) y la UK Bribery Act, junto con legislación nacional de integridad y compliance en la región.

Estos marcos esperan que la organización demuestre diligencia debida, controles sobre terceros, canales de denuncia, formación y un programa de integridad vivo y supervisado por la alta dirección.

ISO 37001 define un sistema de gestión antisoborno con los componentes que estos marcos esperan ver. Implementarlo ayuda a una organización a articular su programa de integridad y a mostrar, ante reguladores o socios, que el control existe y se ejecuta.

Sostenibilidad y climaReporte ambiental y de carbono

Directiva CSRD de la Unión Europea sobre reporte de sostenibilidad corporativa y un conjunto creciente de exigencias de reporte ESG y de huella de carbono a lo largo de las cadenas de valor globales.

Estos marcos piden información ambiental fiable y comparable: gestión de impactos, medición de emisiones y datos que puedan sostenerse ante un tercero, no estimaciones declarativas.

ISO 14001 ordena la gestión ambiental con enfoque de ciclo de vida, y la familia ISO 14064 aporta el marco para cuantificar y verificar emisiones de gases de efecto invernadero. Apoyarse en estas normas ayuda a una organización a producir datos ambientales defendibles para sus reportes de sostenibilidad.

Where certification happens today.

Certificados de sistemas de gestión vigentes en el mundo, por región y por norma.

SOURCE: ISO Survey 2024 · IAF CertSearch · CORTE 2024 · WORLD TOTAL 2.963.855

Asia2.081.67270.2% · norma con más certificados: ISO 9001
Europa671.77422.7% · norma con más certificados: ISO 9001
América Latina y el Caribe86.2322.9% · norma con más certificados: ISO 9001
América del Norte52.2181.8% · norma con más certificados: ISO 9001
Oceanía39.5071.3% · norma con más certificados: ISO 9001
África32.4521.1% · norma con más certificados: ISO 9001
ISO 90011.474.113
ISO 14001676.232
ISO 45001542.526
ISO/IEC 2700196.709
ISO 2200059.521
ISO 5000138.482
ISO 1348531.214
ISO 20000-127.332

Where audits take place and with what arrangement.

Thirty countries declared by the representation for the Americas. In direct-service countries there is a local audit team; in consultation countries, the request is evaluated case by case and coordinated from the nearest office.

Direct service

Local audit team and assigned account executive.

  • Argentina · Buenos Aires · Córdoba · Rosario · Mendoza
  • Chile · Santiago · Antofagasta · Concepción · Valparaíso
  • Uruguay · Montevideo · Punta del Este
  • Paraguay · Asunción · Ciudad del Este
  • Colombia · Bogotá · Medellín · Cali · Barranquilla
  • Ecuador · Quito · Guayaquil · Cuenca
  • Bolivia · Santa Cruz de la Sierra · La Paz · Cochabamba
  • Venezuela · Caracas · Valencia · Maracaibo
  • Panama · Panama City · Colón
  • Guatemala · Guatemala City · Quetzaltenango
  • Honduras · Tegucigalpa · San Pedro Sula
  • El Salvador · San Salvador · Santa Ana
  • Nicaragua · Managua · León
  • Dominican Republic · Santo Domingo · Santiago de los Caballeros · Punta Cana
  • Cuba · Havana · Santiago de Cuba
  • Puerto Rico · San Juan · Ponce
  • Trinidad and Tobago · Port of Spain · San Fernando
  • Jamaica · Kingston · Montego Bay
Consultation

Request evaluated case by case from the nearest office.

  • Peru · Lima · Arequipa · Trujillo · Callao
  • Costa Rica · San José · Alajuela · Cartago
  • Belize · Belize City · Belmopan
  • Mexico · Mexico City · Monterrey · Guadalajara · Querétaro · Tijuana
  • Brazil · São Paulo · Rio de Janeiro · Belo Horizonte · Curitiba · Porto Alegre
  • Guyana · Georgetown
  • Suriname · Paramaribo
  • Bahamas · Nassau · Freeport
  • Barbados · Bridgetown
  • Haiti · Port-au-Prince · Cap-Haïtien
  • Aruba · Oranjestad
  • Curaçao · Willemstad

Coverage communicates scope and availability. The accredited scope by standard is published in the Trust Center.

Artículos técnicos.

Applied explanations on certification, auditing and management systems.

CalidadGuía completa de ISO 9001:2015: requisitos, cláusulas y certificaciónRequisitos de ISO 9001:2015 explicados cláusula por cláusula, con la evidencia que revisa una auditoría de tercera parte y los pasos hasta obtener el certificado.CalidadSiete no conformidades comunes en ISO 9001 (y cómo prevenirlas)Siete zonas de riesgo para revisar con evidencia antes de una auditoría ISO 9001. No son un ranking ni hallazgos automáticos: cada no conformidad exige un criterio aplicable y evidencia objetiva.DecisiónCómo elegir un organismo de certificación ISO: ocho criteriosOcho verificaciones para comparar organismos de certificación: identidad, alcance, acreditación, imparcialidad, competencia, programa, trazabilidad y condiciones contractuales.PyMEsCertificación ISO en PyMEs: mitos y realidadesLa idea de que certificar es solo para grandes empresas frena a muchas PyMEs que ya hacen bien las cosas. La realidad es más accesible de lo que parece.ProcesoCómo prepararse para una auditoría de certificaciónUna guía de campo para llegar a la auditoría con alcance claro, evidencia disponible, responsables preparados y un sistema que puede explicarse sin maquillaje.ProcesoAuditoría remota ISO (IAF MD 4): cuándo aplica y qué esperarGuía para entender cuándo las tecnologías de información pueden apoyar una auditoría, cómo se evalúa su viabilidad y qué evidencia debe preservarse sin degradar la integridad del proceso.Seguridad de la informaciónISO/IEC 27001: cuando la seguridad se vuelve argumento de ventaLos clientes empresariales ya no preguntan si tomas en serio la seguridad. Piden evidencia. ISO/IEC 27001 la provee.Inteligencia artificialISO/IEC 42001: gobernar la inteligencia artificial antes de que sea un problemaLa IA pasó de experimento a infraestructura. Un marco de gestión permite escalarla manteniendo trazabilidad y control.AmbienteISO 14001 y la enmienda de cambio climático 2024Una enmienda breve, pero con efecto concreto: el cambio climático entra explícitamente en el contexto de la organización.
Ver todos los artículos →

Columns and appearances, with their source.

Cada entrada abre el original en su medio.

ARCHIVO: 762 notas · 215 medios · 2024 – 2026

IA · 2026-02-23IA gobernada o IA desordenada: la decisión que define quién lidera y quién pagaRead on eBizLatamCiberseguridad · 2026-01-29La ciberseguridad dejó de ser IT: es continuidad del negocio y reputación en tiempo realRead on Fortuna (Perfil)Ciberseguridad · 2026-01-28Es hora de demostrar control: por qué las empresas deben adoptar un SGSIRead on eBizLatamCiberseguridad · 2025-12-29Por qué se pierde la soberanía digitalRead on PerfilCumplimiento · 2025-11-12Cuando el miedo se sienta en la direcciónRead on PerfilISO normativa · 2025-10-03ISO 9001 dispara las ventas: la certificación que abre mercados y financiamientoRead on InfobaeISO normativa · 2025-09-16La paradoja de la calidad en Latinoamérica: talento e innovación frente a la cultura de la improvisaciónRead on Fortuna (Perfil)Ciberseguridad · 2025-06-25Cercanos y vulnerablesRead on Perfil

Glossary of ISO terms.

The words you will find in a proposal, an audit report or a certificate, with their definition, the clause they come from and an example.

Accreditation

Third-party attestation that a conformity assessment body is competent to perform specific tasks. It is granted by an accreditation body, not the certifier.

ISO/IEC 17000:2020, 7.7
Certification

Third-party attestation related to a conformity assessment object, in this case a management system.

ISO/IEC 17000:2020, 7.6
Certificate scope

Description of the activities, products, services and sites covered by the certification. What is not included in the scope is not certified.

ISO/IEC 17021-1:2015, 9.1.2
Certification decision

Resolution adopted by a person or committee other than those who performed the audit, on granting, maintaining, renewing, extending, reducing, suspending or withdrawing certification.

ISO/IEC 17021-1:2015, 9.5
Impartiality

Presence of objectivity: absence of conflicts of interest, or their resolution in a way that does not influence the body’s activities.

ISO/IEC 17021-1:2015, 3.2
Surveillance audit

Periodic audit, at least annual, that verifies the certified system remains compliant during the cycle.

ISO/IEC 17021-1:2015, 9.6.2
Recertification

Audit performed before the certificate expires to confirm continued conformity and renew the cycle.

ISO/IEC 17021-1:2015, 9.6.3
Certification transfer

Recognition of a valid accredited certification issued by another body, to continue the cycle with the receiving body.

IAF MD 2
Audit

Systematic, independent and documented process for obtaining objective evidence and evaluating it against audit criteria.

ISO 19011:2018, 3.1
Audit evidence

Records, statements of fact or other information relevant to the audit criteria and verifiable.

ISO 19011:2018, 3.8
Audit finding

Result of evaluating the evidence gathered against the criteria. It can indicate conformity, nonconformity or an opportunity for improvement.

ISO 19011:2018, 3.10
Nonconformity

Failure to meet a requirement. In certification it is classified as major (affects the system’s capability) or minor (isolated deviation).

ISO 9000:2015, 3.6.9
Corrective action

Action to eliminate the cause of a nonconformity and prevent its recurrence. It is not the same as an immediate correction.

ISO 9000:2015, 3.12.2
Stage 1 audit

First part of the initial audit: reviews documentation, context and the organization’s readiness for stage 2.

ISO/IEC 17021-1:2015, 9.3.1.2
Stage 2 audit

Evaluation of the implementation and effectiveness of the management system, on-site or remote, with evidence for each requirement.

ISO/IEC 17021-1:2015, 9.3.1.3
Remote audit

Audit that uses information and communication technologies to obtain evidence without physical presence, when feasible and justified.

IAF MD 4
Annex SL · Harmonized structure

Common structure of ISO management system standards: the same clauses 4 to 10, base terms and core text, to facilitate integration.

Directivas ISO/IEC, Parte 1, Anexo SL
Context of the organization

External and internal issues relevant to the organization’s purpose that affect its ability to achieve intended results.

Cláusula 4.1 (Anexo SL)
Interested parties

Person or organization that can affect, be affected by, or perceive itself to be affected by a decision or activity.

ISO 9000:2015, 3.2.3
Documented information

Information the organization must control and maintain, and the medium that contains it. It replaces “documents” and “records”.

ISO 9000:2015, 3.8.6
Management review

Periodic evaluation by top management of the system’s performance, with defined inputs and recorded decisions.

Cláusula 9.3 (Anexo SL)
Continual improvement

Recurring activity to improve performance. It is evidenced by actions and results, not statements.

ISO 9000:2015, 3.3.2
Quality policy

The organization’s intentions and direction regarding quality, formally expressed by top management.

ISO 9001:2015, 5.2
Quality objectives

Results to be achieved, consistent with the policy, measurable, with an owner, deadline and follow-up.

ISO 9001:2015, 6.2
Control of nonconforming outputs

Identification and control of products or services that do not meet requirements, to prevent their unintended use or delivery.

ISO 9001:2015, 8.7
ISMS

Information security management system: part of the overall system that establishes, implements, maintains and improves information security.

ISO/IEC 27000:2018, 3.62
Annex A · Controls

Reference list of information security controls that the organization compares against its risk treatment.

ISO/IEC 27001:2022, Anexo A
Statement of applicability

Document stating which controls apply, their justification and status, and which are excluded and why.

ISO/IEC 27001:2022, 6.1.3 d)
Environmental aspect

Element of an organization’s activities, products or services that interacts or can interact with the environment.

ISO 14001:2015, 3.2.2
Hazard

Source with the potential to cause injury and ill health.

ISO 45001:2018, 3.19

Ninguna definición reemplaza el texto oficial de la norma.

The most frequently asked questions.

Short answers. Each links to the page that resolves the case.

What accreditation does G-CERTI hold?

G-CERTI's accreditation chain and its current scope are published under accredited scope, together with the source and date of the data. The scope must be checked there before presenting a certification to clients, tenders or authorities, and every certificate issued is verified by its code in the verifier.

Which ISO standards do you certify?

G-CERTI certifies management systems within the current accredited scope, which should always be checked before presenting a certification. For ISO/IEC 42001 and other standards outside that scope, G-CERTI does not currently offer certification; it only publishes training or technical content when applicable.

Can a certificate be transferred from another certification body?

Yes. The transfer process is assessed against IAF MD 2. G-CERTI reviews the current certificate, the issuing body, the scope, the audit reports, any open nonconformities and the applicable conditions before confirming whether the transfer is viable. It is not approved automatically.

What happens if I do not pass the audit?

A report is issued listing the nonconformities found, classified as applicable. The organization implements corrective actions and provides closure evidence. The closure is then reviewed and, if appropriate, the process continues with the certification decision and the issuance of the certificate.

Does G-CERTI provide consulting?

Certification is independent of consulting. In accordance with ISO/IEC 17021-1, a certification body maintains strict separation from consulting to the organizations it certifies, to protect the impartiality of the process. Any implementation support is provided by independent third parties, not as part of the certification process.

How do I verify a certificate?

The certificate number is entered on the verification page. The automated lookup searches for the code in G-CERTI's registry; if no result appears or context is needed, assisted verification confirms it within 24 hours.

How is ISO/IEC 42001 (AI) addressed?

ISO/IEC 42001 is addressed through training and guidance-oriented technical content. G-CERTI does not currently offer certification for this standard; any change in status will need to be backed by a current formal scope before being communicated.

Can several ISO standards be certified together?

Yes. Integrated audits allow two or more standards to be reviewed under a single program when the scope, technical compatibility and applicable rules allow it. Common combinations include ISO 9001 + ISO 14001 + ISO 45001, or ISO/IEC 27001 + ISO 22301.

How long does certification take?

The audit and issuance timeline is set out in the proposal, based on the standard, the size of the organization, the number of sites, complexity, documentation maturity and availability. Prior implementation of the management system is additional; there is no universal timeframe for all cases.

What are the stages of the process?

Six stages: 1) application and scope, 2) documentation review, 3) stage 1 audit (documentary), 4) stage 2 audit (on-site or remote), 5) file review and decision by a competent function separate from the audit team, 6) issuance of the verifiable certificate when applicable.

What documentation do I need?

It depends on the standard. In general: a management policy, measurable objectives, a system manual (if applicable), the documented procedures required by the standard, and the records evidencing implementation. A checklist specific to the chosen standard is provided when the process begins.

Can audits be conducted remotely?

Yes. In accordance with IAF MD 4, remote or information-technology-based audits are used when they are technically feasible and justified for the scope involved. The remote proportion depends on the standard, sites, processes, risk and applicable rules.

How long is the certificate valid?

The certificate is valid for 3 years. During that period, annual surveillance audits are carried out to verify the maintenance of the management system. At the end of the cycle, a recertification audit is performed.

How is the scope of a certificate validated?

By reading the certificate issued, the applicable public registry and the requirements of the client or authority requesting it. Looking only at the name of the standard is not enough: the holder, activity, sites, validity, standard and scope must all match.

What underpins international recognition?

Recognition depends on the accreditation chain, the scope of the certificate and the rules applicable to the target market. It is presented as a reference framework, with case-by-case verification, not as universal automatic acceptance.

Is the certificate valid for public tenders?

It may be valid when the tender specifications accept the standard, the scope, the issuing body and the corresponding accreditation chain. Acceptance is checked against the text of the tender, the certificate issued and the target market.

What coverage does G-CERTI operate with?

Applications and audits are coordinated by qualified personnel, and G-CERTI Co., Ltd. keeps the review, the final decision and the issuance control separate. The acceptance of each certificate depends on its scope, validity, accreditation chain and target market.

How much does ISO certification cost?

The cost is per project and depends on the standard, the size of the organization, the number of sites and the complexity of the processes. The proposal is defined after reviewing the scope, mode, country, sites and required cycle.

What does the certification proposal include?

The proposal details the items included and the applicable additional conditions — audit mode, annual surveillance, scope changes, taxes and services not included. The financial scope is documented before the process begins.

Do you offer payment options?

Payment terms are defined by contract and country. Published amounts are expressed in USD, and the formal proposal documents the payment method, taxes and applicable conditions.

Is it worth certifying more than one standard at a time?

Integrated audits optimize time when the standards share structure, processes, sites and a compatible audit team. The optimization is defined according to the scope and applicable rules.

What payment methods do you accept?

Available methods are stated in the corresponding proposal or invoice. They may include bank transfer, card or local options depending on country, legal entity and applicable conditions.

Do you issue a tax invoice?

Yes. An invoice is issued in accordance with the corresponding legal entity and the tax regulations applicable in each country.

Are there any undisclosed costs?

The proposal details all items included and any applicable additional conditions. Every item is documented before proceeding.

What underpins G-CERTI's work?

Impartiality in accordance with ISO/IEC 17021-1 and a traceable documentary review. The schedule is defined by contract according to scope, and acceptance of the certificate is interpreted against the applicable accredited scope; inconclusive cases go to assisted confirmation.

How do I file a complaint or appeal?

In accordance with ISO/IEC 17021-1, G-CERTI maintains a formal complaints and appeals procedure. The complaint is sent to info@gcerti.org or through the corresponding form. Each case is assessed through the defined path and answered according to the applicable procedure.

What do I do if I disagree with the audit result?

The certification decision may be appealed in accordance with the applicable procedure. The appeal is assessed by a body independent of the original audit team, with an objective and impartial review under ISO/IEC 17021-1.

What training does G-CERTI offer?

Specialized diploma programs on ISO standards (9001, 14001, 45001, 27001, 42001, among others), Lead Auditor and Internal Auditor programs, and technical events. All include a training credential issued by G-CERTI; a training credential is not equivalent to the accredited certification of a company's management system.

Are the training programs online or in person?

Both modes are available. Online classes are live, with direct interaction. In-person classes are held in Buenos Aires. In-company training is also offered for teams.

Do you issue a credential for the training programs?

Yes. The programs include an academic credential issued by G-CERTI. It is verified by its code in the same console as the certificates. It is a training credential: it does not replace an accredited certification of a company's management system, nor does it guarantee audit outcomes.

Is a training credential the same as certifying the company?

No, they are different. The credential documents the training completed by a person; certification assesses an organization's management system through third-party audit. They are separate processes.

Where is G-CERTI located?

G-CERTI operates with an international presence and an office in Buenos Aires (Argentina), which coordinates applications and audits. G-CERTI Co., Ltd. retains the final decision and issuance control, subject to the applicable standard and scope.

Who is accountable for G-CERTI?

Operations are handled by G-CERTI's authorized representation, with separate functions: whoever audits does not decide, and the certification decision is made by the issuer (G-CERTI Co., Ltd.).

What is G-CERTI's approach?

Third-party certification remains independent of consulting and training. Its authority rests on traceable accreditation and on documentary verification mechanisms with assisted confirmation when applicable.

Where can I find questions not listed on this page?

If your question is not on this page, the way forward is to write to the team: a technical conversation defines scope, timing and the next step.

Do you need an answer for your case?

Tell us the standard, the scope and your deadline. We reply in writing with what is assessed and how long it takes.

+54 9 11 2299-2087