Skip to content
AI GOVERNANCE · ISO/IEC 42001

ISO/IEC 42001: govern the AI of your organization.

The first certifiable standard for AI management systems: how your organization develops, provides or uses artificial intelligence, with evidence and human oversight.

WHERE EACH THING IS RESOLVED
STANDARDISO/IEC 42001:2023
ENTRYIndicative diagnosis of AI governance. This standard does not enter through a quote.
PATH AND STATUSThey are published on the standard's page, with its source and its date. This page does not duplicate them.
SCOPE OF THIS PATHInitial guidance and separate training. It is not a gap analysis, pre-audit or conformity assessment.
Work room with screens showing artificial intelligence models.
WHAT THE STANDARD REQUIRES

Five key clauses.

ISO/IEC 42001:2023 sets requirements for an AI management system (AIMS). Each clause opens up what the organization has to be able to show.

CLÁUSULA 5.2 · AI POLICY

Document declaring principles, scope and responsible parties. It is the anchor of the AIMS.

WHAT AN ORGANIZATION HAS TO BE ABLE TO SHOW
Formal AI Impact Assessment per AI systemAI governance with roles, policies and responsibilitiesManagement of the AI system's lifecycle (development, deployment, monitoring, retirement)Traceability of training data and modelsDue diligence of third-party AI vendorsTransparency toward end users and interested parties
WHO REQUIRES ITBankingHealthcareTelecommunicationsPublic sectorExporters of AI-based services
G-CERTI KNOWLEDGE BASE BY STANDARD · ISO/IEC 42001:2023 · 2026-09-09

Organizations that develop AI products, integrate third-party models, use AI in critical decisions, or need to prepare governance evidence for regulatory and client requirements.

ORIENTATIONAL ASSESSMENT

Measure your starting point.

Eight statements to review the scope, responsibilities, risks, and evidence of AI governance. The answers remain in the browser of the person who enters them.

Team reviewing an artificial intelligence system on screen.
EIGHT DIMENSIONSInventory · purpose · risks · data · records · competencies · monitoring · governance.
INVENTORY

An inventory of AI systems and use cases under the organization's responsibility exists.

PURPOSE AND RESPONSIBLE PARTIES

Each AI system has a documented purpose, a responsible party, and usage limits.

RISKS AND IMPACTS

Risks and impacts are assessed before introducing or changing an AI system.

DATA AND SUPPLIERS

There are criteria for data, suppliers, third-party models, and human oversight.

RECORD-KEEPING

Relevant decisions, changes, incidents, and exceptions are recorded.

COMPETENCIES

The people who operate or oversee AI know their responsibilities.

MONITORING

Performance is monitored and action is taken when deviation, harm, or unintended use appears.

MANAGEMENT REVIEW

Leadership reviews objectives, risks, and evidence of AI governance.

WHAT IT SAYS
Where the starting point isBrings together in one place the inventory of systems, purpose and responsible parties, risk and impact assessment, data and vendor criteria, decision records, competencies, monitoring and management review.
What information is worth gatheringPoints to the topics on which the organization does not yet have organized evidence, so the next conversation can start there.
An indicative reading, with its bandThe percentage and its band are a reference of what was declared, not a verified measurement of anything.
WHAT IT DOES NOT SAY
Whether the system complies with the standardThe result comes from what someone declares about their own organization, without examined evidence or independent contrast.
Whether the organization is ready for an auditCompleting the questionnaire does not prepare, does not advance, and does not anticipate the outcome of any later evaluation.
Nothing about a certificate issuedA management system certificate is verified by its code in the verifier, which is another document, another record and another page.
ASSISTED PATHThe useful reading is done by a person.

The questionnaire organizes the starting point, but does not examine evidence or know the organization's context. That reading is done by a member of the team, with the scope and AI systems in view. The questionnaire's answers are not attached on their own: the person writing decides what to share.

Human reviewThe answers stay in the browser of whoever writes them: they are not sent, not saved, and no result is published. Sharing information with G-CERTI is a separate decision, with its own form.
PUBLIC FRAMEWORKS

The regulations that require it.

The European AI Regulation already applies its transparency obligations as of August 2, 2026. For an exporter, this is an indirect market requirement. The standard is mapped against that framework, not a replacement for it: it does not grant a presumption of conformity.

EUROPEAN UNIONAI Act (Regulation 2024/1689)Its application is gradual and depends on the system's category. ISO/IEC 42001 can help organize governance evidence, but it does not replace legal assessment.Regulation in force
UNITED STATESNIST AI Risk Management FrameworkVoluntary framework for managing AI risks; also confirm applicable federal and state obligations.Voluntary framework
BRAZILPL 2338/2023Legislative bill in process; verify its status in official sources before asserting obligations.Bill in progress
ARGENTINARecommendations for trustworthy AIIndicative reference; confirm the applicable framework and sector obligations in force.Indicative reference
GLOBALOECD AI Principles + NIST AI RMFComplementary voluntary reference frameworks.Principles
THE STANDARD IS MAPPED AGAINST EACH FRAMEWORK; IT DOES NOT REPLACE IT OR GRANT A PRESUMPTION OF CONFORMITY. RECORD OF PATHS AND POSITIONING BY STANDARD · 2026-08-13See the observatory
SEPARATE TRAINING

Training to audit ISO/IEC 42001.

Three academic paths on artificial intelligence governance: interpreting the requirements, auditing the system from the inside, and covering both in an integrated way. The path is academic and does not implement an organization's system.

IMPLEMENTATIONTraining in AI management on ISO/IEC 42001

Interpret the requirements of the AI management system and translate them into policy, roles, impact assessment and lifecycle.

INTERNAL AUDITInternal auditor of AI management systems

Plan and carry out internal audits of the AIMS: evidence, findings and follow-up.

DIPLOMA PROGRAMISO/IEC 42001 Diploma Program

The integrated path: system design, internal audit and lead auditor, with three training certificates.

See the ISO/IEC 42001 Diploma Program
TRAININGAcademic training and practice

G-CERTI Formación works on interpretation, exercises and internal audit through a common program. It does not design or implement an organization's system within this path.

CERTIFICATIONSubsequent certification, if applicable

An organization that later inquires about certification enters through a different file. Before quoting, scope and impartiality are reviewed; any incompatible advisory work blocks the certification path.

GOVERNANCEHow the separation is maintained

The policy that keeps the two files, their teams and their decisions separate is published in the Trust Center.

See the separation policy
Training develops capabilities to interpret requirements and practice internal auditing. It does not certify an organization's system and does not decide its verification: these are separate processes, with separate files and teams, and having taken the course does not anticipate any outcome.ACADEMIC PORTFOLIO OF G-CERTI FORMACIÓN · 2026-09-02
FREQUENTLY ASKED QUESTIONS

The most frequently asked questions.

NEXT STEP

Start with the diagnosis.

The self-assessment brings together scope, responsible parties, risks, and evidence in one place. It helps decide what information to move forward with, not to declare conformity.

THE ASSESSMENT IS COMPLETED IN THE BROWSER AND ITS RESULT IS NEITHER SENT NOR SAVED. REQUESTING A HUMAN REVIEW IS A SEPARATE DECISION, WITH ITS OWN FORM AND RECEIPT.
+54 9 11 2299-2087