AI Governance
ISO 42001
-
Gap assessment Gap assessment
-
Regulatory implementation Gap closure and evidence
-
Gap assessment + implementation Both services, together−15%
An AI management system built on ISO/IEC 42001:2023, the first certifiable standard in the world on this subject.
There is no need to wait for an AI law: the Law 21,719 already regulates automated decisions on personal data and it is enforceable today. If your organisation uses models that influence decisions about people —selection, scoring, prioritisation, customer service— that obligation applies to you now.
And there is a problem that comes before compliance: almost no organisation knows how many AI systems it has in use. Tools contracted by one area, AI features switched on inside software that was already in use, models connected to production data. The first phase of this programme is usually the most revealing.
ISO/IEC 42001 also allows demonstrate it to a client or a tender, which is where the requirement is appearing before it appears in the law.
ISO/IEC 42001:2023 — AI management system
ISO/IEC 23894 — AI risk management
ISO/IEC 22989 — concepts and terminology
ISO/IEC 42005 — AI system impact assessment
ISO/IEC 5338 — AI system life cycle
NIST AI RMF 1.0 — risk management framework
EU AI Act — for anyone who exports
Estimated duration of 4 to 6 months depending on the number of AI systems in use.
An inventory of the AI systems in use, including the ones that came in without approval. A gap assessment against ISO 42001 and a defined management system scope.
AI policy, roles and responsibilities, governance committee, objectives and acceptable use policy.
A register of systems classified by risk level according to ISO 23894 and the levels of the EU AI Act, with approval criteria for new systems.
Assessments under ISO 42005 of the high-risk systems, covering bias, explainability and impact on people.
Life cycle controls, governance of the training data, management of model suppliers, transparency and human oversight.
Support during rollout, training and an evidence file.
Internal audit, management review and preparation for certification.
The gap assessment can be engaged on its own. Below, the option of integrating it with Privacy Governance into a single management system, which costs less than running them apart.
ISO 42001
One single project, not 2 por separado
How the value is determined
Proposals are quoted in UF, plus VAT. The value of each project comes from four factors:
Build your scope in the quote builder and get the proposal with figures in UF within 24 business hours. No meeting first, and no details needed until the end.
A 30-minute call, at no cost. In most cases the first finding is that there are more AI systems in use than the organisation believed.
Your basket is empty
Add regulatory documentation packs or plans