In December 2023, the International Organization for Standardization published ISO/IEC 42001, the first international standard dedicated specifically to managing artificial intelligence systems inside a company. It doesn't say what an AI should answer. It says how an organization should run its use of AI: with a defined owner, risk assessment, kept evidence, and a review cycle that doesn't end on launch day.
In just over a year, the standard moved from paper to market practice. According to reporting from BrightDefense, more than 100 organizations have already been certified worldwide — among them AWS, Google, Microsoft, Anthropic, Snowflake, ServiceNow, and the consultancy BCG, several of them certifying the very AI services they sell to other companies.
The reason decision-makers should pay attention isn't the seal itself. It's what the research shows behind it: most companies already have some AI policy written down, and most don't have a system that keeps that policy alive day to day.
When policy stays just paper
A 2025 survey by AuditBoard with Panterra Research, covering more than 400 audit and compliance professionals in the United States, Canada, Germany, and the United Kingdom, measured that gap directly. 86% of organizations said they were aware of the rules that affect AI use, from the European law to the US government's AI Risk Management Framework, published by NIST in January 2023. Yet only 25% reported having a fully implemented AI governance program.
The most cited cause wasn't a tool gap — fewer than 15% named that as the main problem. It was a missing owner: 44% cited a lack of clear ownership as the top barrier, followed by a lack of internal expertise (39%) and resource constraints (34%). The report sums up the finding in one line: governance is a capability you operate every day, not a box you check during an audit.
That's exactly the gap ISO/IEC 42001 tries to close. The standard follows the same continuous-cycle structure used by quality and information-security standards — plan, do, check, act — and requires a company to document the scope of its system, define roles and responsibilities, and assess risk against a stated criterion, not against the feeling that everything is fine. A companion standard, ISO/IEC 23894, spells out how that risk should be identified, assessed, and treated across the entire lifecycle of an AI system, from design to daily use.
A policy with no owner doesn't survive the first team change. A policy with no evidence doesn't survive the first audit. A policy with no review cycle goes stale the same month a new AI tool shows up at the company.
Why writing a policy isn't enough

The ISO standard demands the opposite of a stated intention: a dated record of each decision, a written risk criterion, and demonstrable continuous improvement. That's also why certification alone isn't a legal shortcut. According to an analysis by ISMS.online on the European AI law, ISO/IEC 42001 remained outside the circle of standards officially recognized by the European Union: a standard only grants a legal presumption of conformity once it's published with that specific status, and 42001 didn't have that seal yet. Holding the certification proves management maturity; it doesn't, by itself, replace the technical documentation the law requires for high-risk systems.
For companies that sell AI technology to other businesses, the practical effect showed up before the law caught up. The same BrightDefense reporting describes the standard turning into a contractual requirement: corporate customers, especially in regulated sectors like healthcare and financial services, started asking for independent proof that a vendor manages AI risk — not just a promise that it does.
For Brazilian and Latin American companies that haven't thought about certification yet, the takeaway isn't to chase the seal. It's that the market is already defining, in practice, what counts as serious governance: a defined owner, controlled access, a recorded decision, and a recurring review. That holds before, during, and after any formal certification — and it holds for companies that will never get certified but still need to prove it to a customer, a partner, or an auditor.
What has to be in place
An AI management system — certified or not — rests on verifiable mechanisms, not policy text.
Corporate identity, not a personal account. Access to AI comes from the company's own user directory, the same login used to get on the network — not a personal account someone set up on their own. When someone leaves the company, access drops with them, without depending on someone remembering to revoke it.
Access by role, for every person. Every person and every AI agent see only what their role authorizes, including inside a connected tool with dozens of different functions.
Human approval based on risk. Sensitive actions and documents go through review before becoming official information the AI relies on, with whoever writes it separate from whoever approves it.
An audit trail by area. Every relevant decision — creating an agent, approving a document, changing a permission — gets logged and stays searchable afterward. That's exactly the "stated criterion" and "dated record" the standard requires.
Approved knowledge with sources. What the AI uses as a reference comes from documents with an owner and a current version, not just any loose file someone found in a hurry.
Reuse with defined permissions. What works for one person can be made available to others, with reach defined by person, group, or role — without turning into open access for everyone.
This is how Skyller was designed: identity coming from the company directory, human approval based on risk, and an audit trail by default, not as an extra setting someone has to remember to turn on.
The payoff of real governance

The most direct payoff shows up at audit time. When every decision is logged by default, reconstructing what happened — who approved a document, who changed a permission, which agent took which action — is a matter of minutes, not weeks spent gathering screenshots and manual spreadsheets. That's the difference between going through an audit and dreading one.
There's a less obvious payoff that matters just as much: once the approval-and-logging mechanism already exists by design, it doesn't need to be rebuilt every time a law changes or a customer asks for new proof. Skyller, for example, already ships with more than 170 ready-made policy and process templates, so the team adapts an existing approval flow instead of designing each one from scratch.
The side effect is cultural. When the system naturally separates who creates knowledge from who approves it, and logs the difference, the initial pushback of "one more control" tends to turn into "this protects me." The same trail that serves a regulator or an outside auditor also serves, internally, to explain why an AI agent did what it did — without depending on the memory of whoever was in the room that day.
Governance is a core capability of the company, not a compliance step to check off.
A roadmap to get started
Before writing one more AI policy, it's worth mapping out how it will become a system. One possible roadmap:
- Name a single owner for AI governance. As long as responsibility is scattered across IT, legal, and each department on its own, no one will enforce the review cycle — and that's exactly where 44% of the companies in the AuditBoard survey got stuck.
- Inventory what's already in use. Before writing a new rule, list the AI assistants, sanctioned or not, that the team already uses at work today.
- Define access by role, not by person. Decide what each function can do with AI before deciding what each individual will ask for later.
- Choose what requires two-step approval. Not every document needs double review — but the ones that become the reference for AI answers should.
- Make sure every relevant decision gets logged. If reconstructing "who approved what" today means asking people, the system doesn't exist yet — only the intention behind it.






