Elith日本語版
Menu
Article

What's the difference between C Certification and ISO/IEC 42001? How to choose an AI governance certification

As AI use spreads, companies are being asked to reach a state where they can explain not just that they "use AI," but that they "manage it responsibly." In Japan, C Certification exists as a certification for building an AI governance system. There's also the international standard ISO/IEC 42001, and quite a few companies find it hard to tell what the difference is or which one to start with. This time, we spoke with Takeshita, who has been involved in building AI governance and management systems, about the difference between C Certification and ISO/IEC 42001, which companies each one suits, and points to watch after certification. To start, I think both C Certification and ISO/IEC 42001 relate to A

What's the difference between C Certification and ISO/IEC 42001? How to choose an AI governance certification
TopicsHelpful articles

As AI use spreads, companies are being asked to reach a state where they can explain not just that they "use AI," but that they "manage it responsibly."

In Japan, C Certification (AI Governance Core Certification) exists as a certification for building an AI governance system. There's also the international standard ISO/IEC 42001, and quite a few companies find it hard to tell what the difference is or which one to start with.

This time, we spoke with Takeshita, who has been involved in building AI governance and management systems, about the difference between C Certification and ISO/IEC 42001, which companies each one suits, and points to watch after certification.

To start, I think both C Certification and ISO/IEC 42001 relate to AI governance. Broadly speaking, what's the difference between them?

C Certification and ISO/IEC 42001 are both a certification and a standard related to AI governance, but I think it's easier to understand if you see them as covering somewhat different scope and purpose.

C Certification puts its focus on organizing what AI a company is using, what risks each one carries, and what measures are in place. It's essentially a practical certification for advancing an inventory of AI use and risk countermeasures.

ISO/IEC 42001, on the other hand, is an international standard for AI management systems. In general, it requires a mechanism for an organization to continuously manage and improve AI throughout its entire lifecycle — planning, development, provision, operation, and review.

So rather than one being superior to the other, I think it's better to see them as differing in scope and purpose.

What kind of company do you think C Certification suits?

I think C Certification suits companies that are already using AI, or where AI use is spreading within the organization.

For example: using generative AI tools for work, using systems that have AI built in, or using AI features inside external services. In those cases, the first important step is grasping which AI your company is using.

From there, you organize what risks exist in each AI use and what rules or measures are needed. I think C Certification is an accessible entry point for doing that.

Especially for companies that want to tell their customers and business partners, "we manage AI appropriately," C Certification can be an effective option.

On the other hand, how would you position the ISO/IEC 42001 standard?

ISO/IEC 42001 is an international standard for AI management systems.

Generally speaking, ISO/IEC 42001 requires not just setting a policy and management system for AI, but also things like whether it's actually being operated, whether records are kept, and whether it's reviewed periodically.

In other words, it's not enough to just make the rules and stop — what's required is a mechanism for the organization to continuously manage and improve AI.

For that reason, I think ISO/IEC 42001 is worth considering for companies that develop and provide their own AI products, companies that place AI at the core of their business, and companies with global expansion in mind.

Is it difficult for a company that hasn't yet built an AI governance system to go straight for ISO/IEC 42001?

I don't think it's impossible, but the burden of preparation tends to be heavy.

ISO/IEC 42001 requires putting a wide range of elements in place: a management system for AI, operational workflows, risk management, records, internal audits, a mechanism for continuous improvement, and more.

In particular, if you haven't yet sorted out which AI is being used internally, what risks exist, and what rules govern how it's managed, building an entire management system all at once is difficult.

In that sense, I think starting by taking stock of AI use and organizing risk through C Certification also lays the groundwork for pursuing ISO/IEC 42001 later.

What order would you recommend for approaching C Certification and ISO/IEC 42001?

It depends on the company's situation, but if AI governance isn't yet well established, I think it's realistic to start by considering C Certification first.

With C Certification, you take stock of your company's AI use and organize the risks and countermeasures. This is very important for building the foundation of AI governance.

From there, if you're developing and providing AI products, need to explain things to overseas business partners or customers, or want to manage AI as part of an organization-wide management system, it feels natural to move on to considering ISO/IEC 42001.

Of course, if a company already has an AI management system in place, going straight for ISO/IEC 42001 is also an option. But for most companies, the important thing is first grasping where their AI use currently stands.

Learn more about Elith's C Certification support

What characterizes companies that should consider ISO/IEC 42001?

First, companies that develop and provide their own AI products or AI services are worth considering ISO/IEC 42001.

When you plan, develop, provide, and operate an AI system, you need to manage risk across its entire lifecycle. ISO/IEC 42001 is the international standard for an organization to build that kind of AI management system.

ISO/IEC 42001 can also be a way to demonstrate reliability for companies with global expansion in mind, or companies that need to explain their AI management system to overseas business partners and customers.

I also think it suits companies that want to run AI management as an organization-wide mechanism, rather than leaving it to a handful of people in charge.

What should companies be especially careful about after getting certified?

The most important thing is not to treat certification as the goal.

Whether it's C Certification or ISO/IEC 42001, just creating rules and policies isn't enough. It's important to put them into actual operation and keep reviewing them continually.

The state of AI use changes quickly. New AI tools get introduced, the scope of existing AI use expands, and laws, regulations, or guidelines get updated.

Because of that, even something you've organized once can fall out of step with reality if you don't review it periodically. Even after certification, it's essential to keep grasping the state of AI use, review the risks, and improve rules and operations as needed.

Is a visualization mechanism also necessary for managing AI use on an ongoing basis?

I think it becomes necessary.

As long as AI use stays within a limited scope, some of it can be managed by hand. But as the number of AI tools in use grows, or the departments using them expand, it becomes difficult to keep track of who is using which AI and how, by human effort alone.

In particular, tools that are easy for people on the ground to use, like generative AI, can spread without anyone noticing. That's why it's important to build a mechanism for continuous tracking, not just take stock of AI use once.

Going forward, as we work to make AI governance actually effective, I think mechanisms for visualizing and managing AI use will become even more important.

Finally, is there anything you'd like to say to companies considering C Certification or ISO/IEC 42001?

Before deciding which certification to pursue, I think it's important to first sort out what state your company wants to be able to explain.

Are you a company that develops and provides AI products, or one that uses AI in its operations? Do you want to explain things to domestic customers, or to overseas business partners as well? Do you want to build a full organization-wide management system, or start with just taking stock of AI use?

Which certification to aim for, and in what order, changes depending on the company's situation.

But what's common across every certification is that getting it isn't the end. AI will keep changing going forward. I think what will matter in AI governance from here on is continuing to grasp your own AI use, review the risks, and keep improving your operations.

Summary

C Certification and ISO/IEC 42001 aren't a case of one being the right answer and the other not.

C Certification is a certification that tends to serve as a practical entry point for grasping your company's state of AI use and organizing risks and countermeasures. ISO/IEC 42001, meanwhile, is an international standard for building an AI management system across the whole organization and continually operating and improving it.

What matters is thinking about what phase your company is currently in, and to whom, and what, you want to be able to explain.

Rather than making certification itself the goal, see it as building the system for continuing to use AI safely. I believe that perspective is the first step of the AI governance that companies will be expected to have going forward.

As a certified C Certification consulting firm, Elith supports companies in building AI governance systems and working toward C Certification. If you're facing challenges around setting rules and guidelines for using AI in your organization, or building an internal system, please feel free to reach out to us.

We also welcome inquiries at the stage of "we don't know where to start" or "we want to sort out where we currently stand." Even if the specifics aren't decided yet, we'll work with you to figure out an approach that fits your current situation.

Learn more about Elith's C Certification support