
Obtaining C Certification (AI Governance Core Certification) requires taking stock of AI usage, organizing risks, developing rules, and reviewing internal structures. Even after certification, reviewing AI usage and improving operations continues.
That is exactly why this is an area where, if you try to go it alone, it's easy to get lost on questions like "where do we start," "how far do we need to go," and "how do we operate after certification."
Elith can provide end-to-end support, from building AI governance before obtaining C Certification, to improving operations afterward, and even implementing AI security using GENFLUX Security. This time, we spoke with Shinomiya, who is involved in supporting C Certification, about how Elith positions "obtaining certification" and what kind of support it envisions beyond that.
In supporting C Certification, what does Elith value first and foremost?
What Elith values is not letting the process of obtaining C Certification end as mere "work to get certified."
Of course, putting the necessary structure and documentation in place for the review is important. But precisely because Elith is a company working on AI governance and AI security, we look ahead to creating a state where the company can keep using AI safely even after obtaining certification.
How AI is used and managed varies greatly from company to company. Some already have certain rules in place, while others have not fully grasped who is using which AI. That is precisely why we value first understanding actual AI usage and then working together to sort out the structure and operations that company needs.
I think what makes Elith's support unique is treating C Certification not as a goal, but as an entry point for actually making AI governance function.

So it's less about obtaining certification itself and more about looking ahead to what comes after, in terms of operations.
That's right. Even if you put documentation together temporarily just for certification, I think it's meaningless unless it connects to actual internal operations.
For example, one of the documents needed for the review is a list organizing the AI services and AI features used within the company. But rather than making that just a list to submit for review, you need to think through how it will be updated when a new AI tool is introduced, who will manage it, and when it will be reviewed.
Obtaining C Certification does not, by itself, eliminate the risks of AI use. The AI usage rules and management structure put in place when obtaining certification form the core of AI governance. That is precisely why it is important to keep reviewing them continuously after certification and make them function in actual operations.

What is particularly difficult about operations after obtaining certification?
What's difficult, I think, is that the actual state of AI usage changes day by day.
Even if you organize the AI services and features in use and put rules and a management structure in place at the time of certification, that state doesn't last forever. New AI tools get introduced, AI features get added to existing business tools, and how they're used in the field can change.
It's not realistically easy for people to keep track of and check every such change every time. That is exactly why it becomes important to create, not just rules and structure, but a state where you can continuously confirm which AI is actually being used within the company and whether any usage is leading to risk.
Trying to cover this through human operations alone inevitably has limits. That's exactly why, in addition to the core of AI governance, I think a mechanism to visualize actual usage becomes necessary.
Is that "mechanism" what leads to GENFLUX Security?
Yes. Building the core of AI governance through C Certification support, and then continuously supporting its operation with GENFLUX Security — this two-tier approach is what characterizes Elith's support.
Even after C Certification sorts out "what needs to be protected" and "what kind of structure is needed," in the field, new AI tools get used and AI features get added to existing tools, so the state of AI usage keeps changing day by day. That's exactly why, beyond creating rules and structure, you need a mechanism that lets you keep track of actual usage afterward as well.
GENFLUX Security visualizes the AI services and features used within a company and identifies usage that could lead to risk, serving as the foundation for a company to keep using AI safely. Rather than banning the AI being used, it creates a state where it can be used safely. Being able to support operations all the way to that point is, I believe, Elith's unique strength.
Next time, we'll talk with members involved in developing GENFLUX Security about how they visualize hard-to-see AI usage and how they view usage that leads to risk. We'll dig into the role GENFLUX Security plays in helping companies keep using AI safely!
As a certified consulting firm for C Certification, Elith supports companies in building AI governance structures and obtaining C Certification. If you are struggling with formulating rules and guidelines for using AI in your organization, or with building internal structures, please feel free to reach out to us.
We also welcome inquiries at the stage of "I don't know where to start" or "I want to get a clear picture of where we currently stand." Even if the specifics haven't been decided yet, we will work with you to figure out an approach suited to your current situation.

