As AI use spreads, companies are being asked to reach a state where they can explain not just that they "use AI," but that they "manage it responsibly." In Japan, C Certification exists as a certification for building an AI governance system. There's also the international standard ISO/IEC 42001, and quite a few companies find it hard to tell what the difference is or which one to start with. This time, we spoke with Takeshita, who has been involved in building AI governance and management systems, about the difference between C Certification and ISO/IEC 42001, which companies each one suits, and points to watch after certification. To start, I think both C Certification and ISO/IEC 42001 relate to A
Helpful articles.
Official announcements and notes from the field and research, gathered across themes.
Related content
Corporate AI use has already moved past the stage of debating whether to use it at all. AI features are built into more than just generative AI like ChatGPT and Claude — they're now embedded in the SaaS products and work tools people use every day, and the number of moments when employees use AI without even realizing it keeps growing. At the same time, not many companies have a real grasp of which AI is being used, by whom, and how, within their own organization. As convenience takes the lead, there are cases where awareness of risks such as information leaks, misuse, and accountability hasn't caught up. Amid this situation, C Certification is one entry point for building an AI governance system. So why has Elith positioned support for obtaining C Certification as a business, and what possibilities does it see the
Obtaining C Certification requires taking stock of AI usage, organizing risks, developing rules, and reviewing internal structures. Even after certification, reviewing AI usage and improving operations continues. That is exactly why this is an area where, if you try to go it alone, it's easy to get lost on questions like "where do we start," "how far do we need to go," and "how do we operate after certification." Elith can provide end-to-end support, from building AI governance before obtaining C Certification, to improving operations afterward, and even implementing AI security using GENFLUX Security. This time, we spoke with Shinomiya, who is involved in supporting C Certification, about how Elith positions "obtaining certification" and what kind of support it envisions beyond that. When it comes to supporting C Certification,
General-purpose AI like ChatGPT and Claude is one thing, but AI capabilities are now quietly built into the SaaS products and everyday work tools people already use — that's the reality of business in 2026. And it's no longer limited to specialists: it's now common for non-engineers to build their own work tools and automation flows using GitHub Copilot or generative AI. As this convenience grows, new challenges are emerging for companies. It's becoming harder to see the full picture of AI use — not just the AI a company formally adopts, but also the AI employees use on their own judgment, AI features added later to existing tools, and automation flows that have naturally taken hold in day-to-day work. What companies are being asked today isn't whether they use A
'I want to obtain AI governance C Certification, but I can't picture what the process actually looks like, or how much of a burden it will be internally'—this is a common concern among companies considering C Certification. At Elith, we support C Certification in three broad phases. This article explains, from a practical standpoint, what happens in each phase, along with the timeline, deliverables, and the rough workload expected on the client side. Elith, as a certified consulting firm for C Certification, provides support for building AI governance structures and obtaining C Certification. If you're struggling with setting rules and guidelines for using AI in your organization, or with building an internal structure, please feel free to reach out. 'I don't know where to start' or 'I want to sort out
While more companies are using AI as an offensive move, there are no shortage of cases where the "defense" that supports it behind the scenes is not sufficiently in place. To use AI safely and connect it to sustainable growth, you need to establish, at the same time, three pillars that cannot function if even one is missing. This article explains the roles of the three safeguards that support AI use — AI Safety (technical safety), AI governance (organizational control), and certification programs (external proof) — along with concrete examples of related initiatives. Why the three safeguards each play a different role The three safeguards all share the same purpose of "using AI safely," yet they approach it at completely different layers. Safeguard Role Target AI
As AI adoption spreads rapidly, more and more companies are grappling with questions such as "Is our AI use really safe?" and "How should we explain it to our business partners?" As a third-party certification to address these challenges, JDLA (Japan Deep Learning Association) released the "AI Governance C Certification" (hereafter, C Certification) in 2026. Meanwhile, the international standard "ISO/IEC 42001" also exists for AI governance, and many companies are unsure which one to obtain. This article organizes the characteristics and differences between C Certification and ISO/IEC 42001. The comparisons and views in this article are Elith's own, based on its support track record, and do not represent the official
While AI use, starting with generative AI, is spreading company-wide, no shortage of companies have failed to grasp "who is managing which AI, and how." However, the risks associated with AI use are becoming an issue directly tied to management liability that "I didn't know" no longer excuses. This article organizes the risks lurking in AI use into two usage patterns and explains what actual harm can result if countermeasures are neglected. Thinking about risk in terms of two usage patterns Corporate AI use can broadly be divided into the following two patterns, each harboring different risks. Pattern 1: Using existing AI tools (SaaS, etc.) This is where employees individually use general-purpose AI tools such as ChatGPT to
