التفاصيل

Artificial intelligence management system certification

GB/T 45081-2024

01

مقدمة الخدمة

Artificial Intelligence Management System Certification is an authoritative certification mechanism that systematically evaluates an organization's responsible management capabilities throughout the entire lifecycle of AI system development, provision, and use. It aims to help organizations establish effective AI governance systems through a standardized framework, ensuring transparency, fairness, accountability, and security of AI systems. This certification is primarily based on the national standard GB/T 45081-2024/ISO/IEC 42001:2023 "Artificial Intelligence — Management System," which was jointly published by the International Organization for Standardization and the International Electrotechnical Commission in December 2023, with its national standard conversion completed in 2024. It is the first international management system standard specifically targeting artificial intelligence, applicable to various organizations that develop, provide, or use AI system products or services.

Core Certification Content

Artificial Intelligence Management System Certification focuses on the responsible management of AI systems and examines the following dimensions:

Organizational Context and Leadership: Understand the organization and its context, and define the scope of the AI management system. Top management should establish an AI policy, define roles and responsibilities for AI governance, and provide resource support. Organizations should establish an AI governance committee and designate key roles such as executive sponsor, AI risk officer, data governance officer, model owner, and compliance reviewer to ensure clear decision-making authority and accountability pathways.

AI Risk Assessment and Treatment: Based on risk management standards such as ISO/IEC 23894, systematically identify various risks that AI systems may face throughout their lifecycle, including algorithmic bias risks, data privacy risks, system security risks, ethical and moral risks, and legal compliance risks. Organizations should classify AI systems by criticality, establish an AI risk register, and maintain a risk treatment plan. For AI systems driving critical decisions (e.g., batch release, dose changes, quality anomaly determination), stricter governance, monitoring, and escalation mechanisms must be implemented.

AI Lifecycle Management: Covers the entire process of AI systems from concept, design, development, deployment, operation, to decommissioning. Organizations should establish a data governance framework to ensure data quality, lineage, traceability, and version control. A model registry should be created to track model architecture, versions, validation results, owner information, and retirement plans. Change control processes should be defined to ensure clear specifications for model version transitions and retirement criteria.

Support and Operational Controls: Ensure resource allocation, personnel competency development, and training meet management system requirements. Organizations should provide AI governance training to teams such as development, legal, and compliance to enhance capabilities and awareness. In terms of operational controls, the AI lifecycle should be embedded into existing management systems and linked with change control, risk registers, model registers, and quality event management.

Performance Evaluation and Improvement: Assess system effectiveness through monitoring, measurement, and internal audits. Organizations should establish AI key performance indicators, including the number of AI systems in production by risk category, model drift events, incidents caused by AI, audit finding remediation time, and frequency of supplier model changes. Regular internal audits and management reviews should be conducted, with corrective and preventive actions taken for non-conformities to continuously optimize the management system.

AI-Specific Controls: The standard's annex specifies control measures unique to AI systems, covering transparency management, bias identification and mitigation, data governance, incident response, human oversight, and explainability assurance. Organizations should establish internal benchmarks to define metrics for transparency and fairness, ensuring AI systems are traceable during audits.

Certification Levels and Evaluation System

Artificial Intelligence Management System Certification adopts a pass/fail evaluation method without star ratings. The certification body conducts an initial audit of the auditee's AI management system and determines whether to grant certification based on the assessment. After certification, surveillance audits are conducted during the certificate's validity period to confirm continued compliance with certification requirements.

Certification Process

Artificial Intelligence Management System Certification typically includes the following stages:

Application and Acceptance: The applying organization submits an application to the certification body, providing information such as the certification scope, organizational overview, and multi-site details. The certification body reviews the application materials, confirms eligibility, and signs a certification contract.

Certification Audit: The initial audit is divided into two stages. Stage 1 is usually conducted at the client's site to understand the organization's basic situation, review management system documentation, and confirm readiness for Stage 2. Stage 2 is conducted on-site for a comprehensive and systematic evaluation of the organization's AI management system implementation, verifying compliance with standard requirements and effective operation.

Corrective Actions and Review: For non-conformities identified during the audit, the organization must complete corrective actions within a specified period and submit evidence. After review by the audit team, the non-conformities are closed.

Certification Decision and Issuance: After the audit team completes the audit, the certification body conducts a technical review and makes a certification decision. Certificates are issued to organizations that meet the requirements, typically valid for three years.

Surveillance Audits and Recertification: During the certificate's validity period, the certification body conducts at least one surveillance audit per year to confirm continued compliance with standard requirements. The interval between surveillance audits does not exceed 12 months. Before the certificate expires, the organization must apply for recertification to extend certification status.

Value of Certification

Enhanced Compliance Management Capability: Guides organizations in identifying applicable laws, regulations, contractual obligations, and regulatory requirements for AI systems, clarifying compliance objectives and reducing compliance risks and losses.

Increased Market Trust and Competitiveness: Through independent third-party certification, demonstrates to customers, partners, and regulators that the organization has responsible AI management capabilities. ISO/IEC 42001 certification provides internationally recognized proof of a responsible AI governance system, helping build a competitive advantage in the AI-driven market.

Reduced AI-Specific Risks: Helps organizations systematically identify and address AI-specific risks such as algorithmic bias, data privacy, system security, and ethical issues, avoiding reputational damage and economic losses from AI misuse or abuse.

Easy Integration with Existing Management Systems: ISO/IEC 42001 adopts the same high-level structure as other ISO management system standards, enabling seamless integration with existing systems such as ISO 27001, ISO 9001, and ISO 13485, avoiding disjointed governance structures.

Support for Regulatory Compliance: ISO/IEC 42001 is highly aligned with regulatory frameworks such as the EU AI Act, facilitating alignment with documentation standards and risk management requirements, providing a structured approach to addressing increasingly stringent AI regulations.

Promotion of Traceable and Accountable AI Culture: The standard requires documentation of each stage of the AI lifecycle, ensuring AI systems are traceable and auditable internally and for regulators, fostering a culture of responsible AI use within the organization.

03

عملية الخدمة

04

ملف القواعد

هل تحتاج إلى هذه الشهادة؟

اتصل بنا