Initializing portfolio

000

Aravind.
All articles
AI3 min read

An Indian IT firm just got certified against the world's first AI management standard

An Indian IT services firm has been certified against ISO/IEC 42001:2023, the first international standard for AI management systems. A look at what the audit covers and why the certificate is still rare.

AravindChief Technology Officer & Advisor · AI, Cloud & Cybersecurity
An Indian IT firm just got certified against the world's first AI management standard

ISO/IEC 42001 is not a famous certificate. It should be. Published in 2023, it is the first international standard that treats an AI programme the way ISO 27001 treats information security: as a management system with policy, ownership, monitoring and a risk register, instead of a set of good intentions.

On 17 August, CSM Technologies announced it had been certified against it.

The scope is wider than one model

The audit covered CSM's end-to-end technology services. Software and application development, artificial intelligence, machine learning and generative AI work, digital transformation, IT consultancy, systems integration, managed IT and cloud services, and data management and governance.

Four things make up the AI management system the company had to demonstrate:

  • A formal AI policy with measurable objectives, embedded into standard operating procedures rather than published as a statement of values.
  • Controlled AI delivery, using approved tools, defined data classification protocols, and lifecycle documentation across the development pipeline.
  • Ongoing monitoring by an internal Core Technology Group that tracks AI usage, performance and whether the controls are actually working.
  • A dedicated AI risk register, where AI-specific risks are logged, treated and closed rather than noted and forgotten.

The last two are what separate a certification from a slide. A risk register with a close-out step means someone owns the risk. Continuous monitoring means the controls get tested after the auditor leaves.

Certification as a procurement argument

CSM sells into governments and enterprises across India, Africa and North America. Managing director and CEO Priyadarshi Nanu Pany put the certification in procurement terms: clients scaling AI need to know that innovation is matched by discipline, and an independent audit is how you prove it without asking to be trusted.

For most of the last three years, responsible AI at Indian services firms has lived on the marketing surface. A set of principles. A governance council. A page on the website. ISO/IEC 42001 turns it into something a buyer can put in an RFP and an auditor can fail you on.

That distinction will grow. Regulators and large buyers keep converging on the same question, and it is not is your model good. It is show me how you govern it. A certificate does not answer that fully. It does establish that somebody outside the company checked.

What the rarity tells you

The standard is still uncommon enough that achieving it is a press release. Two years after publication, an AI management system certification differentiates a vendor instead of merely qualifying one.

Read that backwards and it is less flattering. It suggests how many organisations now running generative AI at scale have no audited governance layer underneath any of it.

The certification adds to CSM's existing quality and security accreditations. The more useful signal is about where enterprise AI procurement is going: buyers are starting to ask for evidence.

Source: CSM Technologies achieves ISO/IEC 42001:2023 certification for Artificial Intelligence Management System — Express Computer

#India#AI Governance#Enterprise AI#ISO 42001#Responsible AI

Comments

Checking you're human…

Keep reading

Get the next essay first

Checking you're human…

By subscribing you agree to our Privacy Policy. Unsubscribe anytime.