Service

GIC là tổ chức đánh giá sự phù hợp, hoạt động trong lĩnh vực Thử nghiệm - Giám định - Chứng nhận

System Certification

ISO/IEC 42001:2023 Artificial Intelligence Management System Certification

I. INTRODUCTION TO ISO/IEC 42001:2023 CERTIFICATION SERVICES
ISO/IEC 42001 certification

ISO/IEC 42001:2023 is the international standard specifying requirements and providing guidance for establishing, implementing, maintaining and continually improving an Artificial Intelligence Management System (AIMS). It provides a systematic governance framework for organizations to develop, provide or use AI systems responsibly while managing risks and pursuing opportunities in line with their objectives, context and obligations.

ISO/IEC 42001 applies to organizations of all sizes and sectors, including organizations that develop AI models/systems, integrate or provide AI solutions, deploy AI for customers, or use AI in their internal operations. The AIMS scope should clearly define the organizational boundaries, role in the AI value chain, AI systems or groups of AI use cases, life-cycle stages, sites, internal processes and externally provided activities.

ISO/IEC 42001:2023 is the first and current edition of the AI management system standard. Clauses 4 to 10 contain the requirements subject to certification audit; Annex A provides reference control objectives and controls, Annex B provides implementation guidance, Annex C describes potential organizational objectives and risk sources, and Annex D illustrates the use of the AIMS across different domains or sectors. Organizations must select controls based on risk and clearly justify their inclusion or exclusion.

ISO/IEC 23894:2023 can support AI risk management, ISO/IEC 42005:2025 provides guidance on AI system impact assessment, and ISO/IEC 5338:2023 provides AI system life-cycle processes. These standards support implementation, but AIMS certification is conducted against ISO/IEC 42001:2023. Audit and certification activities should consider the specialized requirements for competence, consistency and credibility specified in ISO/IEC 42006:2025.

Key technical requirements of ISO/IEC 42001:2023 include:

  • Context, roles and AIMS scope: Identify internal and external issues, interested parties, and legal, regulatory, contractual and policy requirements; clearly define whether the organization acts as an AI developer, provider, deployer, operator or user.
  • Leadership, policy and accountability: Establish the AI policy, objectives, roles, authorities, oversight arrangements and accountable functions; ensure that AI governance decisions are integrated into business and risk-management processes.
  • Risks, opportunities and controls: Identify, analyze, evaluate and treat AI risks; select controls from Annex A or other sources, prepare a Statement of Applicability, and retain evidence of the suitability, adequacy and effectiveness of the treatment approach.
  • AI system impact assessment: Consider intended and reasonably foreseeable consequences for individuals, groups and society in the context of use; identify affected parties, severity of impacts, treatment measures and the need for reassessment when the system or its use changes.
  • Resources and data governance: Control personnel, competence, computing infrastructure, tools, data, knowledge and documentation; manage data provenance, quality, representativeness, preparation, usage rights, security and relevant limitations.
  • AI system life-cycle governance: Control requirements, design, development, verification, validation, deployment, operation, monitoring, maintenance, changes and decommissioning; maintain acceptance criteria and evidence proportionate to risk.
  • Transparency, human oversight and third parties: Provide appropriate information to interested parties; define levels of human intervention and oversight; control external providers of models, data, platforms, cloud services and other AI components.
  • Monitoring, incidents and improvement: Monitor post-deployment performance and impacts, collect feedback, record and address incidents, conduct internal audits and management reviews, implement corrective action and continually improve the AIMS.
Benefits of implementing and obtaining ISO/IEC 42001:2023 certification
  • A consistent AI governance framework: Connects leadership, legal, risk, technology, data, safety, security and business functions through clearly assigned responsibilities.
  • Life-cycle risk and impact management: Helps identify and address reliability, fairness, transparency, safety, security, privacy, accountability and societal-impact issues at an early stage.
  • Improved data and system quality: Strengthens controls over data provenance, quality and limitations, design requirements, testing criteria, performance monitoring and change management.
  • Control of third-party AI: Establishes criteria for evaluating suppliers, foundation models, APIs, cloud services and datasets; clarifies responsibilities, required information and monitoring arrangements.
  • Greater compliance readiness: Supports the identification, updating and translation of legal, regulatory, contractual, customer and internal policy requirements into evidenced controls.
  • Greater stakeholder confidence: Provides independent evidence of how the organization governs the development, provision or use of AI within the certified scope.
  • Easier system integration: Can be integrated with ISO/IEC 27001, ISO 9001, ISO/IEC 27701, ISO 31000 and existing data, technology, privacy or compliance governance arrangements.

GIC Vietnam provides independent ISO/IEC 42001:2023 artificial intelligence management system certification services for organizations that develop, provide or use AI-based products and services. The certification audit focuses on alignment among the scope, roles, policy, risks, impact assessments, Statement of Applicability, life-cycle controls, data, suppliers, performance monitoring and improvement arrangements.

ISO/IEC 42001 certification is management system certification, not certification or approval of an individual AI model, algorithm, product or service. It does not automatically demonstrate compliance with every legal requirement or guarantee that AI will be free from errors, bias, inaccurate content, security vulnerabilities, privacy breaches or adverse impacts. The organization remains responsible for assessing conformity, risks, impacts and legal requirements for each AI system in its specific context of use.

This service is suitable for:
  • Organizations developing AI and machine-learning models, generative AI, computer vision, natural-language processing, recommendation systems or automated decision-making systems.
  • Providers of platforms, APIs, data, cloud services, AI-enabled software or customized AI solutions.
  • Organizations deploying or using AI in finance, healthcare, manufacturing, retail, education, human resources, transport, public services and other sectors.
  • Organizations using third-party foundation models or AI tools in internal processes, products, services or customer interactions.
  • Government agencies, research institutes, universities, social organizations and other bodies requiring responsible, transparent and auditable AI governance.
  • Organizations requiring certification to meet legal, contractual, tender, customer, corporate, investor or international supply-chain requirements.
II. CERTIFICATION PROCESS
Step 1
Certification application & application review

1. Certification application & application review

The organization contacts GIC Vietnam for guidance and provides information on the AIMS scope, role in the AI value chain, AI systems/use cases, products and services, sites, personnel, life-cycle stages performed, technologies and models, data sources, cloud infrastructure, suppliers, risks/impacts, legal and contractual requirements, and integrated management systems. GIC Vietnam reviews the application to determine the scope, specialist competence, audit duration, sites and audit conditions, and then agrees on the certification fees and contract.

Step 2
Audit planning & preparation

2. Audit planning & preparation

GIC Vietnam establishes the certification programme, appoints an audit team with competence appropriate to the organization's role, AI technologies, use cases and types of impact within the scope, and prepares a detailed audit plan. The plan defines the objectives, scope, criteria, sites, timing, life-cycle processes and AI systems to be sampled. It is communicated to enable the organization to prepare policies, risk and impact records, the Statement of Applicability, technical documentation, data, supplier records, personnel and necessary access rights.

Step 3
Audit process

3. Audit process

The audit is conducted in two stages:

  • Stage 1: Review the context, roles, scope and AIMS policy; risk and impact assessment methodologies; treatment plans and the Statement of Applicability; document controls, internal audits, management review and readiness for the Stage 2 audit.
  • Stage 2: Evaluate the implementation, conformity and effectiveness of the AIMS at the sites, processes and AI systems covered by the certification scope. Sampling focuses on governance and accountability; risk and impact assessment; data and resources; requirements, design, development, testing, deployment, monitoring, changes and decommissioning; transparency, human oversight, suppliers, feedback, incidents and corrective action. The main activities include: Opening meeting → Interviews and record review → Observation, demonstration and system sampling → Consolidation of findings → Closing meeting.
Step 4
Audit report & nonconformity handling

4. Audit report & nonconformity handling

The audit team prepares a report setting out its conclusions and any nonconformities identified. Where necessary, the organization must immediately control affected systems, outputs, data or processes; take immediate action such as increasing human oversight, restricting use, rolling back a version or suspending operation; assess risks and impacts and notify relevant parties where applicable; analyze root causes and propose and implement corrective actions within the specified timeframe. GIC Vietnam reviews the evidence and may conduct a follow-up audit before certification review.

Step 5
Review & certification

5. Review & certification

A person independent of the audit team reviews the complete file, audit report, corrective-action evidence and conclusions concerning the effectiveness of the AIMS, and makes the certification decision. When the file meets all requirements, GIC Vietnam makes the decision and issues an ISO/IEC 42001:2023 certificate clearly identifying the roles, products/services, activities and sites covered by the scope. The certificate remains valid throughout a three-year certification cycle, provided that the organization maintains conformity and completes the required surveillance audits.

Step 6
Periodic surveillance & recertification

6. Periodic surveillance and recertification

During the certification cycle, GIC Vietnam conducts periodic surveillance audits to confirm that the AIMS continues to be maintained and remains effective. The first surveillance audit is conducted no later than 12 months from the date of the initial certification decision. The organization must notify GIC Vietnam of significant changes to the scope, roles, AI systems/use cases, models, data, technologies, suppliers, sites, legal requirements, ownership, or serious incidents that may affect certification. Before the certificate expires, the organization undergoes a recertification audit for renewal into the next certification cycle.

III. WHY CHOOSE GIC VIETNAM?
International reputation and broad recognition

GIC is a reputable certification body whose services are widely recognized through accreditation marks from leading accreditation bodies such as UKAS (United Kingdom), JASANZ (Australia–New Zealand), CPSC (United States), SAC (Singapore), CNAS (China) and VICAS (Vietnam). Certificates issued by GIC are recognized globally through the mutual recognition arrangements (MRAs) of Global ACI and APAC. This helps organizations reduce technical barriers and gain easier access to international markets.

Professional service & cost effectiveness

GIC Vietnam provides services in accordance with the stringent standards of Europe and North America, ensuring independence, impartiality and professionalism throughout the certification audit process. Alongside high-quality service, GIC offers reasonable and competitive fees, enabling organizations to use their resources efficiently while obtaining certification recognized in accordance with international practices.

CONTACT INFORMATION
 
GIC VIETNAM
🏢 Hanoi: 12F, 14 Lang Ha Building, Giang Vo Ward
Tel: 024 6275 2268 | Hotline: 0984 609 469
Email: tuandm@gicvn.vn
🏢 Ho Chi Minh City: R502, 160 Nam Ky Khoi Nghia
Tel: 028 3930 7936
Chia sẻ:

System Certification

Verification, Validation

  • ESG Reports

    The ESG (Environmental, Social, and Governance) framework helps businesses measure their sustainability impacts, guide long-term risk management strategies, and create positive value for both the community and stakeholders.
  • GHG Inventory Reports

    Building trust - Stepping steadily into integration. Independent verification of greenhouse gas inventory reports enhances the reliability and transparency of emissions data and meets international standards.
  • Product Carbon Footprint (CFP)

    Product Carbon Footprint Verification – A solution to build trust and elevate product value in the global supply chain.
  • CBAM Embedded Emissions

    CBAM embedded emissions verification independently assesses monitoring approaches, activity data, emissions calculations and supporting evidence at installations producing CBAM goods. The process helps businesses improve data reliability, identify misstatements and prepare to meet EU CBAM reporting and verification requirements.
  • Singapore Green Labelling

    Green Label helps identify environmentally friendly products and enhances the company's image.

Product, process certification

  • Product Certification

    Product certification is the process of assessing and confirming that a product meets the technical, quality and safety requirements of the applicable standard. Achieving certification helps demonstrate product reliability, build consumer confidence and strengthen the brand’s competitiveness in the market.
  • Technical Regulation Conformity Certification

    Technical regulation compliance certification is the process of evaluating and verifying that products conform to national technical regulations. Understanding the relevant regulations and certification procedures helps businesses ensure strict legal compliance, guarantee product safety, and successfully introduce their goods into the...
  • Traceability

    Certification of the Traceability System according to the ISO 22005 helps businesses in the food and feed chain ensure transparency in the movement of goods, strictly control food safety risks, and simultaneously meet the stringent requirements of partners, consumers, and international...
  • ISO 3834 Welding Process

    ISO 3834 certification service evaluates a manufacturer’s capability to control metallic-material fusion welding against ISO 3834-2, ISO 3834-3 or ISO 3834-4. The assessment covers personnel, WPS and WPQR/PQR, materials, equipment, inspection, NDT and welding quality records.
  • CE Marking

    Affixing the CE mark is a mandatory requirement for many product groups when placed on the EEA market. This article helps Vietnamese businesses determine the scope of application, manufacturer responsibilities, cases requiring a Notified Body, technical documentation, and the conformity assessment...

Improvement Tools Certification

  • 5S Certification

    5S builds a professional image and fosters a dynamic, creative, and efficient work environment.
  • Lean Manufacturing

    Lean optimizes the production process by eliminating waste and increasing customer value.
  • KPIs

    KPI is a metric to evaluate goal achievement for a business, team, or individual.

Coaching and Training